Hi Broni
I had went to a private repair shop and change a new HDD due to my previous BSOD issue
And so I start to scan with Malware and it had 30 infected file on the same day I got back my laptop from the repair.....
I didnt know why this happen cause it was suppose to be virus clean
Can you help me look at the malwarebyte file and let me know if my laptop is fine???
Thanks for the assistance and I sorry to trouble you again
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 2/5/2016
Scan Time: 9:35 PM
Logfile: Malware.txt
Administrator: Yes
Version: 2.2.1.1043
Malware Database: v2016.05.02.02
Rootkit Database: v2016.04.17.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Administrator
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 334187
Time Elapsed: 14 min, 46 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 7
PUP.Optional.SearchManager, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\pilplloabdedfmialnfchjomjmpjcoej, , [8b8fb41d3564e4528b8900ba7d87f010],
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, , [6dad646dedac0e28c230811f4aba15eb],
PUP.Optional.SearchManager, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\pilplloabdedfmialnfchjomjmpjcoej, , [38e2b71a6039c57131e3eeccf1136e92],
PUP.Optional.InstallCore, HKU\S-1-5-21-2359293270-3508907655-1651583001-500\SOFTWARE\csastats, , [8a90fcd58c0dad89a55fbbffdf2522de],
PUP.Optional.SearchManager, HKU\S-1-5-21-2359293270-3508907655-1651583001-500\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\pilplloabdedfmialnfchjomjmpjcoej, , [2cee09c814852610f03560e15fa43ec2],
PUP.Optional.WinYahoo, HKU\S-1-5-21-2359293270-3508907655-1651583001-500\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, , [22f8656cebae45f107eaefb160a4758b],
PUP.Optional.ProductSetup, HKU\S-1-5-21-2359293270-3508907655-1651583001-500\SOFTWARE\PRODUCTSETUP, , [21f9e1f070290234334679d3679de51b],
Registry Values: 5
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, https://sg.search.yahoo.com/yhs/sea...ed_003&type=wbf_fydfs_16_18¶m1=1¶m2=f[6dad646dedac0e28c230811f4aba15eb]D4%26b[6dad646dedac0e28c230811f4aba15eb]DIE%26cc[6dad646dedac0e28c230811f4aba15eb]Dsg%26pa[6dad646dedac0e28c230811f4aba15eb]DWincy%26cd[6dad646dedac0e28c230811f4aba15eb]D2XzuyEtN2Y1L1Qzu0EyEtCtCyD0ByEtC0AyEyByEyE0E0FtBtN0D0Tzu0StCyDzztAtN1L2XzutAtFtBtCtFtCtFtCtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0CyCtDtCyDtCtDtGyCtDtCyEtG0DyB0FtDtGyC0B0AyBtGtAzyyBtAyEtAzzzztAtCyEyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0B0ByCtBtB0C0FtGtAtC0DtCtGyEyCyBzztGzzyE0C0EtG0CyByE0FyDyDzy0AyBtB0BtB2QtN0A0LzuyE%26cr[6dad646dedac0e28c230811f4aba15eb]D1225445295%26a[6dad646dedac0e28c230811f4aba15eb]Dwbf_fydfs_16_18%26os_ver[6dad646dedac0e28c230811f4aba15eb]D6.1%26os[6dad646dedac0e28c230811f4aba15eb]DWindowsB7BHomeBPremium&p={searchTerms}, %4, %5
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|TopResultURLFallback, https://sg.search.yahoo.com/yhs/sea...ed_003&type=wbf_fydfs_16_18¶m1=1¶m2=f[ff1b8a47079237ff549ea000689c0af6]D4%26b[ff1b8a47079237ff549ea000689c0af6]DIE%26cc[ff1b8a47079237ff549ea000689c0af6]Dsg%26pa[ff1b8a47079237ff549ea000689c0af6]DWincy%26cd[ff1b8a47079237ff549ea000689c0af6]D2XzuyEtN2Y1L1Qzu0EyEtCtCyD0ByEtC0AyEyByEyE0E0FtBtN0D0Tzu0StCyDzztAtN1L2XzutAtFtBtCtFtCtFtCtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0CyCtDtCyDtCtDtGyCtDtCyEtG0DyB0FtDtGyC0B0AyBtGtAzyyBtAyEtAzzzztAtCyEyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0B0ByCtBtB0C0FtGtAtC0DtCtGyEyCyBzztGzzyE0C0EtG0CyByE0FyDyDzy0AyBtB0BtB2QtN0A0LzuyE%26cr[ff1b8a47079237ff549ea000689c0af6]D1225445295%26a[ff1b8a47079237ff549ea000689c0af6]Dwbf_fydfs_16_18%26os_ver[ff1b8a47079237ff549ea000689c0af6]D6.1%26os[ff1b8a47079237ff549ea000689c0af6]DWindowsB7BHomeBPremium&p={searchTerms}, %4, %5
PUP.Optional.WinYahoo, HKU\S-1-5-21-2359293270-3508907655-1651583001-500\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, https://sg.search.yahoo.com/yhs/sea...ed_003&type=wbf_fydfs_16_18¶m1=1¶m2=f[22f8656cebae45f107eaefb160a4758b]D4%26b[22f8656cebae45f107eaefb160a4758b]DIE%26cc[22f8656cebae45f107eaefb160a4758b]Dsg%26pa[22f8656cebae45f107eaefb160a4758b]DWincy%26cd[22f8656cebae45f107eaefb160a4758b]D2XzuyEtN2Y1L1Qzu0EyEtCtCyD0ByEtC0AyEyByEyE0E0FtBtN0D0Tzu0StCyDzztAtN1L2XzutAtFtBtCtFtCtFtCtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0CyCtDtCyDtCtDtGyCtDtCyEtG0DyB0FtDtGyC0B0AyBtGtAzyyBtAyEtAzzzztAtCyEyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0B0ByCtBtB0C0FtGtAtC0DtCtGyEyCyBzztGzzyE0C0EtG0CyByE0FyDyDzy0AyBtB0BtB2QtN0A0LzuyE%26cr[22f8656cebae45f107eaefb160a4758b]D1225445295%26a[22f8656cebae45f107eaefb160a4758b]Dwbf_fydfs_16_18%26os_ver[22f8656cebae45f107eaefb160a4758b]D6.1%26os[22f8656cebae45f107eaefb160a4758b]DWindowsB7BHomeBPremium&p={searchTerms}, %4, %5
PUP.Optional.WinYahoo, HKU\S-1-5-21-2359293270-3508907655-1651583001-500\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|TopResultURLFallback, https://sg.search.yahoo.com/yhs/sea...ed_003&type=wbf_fydfs_16_18¶m1=1¶m2=f[8c8e25acecade25437ba8917b450fe02]D4%26b[8c8e25acecade25437ba8917b450fe02]DIE%26cc[8c8e25acecade25437ba8917b450fe02]Dsg%26pa[8c8e25acecade25437ba8917b450fe02]DWincy%26cd[8c8e25acecade25437ba8917b450fe02]D2XzuyEtN2Y1L1Qzu0EyEtCtCyD0ByEtC0AyEyByEyE0E0FtBtN0D0Tzu0StCyDzztAtN1L2XzutAtFtBtCtFtCtFtCtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0CyCtDtCyDtCtDtGyCtDtCyEtG0DyB0FtDtGyC0B0AyBtGtAzyyBtAyEtAzzzztAtCyEyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0B0ByCtBtB0C0FtGtAtC0DtCtGyEyCyBzztGzzyE0C0EtG0CyByE0FyDyDzy0AyBtB0BtB2QtN0A0LzuyE%26cr[8c8e25acecade25437ba8917b450fe02]D1225445295%26a[8c8e25acecade25437ba8917b450fe02]Dwbf_fydfs_16_18%26os_ver[8c8e25acecade25437ba8917b450fe02]D6.1%26os[8c8e25acecade25437ba8917b450fe02]DWindowsB7BHomeBPremium&p={searchTerms}, %4, %5
PUP.Optional.ProductSetup, HKU\S-1-5-21-2359293270-3508907655-1651583001-500\SOFTWARE\PRODUCTSETUP|tb, 0G2O2W1R0C1R1H, , [21f9e1f070290234334679d3679de51b]
Registry Data: 3
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, https://sg.search.yahoo.com/yhs/web...003&type=wbf_fydfs_16_18¶m1=1¶m2=fBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[39e1923f04953204344b11402adb4db3]D1%26bBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[39e1923f04953204344b11402adb4db3]DIE%26ccBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[39e1923f04953204344b11402adb4db3]Dsg%26paBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[39e1923f04953204344b11402adb4db3]DWincy%26cdBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[39e1923f04953204344b11402adb4db3]D2XzuyEtN2Y1L1Qzu0EyEtCtCyD0ByEtC0AyEyByEyE0E0FtBtN0D0Tzu0StCyDzztAtN1L2XzutAtFtBtCtFtCtFtCtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0CyCtDtCyDtCtDtGyCtDtCyEtG0DyB0FtDtGyC0B0AyBtGtAzyyBtAyEtAzzzztAtCyEyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0B0ByCtBtB0C0FtGtAtC0DtCtGyEyCyBzztGzzyE0C0EtG0CyByE0FyDyDzy0AyBtB0BtB2QtN0A0LzuyE%26crBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[39e1923f04953204344b11402adb4db3]D1225445295%26aBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[39e1923f04953204344b11402adb4db3]Dwbf_fydfs_16_18%26os_verBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[39e1923f04953204344b11402adb4db3]D6.1%26osBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[39e1923f04953204344b11402adb4db3]DWindowsGood: (www.google.com)B7Good: (www.google.com)BHomeGood: (www.google.com)BPremium, %4, %5
PUP.Optional.WinYahoo, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, https://sg.search.yahoo.com/yhs/web...003&type=wbf_fydfs_16_18¶m1=1¶m2=fBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[21f90fc2fa9f43f3f08fc889cd38c43c]D1%26bBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[21f90fc2fa9f43f3f08fc889cd38c43c]DIE%26ccBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[21f90fc2fa9f43f3f08fc889cd38c43c]Dsg%26paBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[21f90fc2fa9f43f3f08fc889cd38c43c]DWincy%26cdBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[21f90fc2fa9f43f3f08fc889cd38c43c]D2XzuyEtN2Y1L1Qzu0EyEtCtCyD0ByEtC0AyEyByEyE0E0FtBtN0D0Tzu0StCyDzztAtN1L2XzutAtFtBtCtFtCtFtCtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0CyCtDtCyDtCtDtGyCtDtCyEtG0DyB0FtDtGyC0B0AyBtGtAzyyBtAyEtAzzzztAtCyEyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0B0ByCtBtB0C0FtGtAtC0DtCtGyEyCyBzztGzzyE0C0EtG0CyByE0FyDyDzy0AyBtB0BtB2QtN0A0LzuyE%26crBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[21f90fc2fa9f43f3f08fc889cd38c43c]D1225445295%26aBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[21f90fc2fa9f43f3f08fc889cd38c43c]Dwbf_fydfs_16_18%26os_verBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[21f90fc2fa9f43f3f08fc889cd38c43c]D6.1%26osBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[21f90fc2fa9f43f3f08fc889cd38c43c]DWindowsGood: (www.google.com)B7Good: (www.google.com)BHomeGood: (www.google.com)BPremium, %4, %5
PUP.Optional.WinYahoo, HKU\S-1-5-21-2359293270-3508907655-1651583001-500\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, https://sg.search.yahoo.com/yhs/web...003&type=wbf_fydfs_16_18¶m1=1¶m2=fBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[65b5626fdabf70c64637b79ad92cd42c]D1%26bBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[65b5626fdabf70c64637b79ad92cd42c]DIE%26ccBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[65b5626fdabf70c64637b79ad92cd42c]Dsg%26paBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[65b5626fdabf70c64637b79ad92cd42c]DWincy%26cdBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[65b5626fdabf70c64637b79ad92cd42c]D2XzuyEtN2Y1L1Qzu0EyEtCtCyD0ByEtC0AyEyByEyE0E0FtBtN0D0Tzu0StCyDzztAtN1L2XzutAtFtBtCtFtCtFtCtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0CyCtDtCyDtCtDtGyCtDtCyEtG0DyB0FtDtGyC0B0AyBtGtAzyyBtAyEtAzzzztAtCyEyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0B0ByCtBtB0C0FtGtAtC0DtCtGyEyCyBzztGzzyE0C0EtG0CyByE0FyDyDzy0AyBtB0BtB2QtN0A0LzuyE%26crBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[65b5626fdabf70c64637b79ad92cd42c]D1225445295%26aBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[65b5626fdabf70c64637b79ad92cd42c]Dwbf_fydfs_16_18%26os_verBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[65b5626fdabf70c64637b79ad92cd42c]D6.1%26osBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[65b5626fdabf70c64637b79ad92cd42c]DWindowsGood: (www.google.com)B7Good: (www.google.com)BHomeGood: (www.google.com)BPremium, %4, %5
Folders: 0
(No malicious items detected)
Files: 15
PUP.Optional.Babylon, C:\$Recycle.Bin\S-1-5-21-2359293270-3508907655-1651583001-500\$RG6PW2U.exe, , [071379587623fa3ca0cb0a45728fdc24],
PUP.Optional.Babylon, C:\Users\Administrator\AppData\Local\Temp\HAuT24vp.exe.part, , [71a92da46633ef4783e8262959a825db],
PUP.Optional.Somoto, C:\Users\Administrator\AppData\Local\Temp\nsj64FF.tmp, , [a872f0e19aff2214ae6a30d4fe04db25],
PUP.Optional.Babylon, C:\Users\Administrator\AppData\Local\Temp\DeltaTB.exe, , [0f0b3e93851445f14e1d69e6ad54ba46],
PUP.Optional.AdOffer, C:\Users\Administrator\AppData\Local\Temp\bitool.dll, , [2ceeefe29dfc2511b40e6125e51d6799],
PUP.Optional.OpenCandy, C:\Users\Administrator\AppData\Local\Temp\DAEMON Tools Lite.exe, , [f62418b90297df57b069d491d72e817f],
PUP.Optional.Babylon, C:\Users\Administrator\AppData\Local\Temp\B7AA180F-BAB0-7891-9B32-DA750244C2DB\Latest\BExternal.dll, , [34e6c50cfe9b162029fa32f9946cb050],
PUP.Optional.PriceFountain, C:\Users\Administrator\AppData\Local\Temp\ns6556E8A9\3E87B20F_stp\PFGRP.dll, , [d941904102976ec8eb74250028da1de3],
PUP.Optional.WinYahoo, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HowToRemove.html.lnk, , [0f0bd100c8d1f1451977712e5aaab749],
PUP.Optional.BundleInstaller, C:\Users\Administrator\AppData\Local\Temp\binsis142.xml, , [fd1dc30e7d1c68cefb54dcdde61e6b95],
PUP.Optional.BundleInstaller, C:\Users\Administrator\AppData\Local\Temp\binsischeck654.xml, , [c85202cfc4d50c2a420e2297739157a9],
PUP.Optional.SearchManager, C:\Users\Administrator\AppData\Local\Chromium\User Data\Default\Local Storage\chrome-extension_pilplloabdedfmialnfchjomjmpjcoej_0.localstorage, , [45d55f72b0e90a2c0e04398112f25ba5],
PUP.Optional.SearchManager, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pilplloabdedfmialnfchjomjmpjcoej_0.localstorage, , [76a45d7437623afc6ca7bffb05ff02fe],
PUP.Optional.WinYahoo, C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\m2jozxe3.default\prefs.js, Good: (user_pref("browser.startup.homepage", "https://www.malwarebytes.org/restorebrowser/), Bad: (user_pref("browser.startup.homepage", "https://sg.search.yahoo.com/yhs/web...45295&a=wbf_fydfs_16_18&os_ver=6.1&os=Windows,[61b9725f8316979f1359027dfd08cc34]B7,[61b9725f8316979f1359027dfd08cc34]BHome,[61b9725f8316979f1359027dfd08cc34]BPremium")
, %5
PUP.Optional.WinYahoo, C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\m2jozxe3.default\searchplugins\Search Provided by Yahoo.xml, , [52c8bf121b7e50e65e18304c9e67b947],
Physical Sectors: 0
(No malicious items detected)
(end)
I had went to a private repair shop and change a new HDD due to my previous BSOD issue
And so I start to scan with Malware and it had 30 infected file on the same day I got back my laptop from the repair.....
I didnt know why this happen cause it was suppose to be virus clean
Can you help me look at the malwarebyte file and let me know if my laptop is fine???
Thanks for the assistance and I sorry to trouble you again
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 2/5/2016
Scan Time: 9:35 PM
Logfile: Malware.txt
Administrator: Yes
Version: 2.2.1.1043
Malware Database: v2016.05.02.02
Rootkit Database: v2016.04.17.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Administrator
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 334187
Time Elapsed: 14 min, 46 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 7
PUP.Optional.SearchManager, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\pilplloabdedfmialnfchjomjmpjcoej, , [8b8fb41d3564e4528b8900ba7d87f010],
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, , [6dad646dedac0e28c230811f4aba15eb],
PUP.Optional.SearchManager, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\pilplloabdedfmialnfchjomjmpjcoej, , [38e2b71a6039c57131e3eeccf1136e92],
PUP.Optional.InstallCore, HKU\S-1-5-21-2359293270-3508907655-1651583001-500\SOFTWARE\csastats, , [8a90fcd58c0dad89a55fbbffdf2522de],
PUP.Optional.SearchManager, HKU\S-1-5-21-2359293270-3508907655-1651583001-500\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\pilplloabdedfmialnfchjomjmpjcoej, , [2cee09c814852610f03560e15fa43ec2],
PUP.Optional.WinYahoo, HKU\S-1-5-21-2359293270-3508907655-1651583001-500\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, , [22f8656cebae45f107eaefb160a4758b],
PUP.Optional.ProductSetup, HKU\S-1-5-21-2359293270-3508907655-1651583001-500\SOFTWARE\PRODUCTSETUP, , [21f9e1f070290234334679d3679de51b],
Registry Values: 5
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, https://sg.search.yahoo.com/yhs/sea...ed_003&type=wbf_fydfs_16_18¶m1=1¶m2=f[6dad646dedac0e28c230811f4aba15eb]D4%26b[6dad646dedac0e28c230811f4aba15eb]DIE%26cc[6dad646dedac0e28c230811f4aba15eb]Dsg%26pa[6dad646dedac0e28c230811f4aba15eb]DWincy%26cd[6dad646dedac0e28c230811f4aba15eb]D2XzuyEtN2Y1L1Qzu0EyEtCtCyD0ByEtC0AyEyByEyE0E0FtBtN0D0Tzu0StCyDzztAtN1L2XzutAtFtBtCtFtCtFtCtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0CyCtDtCyDtCtDtGyCtDtCyEtG0DyB0FtDtGyC0B0AyBtGtAzyyBtAyEtAzzzztAtCyEyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0B0ByCtBtB0C0FtGtAtC0DtCtGyEyCyBzztGzzyE0C0EtG0CyByE0FyDyDzy0AyBtB0BtB2QtN0A0LzuyE%26cr[6dad646dedac0e28c230811f4aba15eb]D1225445295%26a[6dad646dedac0e28c230811f4aba15eb]Dwbf_fydfs_16_18%26os_ver[6dad646dedac0e28c230811f4aba15eb]D6.1%26os[6dad646dedac0e28c230811f4aba15eb]DWindowsB7BHomeBPremium&p={searchTerms}, %4, %5
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|TopResultURLFallback, https://sg.search.yahoo.com/yhs/sea...ed_003&type=wbf_fydfs_16_18¶m1=1¶m2=f[ff1b8a47079237ff549ea000689c0af6]D4%26b[ff1b8a47079237ff549ea000689c0af6]DIE%26cc[ff1b8a47079237ff549ea000689c0af6]Dsg%26pa[ff1b8a47079237ff549ea000689c0af6]DWincy%26cd[ff1b8a47079237ff549ea000689c0af6]D2XzuyEtN2Y1L1Qzu0EyEtCtCyD0ByEtC0AyEyByEyE0E0FtBtN0D0Tzu0StCyDzztAtN1L2XzutAtFtBtCtFtCtFtCtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0CyCtDtCyDtCtDtGyCtDtCyEtG0DyB0FtDtGyC0B0AyBtGtAzyyBtAyEtAzzzztAtCyEyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0B0ByCtBtB0C0FtGtAtC0DtCtGyEyCyBzztGzzyE0C0EtG0CyByE0FyDyDzy0AyBtB0BtB2QtN0A0LzuyE%26cr[ff1b8a47079237ff549ea000689c0af6]D1225445295%26a[ff1b8a47079237ff549ea000689c0af6]Dwbf_fydfs_16_18%26os_ver[ff1b8a47079237ff549ea000689c0af6]D6.1%26os[ff1b8a47079237ff549ea000689c0af6]DWindowsB7BHomeBPremium&p={searchTerms}, %4, %5
PUP.Optional.WinYahoo, HKU\S-1-5-21-2359293270-3508907655-1651583001-500\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, https://sg.search.yahoo.com/yhs/sea...ed_003&type=wbf_fydfs_16_18¶m1=1¶m2=f[22f8656cebae45f107eaefb160a4758b]D4%26b[22f8656cebae45f107eaefb160a4758b]DIE%26cc[22f8656cebae45f107eaefb160a4758b]Dsg%26pa[22f8656cebae45f107eaefb160a4758b]DWincy%26cd[22f8656cebae45f107eaefb160a4758b]D2XzuyEtN2Y1L1Qzu0EyEtCtCyD0ByEtC0AyEyByEyE0E0FtBtN0D0Tzu0StCyDzztAtN1L2XzutAtFtBtCtFtCtFtCtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0CyCtDtCyDtCtDtGyCtDtCyEtG0DyB0FtDtGyC0B0AyBtGtAzyyBtAyEtAzzzztAtCyEyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0B0ByCtBtB0C0FtGtAtC0DtCtGyEyCyBzztGzzyE0C0EtG0CyByE0FyDyDzy0AyBtB0BtB2QtN0A0LzuyE%26cr[22f8656cebae45f107eaefb160a4758b]D1225445295%26a[22f8656cebae45f107eaefb160a4758b]Dwbf_fydfs_16_18%26os_ver[22f8656cebae45f107eaefb160a4758b]D6.1%26os[22f8656cebae45f107eaefb160a4758b]DWindowsB7BHomeBPremium&p={searchTerms}, %4, %5
PUP.Optional.WinYahoo, HKU\S-1-5-21-2359293270-3508907655-1651583001-500\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|TopResultURLFallback, https://sg.search.yahoo.com/yhs/sea...ed_003&type=wbf_fydfs_16_18¶m1=1¶m2=f[8c8e25acecade25437ba8917b450fe02]D4%26b[8c8e25acecade25437ba8917b450fe02]DIE%26cc[8c8e25acecade25437ba8917b450fe02]Dsg%26pa[8c8e25acecade25437ba8917b450fe02]DWincy%26cd[8c8e25acecade25437ba8917b450fe02]D2XzuyEtN2Y1L1Qzu0EyEtCtCyD0ByEtC0AyEyByEyE0E0FtBtN0D0Tzu0StCyDzztAtN1L2XzutAtFtBtCtFtCtFtCtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0CyCtDtCyDtCtDtGyCtDtCyEtG0DyB0FtDtGyC0B0AyBtGtAzyyBtAyEtAzzzztAtCyEyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0B0ByCtBtB0C0FtGtAtC0DtCtGyEyCyBzztGzzyE0C0EtG0CyByE0FyDyDzy0AyBtB0BtB2QtN0A0LzuyE%26cr[8c8e25acecade25437ba8917b450fe02]D1225445295%26a[8c8e25acecade25437ba8917b450fe02]Dwbf_fydfs_16_18%26os_ver[8c8e25acecade25437ba8917b450fe02]D6.1%26os[8c8e25acecade25437ba8917b450fe02]DWindowsB7BHomeBPremium&p={searchTerms}, %4, %5
PUP.Optional.ProductSetup, HKU\S-1-5-21-2359293270-3508907655-1651583001-500\SOFTWARE\PRODUCTSETUP|tb, 0G2O2W1R0C1R1H, , [21f9e1f070290234334679d3679de51b]
Registry Data: 3
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, https://sg.search.yahoo.com/yhs/web...003&type=wbf_fydfs_16_18¶m1=1¶m2=fBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[39e1923f04953204344b11402adb4db3]D1%26bBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[39e1923f04953204344b11402adb4db3]DIE%26ccBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[39e1923f04953204344b11402adb4db3]Dsg%26paBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[39e1923f04953204344b11402adb4db3]DWincy%26cdBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[39e1923f04953204344b11402adb4db3]D2XzuyEtN2Y1L1Qzu0EyEtCtCyD0ByEtC0AyEyByEyE0E0FtBtN0D0Tzu0StCyDzztAtN1L2XzutAtFtBtCtFtCtFtCtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0CyCtDtCyDtCtDtGyCtDtCyEtG0DyB0FtDtGyC0B0AyBtGtAzyyBtAyEtAzzzztAtCyEyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0B0ByCtBtB0C0FtGtAtC0DtCtGyEyCyBzztGzzyE0C0EtG0CyByE0FyDyDzy0AyBtB0BtB2QtN0A0LzuyE%26crBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[39e1923f04953204344b11402adb4db3]D1225445295%26aBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[39e1923f04953204344b11402adb4db3]Dwbf_fydfs_16_18%26os_verBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[39e1923f04953204344b11402adb4db3]D6.1%26osBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[39e1923f04953204344b11402adb4db3]DWindowsGood: (www.google.com)B7Good: (www.google.com)BHomeGood: (www.google.com)BPremium, %4, %5
PUP.Optional.WinYahoo, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, https://sg.search.yahoo.com/yhs/web...003&type=wbf_fydfs_16_18¶m1=1¶m2=fBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[21f90fc2fa9f43f3f08fc889cd38c43c]D1%26bBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[21f90fc2fa9f43f3f08fc889cd38c43c]DIE%26ccBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[21f90fc2fa9f43f3f08fc889cd38c43c]Dsg%26paBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[21f90fc2fa9f43f3f08fc889cd38c43c]DWincy%26cdBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[21f90fc2fa9f43f3f08fc889cd38c43c]D2XzuyEtN2Y1L1Qzu0EyEtCtCyD0ByEtC0AyEyByEyE0E0FtBtN0D0Tzu0StCyDzztAtN1L2XzutAtFtBtCtFtCtFtCtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0CyCtDtCyDtCtDtGyCtDtCyEtG0DyB0FtDtGyC0B0AyBtGtAzyyBtAyEtAzzzztAtCyEyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0B0ByCtBtB0C0FtGtAtC0DtCtGyEyCyBzztGzzyE0C0EtG0CyByE0FyDyDzy0AyBtB0BtB2QtN0A0LzuyE%26crBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[21f90fc2fa9f43f3f08fc889cd38c43c]D1225445295%26aBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[21f90fc2fa9f43f3f08fc889cd38c43c]Dwbf_fydfs_16_18%26os_verBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[21f90fc2fa9f43f3f08fc889cd38c43c]D6.1%26osBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[21f90fc2fa9f43f3f08fc889cd38c43c]DWindowsGood: (www.google.com)B7Good: (www.google.com)BHomeGood: (www.google.com)BPremium, %4, %5
PUP.Optional.WinYahoo, HKU\S-1-5-21-2359293270-3508907655-1651583001-500\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, https://sg.search.yahoo.com/yhs/web...003&type=wbf_fydfs_16_18¶m1=1¶m2=fBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[65b5626fdabf70c64637b79ad92cd42c]D1%26bBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[65b5626fdabf70c64637b79ad92cd42c]DIE%26ccBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[65b5626fdabf70c64637b79ad92cd42c]Dsg%26paBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[65b5626fdabf70c64637b79ad92cd42c]DWincy%26cdBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[65b5626fdabf70c64637b79ad92cd42c]D2XzuyEtN2Y1L1Qzu0EyEtCtCyD0ByEtC0AyEyByEyE0E0FtBtN0D0Tzu0StCyDzztAtN1L2XzutAtFtBtCtFtCtFtCtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0CyCtDtCyDtCtDtGyCtDtCyEtG0DyB0FtDtGyC0B0AyBtGtAzyyBtAyEtAzzzztAtCyEyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0B0ByCtBtB0C0FtGtAtC0DtCtGyEyCyBzztGzzyE0C0EtG0CyByE0FyDyDzy0AyBtB0BtB2QtN0A0LzuyE%26crBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[65b5626fdabf70c64637b79ad92cd42c]D1225445295%26aBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[65b5626fdabf70c64637b79ad92cd42c]Dwbf_fydfs_16_18%26os_verBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[65b5626fdabf70c64637b79ad92cd42c]D6.1%26osBad: (https://sg.search.yahoo.com/yhs/web...fs_16_18&os_ver=6.1&os=Windows+7+Home+Premium),,[65b5626fdabf70c64637b79ad92cd42c]DWindowsGood: (www.google.com)B7Good: (www.google.com)BHomeGood: (www.google.com)BPremium, %4, %5
Folders: 0
(No malicious items detected)
Files: 15
PUP.Optional.Babylon, C:\$Recycle.Bin\S-1-5-21-2359293270-3508907655-1651583001-500\$RG6PW2U.exe, , [071379587623fa3ca0cb0a45728fdc24],
PUP.Optional.Babylon, C:\Users\Administrator\AppData\Local\Temp\HAuT24vp.exe.part, , [71a92da46633ef4783e8262959a825db],
PUP.Optional.Somoto, C:\Users\Administrator\AppData\Local\Temp\nsj64FF.tmp, , [a872f0e19aff2214ae6a30d4fe04db25],
PUP.Optional.Babylon, C:\Users\Administrator\AppData\Local\Temp\DeltaTB.exe, , [0f0b3e93851445f14e1d69e6ad54ba46],
PUP.Optional.AdOffer, C:\Users\Administrator\AppData\Local\Temp\bitool.dll, , [2ceeefe29dfc2511b40e6125e51d6799],
PUP.Optional.OpenCandy, C:\Users\Administrator\AppData\Local\Temp\DAEMON Tools Lite.exe, , [f62418b90297df57b069d491d72e817f],
PUP.Optional.Babylon, C:\Users\Administrator\AppData\Local\Temp\B7AA180F-BAB0-7891-9B32-DA750244C2DB\Latest\BExternal.dll, , [34e6c50cfe9b162029fa32f9946cb050],
PUP.Optional.PriceFountain, C:\Users\Administrator\AppData\Local\Temp\ns6556E8A9\3E87B20F_stp\PFGRP.dll, , [d941904102976ec8eb74250028da1de3],
PUP.Optional.WinYahoo, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HowToRemove.html.lnk, , [0f0bd100c8d1f1451977712e5aaab749],
PUP.Optional.BundleInstaller, C:\Users\Administrator\AppData\Local\Temp\binsis142.xml, , [fd1dc30e7d1c68cefb54dcdde61e6b95],
PUP.Optional.BundleInstaller, C:\Users\Administrator\AppData\Local\Temp\binsischeck654.xml, , [c85202cfc4d50c2a420e2297739157a9],
PUP.Optional.SearchManager, C:\Users\Administrator\AppData\Local\Chromium\User Data\Default\Local Storage\chrome-extension_pilplloabdedfmialnfchjomjmpjcoej_0.localstorage, , [45d55f72b0e90a2c0e04398112f25ba5],
PUP.Optional.SearchManager, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pilplloabdedfmialnfchjomjmpjcoej_0.localstorage, , [76a45d7437623afc6ca7bffb05ff02fe],
PUP.Optional.WinYahoo, C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\m2jozxe3.default\prefs.js, Good: (user_pref("browser.startup.homepage", "https://www.malwarebytes.org/restorebrowser/), Bad: (user_pref("browser.startup.homepage", "https://sg.search.yahoo.com/yhs/web...45295&a=wbf_fydfs_16_18&os_ver=6.1&os=Windows,[61b9725f8316979f1359027dfd08cc34]B7,[61b9725f8316979f1359027dfd08cc34]BHome,[61b9725f8316979f1359027dfd08cc34]BPremium")
PUP.Optional.WinYahoo, C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\m2jozxe3.default\searchplugins\Search Provided by Yahoo.xml, , [52c8bf121b7e50e65e18304c9e67b947],
Physical Sectors: 0
(No malicious items detected)
(end)