malsaurus
Posts: 35 +0
Malwarebytes
www.malwarebytes.com
-Log Details-
Scan Date: 11/11/18
Scan Time: 9:28 AM
Log File: 21881070-e551-11e8-9944-342387de9750.json
-Software Information-
Version: 3.6.1.2711
Components Version: 1.0.482
Update Package Version: 1.0.7789
License: Trial
-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: TomDell\Tom
-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 311889
Threats Detected: 133
Threats Quarantined: 133
Time Elapsed: 37 min, 43 sec
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect
-Scan Details-
Process: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registry Key: 16
PUP.Optional.Yontoo, HKLM\SOFTWARE\POLICIES\GOOGLE\CHROME, Quarantined, [33], [-1],0.0.0
PUP.Optional.Yontoo, HKLM\SOFTWARE\WOW6432NODE\POLICIES\GOOGLE\CHROME, Quarantined, [33], [-1],0.0.0
PUP.Optional.BDYahoo, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{295E555F-A5F0-42ED-917A-617F365F50E9}, Quarantined, [6826], [235700],1.0.7789
PUP.Optional.BDYahoo, HKU\S-1-5-21-252852572-1064671646-1800406956-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{295E555F-A5F0-42ED-917A-617F365F50E9}, Quarantined, [6826], [235700],1.0.7789
PUP.Optional.Yontoo, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\OldSearch, Quarantined, [33], [246105],1.0.7789
PUP.Optional.Bandoo.AppFlsh, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2000}, Quarantined, [3], [253586],1.0.7789
PUP.Optional.Bandoo.AppFlsh, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2001}, Quarantined, [3], [253586],1.0.7789
PUP.Optional.Yontoo, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{a62abdee-78a2-4ddb-9355-1c334abd6e43}, Quarantined, [33], [246105],1.0.7789
PUP.Optional.iMeshMusicBoxTB, HKU\S-1-5-21-252852572-1064671646-1800406956-1001_Classes\iMeshIEHelper.DNSGuard.1, Quarantined, [6383], [239379],1.0.7789
PUP.Optional.iMeshMusicBoxTB, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{474597C5-AB09-49D6-A4D5-2E8D7341384E}, Quarantined, [6383], [239379],1.0.7789
PUP.Optional.iMeshMusicBoxTB, HKU\S-1-5-21-252852572-1064671646-1800406956-1001_Classes\iMeshIEHelper.DNSGuard, Quarantined, [6383], [239379],1.0.7789
PUP.Optional.ResultsHub, HKLM\SOFTWARE\WOW6432NODE\RESULTSHUB, Quarantined, [6], [242324],1.0.7789
PUP.Optional.RocketFind, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}, Quarantined, [323], [242376],1.0.7789
PUP.Optional.RocketFind, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}, Quarantined, [323], [242376],1.0.7789
PUP.Optional.Yontoo, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{F83D1872-D9FF-47F8-B5A0-49CC51E24EE8}, Quarantined, [33], [160141],1.0.7789
PUP.Optional.Yontoo, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{F83D1872-D9FF-47F8-B5A0-49CC51E24EE8}, Quarantined, [33], [160141],1.0.7789
Registry Value: 22
PUP.Optional.Yontoo, HKU\S-1-5-21-252852572-1064671646-1800406956-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DONOTASKAGAIN, Quarantined, [33], [246380],1.0.7789
PUP.Optional.BDYahoo, HKU\S-1-5-21-252852572-1064671646-1800406956-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{295E555F-A5F0-42ED-917A-617F365F50E9}|URL, Quarantined, [6826], [235700],1.0.7789
PUP.Optional.Yontoo, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\OldSearch|URL, Quarantined, [33], [246105],1.0.7789
PUP.Optional.Bandoo.AppFlsh, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2000}|URL, Quarantined, [3], [253586],1.0.7789
PUP.Optional.Bandoo.AppFlsh, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, Quarantined, [3], [-1],0.0.0
PUP.Optional.Bandoo.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, Quarantined, [3], [-1],0.0.0
PUP.Optional.ASK, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2000}|SUGGESTIONSURL_JSON, Quarantined, [2], [258454],1.0.7789
PUP.Optional.Bandoo.AppFlsh, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2001}|URL, Quarantined, [3], [253586],1.0.7789
PUP.Optional.ASK, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2001}|SUGGESTIONSURL_JSON, Quarantined, [2], [258454],1.0.7789
PUP.Optional.ASK, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2001}|DEFAULTSUGGESTIONURL, Quarantined, [2], [258454],1.0.7789
PUP.Optional.Yontoo, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{a62abdee-78a2-4ddb-9355-1c334abd6e43}|URL, Quarantined, [33], [246105],1.0.7789
PUP.Optional.ResultsHub, HKLM\SOFTWARE\WOW6432NODE\RESULTSHUB|CG, Quarantined, [6], [242324],1.0.7789
PUP.Optional.Yontoo, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DONOTASKAGAIN, Quarantined, [33], [246380],1.0.7789
PUP.Optional.BDYahoo, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{295E555F-A5F0-42ED-917A-617F365F50E9}|URL, Quarantined, [6826], [235700],1.0.7789
PUP.Optional.RocketFind, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}|URL, Quarantined, [323], [242376],1.0.7789
PUP.Optional.RocketFind, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}|TOPRESULTURLFALLBACK, Quarantined, [323], [242376],1.0.7789
PUP.Optional.RocketFind, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}|URL, Quarantined, [323], [242376],1.0.7789
PUP.Optional.RocketFind, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}|TOPRESULTURLFALLBACK, Quarantined, [323], [242376],1.0.7789
PUP.Optional.Bandoo.AppFlsh, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2000}|FAVICONPATH, Quarantined, [3], [253584],1.0.7789
PUP.Optional.Bandoo.AppFlsh, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2001}|FAVICONPATH, Quarantined, [3], [253584],1.0.7789
PUP.Optional.NotChromeRun, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|GOOGLECHROMEAUTOLAUNCH_5189939A0645355218FFECE1F1491836, Quarantined, [6894], [241243],1.0.7789
PUP.Optional.Yontoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DONOTASKAGAIN, Quarantined, [33], [246561],1.0.7789
Registry Data: 0
(No malicious items detected)
Data Stream: 0
(No malicious items detected)
Folder: 8
PUP.Optional.OpenCandy, C:\Users\jl\AppData\Roaming\OpenCandy\39B986BD64224300A6EFF93BCDD8F515, Quarantined, [1081], [173202],1.0.7789
PUP.Optional.OpenCandy, C:\Users\jl\AppData\Roaming\OpenCandy\426D7886489D440F8CEFD27306A248F6, Quarantined, [1081], [173202],1.0.7789
PUP.Optional.OpenCandy, C:\USERS\JL\APPDATA\ROAMING\OPENCANDY, Quarantined, [1081], [173202],1.0.7789
PUP.Optional.ResultsHub, C:\PROGRAMDATA\3929CB63-CBBD-4B9C-8B92-A50FBD04E656, Quarantined, [6], [179199],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\USERS\TOM\APPDATA\ROAMING\{4CE77A5C-69B5-172A-0283-30F8DE51CDC6}, Quarantined, [704], [492406],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\USERS\TOM\APPDATA\LOCAL\{357E0322-11D6-6F9A-7C4E-4A725826B6EA}, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{D807EE5B-FCAF-82E3-9137-A70BB55F5B93}\HowToRemove, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\USERS\TOM\APPDATA\LOCAL\{D807EE5B-FCAF-82E3-9137-A70BB55F5B93}, Quarantined, [704], [484244],1.0.7789
File: 87
PUP.Optional.OpenCandy, C:\Users\jl\AppData\Roaming\OpenCandy\426D7886489D440F8CEFD27306A248F6\TUU2014-EN-1day-AID1006154.exe, Quarantined, [1081], [173202],1.0.7789
PUP.Optional.WinYahoo, C:\USERS\TOM\APPDATA\LOCALLOW\MICROSOFT\INTERNET EXPLORER\SERVICES\WINCY.ICO, Quarantined, [233], [246865],1.0.7789
PUP.Optional.Yontoo, C:\USERS\TOM\APPDATA\LOCAL\CHROMIUM\USER DATA\DEFAULT\LOCAL STORAGE\https_resultshub-a.akamaihd.net_0.localstorage, Quarantined, [33], [248776],1.0.7789
PUP.Optional.Yontoo, C:\DOCUMENTS AND SETTINGS\ALL USERS\NTUSER.POL, Quarantined, [33], [-1],0.0.0
PUP.Optional.Yontoo, C:\PROGRAMDATA\NTUSER.POL, Quarantined, [33], [-1],0.0.0
PUP.Optional.Yontoo, C:\USERS\JL\NTUSER.POL, Quarantined, [33], [-1],0.0.0
PUP.Optional.Yontoo, C:\USERS\TOM\NTUSER.POL, Quarantined, [33], [-1],0.0.0
PUP.Optional.Yontoo, C:\WINDOWS\SYSTEM32\GROUPPOLICY\USER\REGISTRY.POL, Quarantined, [33], [-1],0.0.0
PUP.Optional.Yontoo, C:\WINDOWS\SYSTEM32\GROUPPOLICY\MACHINE\REGISTRY.POL, Quarantined, [33], [-1],0.0.0
PUP.Optional.Yontoo, C:\USERS\TOM\APPDATA\LOCAL\CHROMIUM\USER DATA\DEFAULT\LOCAL STORAGE\https_resultshub-a.akamaihd.net_0.localstorage-journal, Quarantined, [33], [248776],1.0.7789
PUP.Optional.Yontoo, C:\ODS.EXE.CONFIG, Quarantined, [33], [254948],1.0.7789
PUP.Optional.Yontoo, C:\USERS\JL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EN6YIWOB.DEFAULT\SEARCHPLUGINS\SEARCH-SIMPLE.XML, Quarantined, [33], [252656],1.0.7789
PUP.Optional.ResultsHub, C:\ProgramData\3929cb63-cbbd-4b9c-8b92-a50fbd04e656\temp, Quarantined, [6], [179199],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\USERS\TOM\APPDATA\ROAMING\{4CE77A5C-69B5-172A-0283-30F8DE51CDC6}\productupdate.exe, Quarantined, [704], [492406],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Roaming\{4CE77A5C-69B5-172A-0283-30F8DE51CDC6}\config.dat, Quarantined, [704], [492406],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Roaming\{4CE77A5C-69B5-172A-0283-30F8DE51CDC6}\info.dat, Quarantined, [704], [492406],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Roaming\{4CE77A5C-69B5-172A-0283-30F8DE51CDC6}\STTL.DAT, Quarantined, [704], [492406],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Roaming\{4CE77A5C-69B5-172A-0283-30F8DE51CDC6}\TTL.DAT, Quarantined, [704], [492406],1.0.7789
PUP.Optional.WinYahoo, C:\USERS\TOM\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\6MNCZRHU.DEFAULT-1509552401858\SEARCHPLUGINS\YHS.XML, Quarantined, [233], [457864],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\USERS\TOM\APPDATA\LOCAL\{357E0322-11D6-6F9A-7C4E-4A725826B6EA}\side, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{357E0322-11D6-6F9A-7C4E-4A725826B6EA}\config.dat, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{357E0322-11D6-6F9A-7C4E-4A725826B6EA}\info.dat, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{357E0322-11D6-6F9A-7C4E-4A725826B6EA}\install.log, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{357E0322-11D6-6F9A-7C4E-4A725826B6EA}\Sqlite3.dll, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{357E0322-11D6-6F9A-7C4E-4A725826B6EA}\uninst.dat, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\USERS\TOM\APPDATA\LOCAL\{D807EE5B-FCAF-82E3-9137-A70BB55F5B93}\dasa, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{D807EE5B-FCAF-82E3-9137-A70BB55F5B93}\HowToRemove\chromium-min.jpg, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{D807EE5B-FCAF-82E3-9137-A70BB55F5B93}\HowToRemove\control panel-min-min.JPG, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{D807EE5B-FCAF-82E3-9137-A70BB55F5B93}\HowToRemove\down.png, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{D807EE5B-FCAF-82E3-9137-A70BB55F5B93}\HowToRemove\ff menu.JPG, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{D807EE5B-FCAF-82E3-9137-A70BB55F5B93}\HowToRemove\ff search engine-min.png, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{D807EE5B-FCAF-82E3-9137-A70BB55F5B93}\HowToRemove\HowToRemove.html, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{D807EE5B-FCAF-82E3-9137-A70BB55F5B93}\HowToRemove\hp-min ff.png, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{D807EE5B-FCAF-82E3-9137-A70BB55F5B93}\HowToRemove\hp-min ie.png, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{D807EE5B-FCAF-82E3-9137-A70BB55F5B93}\HowToRemove\search engine.gif, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{D807EE5B-FCAF-82E3-9137-A70BB55F5B93}\HowToRemove\setup pages.gif, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{D807EE5B-FCAF-82E3-9137-A70BB55F5B93}\HowToRemove\sp-min.png, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{D807EE5B-FCAF-82E3-9137-A70BB55F5B93}\HowToRemove\start-min.jpg, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{D807EE5B-FCAF-82E3-9137-A70BB55F5B93}\HowToRemove\up.png, Quarantined, [704], [484244],1.0.7789
PUM.Optional.FireFoxSearchOverride, C:\USERS\JL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EN6YIWOB.DEFAULT\USER.JS, Quarantined, [14236], [302302],1.0.7789
PUP.Optional.WinYahoo, C:\USERS\TOM\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\6MNCZRHU.DEFAULT-1509552401858\PREFS.JS, Replaced, [233], [342418],1.0.7789
PUP.Optional.Yontoo, C:\USERS\JL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EN6YIWOB.DEFAULT\PREFS.JS, Replaced, [33], [301722],1.0.7789
PUP.Optional.Yontoo, C:\USERS\JL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EN6YIWOB.DEFAULT\PREFS.JS, Replaced, [33], [301727],1.0.7789
PUP.Optional.Yontoo, C:\USERS\JL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EN6YIWOB.DEFAULT\PREFS.JS, Replaced, [33], [302786],1.0.7789
PUP.Optional.Yontoo, C:\USERS\JL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EN6YIWOB.DEFAULT\PREFS.JS, Replaced, [33], [303302],1.0.7789
Generic.Malware/Suspicious, C:\USERS\TOM\APPDATA\LOCAL\DSISETUP3359250182.EXE, Quarantined, [0], [392686],1.0.7789
Generic.Malware/Suspicious, C:\USERS\TOM\APPDATA\LOCAL\DSISETUP1488231282.EXE, Quarantined, [0], [392686],1.0.7789
PUP.Optional.InstallCore, C:\$RECYCLE.BIN\S-1-5-21-252852572-1064671646-1800406956-1001\$R07XVFP.EXE, Quarantined, [405], [76818],1.0.7789
PUP.Optional.InstallCore, C:\$RECYCLE.BIN\S-1-5-21-252852572-1064671646-1800406956-1001\$REBX4FP.EXE, Quarantined, [405], [76735],1.0.7789
PUP.Optional.OpenCandy, C:\$RECYCLE.BIN\S-1-5-21-252852572-1064671646-1800406956-1001\$RN3O35B.EXE, Quarantined, [1081], [70383],1.0.7789
PUP.Optional.InstallCore, C:\$RECYCLE.BIN\S-1-5-21-252852572-1064671646-1800406956-1001\$R5FGV4P.EXE, Quarantined, [405], [78790],1.0.7789
PUP.Optional.InstallCore, C:\$RECYCLE.BIN\S-1-5-21-252852572-1064671646-1800406956-1001\$RWYIBCF.EXE, Quarantined, [405], [78790],1.0.7789
PUP.Optional.BundleInstaller, C:\$RECYCLE.BIN\S-1-5-21-252852572-1064671646-1800406956-1001\$RY60G9C.EXE, Quarantined, [419], [575328],1.0.7789
PUP.Optional.BundleInstaller, C:\$RECYCLE.BIN\S-1-5-21-252852572-1064671646-1800406956-1001\$R7M2S07.EXE, Quarantined, [419], [575328],1.0.7789
PUP.Optional.OpenCandy, C:\$RECYCLE.BIN\S-1-5-21-252852572-1064671646-1800406956-1001\$RKTEGBX.EXE, Quarantined, [1081], [70383],1.0.7789
PUP.Optional.BundleInstaller, C:\$RECYCLE.BIN\S-1-5-21-252852572-1064671646-1800406956-1001\$RPG7HAX.EXE, Quarantined, [419], [575328],1.0.7789
Generic.Malware/Suspicious, C:\USERS\TOM\APPDATA\LOCAL\TEMP\F7397982\PATCH_FF.EXE, Quarantined, [0], [392686],1.0.7789
Generic.Malware/Suspicious, C:\USERS\TOM\APPDATA\LOCAL\TEMP\F1737F9A\PATCH_FF.EXE, Quarantined, [0], [392686],1.0.7789
PUP.Optional.BundleInstaller, C:\USERS\TOM\APPDATA\LOCAL\TEMP\CUP\CHROMIUM_INSTALLER.EXE, Quarantined, [419], [520134],1.0.7789
Generic.Malware/Suspicious, C:\USERS\TOM\APPDATA\LOCAL\TEMP\F81F60F7\PATCH_FF.EXE, Quarantined, [0], [392686],1.0.7789
PUP.Optional.Bandoo, C:\USERS\TOM\APPDATA\LOCAL\TEMP\F9587B44\SETUPDATAMNGR_IMESH.EXE, Quarantined, [452], [299994],1.0.7789
Generic.Malware/Suspicious, C:\USERS\TOM\APPDATA\LOCAL\TEMP\F743487B\PATCH_FF.EXE, Quarantined, [0], [392686],1.0.7789
Generic.Malware/Suspicious, C:\USERS\TOM\APPDATA\LOCAL\TEMP\N8484\S8484.EXE, Quarantined, [0], [392686],1.0.7789
Generic.Malware/Suspicious, C:\USERS\TOM\APPDATA\LOCAL\TEMP\NSBA5D4.TMP\NSG26FB.TMP\NEW_FOLDER\DATAMNGRCOORDINATOR.EXE, Quarantined, [0], [392686],1.0.7789
Generic.Malware/Suspicious, C:\USERS\TOM\APPDATA\LOCAL\TEMP\FC6D247D\SETUPDATAMNGR_IMESH.EXE, Quarantined, [0], [392686],1.0.7789
PUP.Optional.Bandoo, C:\USERS\TOM\APPDATA\LOCAL\TEMP\NSLA28C.TMP\UNINSTALL.EXE, Quarantined, [452], [301304],1.0.7789
Generic.Malware/Suspicious, C:\USERS\TOM\APPDATA\LOCAL\TEMP\NSBA5D4.TMP\NSG26FB.TMP\PACK.EXE, Quarantined, [0], [392686],1.0.7789
PUP.Optional.InstallCore, C:\USERS\TOM\APPDATA\LOCAL\TEMP\11532UNINSTALL.EXE, Quarantined, [405], [82351],1.0.7789
Generic.Malware/Suspicious, C:\USERS\TOM\APPDATA\LOCAL\TEMP\BRS.EXE50833315.DEL, Quarantined, [0], [392686],1.0.7789
PUP.Optional.Bandoo, C:\USERS\TOM\APPDATA\LOCAL\TEMP\~NSU.TMP\AU_.EXE, Quarantined, [452], [112584],1.0.7789
Generic.Malware/Suspicious, C:\USERS\TOM\APPDATA\LOCAL\TEMP\SOFTONIC_EN_1-5-11_EN-PRODUCTION_10_CLEANRELEASE[1].EXE, Quarantined, [0], [392686],1.0.7789
Generic.Malware/Suspicious, C:\USERS\TOM\APPDATA\LOCAL\TEMP\SOFTONIC_EN_1-5-11_EN-PRODUCTION_10_CLEANRELEASE[2].EXE, Quarantined, [0], [392686],1.0.7789
PUP.Optional.4Shared, C:\USERS\TOM\DOWNLOADS\ATTACK ON TITANS .EXE, Quarantined, [10615], [52066],1.0.7789
PUP.Optional.InstallRex, C:\USERS\TOM\DOWNLOADS\ARUAROSE - ARUAONLINE - ROSE ONLINE.EXE, Quarantined, [9877], [76024],1.0.7789
PUP.Optional.BestFreeDownloads, C:\USERS\TOM\DOWNLOADS\DOWNLOADMANAGERSETUP.EXE, Quarantined, [14107], [273325],1.0.7789
Generic.Malware/Suspicious, C:\USERS\TOM\APPDATA\LOCAL\TEMP\SOFTONIC_EN_1-5-11_EN-PRODUCTION_10_CLEANRELEASE.EXE, Quarantined, [0], [392686],1.0.7789
PUP.Optional.InstallCore, C:\USERS\TOM\DOWNLOADS\INSTALLER_MINECRAFT_ENGLISH.EXE, Quarantined, [405], [304611],1.0.7789
PUP.Optional.InstallCore, C:\USERS\TOM\DOWNLOADS\AMNESIA-THE-DARK-DESCENT.EXE, Quarantined, [405], [78790],1.0.7789
PUP.Optional.InstallRex, C:\USERS\TOM\DOWNLOADS\MY NEIGHBOR TOTORO 1988 720P BLURAY X264-AMIABLE [PUBLICHD].EXE, Quarantined, [9877], [76049],1.0.7789
PUP.Optional.4Shared, C:\USERS\TOM\DOWNLOADS\SAVEAS(2).EXE, Quarantined, [10615], [52066],1.0.7789
PUP.Optional.InstallRex, C:\USERS\TOM\DOWNLOADS\HIROYUKI+SAWANO+-+VOGEL+IM+KAFIG - [MP3JUICES.COM].EXE, Quarantined, [9877], [277992],1.0.7789
PUP.Optional.4Shared, C:\USERS\TOM\DOWNLOADS\SAVEAS.EXE, Quarantined, [10615], [52066],1.0.7789
PUP.Optional.SimplyTech, C:\USERS\TOM\DOWNLOADS\ZIP.EXE, Quarantined, [2629], [429806],1.0.7789
PUP.Optional.InstallCore, C:\USERS\TOM\DOWNLOADS\CR_DOWNLOADER_FOR_ZELDA---MAJORA'S-MASK.EXE, Quarantined, [405], [273209],1.0.7789
PUP.Optional.4Shared, C:\USERS\TOM\DOWNLOADS\SAVEAS(1).EXE, Quarantined, [10615], [52066],1.0.7789
Generic.Malware/Suspicious, C:\USERS\TOM\DOWNLOADS\Z_DOWNLOADER.EXE, Quarantined, [0], [392686],1.0.7789
MachineLearning/Anomalous.97%, C:\USERS\TOM\APPDATA\ROAMING\TIMEDAC\SYNCTASK.EXE, Quarantined, [0], [392687],1.0.7789
Physical Sector: 0
(No malicious items detected)
WMI: 0
(No malicious items detected)
(end)
www.malwarebytes.com
-Log Details-
Scan Date: 11/11/18
Scan Time: 9:28 AM
Log File: 21881070-e551-11e8-9944-342387de9750.json
-Software Information-
Version: 3.6.1.2711
Components Version: 1.0.482
Update Package Version: 1.0.7789
License: Trial
-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: TomDell\Tom
-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 311889
Threats Detected: 133
Threats Quarantined: 133
Time Elapsed: 37 min, 43 sec
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect
-Scan Details-
Process: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registry Key: 16
PUP.Optional.Yontoo, HKLM\SOFTWARE\POLICIES\GOOGLE\CHROME, Quarantined, [33], [-1],0.0.0
PUP.Optional.Yontoo, HKLM\SOFTWARE\WOW6432NODE\POLICIES\GOOGLE\CHROME, Quarantined, [33], [-1],0.0.0
PUP.Optional.BDYahoo, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{295E555F-A5F0-42ED-917A-617F365F50E9}, Quarantined, [6826], [235700],1.0.7789
PUP.Optional.BDYahoo, HKU\S-1-5-21-252852572-1064671646-1800406956-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{295E555F-A5F0-42ED-917A-617F365F50E9}, Quarantined, [6826], [235700],1.0.7789
PUP.Optional.Yontoo, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\OldSearch, Quarantined, [33], [246105],1.0.7789
PUP.Optional.Bandoo.AppFlsh, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2000}, Quarantined, [3], [253586],1.0.7789
PUP.Optional.Bandoo.AppFlsh, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2001}, Quarantined, [3], [253586],1.0.7789
PUP.Optional.Yontoo, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{a62abdee-78a2-4ddb-9355-1c334abd6e43}, Quarantined, [33], [246105],1.0.7789
PUP.Optional.iMeshMusicBoxTB, HKU\S-1-5-21-252852572-1064671646-1800406956-1001_Classes\iMeshIEHelper.DNSGuard.1, Quarantined, [6383], [239379],1.0.7789
PUP.Optional.iMeshMusicBoxTB, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{474597C5-AB09-49D6-A4D5-2E8D7341384E}, Quarantined, [6383], [239379],1.0.7789
PUP.Optional.iMeshMusicBoxTB, HKU\S-1-5-21-252852572-1064671646-1800406956-1001_Classes\iMeshIEHelper.DNSGuard, Quarantined, [6383], [239379],1.0.7789
PUP.Optional.ResultsHub, HKLM\SOFTWARE\WOW6432NODE\RESULTSHUB, Quarantined, [6], [242324],1.0.7789
PUP.Optional.RocketFind, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}, Quarantined, [323], [242376],1.0.7789
PUP.Optional.RocketFind, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}, Quarantined, [323], [242376],1.0.7789
PUP.Optional.Yontoo, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{F83D1872-D9FF-47F8-B5A0-49CC51E24EE8}, Quarantined, [33], [160141],1.0.7789
PUP.Optional.Yontoo, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{F83D1872-D9FF-47F8-B5A0-49CC51E24EE8}, Quarantined, [33], [160141],1.0.7789
Registry Value: 22
PUP.Optional.Yontoo, HKU\S-1-5-21-252852572-1064671646-1800406956-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DONOTASKAGAIN, Quarantined, [33], [246380],1.0.7789
PUP.Optional.BDYahoo, HKU\S-1-5-21-252852572-1064671646-1800406956-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{295E555F-A5F0-42ED-917A-617F365F50E9}|URL, Quarantined, [6826], [235700],1.0.7789
PUP.Optional.Yontoo, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\OldSearch|URL, Quarantined, [33], [246105],1.0.7789
PUP.Optional.Bandoo.AppFlsh, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2000}|URL, Quarantined, [3], [253586],1.0.7789
PUP.Optional.Bandoo.AppFlsh, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, Quarantined, [3], [-1],0.0.0
PUP.Optional.Bandoo.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, Quarantined, [3], [-1],0.0.0
PUP.Optional.ASK, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2000}|SUGGESTIONSURL_JSON, Quarantined, [2], [258454],1.0.7789
PUP.Optional.Bandoo.AppFlsh, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2001}|URL, Quarantined, [3], [253586],1.0.7789
PUP.Optional.ASK, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2001}|SUGGESTIONSURL_JSON, Quarantined, [2], [258454],1.0.7789
PUP.Optional.ASK, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2001}|DEFAULTSUGGESTIONURL, Quarantined, [2], [258454],1.0.7789
PUP.Optional.Yontoo, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{a62abdee-78a2-4ddb-9355-1c334abd6e43}|URL, Quarantined, [33], [246105],1.0.7789
PUP.Optional.ResultsHub, HKLM\SOFTWARE\WOW6432NODE\RESULTSHUB|CG, Quarantined, [6], [242324],1.0.7789
PUP.Optional.Yontoo, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DONOTASKAGAIN, Quarantined, [33], [246380],1.0.7789
PUP.Optional.BDYahoo, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{295E555F-A5F0-42ED-917A-617F365F50E9}|URL, Quarantined, [6826], [235700],1.0.7789
PUP.Optional.RocketFind, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}|URL, Quarantined, [323], [242376],1.0.7789
PUP.Optional.RocketFind, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}|TOPRESULTURLFALLBACK, Quarantined, [323], [242376],1.0.7789
PUP.Optional.RocketFind, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}|URL, Quarantined, [323], [242376],1.0.7789
PUP.Optional.RocketFind, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}|TOPRESULTURLFALLBACK, Quarantined, [323], [242376],1.0.7789
PUP.Optional.Bandoo.AppFlsh, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2000}|FAVICONPATH, Quarantined, [3], [253584],1.0.7789
PUP.Optional.Bandoo.AppFlsh, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2001}|FAVICONPATH, Quarantined, [3], [253584],1.0.7789
PUP.Optional.NotChromeRun, HKU\S-1-5-21-252852572-1064671646-1800406956-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|GOOGLECHROMEAUTOLAUNCH_5189939A0645355218FFECE1F1491836, Quarantined, [6894], [241243],1.0.7789
PUP.Optional.Yontoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DONOTASKAGAIN, Quarantined, [33], [246561],1.0.7789
Registry Data: 0
(No malicious items detected)
Data Stream: 0
(No malicious items detected)
Folder: 8
PUP.Optional.OpenCandy, C:\Users\jl\AppData\Roaming\OpenCandy\39B986BD64224300A6EFF93BCDD8F515, Quarantined, [1081], [173202],1.0.7789
PUP.Optional.OpenCandy, C:\Users\jl\AppData\Roaming\OpenCandy\426D7886489D440F8CEFD27306A248F6, Quarantined, [1081], [173202],1.0.7789
PUP.Optional.OpenCandy, C:\USERS\JL\APPDATA\ROAMING\OPENCANDY, Quarantined, [1081], [173202],1.0.7789
PUP.Optional.ResultsHub, C:\PROGRAMDATA\3929CB63-CBBD-4B9C-8B92-A50FBD04E656, Quarantined, [6], [179199],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\USERS\TOM\APPDATA\ROAMING\{4CE77A5C-69B5-172A-0283-30F8DE51CDC6}, Quarantined, [704], [492406],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\USERS\TOM\APPDATA\LOCAL\{357E0322-11D6-6F9A-7C4E-4A725826B6EA}, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{D807EE5B-FCAF-82E3-9137-A70BB55F5B93}\HowToRemove, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\USERS\TOM\APPDATA\LOCAL\{D807EE5B-FCAF-82E3-9137-A70BB55F5B93}, Quarantined, [704], [484244],1.0.7789
File: 87
PUP.Optional.OpenCandy, C:\Users\jl\AppData\Roaming\OpenCandy\426D7886489D440F8CEFD27306A248F6\TUU2014-EN-1day-AID1006154.exe, Quarantined, [1081], [173202],1.0.7789
PUP.Optional.WinYahoo, C:\USERS\TOM\APPDATA\LOCALLOW\MICROSOFT\INTERNET EXPLORER\SERVICES\WINCY.ICO, Quarantined, [233], [246865],1.0.7789
PUP.Optional.Yontoo, C:\USERS\TOM\APPDATA\LOCAL\CHROMIUM\USER DATA\DEFAULT\LOCAL STORAGE\https_resultshub-a.akamaihd.net_0.localstorage, Quarantined, [33], [248776],1.0.7789
PUP.Optional.Yontoo, C:\DOCUMENTS AND SETTINGS\ALL USERS\NTUSER.POL, Quarantined, [33], [-1],0.0.0
PUP.Optional.Yontoo, C:\PROGRAMDATA\NTUSER.POL, Quarantined, [33], [-1],0.0.0
PUP.Optional.Yontoo, C:\USERS\JL\NTUSER.POL, Quarantined, [33], [-1],0.0.0
PUP.Optional.Yontoo, C:\USERS\TOM\NTUSER.POL, Quarantined, [33], [-1],0.0.0
PUP.Optional.Yontoo, C:\WINDOWS\SYSTEM32\GROUPPOLICY\USER\REGISTRY.POL, Quarantined, [33], [-1],0.0.0
PUP.Optional.Yontoo, C:\WINDOWS\SYSTEM32\GROUPPOLICY\MACHINE\REGISTRY.POL, Quarantined, [33], [-1],0.0.0
PUP.Optional.Yontoo, C:\USERS\TOM\APPDATA\LOCAL\CHROMIUM\USER DATA\DEFAULT\LOCAL STORAGE\https_resultshub-a.akamaihd.net_0.localstorage-journal, Quarantined, [33], [248776],1.0.7789
PUP.Optional.Yontoo, C:\ODS.EXE.CONFIG, Quarantined, [33], [254948],1.0.7789
PUP.Optional.Yontoo, C:\USERS\JL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EN6YIWOB.DEFAULT\SEARCHPLUGINS\SEARCH-SIMPLE.XML, Quarantined, [33], [252656],1.0.7789
PUP.Optional.ResultsHub, C:\ProgramData\3929cb63-cbbd-4b9c-8b92-a50fbd04e656\temp, Quarantined, [6], [179199],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\USERS\TOM\APPDATA\ROAMING\{4CE77A5C-69B5-172A-0283-30F8DE51CDC6}\productupdate.exe, Quarantined, [704], [492406],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Roaming\{4CE77A5C-69B5-172A-0283-30F8DE51CDC6}\config.dat, Quarantined, [704], [492406],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Roaming\{4CE77A5C-69B5-172A-0283-30F8DE51CDC6}\info.dat, Quarantined, [704], [492406],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Roaming\{4CE77A5C-69B5-172A-0283-30F8DE51CDC6}\STTL.DAT, Quarantined, [704], [492406],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Roaming\{4CE77A5C-69B5-172A-0283-30F8DE51CDC6}\TTL.DAT, Quarantined, [704], [492406],1.0.7789
PUP.Optional.WinYahoo, C:\USERS\TOM\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\6MNCZRHU.DEFAULT-1509552401858\SEARCHPLUGINS\YHS.XML, Quarantined, [233], [457864],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\USERS\TOM\APPDATA\LOCAL\{357E0322-11D6-6F9A-7C4E-4A725826B6EA}\side, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{357E0322-11D6-6F9A-7C4E-4A725826B6EA}\config.dat, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{357E0322-11D6-6F9A-7C4E-4A725826B6EA}\info.dat, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{357E0322-11D6-6F9A-7C4E-4A725826B6EA}\install.log, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{357E0322-11D6-6F9A-7C4E-4A725826B6EA}\Sqlite3.dll, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{357E0322-11D6-6F9A-7C4E-4A725826B6EA}\uninst.dat, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\USERS\TOM\APPDATA\LOCAL\{D807EE5B-FCAF-82E3-9137-A70BB55F5B93}\dasa, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{D807EE5B-FCAF-82E3-9137-A70BB55F5B93}\HowToRemove\chromium-min.jpg, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{D807EE5B-FCAF-82E3-9137-A70BB55F5B93}\HowToRemove\control panel-min-min.JPG, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{D807EE5B-FCAF-82E3-9137-A70BB55F5B93}\HowToRemove\down.png, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{D807EE5B-FCAF-82E3-9137-A70BB55F5B93}\HowToRemove\ff menu.JPG, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{D807EE5B-FCAF-82E3-9137-A70BB55F5B93}\HowToRemove\ff search engine-min.png, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{D807EE5B-FCAF-82E3-9137-A70BB55F5B93}\HowToRemove\HowToRemove.html, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{D807EE5B-FCAF-82E3-9137-A70BB55F5B93}\HowToRemove\hp-min ff.png, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{D807EE5B-FCAF-82E3-9137-A70BB55F5B93}\HowToRemove\hp-min ie.png, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{D807EE5B-FCAF-82E3-9137-A70BB55F5B93}\HowToRemove\search engine.gif, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{D807EE5B-FCAF-82E3-9137-A70BB55F5B93}\HowToRemove\setup pages.gif, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{D807EE5B-FCAF-82E3-9137-A70BB55F5B93}\HowToRemove\sp-min.png, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{D807EE5B-FCAF-82E3-9137-A70BB55F5B93}\HowToRemove\start-min.jpg, Quarantined, [704], [484244],1.0.7789
PUP.Optional.WinYahoo.TskLnk, C:\Users\Tom\AppData\Local\{D807EE5B-FCAF-82E3-9137-A70BB55F5B93}\HowToRemove\up.png, Quarantined, [704], [484244],1.0.7789
PUM.Optional.FireFoxSearchOverride, C:\USERS\JL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EN6YIWOB.DEFAULT\USER.JS, Quarantined, [14236], [302302],1.0.7789
PUP.Optional.WinYahoo, C:\USERS\TOM\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\6MNCZRHU.DEFAULT-1509552401858\PREFS.JS, Replaced, [233], [342418],1.0.7789
PUP.Optional.Yontoo, C:\USERS\JL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EN6YIWOB.DEFAULT\PREFS.JS, Replaced, [33], [301722],1.0.7789
PUP.Optional.Yontoo, C:\USERS\JL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EN6YIWOB.DEFAULT\PREFS.JS, Replaced, [33], [301727],1.0.7789
PUP.Optional.Yontoo, C:\USERS\JL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EN6YIWOB.DEFAULT\PREFS.JS, Replaced, [33], [302786],1.0.7789
PUP.Optional.Yontoo, C:\USERS\JL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\EN6YIWOB.DEFAULT\PREFS.JS, Replaced, [33], [303302],1.0.7789
Generic.Malware/Suspicious, C:\USERS\TOM\APPDATA\LOCAL\DSISETUP3359250182.EXE, Quarantined, [0], [392686],1.0.7789
Generic.Malware/Suspicious, C:\USERS\TOM\APPDATA\LOCAL\DSISETUP1488231282.EXE, Quarantined, [0], [392686],1.0.7789
PUP.Optional.InstallCore, C:\$RECYCLE.BIN\S-1-5-21-252852572-1064671646-1800406956-1001\$R07XVFP.EXE, Quarantined, [405], [76818],1.0.7789
PUP.Optional.InstallCore, C:\$RECYCLE.BIN\S-1-5-21-252852572-1064671646-1800406956-1001\$REBX4FP.EXE, Quarantined, [405], [76735],1.0.7789
PUP.Optional.OpenCandy, C:\$RECYCLE.BIN\S-1-5-21-252852572-1064671646-1800406956-1001\$RN3O35B.EXE, Quarantined, [1081], [70383],1.0.7789
PUP.Optional.InstallCore, C:\$RECYCLE.BIN\S-1-5-21-252852572-1064671646-1800406956-1001\$R5FGV4P.EXE, Quarantined, [405], [78790],1.0.7789
PUP.Optional.InstallCore, C:\$RECYCLE.BIN\S-1-5-21-252852572-1064671646-1800406956-1001\$RWYIBCF.EXE, Quarantined, [405], [78790],1.0.7789
PUP.Optional.BundleInstaller, C:\$RECYCLE.BIN\S-1-5-21-252852572-1064671646-1800406956-1001\$RY60G9C.EXE, Quarantined, [419], [575328],1.0.7789
PUP.Optional.BundleInstaller, C:\$RECYCLE.BIN\S-1-5-21-252852572-1064671646-1800406956-1001\$R7M2S07.EXE, Quarantined, [419], [575328],1.0.7789
PUP.Optional.OpenCandy, C:\$RECYCLE.BIN\S-1-5-21-252852572-1064671646-1800406956-1001\$RKTEGBX.EXE, Quarantined, [1081], [70383],1.0.7789
PUP.Optional.BundleInstaller, C:\$RECYCLE.BIN\S-1-5-21-252852572-1064671646-1800406956-1001\$RPG7HAX.EXE, Quarantined, [419], [575328],1.0.7789
Generic.Malware/Suspicious, C:\USERS\TOM\APPDATA\LOCAL\TEMP\F7397982\PATCH_FF.EXE, Quarantined, [0], [392686],1.0.7789
Generic.Malware/Suspicious, C:\USERS\TOM\APPDATA\LOCAL\TEMP\F1737F9A\PATCH_FF.EXE, Quarantined, [0], [392686],1.0.7789
PUP.Optional.BundleInstaller, C:\USERS\TOM\APPDATA\LOCAL\TEMP\CUP\CHROMIUM_INSTALLER.EXE, Quarantined, [419], [520134],1.0.7789
Generic.Malware/Suspicious, C:\USERS\TOM\APPDATA\LOCAL\TEMP\F81F60F7\PATCH_FF.EXE, Quarantined, [0], [392686],1.0.7789
PUP.Optional.Bandoo, C:\USERS\TOM\APPDATA\LOCAL\TEMP\F9587B44\SETUPDATAMNGR_IMESH.EXE, Quarantined, [452], [299994],1.0.7789
Generic.Malware/Suspicious, C:\USERS\TOM\APPDATA\LOCAL\TEMP\F743487B\PATCH_FF.EXE, Quarantined, [0], [392686],1.0.7789
Generic.Malware/Suspicious, C:\USERS\TOM\APPDATA\LOCAL\TEMP\N8484\S8484.EXE, Quarantined, [0], [392686],1.0.7789
Generic.Malware/Suspicious, C:\USERS\TOM\APPDATA\LOCAL\TEMP\NSBA5D4.TMP\NSG26FB.TMP\NEW_FOLDER\DATAMNGRCOORDINATOR.EXE, Quarantined, [0], [392686],1.0.7789
Generic.Malware/Suspicious, C:\USERS\TOM\APPDATA\LOCAL\TEMP\FC6D247D\SETUPDATAMNGR_IMESH.EXE, Quarantined, [0], [392686],1.0.7789
PUP.Optional.Bandoo, C:\USERS\TOM\APPDATA\LOCAL\TEMP\NSLA28C.TMP\UNINSTALL.EXE, Quarantined, [452], [301304],1.0.7789
Generic.Malware/Suspicious, C:\USERS\TOM\APPDATA\LOCAL\TEMP\NSBA5D4.TMP\NSG26FB.TMP\PACK.EXE, Quarantined, [0], [392686],1.0.7789
PUP.Optional.InstallCore, C:\USERS\TOM\APPDATA\LOCAL\TEMP\11532UNINSTALL.EXE, Quarantined, [405], [82351],1.0.7789
Generic.Malware/Suspicious, C:\USERS\TOM\APPDATA\LOCAL\TEMP\BRS.EXE50833315.DEL, Quarantined, [0], [392686],1.0.7789
PUP.Optional.Bandoo, C:\USERS\TOM\APPDATA\LOCAL\TEMP\~NSU.TMP\AU_.EXE, Quarantined, [452], [112584],1.0.7789
Generic.Malware/Suspicious, C:\USERS\TOM\APPDATA\LOCAL\TEMP\SOFTONIC_EN_1-5-11_EN-PRODUCTION_10_CLEANRELEASE[1].EXE, Quarantined, [0], [392686],1.0.7789
Generic.Malware/Suspicious, C:\USERS\TOM\APPDATA\LOCAL\TEMP\SOFTONIC_EN_1-5-11_EN-PRODUCTION_10_CLEANRELEASE[2].EXE, Quarantined, [0], [392686],1.0.7789
PUP.Optional.4Shared, C:\USERS\TOM\DOWNLOADS\ATTACK ON TITANS .EXE, Quarantined, [10615], [52066],1.0.7789
PUP.Optional.InstallRex, C:\USERS\TOM\DOWNLOADS\ARUAROSE - ARUAONLINE - ROSE ONLINE.EXE, Quarantined, [9877], [76024],1.0.7789
PUP.Optional.BestFreeDownloads, C:\USERS\TOM\DOWNLOADS\DOWNLOADMANAGERSETUP.EXE, Quarantined, [14107], [273325],1.0.7789
Generic.Malware/Suspicious, C:\USERS\TOM\APPDATA\LOCAL\TEMP\SOFTONIC_EN_1-5-11_EN-PRODUCTION_10_CLEANRELEASE.EXE, Quarantined, [0], [392686],1.0.7789
PUP.Optional.InstallCore, C:\USERS\TOM\DOWNLOADS\INSTALLER_MINECRAFT_ENGLISH.EXE, Quarantined, [405], [304611],1.0.7789
PUP.Optional.InstallCore, C:\USERS\TOM\DOWNLOADS\AMNESIA-THE-DARK-DESCENT.EXE, Quarantined, [405], [78790],1.0.7789
PUP.Optional.InstallRex, C:\USERS\TOM\DOWNLOADS\MY NEIGHBOR TOTORO 1988 720P BLURAY X264-AMIABLE [PUBLICHD].EXE, Quarantined, [9877], [76049],1.0.7789
PUP.Optional.4Shared, C:\USERS\TOM\DOWNLOADS\SAVEAS(2).EXE, Quarantined, [10615], [52066],1.0.7789
PUP.Optional.InstallRex, C:\USERS\TOM\DOWNLOADS\HIROYUKI+SAWANO+-+VOGEL+IM+KAFIG - [MP3JUICES.COM].EXE, Quarantined, [9877], [277992],1.0.7789
PUP.Optional.4Shared, C:\USERS\TOM\DOWNLOADS\SAVEAS.EXE, Quarantined, [10615], [52066],1.0.7789
PUP.Optional.SimplyTech, C:\USERS\TOM\DOWNLOADS\ZIP.EXE, Quarantined, [2629], [429806],1.0.7789
PUP.Optional.InstallCore, C:\USERS\TOM\DOWNLOADS\CR_DOWNLOADER_FOR_ZELDA---MAJORA'S-MASK.EXE, Quarantined, [405], [273209],1.0.7789
PUP.Optional.4Shared, C:\USERS\TOM\DOWNLOADS\SAVEAS(1).EXE, Quarantined, [10615], [52066],1.0.7789
Generic.Malware/Suspicious, C:\USERS\TOM\DOWNLOADS\Z_DOWNLOADER.EXE, Quarantined, [0], [392686],1.0.7789
MachineLearning/Anomalous.97%, C:\USERS\TOM\APPDATA\ROAMING\TIMEDAC\SYNCTASK.EXE, Quarantined, [0], [392687],1.0.7789
Physical Sector: 0
(No malicious items detected)
WMI: 0
(No malicious items detected)
(end)