Malwarebytes Anti-Malware (Trial) 1.75.0.1300
www.malwarebytes.org
Database version: v2014.03.13.03
Windows 7 x86 NTFS
Internet Explorer 9.0.8112.16421
User :: USER-PC [administrator]
Protection: Enabled
2014/03/13 04:26:26 PM
mbam-log-2014-03-13 (16-26-26).txt
Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 413605
Time elapsed: 1 hour(s), 56 minute(s), 4 second(s)
Memory Processes Detected: 1
C:\Users\User\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe (PUP.Optional.DefaultTab.A) -> 1840 -> No action taken.
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 69
HKLM\SYSTEM\CurrentControlSet\Services\DefaultTabUpdate (PUP.Optional.DefaultTab.A) -> No action taken.
HKCR\CLSID\{7F6AFBF1-E065-4627-A2FD-810366367D01} (PUP.Optional.DefaultTab) -> No action taken.
HKCR\TypeLib\{FEB62B15-CC00-4736-AAEC-BA046C9DFF73} (PUP.Optional.DefaultTab) -> No action taken.
HKCR\Interface\{1F8EDE97-36D5-422A-B8F0-9406E2D87C60} (PUP.Optional.DefaultTab) -> No action taken.
HKCR\DefaultTabBHO.DefaultTabBrowser.1 (PUP.Optional.DefaultTab) -> No action taken.
HKCR\DefaultTabBHO.DefaultTabBrowser (PUP.Optional.DefaultTab) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01} (PUP.Optional.DefaultTab) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01} (PUP.Optional.DefaultTab) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{7F6AFBF1-E065-4627-A2FD-810366367D01} (PUP.Optional.DefaultTab) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7F6AFBF1-E065-4627-A2FD-810366367D01} (PUP.Optional.DefaultTab) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7F6AFBF1-E065-4627-A2FD-810366367D01} (PUP.Optional.DefaultTab) -> No action taken.
HKCR\AppID\{38495740-0035-4471-851E-F5BBB86AB085} (PUP.Optional.DefaultTab.A) -> No action taken.
HKCR\AppID\{72D89EBF-0C5D-4190-91FD-398E45F1D007} (PUP.Optional.DefaultTab.A) -> No action taken.
HKCR\AppID\{A2773ED4-83BD-488A-A186-73590706C916} (PUP.Optional.MixiDJToolbar.A) -> No action taken.
HKCR\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} (PUP.Optional.Delta.A) -> No action taken.
HKCR\CLSID\{A1E28287-1A31-4b0f-8D05-AA8C465D3C5A} (PUP.Optional.DefaultTab.A) -> No action taken.
HKCR\DefaultTabBHO.DefaultTabBrowserActiveX.1 (PUP.Optional.DefaultTab.A) -> No action taken.
HKCR\DefaultTabBHO.DefaultTabBrowserActiveX (PUP.Optional.DefaultTab.A) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A1E28287-1A31-4B0F-8D05-AA8C465D3C5A} (PUP.Optional.DefaultTab.A) -> No action taken.
HKCR\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115} (PUP.Optional.Datamngr.A) -> No action taken.
HKCR\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87} (PUP.Optional.Datamngr.A) -> No action taken.
HKCR\CLSID\{DF84E609-C3A4-49CB-A160-61767DAF8899} (PUP.Optional.WebCake.A) -> No action taken.
HKCR\CLSID\{e76b4f24-4a2f-4e65-ad36-e2aa934e547c} (PUP.Optional.SerialTrunc.A) -> No action taken.
HKCR\TypeLib\{033a4be2-42b1-4acb-a69f-d362922136f0} (PUP.Optional.SerialTrunc.A) -> No action taken.
HKCR\Interface\{6BA82436-C754-4B49-B6AD-075AFA9FC625} (PUP.Optional.SerialTrunc.A) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76B4F24-4A2F-4E65-AD36-E2AA934E547C} (PUP.Optional.SerialTrunc.A) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{E76B4F24-4A2F-4E65-AD36-E2AA934E547C} (PUP.Optional.SerialTrunc.A) -> No action taken.
HKCR\Typelib\{DCABB943-792E-44C4-9029-ECBEE6265AF9} (PUP.Optional.OutBrowse) -> No action taken.
HKCR\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534} (PUP.Optional.OutBrowse) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{2A5A2A90-3B30-4E6E-A955-2F232C6EF517} (PUP.Optional.WebCake.A) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{AF6B0594-6008-4327-93E5-608AD710A6FA} (PUP.Optional.WebCake.A) -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2D33ED6-EBBD-467C-BF6F-F175D9B51363} (PUP.Optional.DefaultTab.A) -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BAD84EE2-624D-4e7c-A8BB-41EFD720FD77} (PUP.Optional.DefaultTab.A) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GoforFiles (PUP.Optional.GoForFiles.A) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\hosts (PUP.Optional.Hosts.A) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DSite (PUP.Optional.DigitalSites.A) -> No action taken.
HKLM\SYSTEM\CurrentControlSet\Services\DefaultTabSearch (PUP.Optional.DefaultTab.A) -> No action taken.
HKCR\CrossriderApp0035382.BHO (PUP.Optional.CrossRider.A) -> No action taken.
HKCR\CrossriderApp0035382.BHO.1 (PUP.Optional.CrossRider.A) -> No action taken.
HKCR\CrossriderApp0035382.Sandbox (PUP.Optional.CrossRider.A) -> No action taken.
HKCR\CrossriderApp0035382.Sandbox.1 (PUP.Optional.CrossRider.A) -> No action taken.
HKCR\SearchQUIEHelper.DNSGuard (PUP.Optional.SearchQu) -> No action taken.
HKCR\SearchQUIEHelper.DNSGuard.1 (PUP.Optional.SearchQu) -> No action taken.
HKCR\AppID\DefaultTabBHO.DLL (PUP.Optional.DefaultTab.A) -> No action taken.
HKCU\SOFTWARE\DataMngr_Toolbar (PUP.Optional.DataMngr.A) -> No action taken.
HKCU\SOFTWARE\DealPlyLive (PUP.Optional.DealPly.A) -> No action taken.
HKCU\SOFTWARE\DEFAULT TAB (PUP.Optional.DefaultTab.A) -> No action taken.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} (PUP.Optional.Qone8) -> No action taken.
HKCU\Software\DataMngr (PUP.Optional.DataMngr.A) -> No action taken.
HKCU\Software\delta LTD (PUP.Optional.Delta.A) -> No action taken.
HKCU\Software\AppDataLow\Software\Crossrider (PUP.Optional.CrossRider.A) -> No action taken.
HKCU\Software\AppDataLow\Software\DefaultTab (PUP.Optional.DefaultTab.A) -> No action taken.
HKCU\Software\BabSolution\Updater (PUP.Optional.Babylon.A) -> No action taken.
HKCU\Software\Cr_Installer\35382 (PUP.Optional.CrossRider.A) -> No action taken.
HKCU\Software\InstallCore\1I1T1Q1S (PUP.Optional.InstallCore.A) -> No action taken.
HKCU\SOFTWARE\INSTALLCORE (PUP.Optional.InstallCore.A) -> No action taken.
HKCU\Software\InstalledBrowserExtensions\Alex (PUP.Optional.CrossRider.A) -> No action taken.
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\BPROTECTSETTINGS (PUP.Optional.BProtector.A) -> No action taken.
HKLM\SOFTWARE\babylontoolbar (PUP.Optional.Babylon.A) -> No action taken.
HKLM\SOFTWARE\DealPlyLive (PUP.Optional.DealPly.A) -> No action taken.
HKLM\SOFTWARE\qvo6Software (PUP.Optional.qvo6.A) -> No action taken.
HKLM\SOFTWARE\DEFAULT TAB (PUP.Optional.DefaultTab.A) -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} (PUP.Optional.Qone8) -> No action taken.
HKLM\SOFTWARE\Speedchecker Limited\PC Speed Up (PUP.Optional.PCSpeedUp.A) -> No action taken.
HKLM\SOFTWARE\HOSTS\INSTALLER (PUP.Optional.Hosts.A) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DefaultTab (PUP.Optional.DefaultTab.A) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110311531182} (PUP.Optional.CrossRider.M) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110311531182} (PUP.Optional.CrossRider.M) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110311531182} (PUP.Optional.CrossRider.M) -> No action taken.
Registry Values Detected: 7
HKCU\SOFTWARE\Default Tab|Version (PUP.Optional.DefaultTab.A) -> Data: 2.2.3.0 -> No action taken.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|bProtector Start Page (PUP.BProtector) -> Data:
http://mixidj.delta-search.com/?babsrc=HP_ss&mntrId=EC800219F633F6DB&affID=123187&tsp=4970 -> No action taken.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes|bProtectorDefaultScope (PUP.BProtector) -> Data: {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|NextLive (PUP.Optional.NextLive.A) -> Data: C:\Windows\system32\rundll32.exe "C:\Users\User\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l -> No action taken.
HKCU\Software\InstallCore|tb (PUP.Optional.InstallCore.A) -> Data: 0H1L1J1L1S1R1N -> No action taken.
HKLM\SOFTWARE\Default Tab|Version (PUP.Optional.DefaultTab.A) -> Data: 2.2.3.0 -> No action taken.
HKLM\SOFTWARE\hosts\Installer|BundledIe (PUP.Optional.Hosts.A) -> Data: 1 -> No action taken.
Registry Data Items Detected: 6
HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command| (PUP.Optional.Qvo6.A) -> Bad: (C:\Program Files\Mozilla Firefox\firefox.exe
http://www.qvo6.com/?utm_source=b&u...680J9SA00_SB2241KGCDRV0ECDRV0EX&ts=1376786643) Good: (firefox.exe) -> No action taken.
HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command| (PUP.Optional.Qvo6.A) -> Bad: (C:\Program Files\Internet Explorer\iexplore.exe
http://www.qvo6.com/?utm_source=b&u...680J9SA00_SB2241KGCDRV0ECDRV0EX&ts=1376786643) Good: (iexplore.exe) -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes|DefaultScope (PUP.Optional.Qone8) -> Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}) Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}) -> No action taken.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Default_Page_URL (Hijack.StartPage) -> Bad: (
http://www.qvo6.com/?utm_source=b&u...680J9SA00_SB2241KGCDRV0ECDRV0EX&ts=1376786643) Good: (
http://www.google.com) -> Quarantined and repaired successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Default_Page_URL (Hijack.StartPage) -> Bad: (
http://www.qvo6.com/?utm_source=b&u...680J9SA00_SB2241KGCDRV0ECDRV0EX&ts=1376786643) Good: (
http://www.google.com) -> Quarantined and repaired successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (Hijack.StartPage) -> Bad: (
http://www.qvo6.com/?utm_source=b&u...680J9SA00_SB2241KGCDRV0ECDRV0EX&ts=1376786643) Good: (
http://www.google.com) -> Quarantined and repaired successfully.
Folders Detected: 60
C:\Program Files\hosts (PUP.Optional.Hosts.A) -> No action taken.
C:\Users\User\AppData\Roaming\DigitalSites\UpdateProc (PUP.Optional.Updater) -> No action taken.
C:\Program Files\DefaultTab (PUP.Optional.DefaultTab.A) -> No action taken.
C:\ProgramData\DealPlyLive (PUP.Optional.DealPly.A) -> No action taken.
C:\ProgramData\DealPlyLive\Update (PUP.Optional.DealPly.A) -> No action taken.
C:\ProgramData\DealPlyLive\Update\Log (PUP.Optional.DealPly.A) -> No action taken.
C:\Users\User\AppData\Roaming\Dealply (PUP.Optional.DealPly.A) -> No action taken.
C:\Users\User\AppData\Roaming\Dealply\UpdateProc (PUP.Optional.DealPly.A) -> No action taken.
C:\Program Files\DealPlyLive (PUP.Optional.DealPly.A) -> No action taken.
C:\Program Files\DealPlyLive\CrashReports (PUP.Optional.DealPly.A) -> No action taken.
C:\Users\User\AppData\Roaming\OpenCandy (PUP.Optional.OpenCandy) -> No action taken.
C:\Users\User\AppData\Roaming\OpenCandy\27625DABD2F14D5585D7C0EA383D6AD2 (PUP.Optional.OpenCandy) -> No action taken.
C:\Users\User\AppData\Roaming\OpenCandy\2AA6F44EC5C94821A9CD56148A265E4D (PUP.Optional.OpenCandy) -> No action taken.
C:\Users\User\AppData\Roaming\OpenCandy\2D1710B613CE43A790A89727009EB619 (PUP.Optional.OpenCandy) -> No action taken.
C:\Users\User\AppData\Roaming\OpenCandy\AE873514296741EEAB3BF9F0D06875C8 (PUP.Optional.OpenCandy) -> No action taken.
C:\Users\User\AppData\Roaming\File Scout (PUP.Optional.FileScout.A) -> No action taken.
C:\Users\User\AppData\Local\DealPlyLive (PUP.Optional.DealPly.A) -> No action taken.
C:\Users\User\AppData\Local\DealPlyLive\CrashReports (PUP.Optional.DealPly.A) -> No action taken.
C:\Users\User\AppData\Roaming\DefaultTab\DefaultTab (PUP.Optional.DefaultTab.A) -> No action taken.
C:\Users\User\AppData\Roaming\DefaultTab\DefaultTab\Apps (PUP.Optional.DefaultTab.A) -> No action taken.
C:\Users\User\AppData\Roaming\newnext.me (PUP.Optional.NextLive.A) -> No action taken.
C:\Users\User\AppData\Roaming\newnext.me\cache (PUP.Optional.NextLive.A) -> No action taken.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc (PUP.Optional.DefaultTab.A) -> No action taken.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc\2.0.8_0 (PUP.Optional.DefaultTab.A) -> No action taken.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc\2.0.8_0\css (PUP.Optional.DefaultTab.A) -> No action taken.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc\2.0.8_0\css\jquery_ui (PUP.Optional.DefaultTab.A) -> No action taken.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc\2.0.8_0\css\jquery_ui\images (PUP.Optional.DefaultTab.A) -> No action taken.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc\2.0.8_0\images (PUP.Optional.DefaultTab.A) -> No action taken.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc\2.0.8_0\images\engines_icons (PUP.Optional.DefaultTab.A) -> No action taken.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc\2.0.8_0\images\injection (PUP.Optional.DefaultTab.A) -> No action taken.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc\2.0.8_0\js (PUP.Optional.DefaultTab.A) -> No action taken.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc\2.0.8_0\_locales (PUP.Optional.DefaultTab.A) -> No action taken.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc\2.0.8_0\_locales\en (PUP.Optional.DefaultTab.A) -> No action taken.
C:\Windows\System32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc (PUP.Optional.DefaultTab.A) -> No action taken.
C:\Windows\System32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc\1.1.28_0 (PUP.Optional.DefaultTab.A) -> No action taken.
C:\Windows\System32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc\1.1.28_0\css (PUP.Optional.DefaultTab.A) -> No action taken.
C:\Windows\System32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc\1.1.28_0\css\jquery_ui (PUP.Optional.DefaultTab.A) -> No action taken.
C:\Windows\System32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc\1.1.28_0\css\jquery_ui\images (PUP.Optional.DefaultTab.A) -> No action taken.
C:\Windows\System32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc\1.1.28_0\images (PUP.Optional.DefaultTab.A) -> No action taken.
C:\Windows\System32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc\1.1.28_0\images\engines_icons (PUP.Optional.DefaultTab.A) -> No action taken.