Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [code]
- HitmanPro 3.7.8.208
- www.hitmanpro.com
- Computer name . . . . : HERTZOG327-PC
- Windows . . . . . . . : 6.1.0.7600.X64/4
- User name . . . . . . : hertzog327-PC\hertzog327
- UAC . . . . . . . . . : Disabled
- License . . . . . . . : Free
- Scan date . . . . . . : 2014-01-05 11:13:29
- Scan mode . . . . . . : Normal
- Scan duration . . . . : 10m 8s
- Disk access mode . . : Direct disk access (SRB)
- Cloud . . . . . . . . : Internet
- Reboot . . . . . . . : No
- Threats . . . . . . . : 0
- Traces . . . . . . . : 64
- Objects scanned . . . : 2,787,090
- Files scanned . . . . : 160,536
- Remnants scanned . . : 1,292,965 files / 1,333,589 keys
- Suspicious files ____________________________________________________________
- C:\Users\hertzog327\AppData\Local\PunkBuster\FC3\pb\pbcl.dll
- Size . . . . . . . : 953,886 bytes
- Age . . . . . . . : 99.3 days (2013-09-28 05:05:43)
- Entropy . . . . . : 7.6
- SHA-256 . . . . . : 6D5E2CD4A7A43EB00B600BA783AD3BEE6B817C030A40600D40367173A6ECEB13
- Fuzzy . . . . . . : 29.0
- The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
- Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
- Authors name is missing in version info. This is not common to most programs.
- Version control is missing. This file is probably created by an individual. This is not typical for most programs.
- Program contains PE structure anomalies. This is not typical for most programs.
- C:\Users\hertzog327\AppData\Local\PunkBuster\FC3\pb\pbcls.dll
- Size . . . . . . . : 953,886 bytes
- Age . . . . . . . : 99.3 days (2013-09-28 05:05:42)
- Entropy . . . . . : 7.6
- SHA-256 . . . . . : 6D5E2CD4A7A43EB00B600BA783AD3BEE6B817C030A40600D40367173A6ECEB13
- Fuzzy . . . . . . : 29.0
- The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
- Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
- Authors name is missing in version info. This is not common to most programs.
- Version control is missing. This file is probably created by an individual. This is not typical for most programs.
- Program contains PE structure anomalies. This is not typical for most programs.
- C:\Users\hertzog327\AppData\Local\PunkBuster\FC3\pb\PnkBstrK.sys
- Size . . . . . . . : 138,032 bytes
- Age . . . . . . . : 99.3 days (2013-09-28 05:05:58)
- Entropy . . . . . : 7.8
- SHA-256 . . . . . : ABAF3FACF01E10E4C685F79C3B9E5D2118B3CF8629C4277EBE035B2A10474148
- RSA Key Size . . . : 2048
- Authenticode . . . : Valid
- Fuzzy . . . . . . : 22.0
- The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
- Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
- Authors name is missing in version info. This is not common to most programs.
- Version control is missing. This file is probably created by an individual. This is not typical for most programs.
- Program contains PE structure anomalies. This is not typical for most programs.
- The file is a device driver. Device drivers run as trusted (highly privileged) code.
- Program is code signed with a valid Authenticode certificate.
- Potential Unwanted Programs _________________________________________________
- C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\ (Yontoo)
- C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll (Yontoo)
- C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.dat (Yontoo)
- C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe (Yontoo)
- Size . . . . . . . : 227,984 bytes
- Age . . . . . . . : 287.5 days (2013-03-23 22:17:30)
- Entropy . . . . . : 6.4
- SHA-256 . . . . . : 17936188EFAC05A0EF9FD87A79B268445CE307DD37A6F9206D116F195AB049C9
- Product . . . . . : Tarma® Installer
- Publisher . . . . : Tarma Software Research Pty Ltd
- Description . . . : Tarma® Installer
- Version . . . . . : 2011.03.11.1355U
- Copyright . . . . : © 1990-2011 Tarma Software Research Pty Ltd
- RSA Key Size . . . : 2048
- Authenticode . . . : Valid
- Fuzzy . . . . . . : -15.0
- C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.ico (Yontoo)
- HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{80922ee0-8a76-46ae-95d5-bd3c3fe0708d}\ (Yontoo)
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\ (Yontoo)
- HKLM\SOFTWARE\Tarma Installer\Components\{8D8654CD-7FBC-4C7E-84E9-371BFA8DB04E}\ (Yontoo)
- HKLM\SOFTWARE\Tarma Installer\Components\{9D9785E5-3424-40B6-A287-BA143AD53109}\ (Yontoo)
- HKLM\SOFTWARE\Tarma Installer\Components\{B6783DFA-B8C8-4CB6-AB9F-EF1A1F7F7AE8}\ (Yontoo)
- HKLM\SOFTWARE\Tarma Installer\Products\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\ (Yontoo)
- HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc\ (Yontoo)
- HKU\S-1-5-21-166366992-1187241683-1984212088-1000\Software\AppDataLow\Software\Smartbar\ (Conduit)
- HKU\S-1-5-21-166366992-1187241683-1984212088-1000\Software\Softonic\ (Softonic)
- HKU\S-1-5-21-166366992-1187241683-1984212088-1000_Classes\Wow6432Node\CLSID\{80922ee0-8a76-46ae-95d5-bd3c3fe0708d}\ (Yontoo)
- Cookies _____________________________________________________________________
- C:\Users\hertzog327\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.yieldmanager.com
- C:\Users\hertzog327\AppData\Local\Google\Chrome\User Data\Default\Cookies:advertising.com
- C:\Users\hertzog327\AppData\Local\Google\Chrome\User Data\Default\Cookies:apmebf.com
- C:\Users\hertzog327\AppData\Local\Google\Chrome\User Data\Default\Cookies:at.atwola.com
- C:\Users\hertzog327\AppData\Local\Google\Chrome\User Data\Default\Cookies:dmtracker.com
- C:\Users\hertzog327\AppData\Local\Google\Chrome\User Data\Default\Cookies:doubleclick.net
- C:\Users\hertzog327\AppData\Local\Google\Chrome\User Data\Default\Cookies:emjcd.com
- C:\Users\hertzog327\AppData\Local\Google\Chrome\User Data\Default\Cookies:in.getclicky.com
- C:\Users\hertzog327\AppData\Local\Google\Chrome\User Data\Default\Cookies:invitemedia.com
- C:\Users\hertzog327\AppData\Local\Google\Chrome\User Data\Default\Cookies:media6degrees.com
- C:\Users\hertzog327\AppData\Local\Google\Chrome\User Data\Default\Cookies:www.youporn.com
- C:\Users\hertzog327\AppData\Local\Google\Chrome\User Data\Default\Cookies:youporn.com
- C:\Users\hertzog327\AppData\Roaming\Microsoft\Windows\Cookies\JPAGEGZC.txt
- C:\Users\hertzog327\AppData\Roaming\Mozilla\Firefox\Profiles\at9efaal.default\cookies.sqlite:ads.eurogamer.net
- C:\Users\hertzog327\AppData\Roaming\Mozilla\Firefox\Profiles\at9efaal.default\cookies.sqlite:adultswim.com
- C:\Users\hertzog327\AppData\Roaming\Mozilla\Firefox\Profiles\at9efaal.default\cookies.sqlite:animalsexzone.com
- C:\Users\hertzog327\AppData\Roaming\Mozilla\Firefox\Profiles\at9efaal.default\cookies.sqlite:apmebf.com
- C:\Users\hertzog327\AppData\Roaming\Mozilla\Firefox\Profiles\at9efaal.default\cookies.sqlite:cnt.proporn.com
- C:\Users\hertzog327\AppData\Roaming\Mozilla\Firefox\Profiles\at9efaal.default\cookies.sqlite:engine.phn.doublepimp.com
- C:\Users\hertzog327\AppData\Roaming\Mozilla\Firefox\Profiles\at9efaal.default\cookies.sqlite:fastclick.net
- C:\Users\hertzog327\AppData\Roaming\Mozilla\Firefox\Profiles\at9efaal.default\cookies.sqlite:freecamsexposed.com
- C:\Users\hertzog327\AppData\Roaming\Mozilla\Firefox\Profiles\at9efaal.default\cookies.sqlite:freepornerotica.com
- C:\Users\hertzog327\AppData\Roaming\Mozilla\Firefox\Profiles\at9efaal.default\cookies.sqlite:fuckingtoons.com
- C:\Users\hertzog327\AppData\Roaming\Mozilla\Firefox\Profiles\at9efaal.default\cookies.sqlite:games.adultswim.com
- C:\Users\hertzog327\AppData\Roaming\Mozilla\Firefox\Profiles\at9efaal.default\cookies.sqlite:h2porn.com
- C:\Users\hertzog327\AppData\Roaming\Mozilla\Firefox\Profiles\at9efaal.default\cookies.sqlite:hellporno.com
- C:\Users\hertzog327\AppData\Roaming\Mozilla\Firefox\Profiles\at9efaal.default\cookies.sqlite:m.freecamsexposed.com
- C:\Users\hertzog327\AppData\Roaming\Mozilla\Firefox\Profiles\at9efaal.default\cookies.sqlite:pornhub.com
- C:\Users\hertzog327\AppData\Roaming\Mozilla\Firefox\Profiles\at9efaal.default\cookies.sqlite:pornpoly.com
- C:\Users\hertzog327\AppData\Roaming\Mozilla\Firefox\Profiles\at9efaal.default\cookies.sqlite:proporn.com
- C:\Users\hertzog327\AppData\Roaming\Mozilla\Firefox\Profiles\at9efaal.default\cookies.sqlite:rule34.xxx
- C:\Users\hertzog327\AppData\Roaming\Mozilla\Firefox\Profiles\at9efaal.default\cookies.sqlite:sexplaycam.com
- C:\Users\hertzog327\AppData\Roaming\Mozilla\Firefox\Profiles\at9efaal.default\cookies.sqlite:stats.tf
- C:\Users\hertzog327\AppData\Roaming\Mozilla\Firefox\Profiles\at9efaal.default\cookies.sqlite:statse.webtrendslive.com
- C:\Users\hertzog327\AppData\Roaming\Mozilla\Firefox\Profiles\at9efaal.default\cookies.sqlite:sunporno.com
- C:\Users\hertzog327\AppData\Roaming\Mozilla\Firefox\Profiles\at9efaal.default\cookies.sqlite:tokyofacefuck.com
- C:\Users\hertzog327\AppData\Roaming\Mozilla\Firefox\Profiles\at9efaal.default\cookies.sqlite:www.freecamsexposed.com
- C:\Users\hertzog327\AppData\Roaming\Mozilla\Firefox\Profiles\at9efaal.default\cookies.sqlite:www.freepornerotica.com
- C:\Users\hertzog327\AppData\Roaming\Mozilla\Firefox\Profiles\at9efaal.default\cookies.sqlite:www.googleadservices.com
- C:\Users\hertzog327\AppData\Roaming\Mozilla\Firefox\Profiles\at9efaal.default\cookies.sqlite:www.pornhub.com
- C:\Users\hertzog327\AppData\Roaming\Mozilla\Firefox\Profiles\at9efaal.default\cookies.sqlite:www.proporn.com
- C:\Users\hertzog327\AppData\Roaming\Mozilla\Firefox\Profiles\at9efaal.default\cookies.sqlite:www.sexplaycam.com
- C:\Users\hertzog327\AppData\Roaming\Mozilla\Firefox\Profiles\at9efaal.default\cookies.sqlite:www.sunporno.com
- C:\Users\hertzog327\AppData\Roaming\Mozilla\Firefox\Profiles\at9efaal.default\cookies.sqlite:www.youporn.com
- C:\Users\hertzog327\AppData\Roaming\Mozilla\Firefox\Profiles\at9efaal.default\cookies.sqlite:youporn.com
- C:\Users\hertzog327\AppData\Roaming\Mozilla\Firefox\Profiles\at9efaal.default\cookies.sqlite:yourfreeporn.us
- [/code]
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement