Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Malwarebytes
- www.malwarebytes.com
- -Log Details-
- Scan Date: 7/4/17
- Scan Time: 1:35 AM
- Log File:
- Administrator: Yes
- -Software Information-
- Version: 3.1.2.1733
- Components Version: 1.0.160
- Update Package Version: 1.0.2287
- License: Trial
- -System Information-
- OS: Windows 10 (Build 14393.1358)
- CPU: x64
- File System: NTFS
- User: DESKTOP\Phikicheli
- -Scan Summary-
- Scan Type: Threat Scan
- Result: Completed
- Objects Scanned: 403144
- Threats Detected: 54
- Threats Quarantined: 54
- Time Elapsed: 11 min, 8 sec
- -Scan Options-
- Memory: Enabled
- Startup: Enabled
- Filesystem: Enabled
- Archives: Enabled
- Rootkits: Disabled
- Heuristics: Enabled
- PUP: Enabled
- PUM: Enabled
- -Scan Details-
- Process: 0
- (No malicious items detected)
- Module: 0
- (No malicious items detected)
- Registry Key: 8
- Trojan.Clicker, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{E7BC34A3-BA86-11CF-84B1-CBC2DA68BF6C}, Quarantined, [26], [383807],1.0.2287
- Trojan.Clicker, HKLM\SOFTWARE\CLASSES\NTService.Control.1, Quarantined, [26], [383807],1.0.2287
- Trojan.Clicker, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E7BC34A3-BA86-11CF-84B1-CBC2DA68BF6C}, Quarantined, [26], [383807],1.0.2287
- Trojan.Clicker, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{E7BC34A3-BA86-11CF-84B1-CBC2DA68BF6C}\InprocServer32, Quarantined, [26], [383807],1.0.2287
- Trojan.Clicker, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E7BC34A3-BA86-11CF-84B1-CBC2DA68BF6C}\InprocServer32, Quarantined, [26], [383807],1.0.2287
- PUP.Optional.Plumbytes, HKLM\SOFTWARE\MICROSOFT\TRACING\Plumbytes_RASAPI32, Quarantined, [9125], [396951],1.0.2287
- PUP.Optional.Plumbytes, HKLM\SOFTWARE\MICROSOFT\TRACING\Plumbytes_RASMANCS, Quarantined, [9125], [396951],1.0.2287
- PUP.Optional.Plumbytes, HKLM\SOFTWARE\Plumbytes Software, Quarantined, [9125], [262040],1.0.2287
- Registry Value: 1
- PUP.Optional.WinResSync.Generic, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE|WINRESSYNC, Quarantined, [1514], [337571],1.0.2287
- Registry Data: 0
- (No malicious items detected)
- Data Stream: 0
- (No malicious items detected)
- Folder: 7
- Trojan.Clicker, C:\Windows\syswow64\config\systemprofile\AppData\Local\ntuserlitelist\svcvmx\locales, Quarantined, [26], [383807],1.0.2287
- Trojan.Clicker, C:\Windows\syswow64\config\systemprofile\AppData\Local\ntuserlitelist\dataup, Quarantined, [26], [383807],1.0.2287
- PUP.Optional.YSearchTab, C:\Users\Phikicheli\AppData\Roaming\Mozilla\Firefox\Profiles\3b2os9s3.default\storage\default\http+++imdownloader.ysearchtab.com\idb\301792106ttes.files, Quarantined, [9156], [395234],1.0.2287
- PUP.Optional.YSearchTab, C:\Users\Phikicheli\AppData\Roaming\Mozilla\Firefox\Profiles\3b2os9s3.default\storage\default\http+++imdownloader.ysearchtab.com\idb, Quarantined, [9156], [395234],1.0.2287
- PUP.Optional.YSearchTab, C:\USERS\PHIKICHELI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3B2OS9S3.DEFAULT\STORAGE\DEFAULT\http+++imdownloader.ysearchtab.com, Quarantined, [9156], [395234],1.0.2287
- PUP.Optional.BundleInstaller, C:\USERS\PHIKICHELI\APPDATA\LOCAL\TEMP\24515234, Quarantined, [25], [341983],1.0.2287
- PUP.Optional.ThreatSupport, C:\USERS\PHIKICHELI\APPDATA\LOCAL\{12A8CCFE-3C33-4995-BAD8-074E4C5B22FD}, Quarantined, [2055], [343538],1.0.2287
- File: 38
- Trojan.Clicker, C:\Windows\syswow64\config\systemprofile\AppData\Local\ntuserlitelist\dataup\dataup.exe, Quarantined, [26], [383807],1.0.2287
- Trojan.Clicker, C:\Windows\syswow64\config\systemprofile\AppData\Local\ntuserlitelist\dataup\dataup.ini, Quarantined, [26], [383807],1.0.2287
- Trojan.Clicker, C:\Windows\syswow64\config\systemprofile\AppData\Local\ntuserlitelist\dataup\help_dll.dll, Quarantined, [26], [383807],1.0.2287
- Trojan.Clicker, C:\Windows\syswow64\config\systemprofile\AppData\Local\ntuserlitelist\dataup\NTSVC.ocx, Quarantined, [26], [383807],1.0.2287
- Trojan.Clicker, C:\Windows\syswow64\config\systemprofile\AppData\Local\ntuserlitelist\svcvmx\locales\en-US.pak, Quarantined, [26], [383807],1.0.2287
- Trojan.Clicker, C:\Windows\syswow64\config\systemprofile\AppData\Local\ntuserlitelist\svcvmx\locales\zh-CN.pak, Quarantined, [26], [383807],1.0.2287
- Trojan.Clicker, C:\Windows\syswow64\config\systemprofile\AppData\Local\ntuserlitelist\svcvmx\cef.pak, Quarantined, [26], [383807],1.0.2287
- Trojan.Clicker, C:\Windows\syswow64\config\systemprofile\AppData\Local\ntuserlitelist\svcvmx\cef_100_percent.pak, Quarantined, [26], [383807],1.0.2287
- Trojan.Clicker, C:\Windows\syswow64\config\systemprofile\AppData\Local\ntuserlitelist\svcvmx\cef_200_percent.pak, Quarantined, [26], [383807],1.0.2287
- Trojan.Clicker, C:\Windows\syswow64\config\systemprofile\AppData\Local\ntuserlitelist\svcvmx\cef_extensions.pak, Quarantined, [26], [383807],1.0.2287
- Trojan.Clicker, C:\Windows\syswow64\config\systemprofile\AppData\Local\ntuserlitelist\svcvmx\icudtl.dat, Quarantined, [26], [383807],1.0.2287
- Trojan.Clicker, C:\Windows\syswow64\config\systemprofile\AppData\Local\ntuserlitelist\svcvmx\libcef.dll, Quarantined, [26], [383807],1.0.2287
- Trojan.Clicker, C:\Windows\syswow64\config\systemprofile\AppData\Local\ntuserlitelist\svcvmx\libEGL.dll, Quarantined, [26], [383807],1.0.2287
- Trojan.Clicker, C:\Windows\syswow64\config\systemprofile\AppData\Local\ntuserlitelist\svcvmx\libGLESv2.dll, Quarantined, [26], [383807],1.0.2287
- Trojan.Clicker, C:\Windows\syswow64\config\systemprofile\AppData\Local\ntuserlitelist\svcvmx\natives_blob.bin, Quarantined, [26], [383807],1.0.2287
- Trojan.Clicker, C:\Windows\syswow64\config\systemprofile\AppData\Local\ntuserlitelist\svcvmx\snapshot_blob.bin, Quarantined, [26], [383807],1.0.2287
- Trojan.Clicker, C:\Windows\syswow64\config\systemprofile\AppData\Local\ntuserlitelist\svcvmx\svcvmx.exe, Quarantined, [26], [383807],1.0.2287
- Trojan.Clicker, C:\Windows\syswow64\config\systemprofile\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe, Quarantined, [26], [383807],1.0.2287
- Trojan.Clicker, C:\Windows\syswow64\config\systemprofile\AppData\Local\ntuserlitelist\svcvmx\widevinecdm.dll, Quarantined, [26], [383807],1.0.2287
- Trojan.Clicker, C:\Windows\syswow64\config\systemprofile\AppData\Local\ntuserlitelist\svcvmx\widevinecdmadapter.dll, Quarantined, [26], [383807],1.0.2287
- PUP.Optional.YSearchTab, C:\Users\Phikicheli\AppData\Roaming\Mozilla\Firefox\Profiles\3b2os9s3.default\storage\default\http+++imdownloader.ysearchtab.com\idb\301792106ttes.sqlite, Quarantined, [9156], [395234],1.0.2287
- PUP.Optional.YSearchTab, C:\Users\Phikicheli\AppData\Roaming\Mozilla\Firefox\Profiles\3b2os9s3.default\storage\default\http+++imdownloader.ysearchtab.com\.metadata, Quarantined, [9156], [395234],1.0.2287
- PUP.Optional.YSearchTab, C:\Users\Phikicheli\AppData\Roaming\Mozilla\Firefox\Profiles\3b2os9s3.default\storage\default\http+++imdownloader.ysearchtab.com\.metadata-v2, Quarantined, [9156], [395234],1.0.2287
- PUP.Optional.InstallCore, C:\PROGRAM FILES (X86)\KMSPICO\KMSPICO_PATCH.EXE, Quarantined, [3], [386655],1.0.2287
- Trojan.Clicker, C:\WINDOWS\SYSTEM32\TPRDPW64.EXE, Quarantined, [26], [399773],1.0.2287
- PUP.Optional.Plumbytes, C:\$RECYCLE.BIN\S-1-5-21-1712185177-3340612968-1910388385-1001\$RXBRSM5.EXE, Quarantined, [9125], [123575],1.0.2287
- PUP.Optional.Amonetize, C:\USERS\PHIKICHELI\APPDATA\LOCAL\TEMP\AMIPIXEL.CFG, Quarantined, [6], [302488],1.0.2287
- PUP.Optional.ConvertAd, C:\USERS\PHIKICHELI\APPDATA\LOCAL\TEMP\NSK1159.TMP, Quarantined, [386], [290930],1.0.2287
- PUP.Optional.BundleInstaller, C:\USERS\PHIKICHELI\APPDATA\LOCAL\TEMP\ICREINSTALL_KEYGEN-STEP-2.EXE, Quarantined, [25], [342755],1.0.2287
- Trojan.Clicker, C:\USERS\PHIKICHELI\APPDATA\LOCAL\TEMP\1498955546\S5M_INSTALL_325.ZIP, Quarantined, [26], [387412],1.0.2287
- PUP.Optional.Plumbytes, C:\USERS\PHIKICHELI\APPDATA\LOCAL\TEMP\PAIFFC5.TMP, Quarantined, [9125], [123575],1.0.2287
- PUP.Optional.FastDataX, C:\USERS\PHIKICHELI\APPDATA\LOCAL\TEMP\24515234\IC-0.11DD1B68C42F84.EXE, Quarantined, [9347], [407240],1.0.2287
- Adware.Yelloader, C:\USERS\PHIKICHELI\APPDATA\LOCAL\TEMP\1498955546\S5-20170325.ZIP, Quarantined, [1409], [409678],1.0.2287
- PUP.Optional.BundleInstaller, C:\USERS\PHIKICHELI\APPDATA\LOCAL\TEMP\24515234\IC-0.9814C3728F27A.EXE, Quarantined, [25], [341983],1.0.2287
- PUP.Optional.BundleInstaller, C:\Users\Phikicheli\AppData\Local\Temp\24515234\dlreport, Quarantined, [25], [341983],1.0.2287
- PUP.Optional.BundleInstaller, C:\USERS\PHIKICHELI\APPDATA\LOCAL\TEMP\RARSFX6\KEYGEN-STEP-2.EXE, Quarantined, [25], [342755],1.0.2287
- PUP.Optional.ThreatSupport, C:\USERS\PHIKICHELI\APPDATA\LOCAL\{12A8CCFE-3C33-4995-BAD8-074E4C5B22FD}\SCANLOGS.XML, Quarantined, [2055], [343538],1.0.2287
- PUP.Optional.MyRadioXP, C:\USERS\PHIKICHELI\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\chrome-extension_fnhfdmnphmbbjbgppnpcddkefmeokfho_0.localstorage, Quarantined, [2945], [360496],1.0.2287
- Physical Sector: 0
- (No malicious items detected)
- (end)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement