Martin1234 | 25.04.2014 22:53 | Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 22.04.2014
Scan Time: 22:15:25
Logfile: maleware.txt
Administrator: Yes
Version: 2.00.1.1004
Malware Database: v2014.04.22.05
Rootkit Database: v2014.03.27.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Chameleon: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Martin
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 294858
Time Elapsed: 27 min, 14 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled
Processes: 1
RiskWare.Tool.CK, C:\Windows\KMService.exe, 1812, Delete-on-Reboot, [67f6cc610f6cf93dab3094126e937b85]
Modules: 0
(No malicious items detected)
Registry Keys: 148
Adware.Agent, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\DlProtectSvc, Quarantined, [6af3111cf18aa59174960d4b45bcae52],
Adware.Agent, HKU\S-1-5-21-205120009-107262540-2640116156-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{132401a7-2006-4342-b43c-ccf5f02c2b01}, Delete-on-Reboot, [6af3111cf18aa59174960d4b45bcae52],
PUP.Optional.Iminent, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SProtection, Quarantined, [5b027ab3d2a9a98d1eecf60d827fb24e],
PUP.Optional.ResultsAlpha.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update ResultsAlpha, Quarantined, [0f4e65c8cfacfd39c9ba311da160df21],
PUP.Optional.ResultsAlpha.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Util ResultsAlpha, Quarantined, [5d00be6f55261224552e81cdbd449769],
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, Quarantined, [62fb71bcc7b4bb7b3463fb5215ed7c84],
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, Quarantined, [62fb71bcc7b4bb7b3463fb5215ed7c84],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\CLSID\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}, Quarantined, [7ce162cbc1bacc6a677d99b3996937c9],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\CLSID\{5C176BA0-6FC0-4EBD-8ACF-24AC592506B6}, Quarantined, [7ce162cbc1bacc6a677d99b3996937c9],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{A9CAF365-EA35-45DA-BD8B-2EFA09D374AC}, Quarantined, [7ce162cbc1bacc6a677d99b3996937c9],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{C58D664A-3DBC-4925-AE74-0382007DF113}, Quarantined, [7ce162cbc1bacc6a677d99b3996937c9],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{C776D7F4-BA85-4B75-AAFC-3A0A11FE6E36}, Quarantined, [7ce162cbc1bacc6a677d99b3996937c9],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C58D664A-3DBC-4925-AE74-0382007DF113}, Quarantined, [7ce162cbc1bacc6a677d99b3996937c9],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C776D7F4-BA85-4B75-AAFC-3A0A11FE6E36}, Quarantined, [7ce162cbc1bacc6a677d99b3996937c9],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{A9CAF365-EA35-45DA-BD8B-2EFA09D374AC}, Quarantined, [7ce162cbc1bacc6a677d99b3996937c9],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\IminentWebBooster.ScriptExtender.1, Quarantined, [7ce162cbc1bacc6a677d99b3996937c9],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\IminentWebBooster.ScriptExtender, Quarantined, [7ce162cbc1bacc6a677d99b3996937c9],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\IminentWebBooster.ScriptExtender, Quarantined, [7ce162cbc1bacc6a677d99b3996937c9],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\IminentWebBooster.ScriptExtender.1, Quarantined, [7ce162cbc1bacc6a677d99b3996937c9],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5C176BA0-6FC0-4EBD-8ACF-24AC592506B6}, Quarantined, [7ce162cbc1bacc6a677d99b3996937c9],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}, Quarantined, [7ce162cbc1bacc6a677d99b3996937c9],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\IminentWebBooster.BrowserHelperObject.1, Quarantined, [7ce162cbc1bacc6a677d99b3996937c9],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\IminentWebBooster.BrowserHelperObject, Quarantined, [7ce162cbc1bacc6a677d99b3996937c9],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\IminentWebBooster.BrowserHelperObject, Quarantined, [7ce162cbc1bacc6a677d99b3996937c9],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}, Quarantined, [7ce162cbc1bacc6a677d99b3996937c9],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}, Quarantined, [7ce162cbc1bacc6a677d99b3996937c9],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\IminentWebBooster.BrowserHelperObject.1, Quarantined, [7ce162cbc1bacc6a677d99b3996937c9],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\CLSID\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}\INPROCSERVER32, Quarantined, [7ce162cbc1bacc6a677d99b3996937c9],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{01A602A0-D0B9-445B-8081-719E4177C4A7}, Quarantined, [c79633fa8af18aac8a1178d50df50000],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.DataContracts.ShowControlCenterCommand, Quarantined, [c79633fa8af18aac8a1178d50df50000],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.DataContracts.ShowControlCenterCommand, Quarantined, [c79633fa8af18aac8a1178d50df50000],
PUP.Optional.ResultsAlpha.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{cbab673a-a480-4050-bd2b-5de24a7a0282}, Quarantined, [6cf17eaf82f978befb13b06ae9199e62],
PUP.Optional.ResultsAlpha.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{F631E34D-23D3-4ED2-8942-631B8AAF9EA4}, Quarantined, [6cf17eaf82f978befb13b06ae9199e62],
PUP.Optional.ResultsAlpha.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B01A1DA4-813F-44BD-B544-77E5DA7EB5A8}, Quarantined, [6cf17eaf82f978befb13b06ae9199e62],
PUP.Optional.ResultsAlpha.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B01A1DA4-813F-44BD-B544-77E5DA7EB5A8}, Quarantined, [6cf17eaf82f978befb13b06ae9199e62],
PUP.Optional.ResultsAlpha.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{F631E34D-23D3-4ED2-8942-631B8AAF9EA4}, Quarantined, [6cf17eaf82f978befb13b06ae9199e62],
PUP.Optional.ResultsAlpha.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{CBAB673A-A480-4050-BD2B-5DE24A7A0282}, Quarantined, [6cf17eaf82f978befb13b06ae9199e62],
Trojan.Banker, HKU\S-1-5-21-205120009-107262540-2640116156-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{C0F1636E-13A8-4C84-BB11-774BE45E1F83}, Delete-on-Reboot, [b0ad1419cfac70c65ea246db50b236ca],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{0af350d9-3916-454b-ac53-0b0b65f41301}, Quarantined, [025b939af08b37ffc0fcdc71b1511fe1],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{68B81CCD-A80C-4060-8947-5AE69ED01199}, Quarantined, [e37ab974433889ad49741e2fca38fd03],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E6B969FB-6D33-48d2-9061-8BBD4899EB08}, Quarantined, [71eca786582393a34b73c98435cd2ad6],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\IMBoosterARP, Quarantined, [9dc052dbcdaebb7b217fccc8d033946c],
PUP.Optional.ResultsAlpha.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\ResultsAlpha, Quarantined, [f26b4be25f1c54e2d0b0e9bd729116ea],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\Iminent, Quarantined, [2736cf5ecdaec274f626f48e4ab84eb2],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\iminent, Quarantined, [97c640ed90ebb38334695d4f5aa9f50b],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Business.Tinyfying.DownloadArgs, Quarantined, [f4692904215a181e0f49ccccbc47847c],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Business.Tinyfying.LinkToPromoteArgs, Quarantined, [213c2904d4a7c4721a3e395f26dd3bc5],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Business.Tinyfying.RawDataArgs, Quarantined, [8ad3d8552259f73fadab03956b986c94],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Business.Tinyfying.TinyUrlArgs, Quarantined, [f568a08dcead9c9a292f9bfdab58b848],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Business.Tinyfying.ViralLinkArgs, Quarantined, [a2bb2eff56250036f1670098739016ea],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.ClientCallback, Quarantined, [233a61cc116a62d43e71bfd5768dea16],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.ContractBase, Quarantined, [1d40ba73cbb0e94d228d0e86bd465fa1],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.DataContracts.AddToUserContentCommand, Quarantined, [3627c26b2c4fde58436ce9abfe05a15f],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.DataContracts.CheckLoginStatusCommand, Quarantined, [8ecf37f6cbb0c571f7b8c9cb6f948b75],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.DataContracts.CleanCacheCommand, Quarantined, [6cf183aa691269cdf7b87222bc47d12f],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.DataContracts.GameOverCallback, Quarantined, [4815b6771368ef47e7c8cdc70bf85aa6],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.DataContracts.GetCreditCommand, Quarantined, [84d9a18c49328aac03ac3c58d1329967],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.DataContracts.GetInstallationContextCommand, Quarantined, [045946e7c6b55cda7c33464e669dca36],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.DataContracts.GetLoginStatusCommand, Quarantined, [38256fbe5922171fbff08d07a063b749],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.DataContracts.GetLoginStatusResult, Quarantined, [104dd8551a610036951a7d1771921be5],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.DataContracts.GetVariableCommand, Quarantined, [0c5153da6f0c9e98a00ff2a2c1427e82],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.DataContracts.GetVariableResult, Quarantined, [2f2eda53daa1df57129d6d27ea192ed2],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.DataContracts.InstallationContextResult, Quarantined, [a4b91e0f46351b1be6c924703ac9a65a],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.DataContracts.LoadContentCommand, Quarantined, [5eff99941f5cb581a50af99b659e946c],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.DataContracts.LoadContentCommandResult, Quarantined, [4815f835f784ca6cc5ea3163f90ac23e],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.DataContracts.LoginCommand, Quarantined, [322b3fee8cef51e548674f453ac9c63a],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.DataContracts.LoginStatusChangedCallback, Quarantined, [74e9a38a76054beb06a9f59f37ccc739],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.DataContracts.LogoutCommand, Quarantined, [dc819499d0abdb5b901fa8ec34cfbb45],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.DataContracts.MergeIdentityCommand, Quarantined, [451871bcee8d24124c636232f70c5da3],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.DataContracts.MyAccountCommand, Quarantined, [bda09697f883b680d1dee4b0cf343cc4],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.DataContracts.PlayContentCommand, Quarantined, [bf9efd30daa16cca05aa96fe46bd0af6],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.DataContracts.PostContentCallback, Quarantined, [1a439d906714f04646694b49fc07be42],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.DataContracts.RecycleViewsCommand, Quarantined, [67f65ad35427c76fac037a1acd36bb45],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.DataContracts.SetVariableCommand, Quarantined, [3528fa33e09b1c1a614e4d47c1429b65],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.DataContracts.ShowBrowserWindowCommand, Quarantined, [312c191445369c9af8b76c2807fc04fc],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.DataContracts.ShowPluginWindowCommand, Quarantined, [88d59f8e057691a59e1103919c67718f],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.DataContracts.TestContentCommand, Quarantined, [9dc0e449116aad8927880c88cb381ce4],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.DataContracts.UserContentChangedCallback, Quarantined, [3d2071bc7803c47298172f6540c3cd33],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.DataContracts.VariableChangedCallback, Quarantined, [2c311e0f13684fe7a906286c6d968e72],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.DataContracts.WarmUpCommand, Quarantined, [b8a566c7d1aa8caa3e71742022e14fb1],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.DataContracts.WelcomeCommand, Quarantined, [a0bd56d72c4f96a000af623240c354ac],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.ServerCommand, Quarantined, [96c71e0f3942ad89a40bd8bc9d6655ab],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.Communication.ServerResult, Quarantined, [3f1e2b02a6d5eb4bbdf22c68897a4ab6],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.LightContent, Quarantined, [db826cc1abd020168c233460887bd828],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.LightUri, Quarantined, [114c83aa17640531e4cb702449ba27d9],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent.Mediator.MediatorServiceProxy, Quarantined, [45189a93e3983303b7f89bf92ad98d73],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\APPID\Iminent.WebBooster.InternetExplorer.DLL, Quarantined, [35288da0f18a1b1b3d1a425e39cad828],
PUP.Optional.AddPusHD.A, HKLM\SOFTWARE\WOW6432NODE\addplushd, Quarantined, [2e2fd05d08732b0bb2d6146019e97a86],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\Iminent, Quarantined, [bca1230aadceb482809c037fee1417e9],
PUP.Optional.ResultsAlpha.A, HKLM\SOFTWARE\WOW6432NODE\ResultsAlpha, Quarantined, [3b22b77694e766d0c9b87036fe05d42c],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\iminent, Quarantined, [8cd130fd4b300b2b8a13e8c42dd6de22],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Business.Tinyfying.DownloadArgs, Quarantined, [da83f8352556d462be9a1583bf44ea16],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Business.Tinyfying.LinkToPromoteArgs, Quarantined, [cd90f33a0477fd391543d9bf7390c63a],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Business.Tinyfying.RawDataArgs, Quarantined, [1e3fe8458dee66d0e4740494e71cd927],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Business.Tinyfying.TinyUrlArgs, Quarantined, [0b5238f56e0dc86e094ffe9a5ea527d9],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Business.Tinyfying.ViralLinkArgs, Quarantined, [0f4e5cd182f9fd39f563a5f3d62d5ba5],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.ClientCallback, Quarantined, [ce8fe647accf66d0ae01a7edeb18619f],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.ContractBase, Quarantined, [6df0fb327ffcb284d9d6daba53b0ed13],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.DataContracts.AddToUserContentCommand, Quarantined, [adb026075d1e37ff4a65deb656adfc04],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.DataContracts.CheckLoginStatusCommand, Quarantined, [6fee3fee295247efd6d9f59f26ddcd33],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.DataContracts.CleanCacheCommand, Quarantined, [5c01a68784f7181e8827ace830d35ca4],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.DataContracts.GameOverCallback, Quarantined, [1e3f78b5a4d77abc6f40039150b3a45c],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.DataContracts.GetCreditCommand, Quarantined, [ed706ebf04775cda119e7f15689b0ef2],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.DataContracts.GetInstallationContextCommand, Quarantined, [79e4ce5f55260234347b395b2ed5758b],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.DataContracts.GetLoginStatusCommand, Quarantined, [d18c65c88fec0630a9066331c83b14ec],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.DataContracts.GetLoginStatusResult, Quarantined, [f964bb72f4871d19cde2bfd5887b817f],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.DataContracts.GetVariableCommand, Quarantined, [09546fbe0a71c76f228d0d876f946d93],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.DataContracts.GetVariableResult, Quarantined, [24397db05a21e452efc0fa9abe45bc44],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.DataContracts.InstallationContextResult, Quarantined, [124b9d90215a86b0931c3a5a6f942cd4],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.DataContracts.LoadContentCommand, Quarantined, [4a13012c621976c04d62e2b2b25146ba],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.DataContracts.LoadContentCommandResult, Quarantined, [035adb52651681b5c9e6d8bce320946c],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.DataContracts.LoginCommand, Quarantined, [67f62b02e695fb3bf7b8efa5ad56e41c],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.DataContracts.LoginStatusChangedCallback, Quarantined, [2f2eb37a25563ef89a158a0aca3947b9],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.DataContracts.LogoutCommand, Quarantined, [0d5060cdcbb0a591a708326208fbc13f],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.DataContracts.MergeIdentityCommand, Quarantined, [ca9389a4205b10265d52623257ac0bf5],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.DataContracts.MyAccountCommand, Quarantined, [b8a5c06d1f5c87af9a1534607f84a65a],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.DataContracts.PlayContentCommand, Quarantined, [1548ad800378de581e91890b56ada55b],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.DataContracts.PostContentCallback, Quarantined, [382557d6d2a956e04b64c5cfee154fb1],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.DataContracts.RecycleViewsCommand, Quarantined, [5c019796a3d83df9d3dc247061a20ff1],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.DataContracts.SetVariableCommand, Quarantined, [90cd4de03e3d9f9727885044c1422bd5],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.DataContracts.ShowBrowserWindowCommand, Quarantined, [67f6d5587308d36337786d27996a9b65],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.DataContracts.ShowPluginWindowCommand, Quarantined, [0d501c11087339fd6f400d8743c0f709],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.DataContracts.TestContentCommand, Quarantined, [c39a4fde4833ae8809a6692bed16b050],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.DataContracts.UserContentChangedCallback, Quarantined, [97c670bdb8c3ab8bebc4316350b356aa],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.DataContracts.VariableChangedCallback, Quarantined, [025ba08d4734fa3c3976bcd8b84bae52],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.DataContracts.WarmUpCommand, Quarantined, [fb625fce3b40bd791897f59f62a1fb05],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.DataContracts.WelcomeCommand, Quarantined, [de7ff8358cefaa8c307f91039d6611ef],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.ServerCommand, Quarantined, [94c934f90f6ccf67fab51f7534cfc53b],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.Communication.ServerResult, Quarantined, [322bf637f7840135238c1c78d52e1ae6],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.LightContent, Quarantined, [6eef78b59ddec472713e603446bdff01],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.LightUri, Quarantined, [1e3f4ae31962e650149b108401028b75],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent.Mediator.MediatorServiceProxy, Quarantined, [9ac3d05dfa81c373317e5242768d718f],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\Iminent.WebBooster.InternetExplorer.DLL, Quarantined, [4a13bf6eb9c26cca93c4247ceb188c74],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\19979, Quarantined, [e57871bcfc7fae888dadaec628da8c74],
PUP.Optional.Umbrella.A, HKLM\SOFTWARE\WOW6432NODE\UMBRELLA, Quarantined, [8ecf29047efddc5ac6295246e61d7f81],
PUP.Optional.Iminent.A, HKU\S-1-5-21-205120009-107262540-2640116156-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Iminent, Delete-on-Reboot, [06572805c8b35bdb21fc651d8181659b],
PUP.Optional.ResultsAlpha.A, HKU\S-1-5-21-205120009-107262540-2640116156-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\ResultsAlpha, Delete-on-Reboot, [b5a8a6877efd6cca9ae802a4d330b44c],
PUP.Optional.AddPusHD.A, HKU\S-1-5-21-205120009-107262540-2640116156-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\addplushd, Delete-on-Reboot, [3e1f80ad9cdfc175f592baba61a1ed13],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-205120009-107262540-2640116156-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, Delete-on-Reboot, [d786c469502b112574755e4d8182946c],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-205120009-107262540-2640116156-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\19979, Delete-on-Reboot, [70ed48e52457e45295a6680c689a06fa],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-205120009-107262540-2640116156-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\hdideo, Delete-on-Reboot, [a9b4e647790220162069d3a1ee14ec14],
PUP.Optional.Softonic.A, HKU\S-1-5-21-205120009-107262540-2640116156-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, Delete-on-Reboot, [c49931fcfe7d3ef83816c1ae12f060a0],
PUP.Optional.AddPusHD.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{11111111-1111-1111-1111-110511291116}, Quarantined, [f469d4599fdc70c630e00067b84a3fc1],
PUP.Optional.AddPusHD.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110511291116}, Quarantined, [f469d4599fdc70c630e00067b84a3fc1],
PUP.Optional.AddPusHD.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110511291116}, Quarantined, [f469d4599fdc70c630e00067b84a3fc1],
PUP.Optional.AddPusHD.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{22222222-2222-2222-2222-220522292216}, Quarantined, [f469d4599fdc70c630e00067b84a3fc1],
PUP.Optional.AddPusHD.A, HKLM\SOFTWARE\CLASSES\CLSID\{22222222-2222-2222-2222-220522292216}, Quarantined, [f469d4599fdc70c630e00067b84a3fc1],
PUP.Optional.AddPusHD.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\addplushd, Quarantined, [f469d4599fdc70c630e00067b84a3fc1],
Registry Values: 2
PUP.Optional.Umbrella.A, HKLM\SOFTWARE\WOW6432NODE\UMBRELLA|MUpdBlock, {
"MASSUPDATE" : {
"CHROME_MBAR" : {
"Checked" : 1,
"RetryIdx" : 0,
"Version" : 1
},
"FIREFOX_MBAR" : {
"Checked" : 1,
"RetryIdx" : 0,
"Version" : 1
},
"IEXPLORE_BHO" : {
"Checked" : 1,
"RetryIdx" : 0,
"Version" : 4
}
}
}
, Quarantined, [8ecf29047efddc5ac6295246e61d7f81]
PUP.Optional.Iminent.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SPROTECTION|ImagePath, C:\Program Files (x86)\Common Files\Umbrella\umbrella.exe, Quarantined, [124b80adf78430060f8e3064fc07c23e]
Registry Data: 0
(No malicious items detected)
Folders: 58
PUP.Optional.Iminent.A, C:\Program Files (x86)\Iminent, Quarantined, [9dc052dbcdaebb7b217fccc8d033946c],
PUP.Optional.Iminent.A, C:\Program Files (x86)\Iminent\de, Quarantined, [9dc052dbcdaebb7b217fccc8d033946c],
PUP.Optional.Iminent.A, C:\Program Files (x86)\Iminent\en, Quarantined, [9dc052dbcdaebb7b217fccc8d033946c],
PUP.Optional.Iminent.A, C:\Program Files (x86)\Iminent\es, Quarantined, [9dc052dbcdaebb7b217fccc8d033946c],
PUP.Optional.Iminent.A, C:\Program Files (x86)\Iminent\fr, Quarantined, [9dc052dbcdaebb7b217fccc8d033946c],
PUP.Optional.Iminent.A, C:\Program Files (x86)\Iminent\inst, Quarantined, [9dc052dbcdaebb7b217fccc8d033946c],
PUP.Optional.Iminent.A, C:\Program Files (x86)\Iminent\inst\Bootstrapper, Quarantined, [9dc052dbcdaebb7b217fccc8d033946c],
PUP.Optional.Iminent.A, C:\Program Files (x86)\Iminent\it, Quarantined, [9dc052dbcdaebb7b217fccc8d033946c],
PUP.Optional.Iminent.A, C:\Program Files (x86)\Iminent\ro, Quarantined, [9dc052dbcdaebb7b217fccc8d033946c],
PUP.Optional.Iminent.A, C:\Program Files (x86)\Iminent\tr, Quarantined, [9dc052dbcdaebb7b217fccc8d033946c],
PUP.Optional.Iminent.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Iminent, Quarantined, [afae1f0e176441f504f1d0c661a2b749],
PUP.Optional.ResultsAlpha.A, C:\Program Files (x86)\ResultsAlpha, Quarantined, [f26b4be25f1c54e2d0b0e9bd729116ea],
PUP.Optional.ResultsAlpha.A, C:\Program Files (x86)\ResultsAlpha\bin, Quarantined, [f26b4be25f1c54e2d0b0e9bd729116ea],
PUP.Optional.Iminent.A, C:\ProgramData\Iminent\Mediator, Quarantined, [66f779b495e69e98bf62c0a0d62c01ff],
PUP.Optional.Iminent.A, C:\ProgramData\Iminent\Mediator\Datas, Quarantined, [66f779b495e69e98bf62c0a0d62c01ff],
PUP.Optional.Iminent.A, C:\ProgramData\Iminent\Mediator\Datas\Cache, Quarantined, [66f779b495e69e98bf62c0a0d62c01ff],
PUP.Optional.Iminent.A, C:\ProgramData\Iminent\Mediator\Datas\Cache\apix.iminent.com, Quarantined, [66f779b495e69e98bf62c0a0d62c01ff],
PUP.Optional.Iminent.A, C:\Users\Martin\AppData\Roaming\Iminent\Mediator, Quarantined, [431af934f78434023fe265fb43bfc13f],
PUP.Optional.Iminent.A, C:\Users\Martin\AppData\Roaming\Iminent\Mediator\Datas, Quarantined, [431af934f78434023fe265fb43bfc13f],
PUP.Optional.Conduit, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl, Quarantined, [72eb5fce681385b1b3702240c73bdd23],
PUP.Optional.Conduit, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl\7.48.1.1_0, Quarantined, [72eb5fce681385b1b3702240c73bdd23],
PUP.Optional.Conduit, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl\7.48.1.1_0\images, Quarantined, [72eb5fce681385b1b3702240c73bdd23],
PUP.Optional.Conduit, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl\7.48.1.1_0\scripts, Quarantined, [72eb5fce681385b1b3702240c73bdd23],
PUP.Optional.Conduit, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl\7.48.1.1_0\scripts\jquery, Quarantined, [72eb5fce681385b1b3702240c73bdd23],
PUP.Optional.Conduit, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl\7.48.1.1_0\scripts\lib, Quarantined, [72eb5fce681385b1b3702240c73bdd23],
PUP.Optional.Conduit, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl\7.48.1.1_0\scripts\minibar, Quarantined, [72eb5fce681385b1b3702240c73bdd23],
PUP.Optional.Conduit, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl\7.48.1.1_0\scripts\minibar\adapters, Quarantined, [72eb5fce681385b1b3702240c73bdd23],
PUP.Optional.Conduit, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl\7.48.1.1_0\scripts\minibar\content, Quarantined, [72eb5fce681385b1b3702240c73bdd23],
PUP.Optional.Conduit, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl\7.48.1.1_0\scripts\minibar\content\fx2, Quarantined, [72eb5fce681385b1b3702240c73bdd23],
PUP.Optional.Conduit, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl\7.48.1.1_0\scripts\minibar\content\fx2\off, Quarantined, [72eb5fce681385b1b3702240c73bdd23],
PUP.Optional.Conduit, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl\7.48.1.1_0\scripts\minibar\content\fx2\on, Quarantined, [72eb5fce681385b1b3702240c73bdd23],
PUP.Optional.Conduit, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl\7.48.1.1_0\scripts\minibar\content\images, Quarantined, [72eb5fce681385b1b3702240c73bdd23],
PUP.Optional.Conduit, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl\7.48.1.1_0\scripts\minibar\content\images\bhp, Quarantined, [72eb5fce681385b1b3702240c73bdd23],
PUP.Optional.Conduit, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl\7.48.1.1_0\scripts\minibar\content\images\emoji, Quarantined, [72eb5fce681385b1b3702240c73bdd23],
PUP.Optional.Conduit, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl\7.48.1.1_0\scripts\minibar\content\images\ql, Quarantined, [72eb5fce681385b1b3702240c73bdd23],
PUP.Optional.Conduit, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl\7.48.1.1_0\scripts\minibar\games, Quarantined, [72eb5fce681385b1b3702240c73bdd23],
PUP.Optional.Conduit, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl\7.48.1.1_0\scripts\minibar\menu_page, Quarantined, [72eb5fce681385b1b3702240c73bdd23],
PUP.Optional.Conduit, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl\7.48.1.1_0\scripts\minibar\services, Quarantined, [72eb5fce681385b1b3702240c73bdd23],
PUP.Optional.Conduit, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl\7.48.1.1_0\_locales, Quarantined, [72eb5fce681385b1b3702240c73bdd23],
PUP.Optional.Conduit, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl\7.48.1.1_0\_locales\de, Quarantined, [72eb5fce681385b1b3702240c73bdd23],
PUP.Optional.Conduit, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl\7.48.1.1_0\_locales\en, Quarantined, [72eb5fce681385b1b3702240c73bdd23],
PUP.Optional.Conduit, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl\7.48.1.1_0\_locales\es, Quarantined, [72eb5fce681385b1b3702240c73bdd23],
PUP.Optional.Conduit, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl\7.48.1.1_0\_locales\fr, Quarantined, [72eb5fce681385b1b3702240c73bdd23],
PUP.Optional.Conduit, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl\7.48.1.1_0\_locales\it, Quarantined, [72eb5fce681385b1b3702240c73bdd23],
PUP.Optional.Conduit, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl\7.48.1.1_0\_locales\pt_BR, Quarantined, [72eb5fce681385b1b3702240c73bdd23],
PUP.Optional.Conduit, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl\7.48.1.1_0\_locales\tr, Quarantined, [72eb5fce681385b1b3702240c73bdd23],
PUP.Optional.AddPusHD.A, C:\Program Files (x86)\addplushd, Quarantined, [f469d4599fdc70c630e00067b84a3fc1],
PUP.Optional.CrossRider.A, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe, Quarantined, [d4891815cdaed56170a122454ab802fe],
PUP.Optional.CrossRider.A, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0, Quarantined, [d4891815cdaed56170a122454ab802fe],
PUP.Optional.CrossRider.A, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData, Quarantined, [d4891815cdaed56170a122454ab802fe],
PUP.Optional.CrossRider.A, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\plugins, Quarantined, [d4891815cdaed56170a122454ab802fe],
PUP.Optional.CrossRider.A, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\extensionData\userCode, Quarantined, [d4891815cdaed56170a122454ab802fe],
PUP.Optional.CrossRider.A, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\icons, Quarantined, [d4891815cdaed56170a122454ab802fe],
PUP.Optional.CrossRider.A, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\icons\actions, Quarantined, [d4891815cdaed56170a122454ab802fe],
PUP.Optional.CrossRider.A, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\js, Quarantined, [d4891815cdaed56170a122454ab802fe],
PUP.Optional.CrossRider.A, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\js\api, Quarantined, [d4891815cdaed56170a122454ab802fe],
PUP.Optional.CrossRider.A, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\js\lib, Quarantined, [d4891815cdaed56170a122454ab802fe],
PUP.Optional.CrossRider.A, C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.20_0\js\lib\popupResource, Quarantined, [d4891815cdaed56170a122454ab802fe], Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-04-25 20:33:26
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 ST3500418AS rev.CC38 465,76GB
Running: Gmer-19357.exe; Driver: C:\Users\Martin\AppData\Local\Temp\pxdiafow.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff800035b9000 45 bytes [00, 00, 00, 00, 00, 00, 00, ...]
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 575 fffff800035b902f 23 bytes [00, 00, 00, 00, 00, 00, 00, ...]
.text C:\Windows\system32\DRIVERS\USBPORT.SYS!DllUnload fffff88011f52d8c 12 bytes {MOV RAX, 0xfffffa8003f802a0; JMP RAX}
---- User code sections - GMER 2.1 ----
.text C:\Users\Martin\Desktop\Spiele\Metro2033\Steam.exe[2696] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 0000000077461465 2 bytes [46, 77]
.text C:\Users\Martin\Desktop\Spiele\Metro2033\Steam.exe[2696] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 00000000774614bb 2 bytes [46, 77]
.text ... * 2
---- Devices - GMER 2.1 ----
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 fffffa80027a92c0
Device \Driver\atapi \Device\Ide\IdePort0 fffffa80027a92c0
Device \Driver\atapi \Device\Ide\IdePort1 fffffa80027a92c0
Device \Driver\atapi \Device\Ide\IdePort2 fffffa80027a92c0
Device \Driver\atapi \Device\Ide\IdePort3 fffffa80027a92c0
Device \Driver\aj8vws8x \Device\Scsi\aj8vws8x1 fffffa80041812c0
Device \Driver\aj8vws8x \Device\Scsi\aj8vws8x1Port5Path0Target1Lun0 fffffa80041812c0
Device \Driver\aj8vws8x \Device\Scsi\aj8vws8x1Port5Path0Target0Lun0 fffffa80041812c0
Device \Driver\aj8vws8x \Device\Scsi\aj8vws8x1Port5Path0Target3Lun0 fffffa80041812c0
Device \Driver\aj8vws8x \Device\Scsi\aj8vws8x1Port5Path0Target2Lun0 fffffa80041812c0
Device \FileSystem\Ntfs \Ntfs fffffa80027ad2c0
Device \Driver\usbohci \Device\USBPDO-5 fffffa80040982c0
Device \Driver\usbehci \Device\USBFDO-3 fffffa800409a2c0
Device \Driver\NetBT \Device\NetBT_Tcpip_{C12C0FE1-CD7B-4E57-9E25-434124CB3406} fffffa8003d982c0
Device \Driver\usbehci \Device\USBPDO-1 fffffa800409a2c0
Device \Driver\cdrom \Device\CdRom0 fffffa8003dfb2c0
Device \Driver\cdrom \Device\CdRom1 fffffa8003dfb2c0
Device \Driver\cdrom \Device\CdRom2 fffffa8003dfb2c0
Device \Driver\cdrom \Device\CdRom3 fffffa8003dfb2c0
Device \Driver\cdrom \Device\CdRom4 fffffa8003dfb2c0
Device \Driver\usbehci \Device\USBPDO-6 fffffa800409a2c0
Device \Driver\usbohci \Device\USBFDO-4 fffffa80040982c0
Device \Driver\usbohci \Device\USBPDO-2 fffffa80040982c0
Device \Driver\usbohci \Device\USBFDO-0 fffffa80040982c0
Device \Driver\usbohci \Device\USBFDO-5 fffffa80040982c0
Device \Driver\usbehci \Device\USBPDO-3 fffffa800409a2c0
Device \Driver\usbehci \Device\USBFDO-1 fffffa800409a2c0
Device \Driver\volmgr \Device\HarddiskVolume1 fffffa80027a52c0
Device \Driver\volmgr \Device\FtControl fffffa80027a52c0
Device \Driver\volmgr \Device\VolMgrControl fffffa80027a52c0
Device \Driver\volmgr \Device\HarddiskVolume2 fffffa80027a52c0
Device \Driver\NetBT \Device\NetBT_Tcpip_{13987129-3E56-4378-A3C8-6CE5BCA1EB34} fffffa8003d982c0
Device \Driver\NetBT \Device\NetBt_Wins_Export fffffa8003d982c0
Device \Driver\usbehci \Device\USBFDO-6 fffffa800409a2c0
Device \Driver\NetBT \Device\NetBT_Tcpip_{4DB66B84-5481-4440-81C7-C3EDA3C911B5} fffffa8003d982c0
Device \Driver\usbohci \Device\USBPDO-4 fffffa80040982c0
Device \Driver\usbohci \Device\USBFDO-2 fffffa80040982c0
Device \Driver\usbohci \Device\USBPDO-0 fffffa80040982c0
Device \Driver\atapi \Device\ScsiPort1 fffffa80027a92c0
Device \Driver\atapi \Device\ScsiPort2 fffffa80027a92c0
Device \Driver\atapi \Device\ScsiPort3 fffffa80027a92c0
Device \Driver\atapi \Device\ScsiPort4 fffffa80027a92c0
Device \Driver\aj8vws8x \Device\ScsiPort5 fffffa80041812c0
---- Trace I/O - GMER 2.1 ----
Trace ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys >>UNKNOWN [0xfffffa80027a92c0]<< spye.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys fffffa80027a92c0
Trace 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80037dd790] fffffa80037dd790
Trace 3 CLASSPNP.SYS[fffff88001a5743f] -> nt!IofCallDriver -> [0xfffffa8003759560] fffffa8003759560
Trace 5 ACPI.sys[fffff8800100b7a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa800375b680] fffffa800375b680
Trace \Driver\atapi[0xfffffa8002888e70] -> IRP_MJ_CREATE -> 0xfffffa80027a92c0 fffffa80027a92c0
---- Modules - GMER 2.1 ----
Module \SystemRoot\System32\Drivers\aj8vws8x.SYS fffff88011285000-fffff880112ca000 (282624 bytes)
---- Threads - GMER 2.1 ----
Thread C:\Windows\System32\svchost.exe [4776:4860] 000007feefa59688
---- Processes - GMER 2.1 ----
Library C:\Users\Martin\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll (*** suspicious ***) @ C:\Windows\Explorer.EXE [1740] (Dropbox Shell Extension/Dropbox, Inc.)(2011-02-18 05:12:20) 0000000010000000
Library C:\Users\Martin\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll (*** suspicious ***) @ C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe [2244] (Dropbox Shell Extension/Dropbox, Inc.)(2011-02-18 05:12:20) 0000000003890000
Library C:\Users\Martin\AppData\Roaming\Dropbox\bin\MSVCP71.dll (*** suspicious ***) @ C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe [2244] (Microsoft® C++ Runtime Library/Microsoft Corporation)(2011-02-18 05:12:24) 000000007c3a0000
Library C:\Users\Martin\AppData\Roaming\Dropbox\bin\MSVCR71.dll (*** suspicious ***) @ C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe [2244] (Microsoft® C Runtime Library/Microsoft Corporation)(2008-03-04 00:34:38) 000000007c340000
Library C:\ProgramData\Razer\Synapse\Devices\RazerConfigNative.dll (*** suspicious ***) @ C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [3032] (Razer Configurator/Razer Inc.)(2014-03-14 06:33:22) 0000000054a30000
Library C:\Users\Martin\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll (*** suspicious ***) @ C:\Program Files\Java\jre6\bin\javaw.exe [1428] (Dropbox Shell Extension/Dropbox, Inc.)(2011-02-18 05:12:20) 0000000010000000
Library C:\Users\Martin\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll (*** suspicious ***) @ C:\Windows\explorer.exe [424] (Dropbox Shell Extension/Dropbox, Inc.)(2011-02-18 05:12:20) 0000000010000000
Library C:\Users\Martin\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll (*** suspicious ***) @ C:\Windows\system32\notepad.exe [6004] (Dropbox Shell Extension/Dropbox, Inc.)(2011-02-18 05:12:20) 0000000010000000
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xCE 0x89 0xC4 0xDD ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xFD 0x76 0xD4 0x88 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x43 0x3A 0x94 0x7E ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x31 0x19 0x10 0x3B ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2@hdf12 0x6B 0x2D 0x37 0x97 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3@hdf12 0x4D 0xBF 0x4D 0x39 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xCE 0x89 0xC4 0xDD ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xFD 0x76 0xD4 0x88 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x43 0x3A 0x94 0x7E ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x31 0x19 0x10 0x3B ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2@hdf12 0x6B 0x2D 0x37 0x97 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3@hdf12 0x4D 0xBF 0x4D 0x39 ...
---- EOF - GMER 2.1 ---- |