ESET- C:\Users\All Users\{587CB0BF-08FE-6139-B978-11BB69FAC235}\1.7.1.0\colo.dll.mwt a variant of Win32/DealPly.AP potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Consumer Input\CIuninstall.exe.vir a variant of Win32/Compete.C potentially unwanted application deleted
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Consumer Input\InternetExplorer\uninstall.exe.vir a variant of Win32/Compete.C potentially unwanted application deleted
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Consumer Input\Update\1.3.25.309\goopdate.dll.vir a variant of Win32/Compete.A potentially unwanted application cleaned by deleting
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Consumer Input\Update\1.3.25.309\psmachine.dll.vir a variant of Win32/Compete.A potentially unwanted application cleaned by deleting
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Consumer Input\Update\1.3.25.309\psuser.dll.vir a variant of Win32/Compete.A potentially unwanted application cleaned by deleting
C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.3.0\LavasoftLSPInstaller64.exe a variant of Win64/Packed.Komodia.A suspicious application cleaned by deleting
C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.3.0\LavasoftTcpService64.dll a variant of Win64/Packed.Komodia.A suspicious application cleaned by deleting
C:\ProgramData\{587CB0BF-08FE-6139-B978-11BB69FAC235}\1.7.1.0\colo.dll.mwt a variant of Win32/DealPly.AP potentially unwanted application cleaned by deleting
C:\Users\Andrew\AppData\Local\Temp\in668B1079\1E0D3EB1_stp\RAM.dll a variant of Win32/InstallCore.ACL potentially unwanted application cleaned by deleting
C:\Users\Andrew\AppData\Local\Temp\in668B1079\1F6AB224_stp\icmac.dll a variant of Win32/InstallCore.ACL potentially unwanted application cleaned by deleting
C:\Users\Andrew\AppData\Local\Temp\in679F052E\2AA7F4B2_stp\wzro36.exe a variant of Win32/Systweak potentially unwanted application deleted
C:\Users\Andrew\AppData\Local\{28FF1EA3-0C57-721B-61CF-57F345A7AB6B}\uninstall.exe a variant of Win32/DealPly.CS potentially unwanted application cleaned by deleting
C:\Users\Andrew\AppData\Roaming\uTorrent\updates\3.4.2_34537.exe a variant of Win32/AdkDLLWrapper.A potentially unwanted application cleaned by deleting
C:\Users\Andrew\Downloads\AdwCleaner%20Setup.exe a variant of Win32/InstallCore.AFW potentially unwanted application cleaned by deleting
C:\Users\Andrew\Downloads\uTorrent.exe a variant of Win32/AdkDLLWrapper.A potentially unwanted application cleaned by deleting
C:\Windows\System32\LavasoftTcpService64.dll a variant of Win64/Packed.Komodia.A suspicious application cleaned by deleting
C:\Windows\System32\roboot64.exe a variant of Win64/Systweak.A potentially unwanted application cleaned by deleting
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 3/23/2016
Scan Time: 7:55 PM
Logfile: MWB.txt
Administrator: Yes
Version: 2.2.1.1043
Malware Database: v2016.03.23.06
Rootkit Database: v2016.03.12.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Andrew
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 411701
Time Elapsed: 43 min, 41 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 1
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11130\ScreenShotServ.exe, 3180, Delete-on-Reboot, [7fb34a41d5c455e1dd744bfa23e1e818]
Modules: 3
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11130\EVPDR.dll, Delete-on-Reboot, [7fb34a41d5c455e1dd744bfa23e1e818],
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11130\EVPNet.dll, Delete-on-Reboot, [7fb34a41d5c455e1dd744bfa23e1e818],
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11130\EVPTask.dll, Delete-on-Reboot, [7fb34a41d5c455e1dd744bfa23e1e818],
Registry Keys: 12
PUP.Optional.ScreenSnapShotTool, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{61FFE1F9-137D-4c31-A181-3415FCAA5946}, Quarantined, [7fb34a41d5c455e1dd744bfa23e1e818],
PUP.Optional.ScreenSnapShotTool, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TheScreenSnapshotService, Quarantined, [7fb34a41d5c455e1dd744bfa23e1e818],
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, Quarantined, [57db32590297a98da9135b229e6604fc],
PUP.Optional.ScreenSnapShotTool, HKLM\SOFTWARE\SCREENSNAPSHOTTOOL, Quarantined, [ff33ec9fc9d0d4629db2bc8d6d9713ed],
PUP.Optional.NowUSeeItPlayer, HKLM\SOFTWARE\WOW6432NODE\NowUSeeItPlayer, Quarantined, [5ad82a61dbbee74f11959dda6e969967],
PUP.Optional.NowUSeeItPlayer, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{C0AFC06A-6C9E-420F-AABF-B1AC7EE1F589}, Quarantined, [a58d8308a3f690a614d5e0a429db3cc4],
PUP.Optional.WinZipRegOp, HKLM\SOFTWARE\WOW6432NODE\NICO MAK COMPUTING\WinZip Registry Optimizer, Quarantined, [ab87791226730b2be6c72c6956aea15f],
PUP.Optional.InstallCore, HKU\S-1-5-21-1378875358-1120829428-2694025308-1001\SOFTWARE\ICSW1.19, Quarantined, [3df5deade4b5aa8c78880c105da713ed],
Adware.NowUSeeIt, HKU\S-1-5-21-1378875358-1120829428-2694025308-1001\SOFTWARE\NowUSeeItPlayer, Quarantined, [ab870388efaa52e4d230452848bc40c0],
PUP.Optional.WinYahoo, HKU\S-1-5-21-1378875358-1120829428-2694025308-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, Quarantined, [aa883358e6b3e84e873405786d97659b],
PUP.Optional.WinZipRegOp, HKU\S-1-5-21-1378875358-1120829428-2694025308-1001\SOFTWARE\NICO MAK COMPUTING\WinZip Registry Optimizer, Quarantined, [042e8ffc0f8a6dc9d465fa86867ef20e],
PUP.Optional.ProductSetup, HKU\S-1-5-21-1378875358-1120829428-2694025308-1001\SOFTWARE\PRODUCTSETUP, Quarantined, [5dd5f299871265d10cb264c75da76997],
Registry Values: 10
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, https://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_omxmedia_16_12_ssg03¶m1=1¶m2=f[57db32590297a98da9135b229e6604fc]D4%26b[57db32590297a98da9135b229e6604fc]DIE%26cc[57db32590297a98da9135b229e6604fc]Dus%26pa[57db32590297a98da9135b229e6604fc]DWincy%26cd[57db32590297a98da9135b229e6604fc]D2XzuyEtN2Y1L1Qzu0EzztDtAzy0AtC0F0BtDzy0Ezy0CtB0BtN0D0Tzu0StCyDyEtCtN1L2XzutAtFtBtDtFtDtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2StAtD0AtByD0EyBtDtGtAzyyDtCtGzytD0CyDtGyDtD0FtBtG0A0EtD0EtBtB0FzyyCyEyE0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyByE0AyD0D0Dzy0FtGtCyCzz0EtGyE0CzzyDtG0AyBzzyEtGyD0C0BtBtA0FtBzztAyCtB0D2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCyByBtC%26cr[57db32590297a98da9135b229e6604fc]D505644883%26a[57db32590297a98da9135b229e6604fc]Dwbf_omxmedia_16_12_ssg03%26os_ver[57db32590297a98da9135b229e6604fc]D6.1%26os[57db32590297a98da9135b229e6604fc]DWindowsQuarantinedB7QuarantinedBHomeQuarantinedBPremium&p={searchTerms}, %4, %5
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|TopResultURLFallback, https://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_omxmedia_16_12_ssg03¶m1=1¶m2=f[fe341576b3e68fa72696dca1768e5da3]D4%26b[fe341576b3e68fa72696dca1768e5da3]DIE%26cc[fe341576b3e68fa72696dca1768e5da3]Dus%26pa[fe341576b3e68fa72696dca1768e5da3]DWincy%26cd[fe341576b3e68fa72696dca1768e5da3]D2XzuyEtN2Y1L1Qzu0EzztDtAzy0AtC0F0BtDzy0Ezy0CtB0BtN0D0Tzu0StCyDyEtCtN1L2XzutAtFtBtDtFtDtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2StAtD0AtByD0EyBtDtGtAzyyDtCtGzytD0CyDtGyDtD0FtBtG0A0EtD0EtBtB0FzyyCyEyE0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyByE0AyD0D0Dzy0FtGtCyCzz0EtGyE0CzzyDtG0AyBzzyEtGyD0C0BtBtA0FtBzztAyCtB0D2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCyByBtC%26cr[fe341576b3e68fa72696dca1768e5da3]D505644883%26a[fe341576b3e68fa72696dca1768e5da3]Dwbf_omxmedia_16_12_ssg03%26os_ver[fe341576b3e68fa72696dca1768e5da3]D6.1%26os[fe341576b3e68fa72696dca1768e5da3]DWindowsQuarantinedB7QuarantinedBHomeQuarantinedBPremium&p={searchTerms}, %4, %5
PUP.Optional.ScreenSnapShotTool, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{61FFE1F9-137D-4c31-A181-3415FCAA5946}|DisplayIcon, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11130\ScreenSnapshot.exe, Quarantined, [73bf3259554489ad381eaf96d62eb14f]
PUP.Optional.ScreenSnapShotTool, HKLM\SOFTWARE\SCREENSNAPSHOTTOOL|PartnerID, Installchannel2|us|IBD|Bundle, Quarantined, [ff33ec9fc9d0d4629db2bc8d6d9713ed]
PUP.Optional.NowUSeeItPlayer, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|NowUSeeIt Player, "C:\Program Files (x86)\NowUSeeItPlayer\NowUSeeItPlayer.exe" /autostart=1, Quarantined, [d95906859108b77f22dc8f02d0341ae6]
PUP.Optional.NowUSeeItPlayer, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{C0AFC06A-6C9E-420F-AABF-B1AC7EE1F589}|DisplayName, NowUSeeIt Player, Quarantined, [a58d8308a3f690a614d5e0a429db3cc4]
PUP.Optional.WinYahoo, HKU\S-1-5-21-1378875358-1120829428-2694025308-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, https://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_omxmedia_16_12_ssg03¶m1=1¶m2=f[aa883358e6b3e84e873405786d97659b]D4%26b[aa883358e6b3e84e873405786d97659b]DIE%26cc[aa883358e6b3e84e873405786d97659b]Dus%26pa[aa883358e6b3e84e873405786d97659b]DWincy%26cd[aa883358e6b3e84e873405786d97659b]D2XzuyEtN2Y1L1Qzu0EzztDtAzy0AtC0F0BtDzy0Ezy0CtB0BtN0D0Tzu0StCyDyEtCtN1L2XzutAtFtBtDtFtDtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2StAtD0AtByD0EyBtDtGtAzyyDtCtGzytD0CyDtGyDtD0FtBtG0A0EtD0EtBtB0FzyyCyEyE0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyByE0AyD0D0Dzy0FtGtCyCzz0EtGyE0CzzyDtG0AyBzzyEtGyD0C0BtBtA0FtBzztAyCtB0D2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCyByBtC%26cr[aa883358e6b3e84e873405786d97659b]D505644883%26a[aa883358e6b3e84e873405786d97659b]Dwbf_omxmedia_16_12_ssg03%26os_ver[aa883358e6b3e84e873405786d97659b]D6.1%26os[aa883358e6b3e84e873405786d97659b]DWindowsQuarantinedB7QuarantinedBHomeQuarantinedBPremium&p={searchTerms}, %4, %5
PUP.Optional.WinYahoo, HKU\S-1-5-21-1378875358-1120829428-2694025308-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|TopResultURLFallback, https://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_omxmedia_16_12_ssg03¶m1=1¶m2=f[86acb6d5227735012893166748bc07f9]D4%26b[86acb6d5227735012893166748bc07f9]DIE%26cc[86acb6d5227735012893166748bc07f9]Dus%26pa[86acb6d5227735012893166748bc07f9]DWincy%26cd[86acb6d5227735012893166748bc07f9]D2XzuyEtN2Y1L1Qzu0EzztDtAzy0AtC0F0BtDzy0Ezy0CtB0BtN0D0Tzu0StCyDyEtCtN1L2XzutAtFtBtDtFtDtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2StAtD0AtByD0EyBtDtGtAzyyDtCtGzytD0CyDtGyDtD0FtBtG0A0EtD0EtBtB0FzyyCyEyE0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyByE0AyD0D0Dzy0FtGtCyCzz0EtGyE0CzzyDtG0AyBzzyEtGyD0C0BtBtA0FtBzztAyCtB0D2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCyByBtC%26cr[86acb6d5227735012893166748bc07f9]D505644883%26a[86acb6d5227735012893166748bc07f9]Dwbf_omxmedia_16_12_ssg03%26os_ver[86acb6d5227735012893166748bc07f9]D6.1%26os[86acb6d5227735012893166748bc07f9]DWindowsQuarantinedB7QuarantinedBHomeQuarantinedBPremium&p={searchTerms}, %4, %5
Adware.NowUSeeIt, HKU\S-1-5-21-1378875358-1120829428-2694025308-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|NowUSeeIt Player, "C:\Program Files (x86)\NowUSeeItPlayer\NowUSeeItPlayer.exe" /autostart=1, Quarantined, [b18192f99ffa2d09de835b1852b2b54b]
PUP.Optional.ProductSetup, HKU\S-1-5-21-1378875358-1120829428-2694025308-1001\SOFTWARE\PRODUCTSETUP|tb, 0P1S1S1F1D1B2W2O0M2W1D1F1F1G2O, Quarantined, [5dd5f299871265d10cb264c75da76997]
Registry Data: 1
PUP.Optional.WinYahoo, HKU\S-1-5-21-1378875358-1120829428-2694025308-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_omxmedia_16_12_ssg03¶m1=1¶m2=fBad: (https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_omxmedia_16_12_ssg03¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0EzztDtAzy0AtC0F0BtDzy0Ezy0CtB0BtN0D0Tzu0StCyDyEtCtN1L2XzutAtFtBtDtFtDtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2StAtD0AtByD0EyBtDtGtAzyyDtCtGzytD0CyDtGyDtD0FtBtG0A0EtD0EtBtB0FzyyCyEyE0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyByE0AyD0D0Dzy0FtGtCyCzz0EtGyE0CzzyDtG0AyBzzyEtGyD0C0BtBtA0FtBzztAyCtB0D2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCyByBtC%26cr%3D505644883%26a%3Dwbf_omxmedia_16_12_ssg03%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium),Replaced,[e949315aaeeba393f08a2502c93c41bf]D1%26bBad: (https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_omxmedia_16_12_ssg03¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0EzztDtAzy0AtC0F0BtDzy0Ezy0CtB0BtN0D0Tzu0StCyDyEtCtN1L2XzutAtFtBtDtFtDtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2StAtD0AtByD0EyBtDtGtAzyyDtCtGzytD0CyDtGyDtD0FtBtG0A0EtD0EtBtB0FzyyCyEyE0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyByE0AyD0D0Dzy0FtGtCyCzz0EtGyE0CzzyDtG0AyBzzyEtGyD0C0BtBtA0FtBzztAyCtB0D2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCyByBtC%26cr%3D505644883%26a%3Dwbf_omxmedia_16_12_ssg03%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium),Replaced,[e949315aaeeba393f08a2502c93c41bf]DIE%26ccBad: (https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_omxmedia_16_12_ssg03¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0EzztDtAzy0AtC0F0BtDzy0Ezy0CtB0BtN0D0Tzu0StCyDyEtCtN1L2XzutAtFtBtDtFtDtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2StAtD0AtByD0EyBtDtGtAzyyDtCtGzytD0CyDtGyDtD0FtBtG0A0EtD0EtBtB0FzyyCyEyE0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyByE0AyD0D0Dzy0FtGtCyCzz0EtGyE0CzzyDtG0AyBzzyEtGyD0C0BtBtA0FtBzztAyCtB0D2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCyByBtC%26cr%3D505644883%26a%3Dwbf_omxmedia_16_12_ssg03%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium),Replaced,[e949315aaeeba393f08a2502c93c41bf]Dus%26paBad: (https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_omxmedia_16_12_ssg03¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0EzztDtAzy0AtC0F0BtDzy0Ezy0CtB0BtN0D0Tzu0StCyDyEtCtN1L2XzutAtFtBtDtFtDtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2StAtD0AtByD0EyBtDtGtAzyyDtCtGzytD0CyDtGyDtD0FtBtG0A0EtD0EtBtB0FzyyCyEyE0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyByE0AyD0D0Dzy0FtGtCyCzz0EtGyE0CzzyDtG0AyBzzyEtGyD0C0BtBtA0FtBzztAyCtB0D2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCyByBtC%26cr%3D505644883%26a%3Dwbf_omxmedia_16_12_ssg03%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium),Replaced,[e949315aaeeba393f08a2502c93c41bf]DWincy%26cdBad: (https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_omxmedia_16_12_ssg03¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0EzztDtAzy0AtC0F0BtDzy0Ezy0CtB0BtN0D0Tzu0StCyDyEtCtN1L2XzutAtFtBtDtFtDtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2StAtD0AtByD0EyBtDtGtAzyyDtCtGzytD0CyDtGyDtD0FtBtG0A0EtD0EtBtB0FzyyCyEyE0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyByE0AyD0D0Dzy0FtGtCyCzz0EtGyE0CzzyDtG0AyBzzyEtGyD0C0BtBtA0FtBzztAyCtB0D2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCyByBtC%26cr%3D505644883%26a%3Dwbf_omxmedia_16_12_ssg03%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium),Replaced,[e949315aaeeba393f08a2502c93c41bf]D2XzuyEtN2Y1L1Qzu0EzztDtAzy0AtC0F0BtDzy0Ezy0CtB0BtN0D0Tzu0StCyDyEtCtN1L2XzutAtFtBtDtFtDtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2StAtD0AtByD0EyBtDtGtAzyyDtCtGzytD0CyDtGyDtD0FtBtG0A0EtD0EtBtB0FzyyCyEyE0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyByE0AyD0D0Dzy0FtGtCyCzz0EtGyE0CzzyDtG0AyBzzyEtGyD0C0BtBtA0FtBzztAyCtB0D2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCyByBtC%26crBad: (https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_omxmedia_16_12_ssg03¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0EzztDtAzy0AtC0F0BtDzy0Ezy0CtB0BtN0D0Tzu0StCyDyEtCtN1L2XzutAtFtBtDtFtDtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2StAtD0AtByD0EyBtDtGtAzyyDtCtGzytD0CyDtGyDtD0FtBtG0A0EtD0EtBtB0FzyyCyEyE0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyByE0AyD0D0Dzy0FtGtCyCzz0EtGyE0CzzyDtG0AyBzzyEtGyD0C0BtBtA0FtBzztAyCtB0D2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCyByBtC%26cr%3D505644883%26a%3Dwbf_omxmedia_16_12_ssg03%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium),Replaced,[e949315aaeeba393f08a2502c93c41bf]D505644883%26aBad: (https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_omxmedia_16_12_ssg03¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0EzztDtAzy0AtC0F0BtDzy0Ezy0CtB0BtN0D0Tzu0StCyDyEtCtN1L2XzutAtFtBtDtFtDtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2StAtD0AtByD0EyBtDtGtAzyyDtCtGzytD0CyDtGyDtD0FtBtG0A0EtD0EtBtB0FzyyCyEyE0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyByE0AyD0D0Dzy0FtGtCyCzz0EtGyE0CzzyDtG0AyBzzyEtGyD0C0BtBtA0FtBzztAyCtB0D2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCyByBtC%26cr%3D505644883%26a%3Dwbf_omxmedia_16_12_ssg03%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium),Replaced,[e949315aaeeba393f08a2502c93c41bf]Dwbf_omxmedia_16_12_ssg03%26os_verBad: (https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_omxmedia_16_12_ssg03¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0EzztDtAzy0AtC0F0BtDzy0Ezy0CtB0BtN0D0Tzu0StCyDyEtCtN1L2XzutAtFtBtDtFtDtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2StAtD0AtByD0EyBtDtGtAzyyDtCtGzytD0CyDtGyDtD0FtBtG0A0EtD0EtBtB0FzyyCyEyE0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyByE0AyD0D0Dzy0FtGtCyCzz0EtGyE0CzzyDtG0AyBzzyEtGyD0C0BtBtA0FtBzztAyCtB0D2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCyByBtC%26cr%3D505644883%26a%3Dwbf_omxmedia_16_12_ssg03%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium),Replaced,[e949315aaeeba393f08a2502c93c41bf]D6.1%26osBad: (https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_omxmedia_16_12_ssg03¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0EzztDtAzy0AtC0F0BtDzy0Ezy0CtB0BtN0D0Tzu0StCyDyEtCtN1L2XzutAtFtBtDtFtDtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2StAtD0AtByD0EyBtDtGtAzyyDtCtGzytD0CyDtGyDtD0FtBtG0A0EtD0EtBtB0FzyyCyEyE0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyByE0AyD0D0Dzy0FtGtCyCzz0EtGyE0CzzyDtG0AyBzzyEtGyD0C0BtBtA0FtBzztAyCtB0D2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCyByBtC%26cr%3D505644883%26a%3Dwbf_omxmedia_16_12_ssg03%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium),Replaced,[e949315aaeeba393f08a2502c93c41bf]DWindowsGood: (www.google.com)B7Good: (www.google.com)BHomeGood: (www.google.com)BPremium, %4, %5
Folders: 6
PUP.Optional.ScreenSnapShotTool, C:\Users\Andrew\AppData\Roaming\ScreenSnapshotTool\dump, Quarantined, [65cd8308dfba84b29bb5dd685ca8eb15],
PUP.Optional.ScreenSnapShotTool, C:\Users\Andrew\AppData\Roaming\ScreenSnapshotTool, Quarantined, [65cd8308dfba84b29bb5dd685ca8eb15],
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11130, Delete-on-Reboot, [7fb34a41d5c455e1dd744bfa23e1e818],
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11130\EVPData, Quarantined, [7fb34a41d5c455e1dd744bfa23e1e818],
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool, Delete-on-Reboot, [7fb34a41d5c455e1dd744bfa23e1e818],
PUP.Optional.ScreenSnapshot, C:\Users\Public\Documents\Guid\Common\I18N\IPCSUpdateCache\ScreenSnapshot, Quarantined, [a9895a3192070531ec19bb63aa59ad53],
Files: 20
PUP.Optional.WinZipRegOp, C:\Users\Public\Desktop\WinZip Registry Optimizer.lnk, Quarantined, [fa38e2a96732eb4b2b5ffa45ff0542be],
PUP.Optional.ScreenSnapShotTool, C:\Users\Andrew\AppData\Roaming\ScreenSnapshotTool\dump\BugReportConfig.ini, Quarantined, [65cd8308dfba84b29bb5dd685ca8eb15],
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11130\CrashReportModuleConf.ini, Quarantined, [7fb34a41d5c455e1dd744bfa23e1e818],
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11130\CrashReport.exe, Quarantined, [7fb34a41d5c455e1dd744bfa23e1e818],
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11130\CrashUL.exe, Quarantined, [7fb34a41d5c455e1dd744bfa23e1e818],
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11130\EVPConfig.ini, Quarantined, [7fb34a41d5c455e1dd744bfa23e1e818],
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11130\EVPDR.dll, Delete-on-Reboot, [7fb34a41d5c455e1dd744bfa23e1e818],
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11130\EVPHelp.dll, Quarantined, [7fb34a41d5c455e1dd744bfa23e1e818],
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11130\EVPKernel.dll, Quarantined, [7fb34a41d5c455e1dd744bfa23e1e818],
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11130\EVPNet.dll, Delete-on-Reboot, [7fb34a41d5c455e1dd744bfa23e1e818],
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11130\EVPTask.dll, Delete-on-Reboot, [7fb34a41d5c455e1dd744bfa23e1e818],
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11130\InstallHelper.exe, Quarantined, [7fb34a41d5c455e1dd744bfa23e1e818],
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11130\Language.json, Quarantined, [7fb34a41d5c455e1dd744bfa23e1e818],
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11130\Report.exe, Quarantined, [7fb34a41d5c455e1dd744bfa23e1e818],
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11130\ScreenShotServ.exe, Delete-on-Reboot, [7fb34a41d5c455e1dd744bfa23e1e818],
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11130\ScreenSnapshot.exe, Quarantined, [7fb34a41d5c455e1dd744bfa23e1e818],
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11130\EVPData\History.dat, Quarantined, [7fb34a41d5c455e1dd744bfa23e1e818],
PUP.Optional.WinYahoo, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HowToRemove.html.lnk, Quarantined, [3200a1ea54456fc7ca277807e51fb947],
PUP.Optional.SearchManager.ChrmPRST, C:\Users\Andrew\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bahkljhhdeciiaodlkppoonappfnheoi_0.localstorage, Quarantined, [af83692294056fc747a79ef627ddb54b],
PUP.Optional.WinYahoo, C:\Users\Andrew\AppData\Roaming\Mozilla\Firefox\Profiles\5zo6vkca.default\prefs.js, Good: (user_pref("browser.startup.homepage", "https://www.malwarebytes.org/restorebrowser/), Bad: (user_pref("browser.startup.homepage", "https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_omxmedia_16_12_ssg03¶m1=1¶m2=f%3D1%26b%3DFirefox%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0EzztDtAzy0AtC0F0BtDzy0Ezy0CtB0BtN0D0Tzu0StCyDyEtCtN1L2XzutAtFtBtDtFtDtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2StAtD0AtByD0EyBtDtGtAzyyDtCtGzytD0CyDtGyDtD0FtBtG0A0EtD0EtBtB0FzyyCyEyE0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyByE0AyD0D0Dzy0FtGtCyCzz0EtGyE0CzzyDtG0AyBzzyEtGyD0C0BtBtA0FtBzztAyCtB0D2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCyByBtC%26cr%3D505644883%26a%3Dwbf_omxmedia_16_12_ssg03%26os_ver%3D6.1%26os%3DWindowsReplaced,[1e145239d0c986b02e9b56fe6a9b51af]B7Replaced,[1e145239d0c986b02e9b56fe6a9b51af]BHomeReplaced,[1e145239d0c986b02e9b56fe6a9b51af]BPremium");), %5
Physical Sectors: 0
(No malicious items detected)
(end)