Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

NetUtils adware injecting ads into browsers


  • Please log in to reply
23 replies to this topic

#1 Twitch9873

Twitch9873

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:08:50 AM

Posted 11 April 2017 - 07:08 PM

Hello, thank you for reading my post.

 

Somehow, over the course of the past few months, I picked up a very, very elusive bit of malware.  I believe it's called "Netutils," as on certain websites the ads that show say "powered by netutils" at the bottom.  So here are my Symptoms:

 

 

-Upon loading certain websites, my popup blocker blocks ~60ish ads.

 

-Certain websites are unresponsive all of a sudden; whereas the mouse would normally turn into the pointing finger over, say, a hyperlink, it stays as the default pointer.  Then, if I click anywhere on the page, either a generic spam site pops up in a new window or, on the same tab, I am redirected to a page on the following site:

 

http://pwwysydh.com/click?h=Ax722bag...

Which then redirects to a generic spam site.  It then re-opens the page I was trying to visit in a new tab.

 

-Upon starting the PC, I am met with an error message with the title "UpdaterStartupUtility.exe."  The message says something to the affect of "NetUtils.DLL can not be found" or something similar.  There is 2 files in my /system32 called NetUtils.DLL and NetUtils2016.DLL, but when trying to delete it I am not allowed to because they are open in Windows Explorer.

 

I have searched this website, I have searched through search engines, I have tried multiple antiviruses (Avast!, AVG, WinDefender, Sophos, and others I can't think of,) I have tried several registry "fixes" that have to do with Proxies, I have completely removed and re-installed all of my browsers (Chrome is so infected it won't even open at this point.)  I'm blocked from installing malwarebytes (Upon running the installer I get an error that says "runtime error (at 46:120):    Could not call proc.") and at one point, I gave up and just tolerated it for a while.  My last resort is re-formatting my pc, however if I have to, I will.  I don't think it's a "bootkit," however I don't know much about them so I may be wrong.

 

If anyone has any advice or other possible antimalware programs for me to try, I'm willing to give them a shot.  Thanks in advance!



BC AdBot (Login to Remove)

 


#2 iMacg3

iMacg3

    Bleepin' PowerPC G3


  • Malware Study Hall Senior
  • 2,052 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Indiana, USA
  • Local time:07:50 AM

Posted 12 April 2017 - 10:18 AM

Download the Junkware Removal Tool and save it. Run a scan of your system. The tool should produce a log to your desktop called JRT.txt. Paste the log file contents into a post.

 

Download AdwCleaner and save it. Run a scan of your system. After the scan is done, click on Log File. Click on the scan tab. Click the scan that you just did. Paste the log file contents into a post.


Edited by iMacg3, 12 April 2017 - 04:37 PM.

Regards, iMacg3

 

If I do not reply to your malware removal topic in 48 hours, please send me a PM. 

"Do, or do not. There is no try." - Yoda


#3 Twitch9873

Twitch9873
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:08:50 AM

Posted 12 April 2017 - 04:38 PM

I did as you said, and the results are as follows:

 

Junkware Removal Tool

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.3 (04.10.2017)
Operating System: Windows 10 Home x64
Ran by Evan (Limited) on Wed 04/12/2017 at 17:13:54.89
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 4

Successfully deleted: C:\Users\Evan\Appdata\LocalLow\company (Folder)
Successfully deleted: C:\Users\Evan\AppData\Roaming\3909 (Folder)
Successfully deleted: C:\a\winonit.exe (File)
Successfully deleted: C:\Users\Evan\AppData\Roaming\appdataFr25.bin (File)



Registry: 3

Successfully deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\dutoauto (Registry Value)
Successfully deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\rutoauto (Registry Value)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\\cutoauto (Registry Value)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Wed 04/12/2017 at 17:17:09.97
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

 

 

AdWare Cleaner

# AdwCleaner v6.045 - Logfile created 12/04/2017 at 17:22:48
# Updated on 28/03/2017 by Malwarebytes
# Database : 2017-04-11.1 [Server]
# Operating System : Windows 10 Home  (X64)
# Username : Evan - EVANSPC
# Running from : C:\Users\Evan\Downloads\AdwCleaner(1).exe
# Mode: Clean
# Support : https://www.malwarebytes.com/support



***** [ Services ] *****

[-] Service deleted: NetUtils2016


***** [ Folders ] *****



***** [ Files ] *****

[#] File deleted: C:\WINDOWS\SysNative\NetUtils2016.dll
[#] File deleted: C:\WINDOWS\SysNative\drivers\NetUtils2016.sys


***** [ DLL ] *****



***** [ WMI ] *****



***** [ Shortcuts ] *****



***** [ Scheduled Tasks ] *****



***** [ Registry ] *****

[-] Key deleted: [x64] HKLM\SOFTWARE\HDWallpaper
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Maxi
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\cmptch.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\static.cmptch.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\cmptch.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\static.cmptch.com
[#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\cmptch.com
[#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\static.cmptch.com
[#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\cmptch.com
[#] Key deleted on reboot: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\static.cmptch.com


***** [ Web browsers ] *****



*************************

:: "Tracing" keys deleted
:: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [23353 Bytes] - [21/03/2017 17:43:02]
C:\AdwCleaner\AdwCleaner[C2].txt - [1242 Bytes] - [21/03/2017 18:49:56]
C:\AdwCleaner\AdwCleaner[C3].txt - [1474 Bytes] - [21/03/2017 19:06:03]
C:\AdwCleaner\AdwCleaner[C4].txt - [3011 Bytes] - [12/04/2017 17:22:48]
C:\AdwCleaner\AdwCleaner[S0].txt - [21650 Bytes] - [21/03/2017 17:34:36]
C:\AdwCleaner\AdwCleaner[S1].txt - [1373 Bytes] - [21/03/2017 18:38:42]
C:\AdwCleaner\AdwCleaner[S2].txt - [1526 Bytes] - [21/03/2017 19:05:40]
C:\AdwCleaner\AdwCleaner[S3].txt - [3445 Bytes] - [12/04/2017 17:21:56]

########## EOF - C:\AdwCleaner\AdwCleaner[C4].txt - [3377 Bytes] ##########
 

 

 

So it appears that JRT found nothing of importance.  AdW cleaner however seems to have found 2 files called "Netutils2016.DLL" and "NetUtils2016.Sys," in the windows folder SysNative.   Maybe I just don't quite understand how the Windows folder works, but I cannot find the Sysnative folder- even copying it into the location bar at the top of windows explorer comes up with a "cannot find the path specified" error.  I also noticed that the 2 NetUtils files in System32 are still present, and my symptoms unchanged.

 

Edit:  I forgot to mention, I believe I have ran AdWCleaner at some point previously.  If I recall correctly, It repeatedly said that it had found the 2 NetUtils files and question and deleted them.  However, after boot, the files remained, and could be detected by AdWCleaner again.


Edited by Twitch9873, 12 April 2017 - 04:41 PM.


#4 iMacg3

iMacg3

    Bleepin' PowerPC G3


  • Malware Study Hall Senior
  • 2,052 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Indiana, USA
  • Local time:07:50 AM

Posted 12 April 2017 - 05:35 PM

Try using the ESET Online Scanner

Download the scanner from here. Run a scan with the tool. Once the scan is complete, click on the Tools option on the left. Click the More Tools button on the extreme bottom right. Then click log files. Select the logfile and open it. Paste its contents into a post.

 

Are you running the scan tools from an administrator account? If not, you need to run all the scans from an admin account.

Right click on the tools and click "Run As Administrator" and click OK at the User Account Control prompt. Do this even when you run from an administrator account.


Edited by iMacg3, 12 April 2017 - 05:47 PM.

Regards, iMacg3

 

If I do not reply to your malware removal topic in 48 hours, please send me a PM. 

"Do, or do not. There is no try." - Yoda


#5 Twitch9873

Twitch9873
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:08:50 AM

Posted 21 April 2017 - 07:03 PM

Hello again, sorry for such a late reply.  I was trying to get the ESET scanner to run off and on for a few days, and I lost internet (ISP's fault) for about a week on top of that.  But I finally completed the scan, and here are the results:

 

C:\Users\Evan\AppData\Local\Mozilla\Firefox\Profiles\rnpsf3f6.default-1484278554860\cache2\entries\4ED22892E1AF4FD4DB86DF013C55D99F128F4A07
HTML/FakeAlert.JY trojan    

C:\Users\Evan\AppData\Roaming\Google\downloader.exe
Win32/TrojanDownloader.Agent.BTF trojan    

C:\Users\Evan\AppData\Roaming\PowerISO\Upgrade\PowerISO6-x64.exe
Win32/FusionCore.L potentially unwanted application,a variant of Win32/FusionCore.I potentially unwanted application    

C:\Users\Evan\Desktop\installer.exe
a variant of Win32/InstallCore.ACZ potentially unwanted application    

C:\Windows\fluttered.exe
a variant of Win32/Adware.Dotdo.E application    

C:\Windows\glances.exe
a variant of MSIL/Adware.Dotdo.AP application    

C:\Windows\System32\chla\yap\piol.dat
Win32/Qhost trojan
    
C:\Windows\System32\MRT\34E69BB2-EFA0-4905-B7A9-EFBDBA61647B\FilesStash\966C3CE3-D24B-160A-48EF-4FA6A4D543E7_1d1de4595f771fe
a variant of Win32/Adware.MultiPlug.MQ application
    
C:\Windows.old\Users\Evan\Desktop\installer.exe.
a variant of Win32/InstallCore.ACZ potentially unwanted application        
 

 

 

I chose to delete the files found, and after a restart, the symptoms still persist.  And yes, all scanners have been run as an administrator.



#6 iMacg3

iMacg3

    Bleepin' PowerPC G3


  • Malware Study Hall Senior
  • 2,052 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Indiana, USA
  • Local time:07:50 AM

Posted 22 April 2017 - 07:52 PM

Download Hitman Pro. Right click it and select Run as Administrator.

Once it's open, click Settings, then uncheck Scan for Tracking Cookies. 

Click OK, then click Next.

Select No, I only want to perform a one time scan to check this computer and click Next. HitmanPro will start scanning your system. Once done scanning, HitmanPro will display a screen with any threats found. Important: Click on the drop-down tab next to the infection name and then click Apply to All > Ignore. If not, you could cause damage to your operating system! Make sure you choose to Ignore the files and then click next. You will be at the results window. Click "Save Log" and save it to your desktop. Paste its contents into a post.


Regards, iMacg3

 

If I do not reply to your malware removal topic in 48 hours, please send me a PM. 

"Do, or do not. There is no try." - Yoda


#7 Twitch9873

Twitch9873
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:08:50 AM

Posted 24 April 2017 - 08:20 PM

Alright, this one's a little long.

 

HitmanPro 3.7.18.284
www.hitmanpro.com

   Computer name . . . . : EVANSPC
   Windows . . . . . . . : 10.0.0.14393.X64/6
   User name . . . . . . : EVANSPC\Evan
   UAC . . . . . . . . . : Enabled
   License . . . . . . . : Free

   Scan date . . . . . . : 2017-04-24 21:02:14
   Scan mode . . . . . . : Normal
   Scan duration . . . . : 15m 55s
   Disk access mode  . . : Direct disk access (SRB)
   Cloud . . . . . . . . : Internet
   Reboot  . . . . . . . : No

   Threats . . . . . . . : 2
   Traces  . . . . . . . : 6

   Objects scanned . . . : 1,866,365
   Files scanned . . . . : 57,011
   Remnants scanned  . . : 475,214 files / 1,334,140 keys

Malware _____________________________________________________________________

   C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\steam_api.dll
      Size . . . . . . . : 839,168 bytes
      Age  . . . . . . . : 1.9 days (2017-04-22 22:47:15)
      Entropy  . . . . . : 8.0
      SHA-256  . . . . . : DC4A7B0C3779B282771C492B3E50E01FF17707CBE7E54A99476F79A17903206A
      Product  . . . . . : Steam Client API
      Publisher  . . . . : Valve Corporation
      Description  . . . : Steam Client API
      Version  . . . . . : 03.42.61.66
      LanguageID . . . . : 2052
    > HitmanPro  . . . . : Mal/VMProtBad-A
      Fuzzy  . . . . . . : 110.0
      Forensic Cluster
         -3.0s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\
         -3.0s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\ALI213.ini
         -3.0s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\atomstb.dll
         -2.9s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\AtomZombieSmasher.exe
         -2.8s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\
         -2.8s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\comics\
         -2.8s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\comics\alive.txt
         -2.8s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\comics\anything.txt
         -2.8s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\comics\bike.txt
         -2.8s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\comics\bonobo.txt
         -2.8s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\comics\conquer.txt
         -2.8s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\comics\cool.txt
         -2.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\comics\dog.txt
         -2.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\comics\elephantbird.txt
         -2.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\comics\end.txt
         -2.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\comics\footprints.txt
         -2.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\comics\glass.txt
         -2.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\comics\grievance.txt
         -2.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\comics\idle.txt
         -2.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\comics\intro.txt
         -2.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\comics\jeep.txt
         -2.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\comics\katana.txt
         -2.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\comics\know.txt
         -2.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\comics\lanes.txt
         -2.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\comics\lion.txt
         -2.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\comics\manifesto.txt
         -2.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\comics\math.txt
         -2.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\comics\morning.txt
         -2.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\comics\nugget.txt
         -2.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\comics\orange.txt
         -2.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\comics\peachie.txt
         -2.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\comics\pigeons.txt
         -2.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\comics\retribution.txt
         -2.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\comics\robots.txt
         -2.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\comics\speech.txt
         -2.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\comics\superzombie.txt
         -2.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\comics\torch.txt
         -2.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\comics\trip.txt
         -2.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\data\
         -2.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\data\comics.txt
         -2.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\data\manifest.txt
         -2.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\data\menu.sounds
         -2.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\data\music.txt
         -2.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\data\names.txt
         -2.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\data\tips.txt
         -2.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\fonts\
         -2.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\fonts\accid.ttf
         -2.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\fonts\din.ttf
         -2.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\fonts\dustismo.ttf
         -2.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\fonts\dustismoi.ttf
         -2.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\fonts\fette.ttf
         -2.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\fonts\share.ttf
         -2.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\fonts\typolatin.ttf
         -2.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\fonts\veteran.ttf
         -2.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\music\
         -2.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\music\bennyhammond_hangthemhigh.ogg
         -2.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\music\bennyhammond_tsunami.ogg
         -2.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\music\volcanics_bluewithoutyou.ogg
         -2.3s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\music\volcanics_boulevard.ogg
         -2.3s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\music\volcanics_thebaron.ogg
         -2.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\
         -2.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\artyfire01.ogg
         -2.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\artyfire02.ogg
         -2.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\artyfire03.ogg
         -2.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\artyfire04.ogg
         -2.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\artyfire05.ogg
         -2.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\artyplace.ogg
         -2.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\artyradio01.ogg
         -2.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\artyradio02.ogg
         -2.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\artyradio03.ogg
         -2.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\artyradio04.ogg
         -2.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\artyradio05.ogg
         -2.1s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\artyradio06.ogg
         -2.1s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\artyradio07.ogg
         -2.1s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\artyradio08.ogg
         -2.1s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\artyradio09.ogg
         -2.1s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\artyradio10.ogg
         -2.1s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\artyradio11.ogg
         -2.1s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\artyradio12.ogg
         -2.1s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\artyradio13.ogg
         -2.1s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\artyradio14.ogg
         -2.1s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\artyradio15.ogg
         -2.1s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\artyradio16.ogg
         -2.1s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\artyradio17.ogg
         -2.1s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\artyradio18.ogg
         -2.0s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\artyradio19.ogg
         -2.0s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\artyradio20.ogg
         -2.0s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\artyreload.ogg
         -2.0s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\aww1.ogg
         -2.0s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\aww2.ogg
         -2.0s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\aww3.ogg
         -2.0s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\aww4.ogg
         -2.0s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\bark01.ogg
         -2.0s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\bark02.ogg
         -2.0s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\bark03.ogg
         -2.0s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\bark04.ogg
         -1.9s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\bark05.ogg
         -1.9s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\bark06.ogg
         -1.9s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\bark07.ogg
         -1.9s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\birds.ogg
         -1.9s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\camzoomin.ogg
         -1.9s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\camzoomout.ogg
         -1.9s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\capture.ogg
         -1.8s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\cashbeep.ogg
         -1.8s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\cashregister.ogg
         -1.8s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\cello1.ogg
         -1.8s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\cello2.ogg
         -1.8s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\cello3.ogg
         -1.8s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\cello4.ogg
         -1.8s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\cello5.ogg
         -1.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\cheering1.ogg
         -1.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\cheering2.ogg
         -1.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\cheering3.ogg
         -1.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\chime.ogg
         -1.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\clickbeep.ogg
         -1.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\clickerror.ogg
         -1.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\clickselect.ogg
         -1.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\clicktiny.ogg
         -1.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\crickets.ogg
         -1.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\demolition01.ogg
         -1.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\demolition02.ogg
         -1.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\demolition03.ogg
         -1.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\demolition04.ogg
         -1.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\demolition05.ogg
         -1.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\ding2.ogg
         -1.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\ding3.ogg
         -1.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\drill01.ogg
         -1.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\drill02.ogg
         -1.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\drill03.ogg
         -1.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\eisenhower.ogg
         -1.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\elephantready1.ogg
         -1.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\explo01.ogg
         -1.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\explo02.ogg
         -1.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\explo03.ogg
         -1.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\explo04.ogg
         -1.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\explo05.ogg
         -1.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\explo06.ogg
         -1.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\explo07.ogg
         -1.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\explo08.ogg
         -1.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\fanfare.ogg
         -1.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\fanfareitem.ogg
         -1.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\foghorn01.ogg
         -1.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\foghorn02.ogg
         -1.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\foghorn03.ogg
         -1.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\footstep01.ogg
         -1.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\gore01.ogg
         -1.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\gore02.ogg
         -1.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\gore03.ogg
         -1.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\gun01.ogg
         -1.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\gun02.ogg
         -1.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\gun03.ogg
         -1.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\gun04.ogg
         -1.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\gun05.ogg
         -1.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\gun06.ogg
         -1.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\gun07.ogg
         -1.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\gun08.ogg
         -1.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\helileave01.ogg
         -1.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\helileave02.ogg
         -1.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\heliload.ogg
         -1.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\heliloop.ogg
         -1.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\helioverrun01.ogg
         -1.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\helioverrun02.ogg
         -1.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\helioverrun03.ogg
         -1.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\howl01.ogg
         -1.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\infantryradio01.ogg
         -1.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\infantryradio02.ogg
         -1.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\infantryradio03.ogg
         -1.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\infantryradio04.ogg
         -1.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\infantryradio05.ogg
         -1.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\infantryradio06.ogg
         -1.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\infantryradio07.ogg
         -1.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\infantryradio08.ogg
         -1.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\infantryradio09.ogg
         -1.3s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\infantryradio10.ogg
         -1.3s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\infantryradio11.ogg
         -1.3s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\infantryradio12.ogg
         -1.3s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\infantryradio13.ogg
         -1.3s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\infantryradio14.ogg
         -1.3s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\infantryradio15.ogg
         -1.3s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\klaxon.ogg
         -1.3s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\klaxonshort.ogg
         -1.3s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\lab01.ogg
         -1.3s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\lab02.ogg
         -1.3s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\lab03.ogg
         -1.3s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\llama.ogg
         -1.3s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\llamatiny.ogg
         -1.3s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\mercfanfare.ogg
         -1.3s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\minedelete.ogg
         -1.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\mineplace.ogg
         -1.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\minetrigger.ogg
         -1.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\modem.ogg
         -1.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\nectarloop.ogg
         -1.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\nectarstart.ogg
         -1.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\nectarstop.ogg
         -1.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\nighttransition.ogg
         -1.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\pageturn01.ogg
         -1.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\pageturn02.ogg
         -1.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\pageturn03.ogg
         -1.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\pageturn04.ogg
         -1.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\pageturn05.ogg
         -1.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\pageturn06.ogg
         -1.1s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\pause.ogg
         -1.1s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\rain.ogg
         -1.1s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\reloaddone.ogg
         -1.1s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\researchcomplete.ogg
         -1.1s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\rooster1.ogg
         -1.1s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\scientistding01.ogg
         -1.0s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\signature.ogg
         -1.0s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\sniper01.ogg
         -1.0s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\sniper02.ogg
         -1.0s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\sniper03.ogg
         -1.0s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\sniper04.ogg
         -1.0s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\sniperconfirm01.ogg
         -1.0s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\sniperconfirm02.ogg
         -1.0s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\sniperconfirm03.ogg
         -1.0s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\sniperconfirm04.ogg
         -1.0s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\sniperconfirm05.ogg
         -1.0s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\sniperplace.ogg
         -1.0s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\splat.ogg
         -1.0s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\superzombie01.ogg
         -1.0s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\superzombie02.ogg
         -1.0s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\superzombie03.ogg
         -1.0s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\thunder1.ogg
         -1.0s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\thunder2.ogg
         -0.9s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\timer.ogg
         -0.9s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\transport01.ogg
         -0.9s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\transport02.ogg
         -0.9s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\transport03.ogg
         -0.9s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\transport04.ogg
         -0.9s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\transport05.ogg
         -0.9s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\trumpet.ogg
         -0.9s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\unpause.ogg
         -0.9s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\upgrade.ogg
         -0.9s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\whoosh1.ogg
         -0.9s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\whoosh2.ogg
         -0.9s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\whoosh3.ogg
         -0.9s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\wind.ogg
         -0.9s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\write01.ogg
         -0.9s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\write02.ogg
         -0.9s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\write03.ogg
         -0.9s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\zepmove.ogg
         -0.9s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\zepreturn.ogg
         -0.9s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\zom01.ogg
         -0.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\zom02.ogg
         -0.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\zom03.ogg
         -0.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\zom04.ogg
         -0.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\zom05.ogg
         -0.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\zom06.ogg
         -0.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\zom07.ogg
         -0.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\zom08.ogg
         -0.7s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\zom09.ogg
         -0.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\zom10.ogg
         -0.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\zom11.ogg
         -0.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\zom12.ogg
         -0.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\zom13.ogg
         -0.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\zom14.ogg
         -0.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\zom15.ogg
         -0.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\zom16.ogg
         -0.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\zom17.ogg
         -0.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\zom18.ogg
         -0.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\zom19.ogg
         -0.6s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\sounds\zom20.ogg
         -0.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\strings\
         -0.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\strings\en\
         -0.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\strings\en\strings.txt
         -0.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\textures\
         -0.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\textures\blank.png
         -0.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\textures\buildings.png
         -0.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\textures\buildings2.png
         -0.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\textures\comic01.png
         -0.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\textures\comicblank.png
         -0.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\textures\comicfiller.png
         -0.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\textures\end01.png
         -0.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\textures\end02.png
         -0.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\textures\end03.png
         -0.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\textures\icon.png
         -0.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\textures\loading.jpg
         -0.5s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\textures\portraits01.png
         -0.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\textures\portraits02.png
         -0.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\textures\portraits03.png
         -0.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\textures\thumb.png
         -0.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\zedpedia\
         -0.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\zedpedia\assaultmission.zep
         -0.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\zedpedia\barricade.zep
         -0.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\zedpedia\camera.zep
         -0.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\zedpedia\controls.zep
         -0.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\zedpedia\dynamite.zep
         -0.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\zedpedia\evacheli.zep
         -0.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\zedpedia\gaslines.zep
         -0.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\zedpedia\helpmessages.zep
         -0.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\zedpedia\history.zep
         -0.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\zedpedia\his_arouet.zep
         -0.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\zedpedia\his_eighteen.zep
         -0.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\zedpedia\his_hyperborea.zep
         -0.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\zedpedia\his_lewis.zep
         -0.4s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\zedpedia\his_references.zep
         -0.3s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\zedpedia\infantry.zep
         -0.3s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\zedpedia\landmines.zep
         -0.3s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\zedpedia\llamabomb.zep
         -0.3s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\zedpedia\mercenaries.zep
         -0.3s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\zedpedia\missiontypes.zep
         -0.3s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\zedpedia\nectar.zep
         -0.3s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\zedpedia\rescuemission.zep
         -0.3s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\zedpedia\research.zep
         -0.3s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\zedpedia\scientists.zep
         -0.3s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\zedpedia\scorchedearth.zep
         -0.3s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\zedpedia\siegeartillery.zep
         -0.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\zedpedia\snipers.zep
         -0.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\zedpedia\victorytrack.zep
         -0.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\zedpedia\welcome.zep
         -0.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\zedpedia\zedautopsy.zep
         -0.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\zedpedia\zedpedia.zep
         -0.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\content\zedpedia\zeppelin.zep
         -0.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\gamecontrollerdb.txt
         -0.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\GAMESTORRENT.CO.url
         -0.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\IGG-GAMES.COM.url
         -0.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\OpenAL-CS.dll
         -0.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\readme.htm
         -0.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\README.txt
         -0.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\SDL2-CS.dll
         -0.2s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\SDL2.dll
         -0.1s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\soft_oal.dll
         -0.0s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\steamwrapper.dll
          0.0s C:\Users\Evan\Desktop\Atom.Zombie.Smasher.v2.0\steam_api.dll

   C:\Users\Evan\Documents\BFBC2\pb\pbcl.dll
      Size . . . . . . . : 891,962 bytes
      Age  . . . . . . . : 598.0 days (2015-09-04 21:12:37)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : A324BDA2B890227F72D9F12323AD3FF51582CE312286C296F6558BD3F3927616
    > HitmanPro  . . . . : App/Punkbust-B
      Fuzzy  . . . . . . : 129.0


Suspicious files ____________________________________________________________

   C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbcl.dll
      Size . . . . . . . : 953,886 bytes
      Age  . . . . . . . : 11.0 days (2017-04-13 21:27:08)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 6D5E2CD4A7A43EB00B600BA783AD3BEE6B817C030A40600D40367173A6ECEB13
      Fuzzy  . . . . . . : 30.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Time indicates that the file appeared recently on this computer.
         Program contains PE structure anomalies. This is not typical for most programs.
      Forensic Cluster
         -37.3s C:\Users\Evan\AppData\Local\Microsoft\Windows\Notifications\wpnidm\d59ad496.png
         -34.1s C:\Users\Evan\AppData\Roaming\Mozilla\Firefox\Profiles\rnpsf3f6.default-1484278554860\datareporting\archived\2017-04\1492133194447.742a36ba-c334-4edf-b48d-4b5a82b0fec7.main.jsonlz4
         -34.0s C:\ProgramData\Orbit\46\
         -30.5s C:\Users\Evan\Documents\My Games\Far Cry 3\
         -27.7s C:\Users\Evan\AppData\Local\AMD\DxCache\c30e364f97bcdf4e2c36810c49941ac8718055a7309ae286.bin
         -24.3s C:\Windows\Prefetch\FARCRY3.EXE-058EB2A6.pf
         -13.4s C:\Users\Evan\Documents\My Games\Far Cry 3\GamerProfile.xml
         -11.7s C:\ProgramData\Microsoft\Windows Defender\Scans\MetaStore\2\56\A95415AE26963AD4.dat
         -0.2s C:\Users\Evan\AppData\Local\PunkBuster\
         -0.2s C:\Users\Evan\AppData\Local\PunkBuster\FC3\
         -0.2s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\
         -0.2s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbsvgame.cfg
         -0.2s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbsv.dll
         -0.2s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbags.dll
         -0.2s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbcls.dll
         -0.2s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\htm\
         -0.2s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\dll\
         -0.2s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\svlogs\
         -0.1s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\svss\
         -0.1s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbsv.dat
         -0.0s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbclgame.cfg
         -0.0s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbcl.db
          0.0s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbcl.dll
          0.0s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbag.dll
          0.0s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\scrnshot\
          0.1s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\PnkBstrB.exe
          4.6s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbns.dat
          4.7s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbns_c.dat
          6.6s C:\ProgramData\Microsoft\Windows Defender\Scans\MetaStore\2\83\7C291D4F41754707.dat
          7.3s C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7B8944BA8AD0EFDF0E01A43EF62BECD0_300E3B4CF5BE6AE01CD6E8C7B0100089
          7.3s C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7B8944BA8AD0EFDF0E01A43EF62BECD0_300E3B4CF5BE6AE01CD6E8C7B0100089
          8.2s C:\Windows\System32\LogFiles\PunkBuster\PnkBstrB.log
         11.6s C:\ProgramData\Microsoft\Windows Defender\Scans\MetaStore\2\15\3270572BBAD401EF.dat
         11.6s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\PnkBstrK.sys

   C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbcls.dll
      Size . . . . . . . : 953,886 bytes
      Age  . . . . . . . : 11.0 days (2017-04-13 21:27:08)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 6D5E2CD4A7A43EB00B600BA783AD3BEE6B817C030A40600D40367173A6ECEB13
      Fuzzy  . . . . . . : 30.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Time indicates that the file appeared recently on this computer.
         Program contains PE structure anomalies. This is not typical for most programs.
      Forensic Cluster
         -37.1s C:\Users\Evan\AppData\Local\Microsoft\Windows\Notifications\wpnidm\d59ad496.png
         -34.0s C:\Users\Evan\AppData\Roaming\Mozilla\Firefox\Profiles\rnpsf3f6.default-1484278554860\datareporting\archived\2017-04\1492133194447.742a36ba-c334-4edf-b48d-4b5a82b0fec7.main.jsonlz4
         -33.8s C:\ProgramData\Orbit\46\
         -30.4s C:\Users\Evan\Documents\My Games\Far Cry 3\
         -27.5s C:\Users\Evan\AppData\Local\AMD\DxCache\c30e364f97bcdf4e2c36810c49941ac8718055a7309ae286.bin
         -24.1s C:\Windows\Prefetch\FARCRY3.EXE-058EB2A6.pf
         -13.3s C:\Users\Evan\Documents\My Games\Far Cry 3\GamerProfile.xml
         -11.5s C:\ProgramData\Microsoft\Windows Defender\Scans\MetaStore\2\56\A95415AE26963AD4.dat
         -0.0s C:\Users\Evan\AppData\Local\PunkBuster\
         -0.0s C:\Users\Evan\AppData\Local\PunkBuster\FC3\
         -0.0s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\
         -0.0s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbsvgame.cfg
         -0.0s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbsv.dll
         -0.0s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbags.dll
          0.0s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbcls.dll
          0.0s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\htm\
          0.0s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\dll\
          0.0s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\svlogs\
          0.0s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\svss\
          0.0s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbsv.dat
          0.2s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbclgame.cfg
          0.2s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbcl.db
          0.2s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbcl.dll
          0.2s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbag.dll
          0.2s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\scrnshot\
          0.3s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\PnkBstrB.exe
          4.7s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbns.dat
          4.9s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbns_c.dat
          6.7s C:\ProgramData\Microsoft\Windows Defender\Scans\MetaStore\2\83\7C291D4F41754707.dat
          7.4s C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7B8944BA8AD0EFDF0E01A43EF62BECD0_300E3B4CF5BE6AE01CD6E8C7B0100089
          7.4s C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7B8944BA8AD0EFDF0E01A43EF62BECD0_300E3B4CF5BE6AE01CD6E8C7B0100089
          8.3s C:\Windows\System32\LogFiles\PunkBuster\PnkBstrB.log
         11.7s C:\ProgramData\Microsoft\Windows Defender\Scans\MetaStore\2\15\3270572BBAD401EF.dat
         11.8s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\PnkBstrK.sys

   C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\PnkBstrK.sys
      Size . . . . . . . : 138,032 bytes
      Age  . . . . . . . : 11.0 days (2017-04-13 21:27:20)
      Entropy  . . . . . : 7.8
      SHA-256  . . . . . : ABAF3FACF01E10E4C685F79C3B9E5D2118B3CF8629C4277EBE035B2A10474148
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 23.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Time indicates that the file appeared recently on this computer.
         Program contains PE structure anomalies. This is not typical for most programs.
         The file is a device driver. Device drivers run as trusted (highly privileged) code.
         Program is code signed with a valid Authenticode certificate.
      Forensic Cluster
         -48.9s C:\Users\Evan\AppData\Local\Microsoft\Windows\Notifications\wpnidm\d59ad496.png
         -45.7s C:\Users\Evan\AppData\Roaming\Mozilla\Firefox\Profiles\rnpsf3f6.default-1484278554860\datareporting\archived\2017-04\1492133194447.742a36ba-c334-4edf-b48d-4b5a82b0fec7.main.jsonlz4
         -45.6s C:\ProgramData\Orbit\46\
         -42.2s C:\Users\Evan\Documents\My Games\Far Cry 3\
         -39.3s C:\Users\Evan\AppData\Local\AMD\DxCache\c30e364f97bcdf4e2c36810c49941ac8718055a7309ae286.bin
         -35.9s C:\Windows\Prefetch\FARCRY3.EXE-058EB2A6.pf
         -25.1s C:\Users\Evan\Documents\My Games\Far Cry 3\GamerProfile.xml
         -23.3s C:\ProgramData\Microsoft\Windows Defender\Scans\MetaStore\2\56\A95415AE26963AD4.dat
         -11.8s C:\Users\Evan\AppData\Local\PunkBuster\
         -11.8s C:\Users\Evan\AppData\Local\PunkBuster\FC3\
         -11.8s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\
         -11.8s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbsvgame.cfg
         -11.8s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbsv.dll
         -11.8s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbags.dll
         -11.8s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbcls.dll
         -11.8s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\htm\
         -11.8s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\dll\
         -11.8s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\svlogs\
         -11.8s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\svss\
         -11.8s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbsv.dat
         -11.6s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbclgame.cfg
         -11.6s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbcl.db
         -11.6s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbcl.dll
         -11.6s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbag.dll
         -11.6s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\scrnshot\
         -11.5s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\PnkBstrB.exe
         -7.0s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbns.dat
         -6.9s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\pbns_c.dat
         -5.0s C:\ProgramData\Microsoft\Windows Defender\Scans\MetaStore\2\83\7C291D4F41754707.dat
         -4.3s C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7B8944BA8AD0EFDF0E01A43EF62BECD0_300E3B4CF5BE6AE01CD6E8C7B0100089
         -4.3s C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7B8944BA8AD0EFDF0E01A43EF62BECD0_300E3B4CF5BE6AE01CD6E8C7B0100089
         -3.5s C:\Windows\System32\LogFiles\PunkBuster\PnkBstrB.log
         -0.0s C:\ProgramData\Microsoft\Windows Defender\Scans\MetaStore\2\15\3270572BBAD401EF.dat
          0.0s C:\Users\Evan\AppData\Local\PunkBuster\FC3\pb\PnkBstrK.sys

   C:\Users\Evan\Desktop\My.Summer.Car\mysummercar.exe
      Size . . . . . . . : 15,651,616 bytes
      Age  . . . . . . . : 167.9 days (2016-11-07 22:29:02)
      Entropy  . . . . . : 6.7
      SHA-256  . . . . . : 88B0484ECE31896F0D60E113D92991D9722440E083CF59122DE8B9CD3438E755
      Version  . . . . . : 5.0.0.6002871
      RSA Key Size . . . : 2048
      Authenticode . . . : Invalid
      Fuzzy  . . . . . . : 23.0
         Program is altered or corrupted since it was code signed by its author. This is typical for malware and pirated software.
         Authors name is missing in version info. This is not common to most programs.
 

#8 iMacg3

iMacg3

    Bleepin' PowerPC G3


  • Malware Study Hall Senior
  • 2,052 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Indiana, USA
  • Local time:07:50 AM

Posted 24 April 2017 - 08:56 PM

Please back up your files just in case. 

Rerun Hitman Pro and choose to remove threats.


Regards, iMacg3

 

If I do not reply to your malware removal topic in 48 hours, please send me a PM. 

"Do, or do not. There is no try." - Yoda


#9 Twitch9873

Twitch9873
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:08:50 AM

Posted 24 April 2017 - 10:03 PM

Done.  Did not damage my OS in any way.  The error at startup is gone, but unfortunately all other symptoms still persist.



#10 iMacg3

iMacg3

    Bleepin' PowerPC G3


  • Malware Study Hall Senior
  • 2,052 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Indiana, USA
  • Local time:07:50 AM

Posted 24 April 2017 - 10:10 PM

Go to Control Panel>Uninstall a program. Look for any suspicious programs that you didn't install or are recently installed. Look for the programs "GameLauncher", "Host Service", and "CondRed."

 

Do not delete the programs, just list them here.


Regards, iMacg3

 

If I do not reply to your malware removal topic in 48 hours, please send me a PM. 

"Do, or do not. There is no try." - Yoda


#11 Twitch9873

Twitch9873
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:08:50 AM

Posted 24 April 2017 - 10:22 PM

Hmm.  The three programs that you mentioned are not listed.  All of the suspicious programs I can find are the following:

 

ESN Sonar

TailCutter

Vulkan RunTime Libraries

 

Upon a quick google search, ESN Sonar has to do with battlefield, TailCutter appears to be AdWare, And Vulkan appears to be a graphics API.

the only possible problem seems to be TailCutter.  Anything to note before I remove it?



#12 iMacg3

iMacg3

    Bleepin' PowerPC G3


  • Malware Study Hall Senior
  • 2,052 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Indiana, USA
  • Local time:07:50 AM

Posted 25 April 2017 - 05:53 PM

Go ahead and uninstall TailCutter.


Regards, iMacg3

 

If I do not reply to your malware removal topic in 48 hours, please send me a PM. 

"Do, or do not. There is no try." - Yoda


#13 Twitch9873

Twitch9873
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:08:50 AM

Posted 25 April 2017 - 09:45 PM

Just tried.  I get an error called "RunDLL" and says the following:

 

"There was a problem starting C:\PROGRA~2\TAILCU~1\TAILCU~1.DLL

The specified module could not be found"

 

So, given that it's known adware and resisting the simplest conventional method of deleting it (and the suspicious file path in the error message,) this is a possible culprit. 

 

I don't know if this is helpful information, but upon choosing to delete from the Add or Remove programs list, a user account control popup appears asking if I want to allow Windows Host Process(RunDLL32) to make changes.  If I hit show more details, It shows the programs location as the following:

 

"C:\Windows\System32\RUNDLL32.EXE" "C:\PROGRA~2\TAILCU~1\TAILCU~1.DLL",_uninstall /un

 

And a windows explorer search of tailcutter shows no results.



#14 iMacg3

iMacg3

    Bleepin' PowerPC G3


  • Malware Study Hall Senior
  • 2,052 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Indiana, USA
  • Local time:07:50 AM

Posted 26 April 2017 - 10:09 AM

Malware not wanting to uninstall is common.

 

Download Malwarebytes Anti-Malware and save it to your desktop.

  1. Double-click the .exe file you downloaded and go through the install wizard for MBAM.
  2. Once installed, open MBAM (right-click and select Run as Administrator).
  3. Click Scan Now on the bottom of the window.
  4. MBAM will begin to download definition updates and scan your computer.
  5. Once complete, it will display a list of threats. Quarantine the found threats by clicking Quarantine Selected.
  6. Once done quarantining, click History on the left and then select the logfile for the most recent scan.
  7. Paste the log contents into a post.

Edited by iMacg3, 26 April 2017 - 10:12 AM.

Regards, iMacg3

 

If I do not reply to your malware removal topic in 48 hours, please send me a PM. 

"Do, or do not. There is no try." - Yoda


#15 Twitch9873

Twitch9873
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:08:50 AM

Posted 26 April 2017 - 04:23 PM

I am not able to install malwarebytes unfortunately.  From the original post:

 

 

I'm blocked from installing malwarebytes (Upon running the installer I get an error that says "runtime error (at 46:120):    Could not call proc.")

 

I don't know what the problem with that could be; and I remember not being able to find an answer for it online.

 

 

EDIT: I've also tried the Mbam clean tool, which made no difference.


Edited by Twitch9873, 26 April 2017 - 04:24 PM.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users