Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 6/26/2014 Scan Time: 6:43:03 AM Logfile: Administrator: Yes Version: 2.00.2.1012 Malware Database: v2014.06.26.05 Rootkit Database: v2014.06.23.02 License: Free Malware Protection: Disabled Malicious Website Protection: Disabled Self-protection: Disabled OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: BOZO Scan Type: Threat Scan Result: Completed Objects Scanned: 315896 Time Elapsed: 7 min, 19 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 1 RiskWare.Tool.CK, C:\Windows\KMService.exe, 2160, No Action By User, [d33ad6a7196239fdc84604c90cf5fa06] Modules: 0 (No malicious items detected) Registry Keys: 1 PUP.Optional.TopArcadeHits.A, HKU\S-1-5-21-2679724477-3412073176-657282893-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{CF190686-9E72-403C-B99D-682ABDB63C5B}, Quarantined, [bf4ebfbeadceda5cbcce0b745da5c739], Registry Values: 1 Trojan.Agent.CK, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|TNOD UP, "C:\Program Files (x86)\TNod-1.4.2.1-Final-Portable\TNODUP-Portable.exe" /i, No Action By User, [5fae4b32730836007c1f1e7ade26a25e] Registry Data: 0 (No malicious items detected) Folders: 0 (No malicious items detected) Files: 6 RiskWare.Tool.CK, C:\Windows\KMService.exe, No Action By User, [d33ad6a7196239fdc84604c90cf5fa06], Trojan.Agent.CK, C:\Program Files (x86)\TNod-1.4.2.1-Final-Portable\TNODUP-Portable.exe, No Action By User, [5fae4b32730836007c1f1e7ade26a25e], Trojan.Agent.CK, C:\Users\BOZO\Downloads\TNod-1.4.2.3-Final-Portable (1).rar, No Action By User, [4cc10a73512a10260a91d1c7f60e946c], Trojan.Agent.CK, C:\Users\BOZO\Downloads\TNod-1.4.2.3-Final-Portable.rar, No Action By User, [5bb2700dc7b4da5ca6f5d9bff50f08f8], PUP.Optional.OpenCandy, C:\Users\BOZO\Downloads\FreemakeVideoConverter_4.1.3.5.exe, No Action By User, [f21b6419dc9ff541b1126fa3cf3204fc], PUP.Optional.WeCare.A, C:\ProgramData\ReadOnlyInstaller.msi, Quarantined, [9776512c0f6c2d09618a8c92a75906fa], Physical Sectors: 0 (No malicious items detected) (end)