Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 12/7/17 Scan Time: 11:49 PM Log File: 423f55ce-dba9-11e7-a3a9-3863bb8e97c5.json Administrator: Yes -Software Information- Version: 3.3.1.2183 Components Version: 1.0.262 Update Package Version: 1.0.3440 License: Trial -System Information- OS: Windows 10 (Build 14393.1770) CPU: x64 File System: NTFS User: AMYSCOMPUTER\Amy -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 294152 Threats Detected: 62 Threats Quarantined: 61 Time Elapsed: 13 min, 8 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Detect PUM: Detect -Scan Details- Process: 1 PUP.Optional.SlimServices, C:\PROGRAM FILES\SLIMWARE UTILITIES\SERVICES\SLIMWARE.SERVICES.EXE, Quarantined, [14717], [452421],1.0.3440 Module: 1 PUP.Optional.SlimServices, C:\PROGRAM FILES\SLIMWARE UTILITIES\SERVICES\SLIMWARE.SERVICES.EXE, Quarantined, [14717], [452421],1.0.3440 Registry Key: 11 PUP.Optional.ASK, HKU\S-1-5-21-1400221839-1314888541-504861578-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{7C5F16EE-512E-4D7D-912C-5CB94C7ED997}, Quarantined, [472], [258454],1.0.3440 PUP.Optional.Spigot, HKU\S-1-5-21-1400221839-1314888541-504861578-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E047F502-F9FF-4F1C-8A5A-136AF797F57F}, Quarantined, [583], [243431],1.0.3440 PUP.Optional.SlimServices, HKLM\SOFTWARE\CLASSES\TYPELIB\{58A8BF1A-3608-41EA-AAD1-581AB79105E6}, Quarantined, [14717], [452421],1.0.3440 PUP.Optional.SlimServices, HKLM\SOFTWARE\CLASSES\INTERFACE\{E58DA376-0D39-45ED-A6EE-A7B6DD10BED2}, Quarantined, [14717], [452421],1.0.3440 PUP.Optional.SlimServices, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{58A8BF1A-3608-41EA-AAD1-581AB79105E6}, Quarantined, [14717], [452421],1.0.3440 PUP.Optional.SlimServices, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{58A8BF1A-3608-41EA-AAD1-581AB79105E6}, Quarantined, [14717], [452421],1.0.3440 PUP.Optional.SlimServices, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SlimWareServices, Quarantined, [14717], [452421],1.0.3440 PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{ABA29C63-B22D-45F8-BA20-7C8EF17B5E62}, Quarantined, [991], [335437],1.0.3440 PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\TYPELIB\{95F57E4A-1FFA-4814-9AEC-34D22DF3D8FA}, Quarantined, [1315], [335828],1.0.3440 PUP.Optional.DriverUpdate, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{95F57E4A-1FFA-4814-9AEC-34D22DF3D8FA}, Quarantined, [1315], [335828],1.0.3440 PUP.Optional.DriverUpdate, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{95F57E4A-1FFA-4814-9AEC-34D22DF3D8FA}, Quarantined, [1315], [335828],1.0.3440 Registry Value: 4 PUP.Optional.ASK, HKU\S-1-5-21-1400221839-1314888541-504861578-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{7C5F16EE-512E-4D7D-912C-5CB94C7ED997}|URL, Quarantined, [472], [258454],1.0.3440 PUP.Optional.Spigot, HKU\S-1-5-21-1400221839-1314888541-504861578-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E047F502-F9FF-4F1C-8A5A-136AF797F57F}|URL, Quarantined, [583], [243431],1.0.3440 PUP.Optional.DriverUpdate, HKU\S-1-5-21-1400221839-1314888541-504861578-1002\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|DRIVERUPDATE, Quarantined, [1315], [331450],1.0.3440 PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{ABA29C63-B22D-45F8-BA20-7C8EF17B5E62}|DISPLAYNAME, Quarantined, [991], [335437],1.0.3440 Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 7 PUP.Optional.CrazyScore, C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jmmefmclajgpfbinkkojcomjjbhcapmd, Quarantined, [6387], [301821],1.0.3440 PUP.Optional.CrazyScore, C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmmefmclajgpfbinkkojcomjjbhcapmd\1.0.5598.26372_0, Quarantined, [6387], [301821],1.0.3440 PUP.Optional.CrazyScore, C:\USERS\AMY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\JMMEFMCLAJGPFBINKKOJCOMJJBHCAPMD, Quarantined, [6387], [301821],1.0.3440 PUP.Optional.QuickSearcher, C:\Users\Amy\AppData\Roaming\Opera Software\Opera Stable\Extensions\pbdpajcdgknpendpmecafmopknefafha\1.1.3\images, Quarantined, [73], [373206],1.0.3440 PUP.Optional.QuickSearcher, C:\Users\Amy\AppData\Roaming\Opera Software\Opera Stable\Extensions\pbdpajcdgknpendpmecafmopknefafha\1.1.3\js, Quarantined, [73], [373206],1.0.3440 PUP.Optional.QuickSearcher, C:\Users\Amy\AppData\Roaming\Opera Software\Opera Stable\Extensions\pbdpajcdgknpendpmecafmopknefafha\1.1.3, Quarantined, [73], [373206],1.0.3440 PUP.Optional.QuickSearcher, C:\USERS\AMY\APPDATA\ROAMING\OPERA SOFTWARE\OPERA STABLE\EXTENSIONS\PBDPAJCDGKNPENDPMECAFMOPKNEFAFHA, Quarantined, [73], [373206],1.0.3440 File: 38 PUP.Optional.SlimServices, C:\PROGRAM FILES\SLIMWARE UTILITIES\SERVICES\SLIMWARE.SERVICES.EXE, Delete-on-Reboot, [14717], [452421],1.0.3440 PUP.Optional.CrazyScore, C:\USERS\AMY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Removal Failed, [6387], [301821],1.0.3440 PUP.Optional.CrazyScore, C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jmmefmclajgpfbinkkojcomjjbhcapmd\000253.ldb, Quarantined, [6387], [301821],1.0.3440 PUP.Optional.CrazyScore, C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jmmefmclajgpfbinkkojcomjjbhcapmd\000506.log, Quarantined, [6387], [301821],1.0.3440 PUP.Optional.CrazyScore, C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jmmefmclajgpfbinkkojcomjjbhcapmd\000509.ldb, Quarantined, [6387], [301821],1.0.3440 PUP.Optional.CrazyScore, C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jmmefmclajgpfbinkkojcomjjbhcapmd\CURRENT, Quarantined, [6387], [301821],1.0.3440 PUP.Optional.CrazyScore, C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jmmefmclajgpfbinkkojcomjjbhcapmd\LOCK, Quarantined, [6387], [301821],1.0.3440 PUP.Optional.CrazyScore, C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jmmefmclajgpfbinkkojcomjjbhcapmd\MANIFEST-000001, Quarantined, [6387], [301821],1.0.3440 PUP.Optional.CrazyScore, C:\USERS\AMY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\JMMEFMCLAJGPFBINKKOJCOMJJBHCAPMD\1.0.5598.26372_0\MANIFEST.JSON, Quarantined, [6387], [301821],1.0.3440 PUP.Optional.CrazyScore, C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmmefmclajgpfbinkkojcomjjbhcapmd\1.0.5598.26372_0\background.js, Quarantined, [6387], [301821],1.0.3440 PUP.Optional.CrazyScore, C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmmefmclajgpfbinkkojcomjjbhcapmd\1.0.5598.26372_0\content.js, Quarantined, [6387], [301821],1.0.3440 PUP.Optional.CrazyScore, C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmmefmclajgpfbinkkojcomjjbhcapmd\1.0.5598.26372_0\icon.png, Quarantined, [6387], [301821],1.0.3440 PUP.Optional.QuickSearcher, C:\USERS\AMY\APPDATA\ROAMING\OPERA SOFTWARE\OPERA STABLE\EXTENSIONS\PBDPAJCDGKNPENDPMECAFMOPKNEFAFHA\1.1.3\MANIFEST.JSON, Quarantined, [73], [373206],1.0.3440 PUP.Optional.QuickSearcher, C:\Users\Amy\AppData\Roaming\Opera Software\Opera Stable\Extensions\pbdpajcdgknpendpmecafmopknefafha\1.1.3\images\icon-128.png, Quarantined, [73], [373206],1.0.3440 PUP.Optional.QuickSearcher, C:\Users\Amy\AppData\Roaming\Opera Software\Opera Stable\Extensions\pbdpajcdgknpendpmecafmopknefafha\1.1.3\images\icon-18.png, Quarantined, [73], [373206],1.0.3440 PUP.Optional.QuickSearcher, C:\Users\Amy\AppData\Roaming\Opera Software\Opera Stable\Extensions\pbdpajcdgknpendpmecafmopknefafha\1.1.3\images\icon-48.png, Quarantined, [73], [373206],1.0.3440 PUP.Optional.QuickSearcher, C:\Users\Amy\AppData\Roaming\Opera Software\Opera Stable\Extensions\pbdpajcdgknpendpmecafmopknefafha\1.1.3\images\icon-64.png, Quarantined, [73], [373206],1.0.3440 PUP.Optional.QuickSearcher, C:\Users\Amy\AppData\Roaming\Opera Software\Opera Stable\Extensions\pbdpajcdgknpendpmecafmopknefafha\1.1.3\js\background.js, Quarantined, [73], [373206],1.0.3440 PUP.Optional.QuickSearcher, C:\Users\Amy\AppData\Roaming\Opera Software\Opera Stable\Extensions\pbdpajcdgknpendpmecafmopknefafha\1.1.3\003b8b06, Quarantined, [73], [373206],1.0.3440 PUP.Optional.QuickSearcher, C:\Users\Amy\AppData\Roaming\Opera Software\Opera Stable\Extensions\pbdpajcdgknpendpmecafmopknefafha\1.1.3\index.html, Quarantined, [73], [373206],1.0.3440 Rootkit.Agent.PUA, C:\PROGRAMDATA\MALWAREBYTES' ANTI-MALWARE (PORTABLE)\WINFINSV.SYS-(1)-R.MBAM, Quarantined, [5642], [427182],1.0.3440 Rootkit.Agent.PUA, C:\PROGRAMDATA\MALWAREBYTES' ANTI-MALWARE (PORTABLE)\WINFINSV.SYS-(3)-R.MBAM, Quarantined, [5642], [427182],1.0.3440 Rootkit.Agent.PUA, C:\PROGRAMDATA\MALWAREBYTES' ANTI-MALWARE (PORTABLE)\WINFINSV.SYS-(9)-R.MBAM, Quarantined, [5642], [427182],1.0.3440 Rootkit.Agent.PUA, C:\PROGRAMDATA\MALWAREBYTES' ANTI-MALWARE (PORTABLE)\WINFINSV.SYS-(11)-R.MBAM, Quarantined, [5642], [427182],1.0.3440 Rootkit.Agent.PUA, C:\PROGRAMDATA\MALWAREBYTES' ANTI-MALWARE (PORTABLE)\WINFINSV.SYS-(5)-R.MBAM, Quarantined, [5642], [427182],1.0.3440 Rootkit.Agent.PUA, C:\PROGRAMDATA\MALWAREBYTES' ANTI-MALWARE (PORTABLE)\WINFINSV.SYS-R.MBAM, Quarantined, [5642], [427182],1.0.3440 Adware.5Hex, C:\PROGRAMDATA\MALWAREBYTES' ANTI-MALWARE (PORTABLE)\MSIDNTFS.SYS-U.MBAM, Quarantined, [5057], [425145],1.0.3440 Rootkit.Agent.PUA, C:\PROGRAMDATA\MALWAREBYTES' ANTI-MALWARE (PORTABLE)\WINFINSV.SYS-(13)-R.MBAM, Quarantined, [5642], [427182],1.0.3440 Rootkit.Agent.PUA, C:\PROGRAMDATA\MALWAREBYTES' ANTI-MALWARE (PORTABLE)\WINFINSV.SYS-(7)-R.MBAM, Quarantined, [5642], [427182],1.0.3440 Adware.5Hex, C:\PROGRAMDATA\MALWAREBYTES' ANTI-MALWARE (PORTABLE)\MSIDNTFS.SYS-K.MBAM, Quarantined, [5057], [425145],1.0.3440 Rootkit.Agent.PUA, C:\PROGRAMDATA\MALWAREBYTES' ANTI-MALWARE (PORTABLE)\WINFINSV.SYS-(12)-R.MBAM, Quarantined, [5642], [427182],1.0.3440 Rootkit.Agent.PUA, C:\PROGRAMDATA\MALWAREBYTES' ANTI-MALWARE (PORTABLE)\WINFINSV.SYS-(6)-R.MBAM, Quarantined, [5642], [427182],1.0.3440 Rootkit.Agent.PUA, C:\PROGRAMDATA\MALWAREBYTES' ANTI-MALWARE (PORTABLE)\WINFINSV.SYS-(10)-R.MBAM, Quarantined, [5642], [427182],1.0.3440 Rootkit.Agent.PUA, C:\PROGRAMDATA\MALWAREBYTES' ANTI-MALWARE (PORTABLE)\WINFINSV.SYS-(4)-R.MBAM, Quarantined, [5642], [427182],1.0.3440 Rootkit.Agent.PUA, C:\PROGRAMDATA\MALWAREBYTES' ANTI-MALWARE (PORTABLE)\WINFINSV.SYS-K.MBAM, Quarantined, [5642], [427182],1.0.3440 Rootkit.Agent.PUA, C:\PROGRAMDATA\MALWAREBYTES' ANTI-MALWARE (PORTABLE)\WINFINSV.SYS-(2)-R.MBAM, Quarantined, [5642], [427182],1.0.3440 Rootkit.Agent.PUA, C:\PROGRAMDATA\MALWAREBYTES' ANTI-MALWARE (PORTABLE)\WINFINSV.SYS-(8)-R.MBAM, Quarantined, [5642], [427182],1.0.3440 Adware.Elex.ShrtCln, C:\USERS\AMY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Web Data, Replaced, [2120], [454711],1.0.3440 Physical Sector: 0 (No malicious items detected) (end)