Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Database version: v2013.10.24.05 Windows 7 x86 NTFS Internet Explorer 8.0.7600.16385 Stefan :: STEFAN-PC [administrator] 2013/10/24 17:54:56 PM mbam-log-2013-10-24 (17-54-56).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 244779 Time elapsed: 4 minute(s), 1 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 29 HKCR\AppID\{38495740-0035-4471-851E-F5BBB86AB085} (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully. HKCR\AppID\{72D89EBF-0C5D-4190-91FD-398E45F1D007} (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully. HKCR\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} (PUP.Optional.BrowseFox.A) -> Quarantined and deleted successfully. HKCR\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9} (PUP.Software.Updater) -> Quarantined and deleted successfully. HKCR\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476} (PUP.Software.Updater) -> Quarantined and deleted successfully. HKCR\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67} (PUP.Software.Updater) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96} (PUP.Software.Updater) -> Quarantined and deleted successfully. HKCR\Updater.AmiUpd.1 (PUP.Software.Updater) -> Quarantined and deleted successfully. HKCR\Updater.AmiUpd (PUP.Software.Updater) -> Quarantined and deleted successfully. HKCR\CLSID\{A1E28287-1A31-4b0f-8D05-AA8C465D3C5A} (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully. HKCR\DefaultTabBHO.DefaultTabBrowserActiveX.1 (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully. HKCR\DefaultTabBHO.DefaultTabBrowserActiveX (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A1E28287-1A31-4B0F-8D05-AA8C465D3C5A} (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01} (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2D33ED6-EBBD-467C-BF6F-F175D9B51363} (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BAD84EE2-624D-4e7c-A8BB-41EFD720FD77} (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{96E277C1-EFCC-6C5F-F089-7BF080367B2E} (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{29A2FD27-9630-A0E7-005B-845CC22AE62A} (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully. HKCR\CrossriderApp0041844.BHO (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully. HKCR\CrossriderApp0041844.Sandbox (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully. HKCR\CrossriderApp0041844.Sandbox.1 (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully. HKCR\AppID\DefaultTabBHO.DLL (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully. HKCU\SOFTWARE\DEFAULT TAB (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully. HKCU\Software\AppDataLow\SProtector (PUP.Optional.SProtector.A) -> Quarantined and deleted successfully. HKCU\Software\AppDataLow\Software\DefaultTab (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully. HKCU\SOFTWARE\INSTALLCORE (PUP.Optional.InstallCore.A) -> Quarantined and deleted successfully. HKLM\SOFTWARE\DEFAULT TAB (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Speedchecker Limited\PC Speed Up (PUP.Optional.PCSpeedUp.A) -> Quarantined and deleted successfully. HKLM\Software\ElectroLyrics-1 (PUP.Optional.ElectroLyrics.A) -> Quarantined and deleted successfully. Registry Values Detected: 3 HKCU\SOFTWARE\Default Tab|Version (PUP.Optional.DefaultTab.A) -> Data: 2.2.8.0 -> Quarantined and deleted successfully. HKCU\Software\InstallCore|tb (PUP.Optional.InstallCore.A) -> Data: 0A2T1U1Q0StGyEtH1I2Y0StGtBtH1N1QtI0EtGzv -> Quarantined and deleted successfully. HKLM\SOFTWARE\Default Tab|Version (PUP.Optional.DefaultTab.A) -> Data: 2.2.8.0 -> Quarantined and deleted successfully. Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 8 C:\ProgramData\Tarma Installer (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully. C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504} (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully. C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Cache (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully. C:\Users\Stefan\AppData\Roaming\OpenCandy (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully. C:\Users\Stefan\AppData\Roaming\OpenCandy\0F379A89265945DEAD8E072F98CB17CC (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully. C:\Users\Stefan\AppData\Roaming\OpenCandy\A7B1587E199847E3A81B5C9C2D01AFD5 (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully. C:\Users\Stefan\AppData\Roaming\OpenCandy\OpenCandy_A7B1587E199847E3A81B5C9C2D01AFD5 (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully. C:\Users\Stefan\AppData\Roaming\File Scout (PUP.Optional.FileScout.A) -> Quarantined and deleted successfully. Files Detected: 25 C:\Users\Stefan\AppData\Local\SwvUpdater\Updater.exe (PUP.Software.Updater) -> Quarantined and deleted successfully. C:\ProgramData\ccoonntoinuUEtossavea\5182b065d252e.dll (PUP.Optional.MultiPlug.A) -> Quarantined and deleted successfully. C:\ProgramData\InstallMate\{AF0AF371-584C-4B47-A9AC-106E74E9D187}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully. C:\ProgramData\InstallMate\{AF0AF371-584C-4B47-A9AC-106E74E9D187}\TsuDll.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully. C:\ProgramData\InstallMate\{CEFF2BF8-4E61-49C6-AB2D-0643151C090E}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully. C:\ProgramData\InstallMate\{CEFF2BF8-4E61-49C6-AB2D-0643151C090E}\TsuDll.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully. C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully. C:\ProgramData\YTD Video Downloader\ytd_installer.exe (PUP.Optional.Spigot.A) -> Quarantined and deleted successfully. C:\Users\Stefan\AppData\Roaming\File Scout\filescout.exe (PUP.Optional.FileScout.A) -> Quarantined and deleted successfully. C:\Users\Stefan\dxqzso.exe (Trojan.Dropper.AI) -> Quarantined and deleted successfully. C:\Users\Stefan\Downloads\77ZipSetup.exe (Adware.InstallBrain) -> Quarantined and deleted successfully. C:\Users\Stefan\Downloads\setup.exe (PUP.Optional.ExpressInstall.A) -> Quarantined and deleted successfully. C:\Users\Stefan\Downloads\SoftonicDownloader_for_vlc-media-player.exe (PUP.Optional.Softonic) -> Quarantined and deleted successfully. C:\Users\Stefan\Downloads\SoftonicDownloader_for_winamp.exe (PUP.Optional.Softonic) -> Quarantined and deleted successfully. C:\Users\Stefan\Downloads\sweetimsetup.exe (PUP.Optional.SweetIM) -> Quarantined and deleted successfully. C:\Users\Stefan\Downloads\ELe.1.20.x264.rar.exe (PUP.Optional.Installex) -> Quarantined and deleted successfully. C:\Users\Stefan\Downloads\Dexter.S08E02.Every.Silver.Lining..XviD-MGD[ettv].exe (PUP.Optional.Installex) -> Quarantined and deleted successfully. C:\Windows\Tasks\AmiUpdXp.job (PUP.Software.Updater) -> Quarantined and deleted successfully. C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.dat (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully. C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.ico (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully. C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setup.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully. C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully. C:\Users\Stefan\AppData\Roaming\OpenCandy\0F379A89265945DEAD8E072F98CB17CC\IE9-Windows7-x86-enu.exe (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully. C:\Users\Stefan\AppData\Roaming\OpenCandy\A7B1587E199847E3A81B5C9C2D01AFD5\PCSU_SL_3.1.2.exe (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully. C:\Users\Stefan\AppData\Roaming\File Scout\uninst.exe (PUP.Optional.FileScout.A) -> Quarantined and deleted successfully. (end)