Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 24-12-2014 Scan Time: 22:25:48 Logfile: MBAM Scanlog1.txt Administrator: Yes Version: 2.00.4.1028 Malware Database: v2014.12.24.13 Rootkit Database: v2014.12.23.02 License: Free Malware Protection: Disabled Malicious Website Protection: Disabled Self-protection: Disabled OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: Hayel Scan Type: Threat Scan Result: Completed Objects Scanned: 338308 Time Elapsed: 46 min, 18 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 0 (No malicious items detected) Modules: 0 (No malicious items detected) Registry Keys: 77 PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\APPID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}, Quarantined, [4c611e48bebe94a25f0750c2d72c40c0], PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}, Quarantined, [4c611e48bebe94a25f0750c2d72c40c0], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{965B9DBE-B104-44AC-950A-8A5F97AFF439}, Quarantined, [98155d095527a1957a4553ba857e6e92], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A9DB719C-7156-415E-B49D-BAD039DE4F13}, Quarantined, [6548d195c9b3ce68348f7b9216ed857b], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\funmoodsApp.appCore.1, Quarantined, [6548d195c9b3ce68348f7b9216ed857b], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\funmoodsApp.appCore, Quarantined, [6548d195c9b3ce68348f7b9216ed857b], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\funmoodsApp.appCore, Quarantined, [6548d195c9b3ce68348f7b9216ed857b], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\funmoodsApp.appCore.1, Quarantined, [6548d195c9b3ce68348f7b9216ed857b], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{F03FD9D0-4F2B-497C-8A71-DD41D70B07D9}, Quarantined, [327b9cca3745a591784cf6170cf7ce32], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\f, Quarantined, [327b9cca3745a591784cf6170cf7ce32], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\f, Quarantined, [327b9cca3745a591784cf6170cf7ce32], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{1D085C0A-E4F4-4F66-BDBF-4BE51015BFC3}, Quarantined, [8d2081e593e993a396c65b8eb34f867a], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{0D80F1C5-D17B-4177-AC68-955F3EF9F191}, Quarantined, [8d2081e593e993a396c65b8eb34f867a], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{23C70BCA-6E23-4A65-AD2E-1389062074F1}, Quarantined, [8d2081e593e993a396c65b8eb34f867a], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{23D8EEF7-0E13-4000-B9C4-6603C1E912D1}, Quarantined, [8d2081e593e993a396c65b8eb34f867a], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{295CACB4-51F5-46FD-914E-C72BAAE1B672}, Quarantined, [8d2081e593e993a396c65b8eb34f867a], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{2CE5C4B9-6DBE-4528-96FA-C9FF38EF1762}, Quarantined, [8d2081e593e993a396c65b8eb34f867a], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{34C1FDF7-02C1-4F23-B393-F48B16E071D1}, Quarantined, [8d2081e593e993a396c65b8eb34f867a], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{54291324-7A3D-4F11-B707-3FB6A2C97BD9}, Quarantined, [8d2081e593e993a396c65b8eb34f867a], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{59C63F11-D4E5-46E7-9B8A-EE158DCA83A8}, Quarantined, [8d2081e593e993a396c65b8eb34f867a], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{5DA22CBD-0029-4A09-B757-CF0FAFC488ED}, Quarantined, [8d2081e593e993a396c65b8eb34f867a], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{77A6E7D4-4A83-4A9B-A2A0-EF3B125DC29D}, Quarantined, [8d2081e593e993a396c65b8eb34f867a], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{C0585B2F-74D7-4734-88DE-6C150C5D4036}, Quarantined, [8d2081e593e993a396c65b8eb34f867a], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{CA17D76B-F91D-4659-A7FD-A9F7ED375CDD}, Quarantined, [8d2081e593e993a396c65b8eb34f867a], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{D8242E89-2F81-484A-AE5B-BA8CAD5B7347}, Quarantined, [8d2081e593e993a396c65b8eb34f867a], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{EF0588D6-1621-4A75-B8BE-F4BC34794136}, Quarantined, [8d2081e593e993a396c65b8eb34f867a], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{0D80F1C5-D17B-4177-AC68-955F3EF9F191}, Quarantined, [8d2081e593e993a396c65b8eb34f867a], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{23C70BCA-6E23-4A65-AD2E-1389062074F1}, Quarantined, [8d2081e593e993a396c65b8eb34f867a], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{23D8EEF7-0E13-4000-B9C4-6603C1E912D1}, Quarantined, [8d2081e593e993a396c65b8eb34f867a], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{295CACB4-51F5-46FD-914E-C72BAAE1B672}, Quarantined, [8d2081e593e993a396c65b8eb34f867a], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{2CE5C4B9-6DBE-4528-96FA-C9FF38EF1762}, Quarantined, [8d2081e593e993a396c65b8eb34f867a], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{34C1FDF7-02C1-4F23-B393-F48B16E071D1}, Quarantined, [8d2081e593e993a396c65b8eb34f867a], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{54291324-7A3D-4F11-B707-3FB6A2C97BD9}, Quarantined, [8d2081e593e993a396c65b8eb34f867a], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{59C63F11-D4E5-46E7-9B8A-EE158DCA83A8}, Quarantined, [8d2081e593e993a396c65b8eb34f867a], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{5DA22CBD-0029-4A09-B757-CF0FAFC488ED}, Quarantined, [8d2081e593e993a396c65b8eb34f867a], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{77A6E7D4-4A83-4A9B-A2A0-EF3B125DC29D}, Quarantined, [8d2081e593e993a396c65b8eb34f867a], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C0585B2F-74D7-4734-88DE-6C150C5D4036}, Quarantined, [8d2081e593e993a396c65b8eb34f867a], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{CA17D76B-F91D-4659-A7FD-A9F7ED375CDD}, Quarantined, [8d2081e593e993a396c65b8eb34f867a], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{D8242E89-2F81-484A-AE5B-BA8CAD5B7347}, Quarantined, [8d2081e593e993a396c65b8eb34f867a], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{EF0588D6-1621-4A75-B8BE-F4BC34794136}, Quarantined, [8d2081e593e993a396c65b8eb34f867a], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{1D085C0A-E4F4-4F66-BDBF-4BE51015BFC3}, Quarantined, [8d2081e593e993a396c65b8eb34f867a], PUP.Optional.Snapdo.T, HKU\S-1-5-21-1956934913-172480106-3488795705-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, Quarantined, [d8d5afb7acd03bfbce438b8a59aa36ca], PUP.Optional.Blabbers, HKLM\SOFTWARE\CLASSES\updatebho.TimerBHO, Quarantined, [971632347507d3638783ebffe81a9868], PUP.Optional.Blabbers, HKLM\SOFTWARE\CLASSES\updatebho.TimerBHO.1, Quarantined, [7736e185e9936fc7ab5f27c3a0621ce4], PUP.Optional.Blabbers, HKLM\SOFTWARE\WOW6432NODE\CLASSES\updatebho.TimerBHO, Quarantined, [7736e185e9936fc7ab5f27c3a0621ce4], PUP.Optional.Blabbers, HKLM\SOFTWARE\WOW6432NODE\CLASSES\updatebho.TimerBHO.1, Quarantined, [7736e185e9936fc7ab5f27c3a0621ce4], PUP.Optional.Blabbers, HKLM\SOFTWARE\CLASSES\wit4ie.WitBHO, Quarantined, [3a734323c3b9d36343c88b5f33cfe41c], PUP.Optional.Blabbers, HKLM\SOFTWARE\CLASSES\wit4ie.WitBHO.2, Quarantined, [4469bfa797e592a410fb47a325ddef11], PUP.Optional.Blabbers, HKLM\SOFTWARE\WOW6432NODE\CLASSES\wit4ie.WitBHO, Quarantined, [4469bfa797e592a410fb47a325ddef11], PUP.Optional.Blabbers, HKLM\SOFTWARE\WOW6432NODE\CLASSES\wit4ie.WitBHO.2, Quarantined, [4469bfa797e592a410fb47a325ddef11], PUP.Optional.Blabbers, HKLM\SOFTWARE\CLASSES\tdataprotocol.CTData, Quarantined, [c3eae5816b114aecb05c2bbfef1348b8], PUP.Optional.Blabbers, HKLM\SOFTWARE\CLASSES\tdataprotocol.CTData.1, Quarantined, [446971f53547d95df3197a70c83a0000], PUP.Optional.Blabbers, HKLM\SOFTWARE\WOW6432NODE\CLASSES\tdataprotocol.CTData, Quarantined, [446971f53547d95df3197a70c83a0000], PUP.Optional.Blabbers, HKLM\SOFTWARE\WOW6432NODE\CLASSES\tdataprotocol.CTData.1, Quarantined, [446971f53547d95df3197a70c83a0000], PUP.Optional.FunMoods.A, HKLM\SOFTWARE\CLASSES\funmoods.funmoodsHlpr, Quarantined, [8924006675079e98bcb77676eb1715eb], PUP.Optional.FunMoods.A, HKLM\SOFTWARE\CLASSES\funmoods.funmoodsHlpr.1, Quarantined, [6e3f51154b31999d056e6488df23c937], PUP.Optional.FunMoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\funmoods.funmoodsHlpr, Quarantined, [6e3f51154b31999d056e6488df23c937], PUP.Optional.FunMoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\funmoods.funmoodsHlpr.1, Quarantined, [6e3f51154b31999d056e6488df23c937], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\funmoods.dskBnd, Quarantined, [ddd022441369e74ffcc6f91429da916f], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\funmoods.dskBnd.1, Quarantined, [7934d88e4537d85e5c66c7466e95b749], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\funmoods.dskBnd, Quarantined, [7934d88e4537d85e5c66c7466e95b749], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\funmoods.dskBnd.1, Quarantined, [7934d88e4537d85e5c66c7466e95b749], PUP.Optional.Blabbers, HKLM\SOFTWARE\CLASSES\PROTOCOLS\HANDLER\BASE64, Quarantined, [505d44225b218caa939976067a8a5fa1], PUP.Optional.Blabbers, HKLM\SOFTWARE\CLASSES\PROTOCOLS\HANDLER\CHROME, Quarantined, [7a33e77f562684b23bf25c20798b7090], PUP.Optional.Blabbers, HKLM\SOFTWARE\CLASSES\PROTOCOLS\HANDLER\PROX, Quarantined, [228b44221666bc7a34fa99e3f60e46ba], PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\Iminent, Quarantined, [8e1f7aeceb918aac3b26aef0f310cd33], PUP.Optional.ISearch.A, HKLM\SOFTWARE\WOW6432NODE\omiga-plusSoftware, Quarantined, [a904293d44384fe71d5e408b6b99837d], PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\SweetIM, Quarantined, [2f7eaeb8f488171f90b50c4fd33033cd], PUP.Optional.Blabbers, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PROTOCOLS\HANDLER\BASE64, Quarantined, [307d4b1b98e488ae57d5ec9010f457a9], PUP.Optional.Blabbers, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PROTOCOLS\HANDLER\CHROME, Quarantined, [1994184e43394fe70825c7b58d77b947], PUP.Optional.Blabbers, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PROTOCOLS\HANDLER\PROX, Quarantined, [d0dd3c2ae19b360067c78cf056aee020], PUP.Optional.TornTV.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\TornTv Downloader, Quarantined, [6c416006eb913ef8df1a293636cdeb15], PUP.Optional.1ClickDownload.A, HKU\S-1-5-21-1956934913-172480106-3488795705-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\1ClickDownload, Quarantined, [cce1ef7726563ff716c5eaca758f6898], PUP.Optional.Softonic.A, HKU\S-1-5-21-1956934913-172480106-3488795705-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Softonic, Quarantined, [2f7e4422740883b325b71d3fb053f010], PUP.Optional.SweetIM.A, HKU\S-1-5-21-1956934913-172480106-3488795705-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SweetIM, Quarantined, [7f2e5f078cf0b383182c87d4c43fa25e], Adware.TryMedia, HKU\S-1-5-21-1956934913-172480106-3488795705-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Trymedia Systems, Quarantined, [88252c3a601c70c6d9d8de392cd8847c], PUP.Optional.CrossRider.A, HKU\S-1-5-21-1956934913-172480106-3488795705-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, Quarantined, [b3fa92d4a1dba195a6155374c73d2cd4], Registry Values: 6 PUP.Optional.Blabbers, HKLM\SOFTWARE\CLASSES\PROTOCOLS\HANDLER\BASE64|CLSID, {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1}, Quarantined, [505d44225b218caa939976067a8a5fa1] PUP.Optional.Blabbers, HKLM\SOFTWARE\CLASSES\PROTOCOLS\HANDLER\CHROME|CLSID, {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1}, Quarantined, [7a33e77f562684b23bf25c20798b7090] PUP.Optional.Blabbers, HKLM\SOFTWARE\CLASSES\PROTOCOLS\HANDLER\PROX|CLSID, {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1}, Quarantined, [228b44221666bc7a34fa99e3f60e46ba] PUP.Optional.Blabbers, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PROTOCOLS\HANDLER\BASE64|CLSID, {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1}, Quarantined, [307d4b1b98e488ae57d5ec9010f457a9] PUP.Optional.Blabbers, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PROTOCOLS\HANDLER\CHROME|CLSID, {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1}, Quarantined, [1994184e43394fe70825c7b58d77b947] PUP.Optional.Blabbers, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PROTOCOLS\HANDLER\PROX|CLSID, {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1}, Quarantined, [d0dd3c2ae19b360067c78cf056aee020] Registry Data: 2 PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Replaced,[3f6e8cda67155ed8bf4fdd9f56afa55b] PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Replaced,[d9d48dd9fd7f0a2c5cb26616c342c53b] Folders: 1 PUP.Optional.SpamFreeSearch.A, C:\Users\Hayel\AppData\LocalLow\blekko\spamfreesearch, Quarantined, [238a88de215bc96d8cbccb84e61d47b9], Files: 2 PUP.Optional.SmartBar.A, C:\Users\Hayel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_amfclgbdpgndipgoegfpkkgobahigbcl_0.localstorage, Quarantined, [f8b52046a0dc1b1b47534717ce35c739], PUP.Optional.SmartBar.A, C:\Users\Hayel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_amfclgbdpgndipgoegfpkkgobahigbcl_0.localstorage-journal, Quarantined, [921b95d1d1abf541acee9dc16c97a65a], Physical Sectors: 0 (No malicious items detected) (end)