

Logy:
Malwarebytes Anti-Malware
http://www.malwarebytes.org
Scan Date: 16.4.2014
Scan Time: 23:50:45
Logfile: Malwarebytes Anti-Malware log.txt
Administrator: Yes
Version: 2.00.1.1004
Malware Database: v2014.04.16.10
Rootkit Database: v2014.03.27.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Chameleon: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: flash666
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 254331
Time Elapsed: 10 min, 24 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 42
PUP.Optional.PutLocker.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{11111111-1111-1111-1111-110311551180}, Quarantined, [f713fe2d295252e43a6c50f98a78c040],
PUP.Optional.PutLocker.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440344554480}, Quarantined, [f713fe2d295252e43a6c50f98a78c040],
PUP.Optional.PutLocker.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550355555580}, Quarantined, [f713fe2d295252e43a6c50f98a78c040],
PUP.Optional.PutLocker.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660366556680}, Quarantined, [f713fe2d295252e43a6c50f98a78c040],
PUP.Optional.PutLocker.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550355555580}, Quarantined, [f713fe2d295252e43a6c50f98a78c040],
PUP.Optional.PutLocker.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660366556680}, Quarantined, [f713fe2d295252e43a6c50f98a78c040],
PUP.Optional.PutLocker.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440344554480}, Quarantined, [f713fe2d295252e43a6c50f98a78c040],
PUP.Optional.PutLocker.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0035580.BHO.1, Quarantined, [f713fe2d295252e43a6c50f98a78c040],
PUP.Optional.PutLocker.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110311551180}, Quarantined, [f713fe2d295252e43a6c50f98a78c040],
PUP.Optional.PutLocker.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0035580.BHO, Quarantined, [f713fe2d295252e43a6c50f98a78c040],
PUP.Optional.PutLocker.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0035580.BHO, Quarantined, [f713fe2d295252e43a6c50f98a78c040],
PUP.Optional.PutLocker.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0035580.BHO.1, Quarantined, [f713fe2d295252e43a6c50f98a78c040],
PUP.Optional.PutLocker.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{11111111-1111-1111-1111-110311551180}, Quarantined, [f713fe2d295252e43a6c50f98a78c040],
PUP.Optional.WebCake.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{DF84E609-C3A4-49CB-A160-61767DAF8899}, Quarantined, [c941cf5c512a0f27285e7fcbbd4541bf],
PUP.Optional.WebCake.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{DF84E609-C3A4-49CB-A160-61767DAF8899}, Quarantined, [c941cf5c512a0f27285e7fcbbd4541bf],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0035578.BHO, Quarantined, [e42635f633483cfaa944187bcc37966a],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0035578.BHO.1, Quarantined, [57b30e1d8cef61d5a845aae9a75c9769],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0035578.Sandbox, Quarantined, [c743bc6fdba08bab20cdb9da1fe43ec2],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0035578.Sandbox.1, Quarantined, [3bcfd9526417eb4b67862f6416ed7d83],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0035580.Sandbox, Quarantined, [15f58e9d1665c96d2dc0b6ddc53ec937],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0035580.Sandbox.1, Quarantined, [65a549e23348cb6b18d5771c43c0758b],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0035578.BHO, Quarantined, [749646e52c4f40f6f9f44350976ced13],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0035578.BHO.1, Quarantined, [67a30b201c5f8caacd20b5de93703ec2],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0035578.Sandbox, Quarantined, [a2688d9e1467092d6588e3b01ce75aa6],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0035578.Sandbox.1, Quarantined, [ae5c79b2daa15bdb29c43063d033d32d],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0035580.Sandbox, Quarantined, [76947ead6e0d77bf6b82a3f05aa9f40c],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0035580.Sandbox.1, Quarantined, [15f5b7740873bb7bf6f7741f50b38779],
PUP.Optional.TornTV.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\bicnnkjibmphdeigoodpjlcklcnaobdj, Quarantined, [f416da51a8d37db9c12aef7e0df510f0],
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\SWEETIM, Quarantined, [bb4fde4d0a717fb737ba355e40c321df],
PUP.Optional.1ClickDownload.A, HKU\S-1-5-21-2724579339-3348248144-3881584662-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\1ClickDownload, Quarantined, [000ad7541c5f290df4683e5612f1b947],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2724579339-3348248144-3881584662-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, Quarantined, [799131fa0c6f60d64e4a3671c83b0cf4],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2724579339-3348248144-3881584662-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\installdaddy, Quarantined, [46c49f8c5922e74f6a84b9da45beb749],
PUP.Optional.SweetIM.A, HKU\S-1-5-21-2724579339-3348248144-3881584662-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM, Quarantined, [050579b2f685cb6b1cd4157e4cb7c937],
PUP.Optional.CrossRider.M, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110311551178}, Quarantined, [9c6ec3684c2ff6408d6dab7dd43045bb],
PUP.Optional.CrossRider.M, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{11111111-1111-1111-1111-110311551178}, Quarantined, [9c6ec3684c2ff6408d6dab7dd43045bb],
PUP.Optional.CrossRider.M, HKLM\SOFTWARE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440344554478}, Quarantined, [9c6ec3684c2ff6408d6dab7dd43045bb],
PUP.Optional.CrossRider.M, HKLM\SOFTWARE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550355555578}, Quarantined, [9c6ec3684c2ff6408d6dab7dd43045bb],
PUP.Optional.CrossRider.M, HKLM\SOFTWARE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660366556678}, Quarantined, [9c6ec3684c2ff6408d6dab7dd43045bb],
PUP.Optional.CrossRider.M, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550355555578}, Quarantined, [9c6ec3684c2ff6408d6dab7dd43045bb],
PUP.Optional.CrossRider.M, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660366556678}, Quarantined, [9c6ec3684c2ff6408d6dab7dd43045bb],
PUP.Optional.CrossRider.M, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440344554478}, Quarantined, [9c6ec3684c2ff6408d6dab7dd43045bb],
PUP.Optional.CrossRider.M, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{11111111-1111-1111-1111-110311551178}, Quarantined, [9c6ec3684c2ff6408d6dab7dd43045bb],
Registry Values: 2
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\SWEETIM|simapp_id, {6FDF2324-0103-11E3-9C5B-1C6F655C0F34}, Quarantined, [bb4fde4d0a717fb737ba355e40c321df]
PUP.Optional.SweetIM.A, HKU\S-1-5-21-2724579339-3348248144-3881584662-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM|simapp_id, {6FDF2324-0103-11E3-9C5B-1C6F655C0F34}, Quarantined, [050579b2f685cb6b1cd4157e4cb7c937]
Registry Data: 0
(No malicious items detected)
Folders: 2
PUP.Optional.OpenCandy, C:\Users\flash666\AppData\Roaming\OpenCandy, Quarantined, [8684b17a552674c2b7a47de0c73bfb05],
PUP.Optional.OpenCandy, C:\Users\flash666\AppData\Roaming\OpenCandy\510A4D73DE5B4CE88917951A122C504A, Quarantined, [8684b17a552674c2b7a47de0c73bfb05],
Files: 8
PUP.Optional.Spigot.A, C:\Users\flash666\Desktop\aTubeCatcher.exe, Quarantined, [bf4b3cef007b4ee892c738e72dd4936d],
PUP.Optional.TornTV.A, C:\Windows\Tasks\Torntv 2-codedownloader.job, Quarantined, [27e3dc4f69124bebc6f4126ccb377d83],
PUP.Optional.TornTV.A, C:\Windows\Tasks\Torntv 2-enabler.job, Quarantined, [3eccfd2e0576c373c8f2e39b6c96738d],
PUP.Optional.TornTV.A, C:\Windows\Tasks\Torntv 2-updater.job, Quarantined, [44c644e77dfee74f6b4f1a645ea41ae6],
PUP.Optional.PutLocker.A, C:\Windows\Tasks\PutLockerDownloader V3.0-codedownloader.job, Quarantined, [7b8f39f2fb80171f9e489bf554af0000],
PUP.Optional.PutLocker.A, C:\Windows\Tasks\PutLockerDownloader V3.0-enabler.job, Quarantined, [c14978b35f1cfa3c6086a0f01ce7b44c],
PUP.Optional.PutLocker.A, C:\Windows\Tasks\PutLockerDownloader V3.0-updater.job, Quarantined, [c44669c2225967cf974f7c144cb7b54b],
PUP.Optional.OpenCandy, C:\Users\flash666\AppData\Roaming\OpenCandy\510A4D73DE5B4CE88917951A122C504A\TuneUpUtilities2013-2200329_cs-CZ.exe, Quarantined, [8684b17a552674c2b7a47de0c73bfb05],
Physical Sectors: 0
(No malicious items detected)
(end)
*******************************************************************************************************************************************************************************************************************************************************************************************************************************************************************************************************************************************************************************************************************************************************************************************************************************************
# AdwCleaner v3.023 - Report created 16/04/2014 at 23:51:58
# Updated 01/04/2014 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)
# Username : flash666 - HELLMACHINE
# Running from : C:\Users\flash666\Desktop\CLEAN\adwcleaner.exe
# Option : Scan
***** [ Services ] *****
Service Found : APNMCP
***** [ Files / Folders ] *****
Folder Found C:\Program Files (x86)\AskPartnerNetwork
Folder Found C:\Program Files (x86)\Movdap
Folder Found C:\ProgramData\apn
Folder Found C:\ProgramData\AskPartnerNetwork
Folder Found C:\ProgramData\Tarma Installer
Folder Found C:\Users\flash666\AppData\Local\cool_mirage
Folder Found C:\Users\flash666\AppData\Local\CrashRpt
Folder Found C:\Users\flash666\AppData\Roaming\Movdap
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\AskPartnerNetwork
Key Found : HKCU\Software\installedbrowserextensions
Key Found : [x64] HKCU\Software\AskPartnerNetwork
Key Found : [x64] HKCU\Software\installedbrowserextensions
Key Found : HKLM\Software\AskPartnerNetwork
Key Found : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220322552278}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220322552280}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{44CBC005-6243-4502-8A02-3A096A282664}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{80703783-E415-4EE3-AB60-D36981C5A6F1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{D8278076-BC68-4484-9233-6E7F1628B56C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F297534D-7B06-459D-BC19-2DD8EF69297B}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{0AFD55C8-ADF8-4A33-A6E1-DEDB7A36AEB4}
Key Found : HKLM\SOFTWARE\Classes\Interface\{80703783-E415-4EE3-AB60-D36981C5A6F1}
Key Found : HKLM\SOFTWARE\Classes\PutLockerDownloader
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9945959C-AAD8-4312-8B57-2DE11927E770}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6978F29A-3493-40B2-8CDC-9C13A02F85A4}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D}
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\BundleSweetIMSetup_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\BundleSweetIMSetup_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASMANCS
Key Found : [x64] HKLM\SOFTWARE\AskPartnerNetwork
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6978F29A-3493-40B2-8CDC-9C13A02F85A4}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D}
Key Found : [x64] HKLM\SOFTWARE\Tarma Installer
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{D8278076-BC68-4484-9233-6E7F1628B56C}]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnTbMon]
***** [ Browsers ] *****
-\\ Internet Explorer v8.0.7601.17514
Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.search.ask.com/?p2=%5EB7N%5E ... 6spr%253Da
-\\ Mozilla Firefox v24.0 (cs)
[ File : C:\Users\flash666\AppData\Roaming\Mozilla\Firefox\Profiles\60vjcfs4.default\prefs.js ]
-\\ Google Chrome v34.0.1847.116
[ File : C:\Users\flash666\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [3923 octets] - [16/04/2014 23:51:58]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [3983 octets] ##########