Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 8-4-2015 Scan Time: 15:35:38 Logfile: Anti-malware log.txt Administrator: Yes Version: 2.00.4.1028 Malware Database: v2015.04.08.04 Rootkit Database: v2015.03.31.01 License: Trial Malware Protection: Enabled Malicious Website Protection: Enabled Self-protection: Disabled OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: Aart Scan Type: Threat Scan Result: Completed Objects Scanned: 347072 Time Elapsed: 22 min, 48 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 0 (No malicious items detected) Modules: 0 (No malicious items detected) Registry Keys: 22 PUP.Optional.Ominent.A, HKLM\SOFTWARE\CLASSES\APPID\{9A246976-806F-4B2E-B3B9-A9A58F5685AA}, Quarantined, [73b16cfe4c3e0c2a25d9ff3cc340ef11], PUP.Optional.Ominent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{9A246976-806F-4B2E-B3B9-A9A58F5685AA}, Quarantined, [73b16cfe4c3e0c2a25d9ff3cc340ef11], PUP.Optional.Ominent.A, HKLM\SOFTWARE\CLASSES\ominent.ominentHlpr, Quarantined, [0420f6741a701b1b5c2e95dde122d12f], PUP.Optional.Ominent.A, HKLM\SOFTWARE\CLASSES\ominent.ominentHlpr.1, Quarantined, [998be981d9b15fd7a3e74a288d760bf5], PUP.Optional.Ominent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ominent.ominentHlpr, Quarantined, [998be981d9b15fd7a3e74a288d760bf5], PUP.Optional.Ominent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ominent.ominentHlpr.1, Quarantined, [998be981d9b15fd7a3e74a288d760bf5], PUP.Optional.Ominent.A, HKLM\SOFTWARE\CLASSES\esrv.ominentESrvc, Quarantined, [c262e684cdbdc37302fa45e8c83d2ed2], PUP.Optional.Ominent.A, HKLM\SOFTWARE\CLASSES\esrv.ominentESrvc.1, Quarantined, [c75d89e1296166d05ba1a489ff063ec2], PUP.Optional.Ominent.A, HKLM\SOFTWARE\CLASSES\ominent.ominentappCore, Quarantined, [958f1e4c7218102697660b22a461c43c], PUP.Optional.Ominent.A, HKLM\SOFTWARE\CLASSES\ominent.ominentappCore.1, Quarantined, [ed3785e5e4a674c253aa6ac365a0e41c], PUP.Optional.Ominent.A, HKLM\SOFTWARE\CLASSES\ominent.ominentdskBnd, Quarantined, [4dd7046692f8ed49bc41df4e53b2e719], PUP.Optional.Ominent.A, HKLM\SOFTWARE\CLASSES\ominent.ominentdskBnd.1, Quarantined, [32f2f1797b0f1d1936c7eb428e77d729], PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}, Quarantined, [f03487e346440f275558fc47b74eeb15], PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{cf2797aa-b7ec-e311-8ed9-005056c00008}, Quarantined, [31f377f3177378bec5e72023669f36ca], PUP.Optional.weDownload.A, HKLM\SOFTWARE\WOW6432NODE\weDownload Ltd, Quarantined, [0e160f5bc3c747ef0033ab5f9a6a629e], PUP.Optional.Ominent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.ominentESrvc, Quarantined, [c65ebdad2f5b81b509f3cc618a7b4cb4], PUP.Optional.Ominent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.ominentESrvc.1, Quarantined, [988c87e3d2b8f93d2cd0d25b23e2956b], PUP.Optional.Ominent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ominent.ominentappCore, Quarantined, [84a09ecc5f2bc37307f6f33a51b49c64], PUP.Optional.Ominent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ominent.ominentappCore.1, Quarantined, [61c3501a8208af874cb1ac81669f7090], PUP.Optional.Ominent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ominent.ominentdskBnd, Quarantined, [869e79f129614beb708d5fce8e7738c8], PUP.Optional.Ominent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ominent.ominentdskBnd.1, Quarantined, [2afaf872e3a74beb14e9f637ae579769], PUP.Optional.weDownload.A, HKU\S-1-5-21-2110397448-1678517468-774889301-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\weDownload Ltd, Quarantined, [b074f377f496b482eb47e9211aeade22], Registry Values: 1 Trojan.Agent, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|QuickTime Update Completion 0, "C:\Windows\SysWOW64\QuickTime\QuickTimeUpdateHelper.exe" -uninstallwithapps -destfullpath "C:\Program Files (x86)\QuickTime\QuickTimeUpdater.exe" -sourcefullpath "C:\Program Files (x86)\QuickTime\TempUpdater.exe" -atboottime "QuickTime Update Completion 0", Quarantined, [a77dabbfddad60d6d55d5d719f656898] Registry Data: 0 (No malicious items detected) Folders: 4 PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaInternetEnhance, Quarantined, [c95b38320b7f0b2bc4134c6162a118e8], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaInternetEnhance\Explore Social Search, Quarantined, [c95b38320b7f0b2bc4134c6162a118e8], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaInternetEnhance\Explore Social Shopping, Quarantined, [c95b38320b7f0b2bc4134c6162a118e8], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaInternetEnhance\Uninstall Wajam, Quarantined, [c95b38320b7f0b2bc4134c6162a118e8], Files: 30 PUP.Optional.WebCake.A, C:\Program Files (x86)\WBDesearch, Quarantined, [6db7aebc1278d95d9e0a52e7d829ba46], PUP.Optional.WebCake.A, C:\Program Files (x86)\WBDesktop.Updater.exe, Quarantined, [ea3ad199058593a3e4c43affc140dc24], PUP.AdBundle, C:\Users\Aart\Downloads\PDFCreatorSetup.exe, Quarantined, [d252e8826723fc3a7f3288552cd4a858], Trojan.Agent, C:\Windows\SysWOW64\QuickTime\QuickTimeUpdateHelper.exe, Quarantined, [a77dabbfddad60d6d55d5d719f656898], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaInternetEnhance\Settings.lnk, Quarantined, [c95b38320b7f0b2bc4134c6162a118e8], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaInternetEnhance\SignIn with Facebook.lnk, Quarantined, [c95b38320b7f0b2bc4134c6162a118e8], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaInternetEnhance\SignIn with Twitter.lnk, Quarantined, [c95b38320b7f0b2bc4134c6162a118e8], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaInternetEnhance\Wajam Website.lnk, Quarantined, [c95b38320b7f0b2bc4134c6162a118e8], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaInternetEnhance\Explore Social Search\Ask.lnk, Quarantined, [c95b38320b7f0b2bc4134c6162a118e8], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaInternetEnhance\Explore Social Search\Google.lnk, Quarantined, [c95b38320b7f0b2bc4134c6162a118e8], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaInternetEnhance\Explore Social Search\IMDb.lnk, Quarantined, [c95b38320b7f0b2bc4134c6162a118e8], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaInternetEnhance\Explore Social Search\Shopping.com.lnk, Quarantined, [c95b38320b7f0b2bc4134c6162a118e8], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaInternetEnhance\Explore Social Search\TripAdvisor.lnk, Quarantined, [c95b38320b7f0b2bc4134c6162a118e8], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaInternetEnhance\Explore Social Search\Wikipedia.lnk, Quarantined, [c95b38320b7f0b2bc4134c6162a118e8], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaInternetEnhance\Explore Social Search\Yahoo!.lnk, Quarantined, [c95b38320b7f0b2bc4134c6162a118e8], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaInternetEnhance\Explore Social Shopping\Amazon.lnk, Quarantined, [c95b38320b7f0b2bc4134c6162a118e8], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaInternetEnhance\Explore Social Shopping\Argos.lnk, Quarantined, [c95b38320b7f0b2bc4134c6162a118e8], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaInternetEnhance\Explore Social Shopping\Ebay.lnk, Quarantined, [c95b38320b7f0b2bc4134c6162a118e8], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaInternetEnhance\Explore Social Shopping\Etsy.lnk, Quarantined, [c95b38320b7f0b2bc4134c6162a118e8], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaInternetEnhance\Explore Social Shopping\HomeDepot.lnk, Quarantined, [c95b38320b7f0b2bc4134c6162a118e8], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaInternetEnhance\Explore Social Shopping\Ikea.lnk, Quarantined, [c95b38320b7f0b2bc4134c6162a118e8], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaInternetEnhance\Explore Social Shopping\Lowe's.lnk, Quarantined, [c95b38320b7f0b2bc4134c6162a118e8], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaInternetEnhance\Explore Social Shopping\Mercadolivre.lnk, Quarantined, [c95b38320b7f0b2bc4134c6162a118e8], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaInternetEnhance\Explore Social Shopping\MyShopping.lnk, Quarantined, [c95b38320b7f0b2bc4134c6162a118e8], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaInternetEnhance\Explore Social Shopping\Sears.lnk, Quarantined, [c95b38320b7f0b2bc4134c6162a118e8], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaInternetEnhance\Explore Social Shopping\Target.lnk, Quarantined, [c95b38320b7f0b2bc4134c6162a118e8], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaInternetEnhance\Explore Social Shopping\Tesco.lnk, Quarantined, [c95b38320b7f0b2bc4134c6162a118e8], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaInternetEnhance\Explore Social Shopping\Walmart.lnk, Quarantined, [c95b38320b7f0b2bc4134c6162a118e8], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaInternetEnhance\Explore Social Shopping\Zalando.lnk, Quarantined, [c95b38320b7f0b2bc4134c6162a118e8], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaInternetEnhance\Uninstall Wajam\uninstall.lnk, Quarantined, [c95b38320b7f0b2bc4134c6162a118e8], Physical Sectors: 0 (No malicious items detected) (end)