Malwarebytes Anti-Malware
Malwarebytes | Free Anti-Malware & Internet Security Software
Scan Date: 25/05/2015
Scan Time: 13:20:22
Logfile: lgg2.txt
Administrator: Yes
Version: 2.01.6.1022
Malware Database: v2015.05.25.03
Rootkit Database: v2015.05.24.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Daniel
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 682084
Time Elapsed: 20 min, 57 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 1
Backdoor.MSIL.PGen, C:\Windows\SysWOW64\surrasiltshawks.exe, 1804, Delete-on-Reboot, [f5e2781f830758de46cab09cac5615eb]
Modules: 0
(No malicious items detected)
Registry Keys: 4
Backdoor.MSIL.PGen, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ConkAuralQuoth, Quarantined, [f5e2781f830758de46cab09cac5615eb],
PUP.Optional.DefaultSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}, Quarantined, [3c9bbed9f694e452eb99670842c3c937],
PUP.Optional.DefaultSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}, Quarantined, [2aad5e3981091d19a7dd4e21bc49649c],
PUP.Optional.DefaultSearch.A, HKU\S-1-5-21-2583720070-748624027-3842895589-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}, Quarantined, [8d4a30673d4de5517b08abc4c144af51],
Registry Values: 10
PUP.Optional.DefaultSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}|DisplayName, default-search.net, Quarantined, [3c9bbed9f694e452eb99670842c3c937]
PUP.Optional.DefaultSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}|URL, http://www.default-search.net/search?sid=492&aid=199&itype=n&ver=12565&tm=386&src=ds&p={searchTerms}, Quarantined, [0dcae7b0aedc53e36321c0afbc4906fa]
PUP.Optional.DefaultSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}|SuggestionsURL_JSON, http://www.default-search.net?sid=492&aid=199&itype=n&ver=12565&tm=386&src=ds&p={searchTerms}&ft=json, Quarantined, [d007dcbb2e5cca6c81030c63b84dfc04]
PUP.Optional.DefaultSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}|DisplayName, default-search.net, Quarantined, [2aad5e3981091d19a7dd4e21bc49649c]
PUP.Optional.DefaultSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}|URL, http://www.default-search.net/search?sid=492&aid=199&itype=n&ver=12565&tm=386&src=ds&p={searchTerms}, Quarantined, [9f3870277614c1754e3674fbfd0851af]
PUP.Optional.DefaultSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}|SuggestionsURL_JSON, http://www.default-search.net?sid=492&aid=199&itype=n&ver=12565&tm=386&src=ds&p={searchTerms}&ft=json, Quarantined, [795e98ff90faec4a265e77f838cd58a8]
PUP.Optional.MySearchResults.A, HKU\S-1-5-21-2583720070-748624027-3842895589-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{90FFB6C9-B59E-4620-88B6-5450D860C7EA}|URL, http://www.mysearchresults.com/search?c=3513&t=07&q={searchTerms}, Quarantined, [14c37c1b6129ab8bb23a0dcfb94a6c94]
PUP.Optional.DefaultSearch.A, HKU\S-1-5-21-2583720070-748624027-3842895589-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}|DisplayName, default-search.net, Quarantined, [8d4a30673d4de5517b08abc4c144af51]
PUP.Optional.DefaultSearch.A, HKU\S-1-5-21-2583720070-748624027-3842895589-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}|URL, http://www.default-search.net/search?sid=492&aid=199&itype=n&ver=12565&tm=386&src=ds&p={searchTerms}, Quarantined, [a334a8efc5c5a096f58eeb8455b0f010]
PUP.Optional.DefaultSearch.A, HKU\S-1-5-21-2583720070-748624027-3842895589-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}|SuggestionsURL_JSON, http://www.default-search.net?sid=492&aid=199&itype=n&ver=12565&tm=386&src=ds&p={searchTerms}&ft=json, Quarantined, [3b9cdcbbe2a862d49be8e08fd92c08f8]
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 1
Backdoor.MSIL.PGen, C:\Windows\SysWOW64\surrasiltshawks.exe, Delete-on-Reboot, [f5e2781f830758de46cab09cac5615eb],
Physical Sectors: 0
(No malicious items detected)
(end)