HitmanPro 3.7.8.207
[URL="http://www.hitmanpro.com"]www.hitmanpro.com[/URL]
Computer name . . . . : CJAM3X4-PC
Windows . . . . . . . : 6.1.1.7601.X64/4
User name . . . . . . : cjAM3x4-PC\caroljim
UAC . . . . . . . . . : Enabled
License . . . . . . . : Free
Scan date . . . . . . : 2013-10-29 15:05:04
Scan mode . . . . . . : Normal
Scan duration . . . . : 3m 35s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : No
Threats . . . . . . . : 2
Traces . . . . . . . : 7
Objects scanned . . . : 1,571,333
Files scanned . . . . : 33,173
Remnants scanned . . : 388,434 files / 1,149,726 keys
Malware _____________________________________________________________________
C:\Games\EasyUO Script\EasyUO\EUOX.exe
Size . . . . . . . : 1,112,064 bytes
Age . . . . . . . : 318.1 days (2012-12-15 11:47:48)
Entropy . . . . . : 6.7
SHA-256 . . . . . : 704712023147CF72236BD23A27CC34DCCC6346FB8B5643DFB43D2D9D36844B32
> Ikarus . . . . . . : Trojan.Win32.VB!IK
Fuzzy . . . . . . : 106.0
References
C:\Users\caroljim\Desktop\EUOX.lnk
HKU\S-1-5-21-2066651824-2471372917-1354444347-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\C:\Games\EasyUO Script\EasyUO\EUOX.exe
C:\Users\caroljim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\106MFXVI\D2M-Precheck[1].exe
Size . . . . . . . : 508,928 bytes
Age . . . . . . . : 4.6 days (2013-10-25 01:31:48)
Entropy . . . . . : 8.0
SHA-256 . . . . . : C15CF5553D2B48EF501AB7D2972BAF2D5825218BBA292938E3B8556E7C5C095E
Product . . . . . : D2M-Precheck
Publisher . . . . : Appcaster
Description . . . : D2M-Precheck
Version . . . . . : 1.0.0.0
Copyright . . . . : Copyright © Appcaster 2013
Source URL . . . . : hxxp://ddnw0hpcyyfnj.cloudfront.net/D2M-Precheck.exe
> Ikarus . . . . . . : Trojan.SuspectCRC!IK
Fuzzy . . . . . . : 110.0
Forensic Cluster
-0.8s C:\Users\caroljim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L6YUTHQ2\win98_top_min[1].jpg
-0.7s C:\Users\caroljim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S45S397Z\win98_left[1].jpg
-0.7s C:\Users\caroljim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\106MFXVI\win98_bottom[1].jpg
-0.6s C:\Users\caroljim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L6YUTHQ2\win98_accept_button[1].jpg
-0.6s C:\Users\caroljim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GE0Q74DV\win98_decline_button[1].jpg
-0.6s C:\Users\caroljim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S45S397Z\win98_cancel_button[1].jpg
-0.5s C:\Users\caroljim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\106MFXVI\win98_skip_button[1].jpg
-0.5s C:\Users\caroljim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L6YUTHQ2\welcome_generic[1].jpg
-0.4s C:\Users\caroljim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GE0Q74DV\header_premiuminstaller[1].jpg
-0.3s C:\Users\caroljim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S45S397Z\bundled_whitesmokej[1].jpg
0.0s C:\Users\caroljim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\106MFXVI\D2M-Precheck[1].exe
6.4s C:\Users\caroljim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L6YUTHQ2\muted_greatarcade_eula[1].jpg
6.5s C:\Users\caroljim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GE0Q74DV\greatarcade_eula[1].htm
6.6s C:\Users\caroljim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S45S397Z\muted_optimizerpro_eula[1].jpg
6.8s C:\Users\caroljim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\106MFXVI\optimizerpro_eula[1].htm
6.8s C:\Users\caroljim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L6YUTHQ2\muted_scorpionsaver_eula[1].jpg
6.9s C:\Users\caroljim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GE0Q74DV\scorpionsaver_eula[1].htm
7.0s C:\Users\caroljim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S45S397Z\muted_defaulttab_clean[1].jpg
7.1s C:\Users\caroljim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\106MFXVI\defaulttab_terms[1].htm
8.0s C:\Users\caroljim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L6YUTHQ2\cloud_progress_screen[1].jpg
8.0s C:\Users\caroljim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L6YUTHQ2\cloud_progress_screen[1].jpg
8.3s C:\Users\caroljim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GE0Q74DV\amazon_finished[1].jpg
Cookies _____________________________________________________________________
C:\Users\caroljim\AppData\Roaming\Microsoft\Windows\Cookies\GSOLGU53.txt
C:\Users\caroljim\AppData\Roaming\Microsoft\Windows\Cookies\OFP3XX5F.txt
C:\Users\caroljim\AppData\Roaming\Microsoft\Windows\Cookies\TIGKXCHC.txt