<?xml version="1.0" encoding="UTF-16" ?>
<mbam-log>
<header>
<date>2015/07/09 22:03:07 -0400</date>
<logfile>mbam-log-2015-07-09 (22-03-07).xml</logfile>
<isadmin>yes</isadmin>
</header>
<engine>
<version>2.01.6.1022</version>
<malware-database>v2015.03.09.05</malware-database>
<rootkit-database>v2015.02.25.01</rootkit-database>
<license>trial</license>
<file-protection>enabled</file-protection>
<web-protection>enabled</web-protection>
<self-protection>disabled</self-protection>
</engine>
<system>
<osversion>Windows 7 Service Pack 1</osversion>
<arch>x64</arch>
<username>Warren</username>
<filesys>NTFS</filesys>
</system>
<summary>
<type>threat</type>
<result>completed</result>
<objects>425583</objects>
<time>830</time>
<processes>8</processes>
<modules>0</modules>
<keys>210</keys>
<values>4</values>
<datas>0</datas>
<folders>153</folders>
<files>594</files>
<sectors>0</sectors>
</summary>
<options>
<memory>enabled</memory>
<startup>enabled</startup>
<filesystem>enabled</filesystem>
<archives>enabled</archives>
<rootkits>disabled</rootkits>
<deeprootkit>disabled</deeprootkit>
<heuristics>enabled</heuristics>
<pup>warn</pup>
<pum>enabled</pum>
</options>
<items>
<process><path>C:\Program Files (x86)\HQCinema Pro 2.1V09.07\65cd391c-8991-4061-9130-e6cdb77e5f59-10.exe</path><vendor>PUP.Optional.CrossRider.A</vendor><action>delete-on-reboot</action><pid>7420</pid><hash>e792d46f434704328d53ca4b34d2639d</hash></process>
<process><path>C:\Program Files (x86)\HQCinema Pro 2.1V09.07\65cd391c-8991-4061-9130-e6cdb77e5f59-6.exe</path><vendor>PUP.Optional.CrossRider.A</vendor><action>delete-on-reboot</action><pid>28472</pid><hash>6d0c5be8454575c138a8d14433d3a957</hash></process>
<process><path>C:\Program Files (x86)\HQCinema Pro 2.1V09.07\65cd391c-8991-4061-9130-e6cdb77e5f59-1-6.exe</path><vendor>PUP.Optional.CrossRider.A</vendor><action>delete-on-reboot</action><pid>28212</pid><hash>d8a1e95a5a3038fee5fb1ff6ba4c43bd</hash></process>
<process><path>C:\Program Files (x86)\StormWatch\StormWatchApp.exe</path><vendor>PUP.Optional.StormWatch.A</vendor><action>delete-on-reboot</action><pid>27884</pid><hash>f287e063becc1422bb12b99c827ef10f</hash></process>
<process><path>C:\Program Files (x86)\StormWatch\SWUpdaterSvc.exe</path><vendor>PUP.Optional.StormWatch.A</vendor><action>delete-on-reboot</action><pid>28228</pid><hash>3f3a7bc8127834021e6c31cfe71bdb25</hash></process>
<process><path>C:\Program Files (x86)\StormWatch\StormWatchSrv.exe</path><vendor>PUP.Optional.StormWatch.A</vendor><action>delete-on-reboot</action><pid>10412</pid><hash>b9c0ae954a40b284235dd2e33ac91ee2</hash></process>
<process><path>C:\Program Files (x86)\RadPlayer\myradioplayer.exe</path><vendor>PUP.Optional.MyRadioPlayer.A</vendor><action>delete-on-reboot</action><pid>25744</pid><hash>760347fcd8b2fb3b9dd50a2745c009f7</hash></process>
<process><path>C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe</path><vendor>PUP.Optional.Consumer.Input.A</vendor><action>delete-on-reboot</action><pid>24876</pid><hash>b2c75ce7424894a2928eb4b7a0632bd5</hash></process>
<key><path>HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SWUpdater</path><vendor>PUP.Optional.StormWatch.A</vendor><action>success</action><hash>3f3a7bc8127834021e6c31cfe71bdb25</hash></key>
<key><path>HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\consumerinput_update</path><vendor>PUP.Optional.ConsumerInput.A</vendor><action>success</action><hash>aecbb192e2a877bf771e2768f30e28d8</hash></key>
<key><path>HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\consumerinput_updatem</path><vendor>PUP.Optional.ConsumerInput.A</vendor><action>success</action><hash>aecbb192e2a877bf771e2768f30e28d8</hash></key>
<key><path>HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\CONSUMERINPUTUPDATE.EXE</path><vendor>PUP.Optional.ConsumerInput.A</vendor><action>success</action><hash>aecbb192e2a877bf771e2768f30e28d8</hash></key>
<key><path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\CONSUMERINPUTUPDATE.EXE</path><vendor>PUP.Optional.ConsumerInput.A</vendor><action>success</action><hash>aecbb192e2a877bf771e2768f30e28d8</hash></key>
<key><path>HKLM\SOFTWARE\CLASSES\CLSID\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}</path><vendor>PUP.Optional.Consumer.Input.A</vendor><action>success</action><hash>3c3d52f17b0f0531137cdf42aa59b14f</hash></key>
<key><path>HKLM\SOFTWARE\CLASSES\TYPELIB\{7BAB653D-88FB-4F60-AFC2-8E6FD59FAFF3}</path><vendor>PUP.Optional.Consumer.Input.A</vendor><action>success</action><hash>3c3d52f17b0f0531137cdf42aa59b14f</hash></key>
<key><path>HKLM\SOFTWARE\CLASSES\INTERFACE\{DD05B915-F77B-474A-9D42-9FEEAF5475C4}</path><vendor>PUP.Optional.Consumer.Input.A</vendor><action>success</action><hash>3c3d52f17b0f0531137cdf42aa59b14f</hash></key>
<key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{DD05B915-F77B-474A-9D42-9FEEAF5475C4}</path><vendor>PUP.Optional.Consumer.Input.A</vendor><action>success</action><hash>3c3d52f17b0f0531137cdf42aa59b14f</hash></key>
<key><path>HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{DD05B915-F77B-474A-9D42-9FEEAF5475C4}</path><vendor>PUP.Optional.Consumer.Input.A</vendor><action>success</action><hash>3c3d52f17b0f0531137cdf42aa59b14f</hash></key>
<key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{7BAB653D-88FB-4F60-AFC2-8E6FD59FAFF3}</path><vendor>PUP.Optional.Consumer.Input.A</vendor><action>success</action><hash>3c3d52f17b0f0531137cdf42aa59b14f</hash></key>
<key><path>HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{7BAB653D-88FB-4F60-AFC2-8E6FD59FAFF3}</path><vendor>PUP.Optional.Consumer.Input.A</vendor><action>success</action><hash>3c3d52f17b0f0531137cdf42aa59b14f</hash></key>
<key><path>HKLM\SOFTWARE\CLASSES\CLSID\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}\INPROCSERVER32</path><vendor>PUP.Optional.Consumer.Input.A</vendor><action>success</action><hash>3c3d52f17b0f0531137cdf42aa59b14f</hash></key>
<key><path>HKLM\SOFTWARE\CLASSES\dcabho.Dca.1</path><vendor>PUP.Optional.Consumer.Input.A</vendor><action>success</action><hash>3c3d52f17b0f0531137cdf42aa59b14f</hash></key>
<key><path>HKLM\SOFTWARE\CLASSES\dcabho.Dca</path><vendor>PUP.Optional.Consumer.Input.A</vendor><action>success</action><hash>3c3d52f17b0f0531137cdf42aa59b14f</hash></key>
<key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\dcabho.Dca</path><vendor>PUP.Optional.Consumer.Input.A</vendor><action>success</action><hash>3c3d52f17b0f0531137cdf42aa59b14f</hash></key>
<key><path>HKLM\SOFTWARE\CLASSES\WOW6432NODE\dcabho.Dca</path><vendor>PUP.Optional.Consumer.Input.A</vendor><action>success</action><hash>3c3d52f17b0f0531137cdf42aa59b14f</hash></key>
<key><path>HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}</path><vendor>PUP.Optional.Consumer.Input.A</vendor><action>success</action><hash>3c3d52f17b0f0531137cdf42aa59b14f</hash></key>
<key><path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}</path><vendor>PUP.Optional.Consumer.Input.A</vendor><action>success</action><hash>3c3d52f17b0f0531137cdf42aa59b14f</hash></key>
rest deleted as too long and got an error after posting.