Save On 2.14
Hej med Jer.Her den 19. juni 2014 er der røget en Ad på min computer ved navn "Save On 2.14".
Den er jævnt irriterende, og jeg ved ikke hvordan at jeg slipper af med den.
Jeg har vedhæftet loggen fra MBAM som var rimelig kritisk her:
Håber at der er én af Jer der vil hjælpe mig.
Mvh,
Sirus
_________________
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 22-06-2014
Scan Time: 15:57:41
Logfile: 220614.txt
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.06.22.02
Rootkit Database: v2014.06.20.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Sirus
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 336252
Time Elapsed: 17 min, 10 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 57
PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\APPID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}, Quarantined, [7703a8d3a2d9f244f491572530d251af],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}, Quarantined, [7703a8d3a2d9f244f491572530d251af],
PUP.Optional.SearchQu, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}, Quarantined, [403a3744c9b2b87e60aee465b74ba25e],
PUP.Optional.SearchQu, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{99079A25-328F-4BD4-BE04-00955ACAA0A7}, Quarantined, [403a3744c9b2b87e60aee465b74ba25e],
PUP.Optional.SearchQu, HKU\S-1-5-21-675772905-361709593-858469613-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{99079A25-328F-4BD4-BE04-00955ACAA0A7}, Quarantined, [403a3744c9b2b87e60aee465b74ba25e],
PUP.Optional.SearchQu, HKU\S-1-5-21-675772905-361709593-858469613-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{99079A25-328F-4BD4-BE04-00955ACAA0A7}, Quarantined, [403a3744c9b2b87e60aee465b74ba25e],
PUP.Optional.SearchQu, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{99079A25-328F-4BD4-BE04-00955ACAA0A7}, Quarantined, [403a3744c9b2b87e60aee465b74ba25e],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}, Quarantined, [a4d659221269ed49434a364657ab07f9],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}, Quarantined, [a4d659221269ed49434a364657ab07f9],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}, Quarantined, [a4d659221269ed49434a364657ab07f9],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}, Quarantined, [a4d659221269ed49434a364657ab07f9],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}, Quarantined, [a4d659221269ed49434a364657ab07f9],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}, Quarantined, [a4d659221269ed49434a364657ab07f9],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}, Quarantined, [a4d659221269ed49434a364657ab07f9],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\CLASSES\SearchQUIEHelper.DNSGuard, Quarantined, [a4d659221269ed49434a364657ab07f9],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\CLASSES\SearchQUIEHelper.DNSGuard.1, Quarantined, [a4d659221269ed49434a364657ab07f9],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SearchQUIEHelper.DNSGuard, Quarantined, [a4d659221269ed49434a364657ab07f9],
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SearchQUIEHelper.DNSGuard.1, Quarantined, [a4d659221269ed49434a364657ab07f9],
PUP.Optional.Datamngr.A, HKU\S-1-5-21-675772905-361709593-858469613-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}, Quarantined, [a4d659221269ed49434a364657ab07f9],
PUP.Optional.Datamngr.A, HKU\S-1-5-21-675772905-361709593-858469613-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}, Quarantined, [a4d659221269ed49434a364657ab07f9],
PUP.Optional.FaceMoods.A, HKU\S-1-5-21-675772905-361709593-858469613-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0D7562AE-8EF6-416d-A838-AB665251703A}, Quarantined, [cdad5e1d1b6044f2234676cf03ff08f8],
PUP.Optional.Wajam.A, HKU\S-1-5-21-675772905-361709593-858469613-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}, Quarantined, [d0aaccaf0e6d15217f939aaf9270b44c],
PUP.Optional.FaceMoods.A, HKU\S-1-5-21-675772905-361709593-858469613-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{DB4E9724-F518-4dfd-9C7C-78B52103CAB9}, Quarantined, [db9f4932116a69cda3c59da80cf622de],
PUP.Optional.Yontoo.A, HKU\S-1-5-21-675772905-361709593-858469613-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}, Quarantined, [15650f6c4d2e76c015492221c83a6799],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, Quarantined, [bbbfa8d3bebd6cca9919f8f3b152f907],
PUP.Optional.DataMangr.A, HKLM\SOFTWARE\WOW6432NODE\DataMngr, Quarantined, [0d6d7506463577bf9e3d9b1029d99868],
PUP.Optional.InstallBrain.A, HKLM\SOFTWARE\WOW6432NODE\InstallIQ, Quarantined, [700a6e0d7605ef47cb2ccbf8bc46ef11],
PUP.Optional.qvo6.A, HKLM\SOFTWARE\WOW6432NODE\qvo6Software, Quarantined, [dc9ecdae3546bb7be3641dc5b1527789],
PUP.Optional.TornTV.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\bicnnkjibmphdeigoodpjlcklcnaobdj, Quarantined, [2159b2c987f4989e6e0a7843ee14bb45],
PUP.Optional.Complitly.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\dlfienamagdnkekbbbocojppncdambda, Quarantined, [a9d10e6dd8a39e98d01f0ba450b2619f],
PUP.Optional.Elex.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\ifohbjbgfchkkfhphahclmkpgejiplfo, Quarantined, [aecc14677506fb3b4786d70c08fb6997],
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, Quarantined, [3d3d2754b5c6c86eab07bc2f5da6c739],
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\SWEETIM, Quarantined, [a1d9ef8cb9c2280e5889dd03a85b43bd],
PUP.Optional.1ClickDownload.A, HKU\S-1-5-21-675772905-361709593-858469613-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\1ClickDownload, Quarantined, [cbaf5229d3a885b153f90cd5857e27d9],
PUP.Optional.DataMngr.A, HKU\S-1-5-21-675772905-361709593-858469613-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr, Quarantined, [413906750675b18597389d42c53e1ae6],
PUP.Optional.DataMngr.A, HKU\S-1-5-21-675772905-361709593-858469613-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr_Toolbar, Quarantined, [017983f8eb9093a3d9f5716eab5814ec],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-675772905-361709593-858469613-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, Quarantined, [d8a2e9924f2c95a15c105c983fc4c937],
PUP.Optional.Babylon.A, HKU\S-1-5-21-675772905-361709593-858469613-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BABSOLUTION\Updater, Quarantined, [c5b57308106beb4b963f28b87c87aa56],
PUP.Optional.Qone8, HKU\S-1-5-21-675772905-361709593-858469613-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, Quarantined, [a9d16516c1ba14221c95bd2ed92a728e],
PUP.Optional.BProtector.A, HKU\S-1-5-21-675772905-361709593-858469613-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\bProtectSettings, Quarantined, [bcbe2d4eb3c8da5ca780bf24be45cd33],
PUP.Optional.Softonic.A, HKU\S-1-5-21-675772905-361709593-858469613-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, Quarantined, [1f5b3f3c4c2fd165d3c02b8d51b1758b],
PUP.Optional.SweetIM.A, HKU\S-1-5-21-675772905-361709593-858469613-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM, Quarantined, [92e83f3c65169d9927b968780df651af],
PUP.Optional.Complitly.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{0FB6A909-6086-458F-BD92-1F8EE10042A0}, Quarantined, [4d2d2a51e299e45240af5f27dd271de3],
PUP.Optional.Complitly.A, HKLM\SOFTWARE\CLASSES\CLSID\{0FB6A909-6086-458F-BD92-1F8EE10042A0}, Quarantined, [4d2d2a51e299e45240af5f27dd271de3],
PUP.Optional.Complitly.A, HKLM\SOFTWARE\CLASSES\CLSID\{0FB6A909-6086-458F-BD92-1F8EE10042A0}\INPROCSERVER32, Quarantined, [4d2d2a51e299e45240af5f27dd271de3],
PUP.Optional.Complitly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{0FB6A909-6086-458F-BD92-1F8EE10042A0}, Quarantined, [4d2d2a51e299e45240af5f27dd271de3],
PUP.Optional.Complitly.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{01BCB858-2F62-4F06-A8F4-48F927C15333}, Quarantined, [4d2d2a51e299e45240af5f27dd271de3],
PUP.Optional.Complitly.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{C9AE652B-8C99-4AC2-B556-8B501182874E}, Quarantined, [4d2d2a51e299e45240af5f27dd271de3],
PUP.Optional.Complitly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C9AE652B-8C99-4AC2-B556-8B501182874E}, Quarantined, [4d2d2a51e299e45240af5f27dd271de3],
PUP.Optional.Complitly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{01BCB858-2F62-4F06-A8F4-48F927C15333}, Quarantined, [4d2d2a51e299e45240af5f27dd271de3],
PUP.Optional.Complitly.A, HKLM\SOFTWARE\CLASSES\SuggestMeYes.SuggestMeYesBHO.1, Quarantined, [4d2d2a51e299e45240af5f27dd271de3],
PUP.Optional.Complitly.A, HKLM\SOFTWARE\CLASSES\SuggestMeYes.SuggestMeYesBHO, Quarantined, [4d2d2a51e299e45240af5f27dd271de3],
PUP.Optional.Complitly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SuggestMeYes.SuggestMeYesBHO, Quarantined, [4d2d2a51e299e45240af5f27dd271de3],
PUP.Optional.Complitly.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{0FB6A909-6086-458F-BD92-1F8EE10042A0}, Quarantined, [4d2d2a51e299e45240af5f27dd271de3],
PUP.Optional.Complitly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SuggestMeYes.SuggestMeYesBHO.1, Quarantined, [4d2d2a51e299e45240af5f27dd271de3],
PUP.Optional.Complitly.A, HKU\S-1-5-21-675772905-361709593-858469613-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{0FB6A909-6086-458F-BD92-1F8EE10042A0}, Quarantined, [4d2d2a51e299e45240af5f27dd271de3],
PUP.Optional.Complitly.A, HKU\S-1-5-21-675772905-361709593-858469613-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{0FB6A909-6086-458F-BD92-1F8EE10042A0}, Quarantined, [4d2d2a51e299e45240af5f27dd271de3],
Registry Values: 11
PUP.Optional.SearchQu, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{99079A25-328F-4BD4-BE04-00955ACAA0A7}, Searchqu Toolbar, Quarantined, [403a3744c9b2b87e60aee465b74ba25e]
PUP.Optional.SearchQu, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{99079a25-328f-4bd4-be04-00955acaa0a7}, Quarantined, [90eac1bae19a4aecec22dc6d56ac9f61],
PUP.Optional.SearchCertified.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCH|Search Bar, http://search.certified-toolbar.com?si=62606&tid=6533&ver=4.7&ts=1378642399025&tguid=62606-6533-1378642399025-A987D0BF793DFEDBDE8CA218E590D180&st=chrome&q=, Quarantined, [4733e19ae5962b0b25cb1c8b08fac33d]
PUP.Optional.CertifiedToolBar.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHURI|(Default), http://search.certified-toolbar.com?si=62606&st=bs&tid=6533&ver=4.7&ts=1378642399025&tguid=62606-6533-1378642399025-A987D0BF793DFEDBDE8CA218E590D180&q=%s, Quarantined, [3f3b4f2c3c3ff73fbc05d8ce12f0fb05]
PUP.Optional.CertifiedToolBar.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|(Default), http://search.certified-toolbar.com?si=62606&st=bs&tid=6533&ver=4.7&ts=1378642399025&tguid=62606-6533-1378642399025-A987D0BF793DFEDBDE8CA218E590D180&q=%s, Quarantined, [adcd1a611a618fa7566c337325dd0ef2]
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\SWEETIM|simapp_id, {355AEBE1-042A-11E3-B66C-F80F410596E4}, Quarantined, [a1d9ef8cb9c2280e5889dd03a85b43bd]
PUP.BProtector, HKU\S-1-5-21-675772905-361709593-858469613-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|bProtector Start Page, http://www.claro-search.com/?affID=114508&tt=4112_8&babsrc=HP_clro&mntrId=4666979e000000000000f80f410596e4, Quarantined, [08726c0f106b89ad26aabc23986b748c]
PUP.Optional.SearchCertified.A, HKU\S-1-5-21-675772905-361709593-858469613-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Search Bar, http://search.certified-toolbar.com?si=62606&tid=6533&ver=4.7&ts=1378642399025&tguid=62606-6533-1378642399025-A987D0BF793DFEDBDE8CA218E590D180&st=chrome&q=, Quarantined, [ff7b7dfe512aca6ce7078225639fdc24]
PUP.BProtector, HKU\S-1-5-21-675772905-361709593-858469613-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|bProtectorDefaultScope, {0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}, Quarantined, [7802f18a5c1f50e6eae7a23d7c87ff01]
PUP.Optional.Wajam.A, HKU\S-1-5-21-675772905-361709593-858469613-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}, C:\Program Files (x86)\Wajam\Firefox\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}.xpi, Quarantined, [e199e09b3b40f640f97eaa05867c07f9]
PUP.Optional.SweetIM.A, HKU\S-1-5-21-675772905-361709593-858469613-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM|simapp_id, {355AEBE1-042A-11E3-B66C-F80F410596E4}, Quarantined, [92e83f3c65169d9927b968780df651af]
Registry Data: 20
PUP.Optional.Qvo6.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe http://www.qvo6.com/?utm_source=b&utm_medium=tugs&utm_campaign=eXQ&utm_content=sc&from=tugs&uid=WDCXWD15EADS-22P8B0_WD-WMAVU381638616386&ts=1379777740, Good: (iexplore.exe), Bad: (C:\Program Files\Internet Explorer\iexplore.exe http://www.qvo6.com/?utm_source=b&utm_medium=tugs&utm_campaign=eXQ&utm_content=sc&from=tugs&uid=WDCXWD15EADS-22P8B0_WD-WMAVU381638616386&ts=1379777740),Replaced,[bbbf4338a8d3c373cfc597ebc73d02fe]
Hijack.StartPage, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://www.qvo6.com/?utm_source=b&utm_medium=tugs&utm_campaign=eXQ&utm_content=hp&from=tugs&uid=WDCXWD15EADS-22P8B0_WD-WMAVU381638616386&ts=1379777740, Good: (http://www.google.com), Bad: (http://www.qvo6.com/?utm_source=b&utm_medium=tugs&utm_campaign=eXQ&utm_content=hp&from=tugs&uid=WDCXWD15EADS-22P8B0_WD-WMAVU381638616386&ts=1379777740),Replaced,[2d4df18a7cff58def8aa0e73e4201de3]
Hijack.StartPage, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://www.qvo6.com/?utm_source=b&utm_medium=tugs&utm_campaign=eXQ&utm_content=hp&from=tugs&uid=WDCXWD15EADS-22P8B0_WD-WMAVU381638616386&ts=1379777740, Good: (http://www.google.com), Bad: (http://www.qvo6.com/?utm_source=b&utm_medium=tugs&utm_campaign=eXQ&utm_content=hp&from=tugs&uid=WDCXWD15EADS-22P8B0_WD-WMAVU381638616386&ts=1379777740),Replaced,[2753bfbc027947ef7f21641db84c3ac6]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Replaced,[eb8f7ffc6f0c0e2854abb1d061a3f40c]
PUP.Optional.Qvo6.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe http://www.qvo6.com/?utm_source=b&utm_medium=tugs&utm_campaign=eXQ&utm_content=sc&from=tugs&uid=WDCXWD15EADS-22P8B0_WD-WMAVU381638616386&ts=1379777740, Good: (iexplore.exe), Bad: (C:\Program Files\Internet Explorer\iexplore.exe http://www.qvo6.com/?utm_source=b&utm_medium=tugs&utm_campaign=eXQ&utm_content=sc&from=tugs&uid=WDCXWD15EADS-22P8B0_WD-WMAVU381638616386&ts=1379777740),Replaced,[90eaec8f4833c571553f7f03d52f35cb]
Hijack.StartPage, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://www.qvo6.com/?utm_source=b&utm_medium=tugs&utm_campaign=eXQ&utm_content=hp&from=tugs&uid=WDCXWD15EADS-22P8B0_WD-WMAVU381638616386&ts=1379777740, Good: (http://www.google.com), Bad: (http://www.qvo6.com/?utm_source=b&utm_medium=tugs&utm_campaign=eXQ&utm_content=hp&from=tugs&uid=WDCXWD15EADS-22P8B0_WD-WMAVU381638616386&ts=1379777740),Replaced,[0e6cf8836a112016851daad735cfcf31]
Hijack.StartPage, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://www.qvo6.com/?utm_source=b&utm_medium=tugs&utm_campaign=eXQ&utm_content=hp&from=tugs&uid=WDCXWD15EADS-22P8B0_WD-WMAVU381638616386&ts=1379777740, Good: (http://www.google.com), Bad: (http://www.qvo6.com/?utm_source=b&utm_medium=tugs&utm_campaign=eXQ&utm_content=hp&from=tugs&uid=WDCXWD15EADS-22P8B0_WD-WMAVU381638616386&ts=1379777740),Replaced,[6713116a176452e4d4cc176a5fa59769]
Hijack.SearchPage, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, http://search.certified-toolbar.com?si=62606&tid=6533&ver=4.7&ts=1378642399025&tguid=62606-6533-1378642399025-A987D0BF793DFEDBDE8CA218E590D180&st=chrome&q=, Good: (http://www.google.com), Bad: (http://search.certified-toolbar.com?si=62606&tid=6533&ver=4.7&ts=1378642399025&tguid=62606-6533-1378642399025-A987D0BF793DFEDBDE8CA218E590D180&st=chrome&q=),Replaced,[7208c7b494e790a66335abd5669e4fb1]
PUP.Optional.FaceMoods.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, http://start.facemoods.com/?a=make&s={searchTerms}&f=4, Good: (www.google.com), Bad: (http://start.facemoods.com/?a=make&s={searchTerms}&f=4),Replaced,[0f6ba2d99edd191dd7eaa4de15ef11ef]
Hijack.SearchPage, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, http://search.certified-toolbar.com?si=62606&tid=6533&ver=4.7&ts=1378642399025&tguid=62606-6533-1378642399025-A987D0BF793DFEDBDE8CA218E590D180&st=chrome&q=, Good: (http://www.google.com/), Bad: (http://search.certified-toolbar.com?si=62606&tid=6533&ver=4.7&ts=1378642399025&tguid=62606-6533-1378642399025-A987D0BF793DFEDBDE8CA218E590D180&st=chrome&q=),Replaced,[18627b003c3f4bebf4a60d73947030d0]
PUP.Optional.CertifiedToolBar.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCH|Search Page, http://search.certified-toolbar.com?si=62606&tid=6533&ver=4.7&ts=1378642399025&tguid=62606-6533-1378642399025-A987D0BF793DFEDBDE8CA218E590D180&st=chrome&q=, Good: (www.google.com), Bad: (http://search.certified-toolbar.com?si=62606&tid=6533&ver=4.7&ts=1378642399025&tguid=62606-6533-1378642399025-A987D0BF793DFEDBDE8CA218E590D180&st=chrome&q=),Replaced,[6119b0cb77041e1860e9f087d82cf907]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Replaced,[ceacc8b3c9b2c96d7f8089f8b25203fd]
Hijack.StartPage, HKU\S-1-5-21-675772905-361709593-858469613-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://www.qvo6.com/?utm_source=b&utm_medium=tugs&utm_campaign=eXQ&utm_content=hp&from=tugs&uid=WDCXWD15EADS-22P8B0_WD-WMAVU381638616386&ts=1379777740, Good: (http://www.google.com), Bad: (http://www.qvo6.com/?utm_source=b&utm_medium=tugs&utm_campaign=eXQ&utm_content=hp&from=tugs&uid=WDCXWD15EADS-22P8B0_WD-WMAVU381638616386&ts=1379777740),Replaced,[5c1ee893d4a7e94dc6d9d8a9e1239967]
Hijack.StartPage, HKU\S-1-5-21-675772905-361709593-858469613-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://www.qvo6.com/?utm_source=b&utm_medium=tugs&utm_campaign=eXQ&utm_content=hp&from=tugs&uid=WDCXWD15EADS-22P8B0_WD-WMAVU381638616386&ts=1379777740, Good: (http://www.google.com), Bad: (http://www.qvo6.com/?utm_source=b&utm_medium=tugs&utm_campaign=eXQ&utm_content=hp&from=tugs&uid=WDCXWD15EADS-22P8B0_WD-WMAVU381638616386&ts=1379777740),Replaced,[53273e3d90eb70c65849740d0ff5cb35]
Hijack.SearchPage, HKU\S-1-5-21-675772905-361709593-858469613-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, http://search.certified-toolbar.com?si=62606&tid=6533&ver=4.7&ts=1378642399025&tguid=62606-6533-1378642399025-A987D0BF793DFEDBDE8CA218E590D180&st=chrome&q=, Good: (http://www.google.com), Bad: (http://search.certified-toolbar.com?si=62606&tid=6533&ver=4.7&ts=1378642399025&tguid=62606-6533-1378642399025-A987D0BF793DFEDBDE8CA218E590D180&st=chrome&q=),Replaced,[4535e79495e660d6eea627592adac13f]
Hijack.SearchPage, HKU\S-1-5-21-675772905-361709593-858469613-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, http://search.certified-toolbar.com?si=62606&tid=6533&ver=4.7&ts=1378642399025&tguid=62606-6533-1378642399025-A987D0BF793DFEDBDE8CA218E590D180&st=chrome&q=, Good: (http://www.google.com), Bad: (http://search.certified-toolbar.com?si=62606&tid=6533&ver=4.7&ts=1378642399025&tguid=62606-6533-1378642399025-A987D0BF793DFEDBDE8CA218E590D180&st=chrome&q=),Replaced,[7901017a7dfe9a9c40557d03966eab55]
Hijack.SearchPage, HKU\S-1-5-21-675772905-361709593-858469613-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, http://search.certified-toolbar.com?si=62606&tid=6533&ver=4.7&ts=1378642399025&tguid=62606-6533-1378642399025-A987D0BF793DFEDBDE8CA218E590D180&st=chrome&q=, Good: (http://www.google.com/), Bad: (http://search.certified-toolbar.com?si=62606&tid=6533&ver=4.7&ts=1378642399025&tguid=62606-6533-1378642399025-A987D0BF793DFEDBDE8CA218E590D180&st=chrome&q=),Replaced,[3d3d08734d2e57df207bb6cae81c1be5]
PUP.Optional.CertifiedToolBar.A, HKU\S-1-5-21-675772905-361709593-858469613-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Search Page, http://search.certified-toolbar.com?si=62606&tid=6533&ver=4.7&ts=1378642399025&tguid=62606-6533-1378642399025-A987D0BF793DFEDBDE8CA218E590D180&st=chrome&q=, Good: (www.google.com), Bad: (http://search.certified-toolbar.com?si=62606&tid=6533&ver=4.7&ts=1378642399025&tguid=62606-6533-1378642399025-A987D0BF793DFEDBDE8CA218E590D180&st=chrome&q=),Replaced,[d7a37209df9c57df49fc205759ab12ee]
PUP.Optional.SearchCertifiedTB.A, HKU\S-1-5-21-675772905-361709593-858469613-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURI|(Default), http://search.certified-toolbar.com?si=62606&st=bs&tid=6533&ver=4.7&ts=1378642399025&tguid=62606-6533-1378642399025-A987D0BF793DFEDBDE8CA218E590D180&q=%s, Good: (http://www.google.com), Bad: (http://search.certified-toolbar.com?si=62606&st=bs&tid=6533&ver=4.7&ts=1378642399025&tguid=62606-6533-1378642399025-A987D0BF793DFEDBDE8CA218E590D180&q=%s),Replaced,[5723d5a63f3cac8a84286a1808fc48b8]
PUP.Optional.SearchCertifiedTB.A, HKU\S-1-5-21-675772905-361709593-858469613-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|(Default), http://search.certified-toolbar.com?si=62606&st=bs&tid=6533&ver=4.7&ts=1378642399025&tguid=62606-6533-1378642399025-A987D0BF793DFEDBDE8CA218E590D180&q=%s, Good: (http://www.google.com/), Bad: (http://search.certified-toolbar.com?si=62606&st=bs&tid=6533&ver=4.7&ts=1378642399025&tguid=62606-6533-1378642399025-A987D0BF793DFEDBDE8CA218E590D180&q=%s),Replaced,[1268156693e8e4523f6e0f73c242e61a]
Folders: 7
PUP.Optional.eSafe.A, C:\ProgramData\eSafe\log, Quarantined, [2753a4d72c4fdd599d8d51750002be42],
PUP.Optional.TornTV.A, C:\Program Files (x86)\TornTV.com, Quarantined, [84f6ec8f8af13bfbf3d4ccc98b7738c8],
PUP.Optional.TornTV.A, C:\Program Files (x86)\TornTV.com\log, Quarantined, [84f6ec8f8af13bfbf3d4ccc98b7738c8],
PUP.Optional.TornTV.A, C:\Program Files (x86)\TornTV.com\Torrents, Quarantined, [84f6ec8f8af13bfbf3d4ccc98b7738c8],
PUP.Optional.MultiPlug.A, C:\Program Files (x86)\save onu, Quarantined, [6812314aafcc73c346b5e0c48b779f61],
PUP.Optional.MultiPlug.A, C:\ProgramData\save onu, Quarantined, [91e9e19ab4c7a0964bb1dbc9a65ccf31],
PUP.Optional.Booster.A, C:\ProgramData\AppSnow\SO_Booster, Quarantined, [a8d2d2a91a6114228460eeb729d9e917],
Files: 32
PUP.Optional.SearchQu, C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll, Quarantined, [403a3744c9b2b87e60aee465b74ba25e],
PUP.Optional.Datamngr.A, C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\IEBHO.dll, Quarantined, [a4d659221269ed49434a364657ab07f9],
PUP.Optional.Booster.A, C:\ProgramData\AppSnow\SO_Booster\SO_Booster.exe, Quarantined, [53272c4fabd09c9ade7b330f2fd358a8],
PUP.Optional.MultiPlug.A, C:\ProgramData\save onu\TTgaUCEN.exe, Quarantined, [80faf4877704d85ecd9d27226b9519e7],
PUP.Optional.OneClickDownloader.A, C:\Users\Sirus\AppData\Roaming\Azureus\torrents\Deadpool_FLT.exe, Quarantined, [e298f487c8b3f14576c09a7c07fa867a],
PUP.Optional.HomeTab.A, C:\Users\Sirus\AppData\Roaming\Complitly\hometab.exe, Quarantined, [176375064a319e9855bdae710cf507f9],
PUP.Optional.InstallIQ, C:\Users\Sirus\Downloads\freeopener_1390.exe, Quarantined, [6515512a4e2d47ef416a9f7fd72a9d63],
PUP.Optional.InstalleRex, C:\Users\Sirus\Downloads\BioShock Infinite Mind in Revolt (SF12).zip.exe, Quarantined, [b5c51b607b001d19220ea3eb47bac23e],
PUP.Optional.OpenCandy, C:\Users\Sirus\Downloads\veetle-0.9.19.exe, Quarantined, [7ffb4c2f740737ff0f36a9fdcf35e21e],
PUP.Optional.Softonic.A, C:\Users\Sirus\Downloads\SoftonicDownloader_for_avg-antivirus-plus-firewall.exe, Quarantined, [7406611aff7ce353e859ca5afa07f30d],
Trojan.Agent, C:\Users\Sirus\Downloads\FFSetup180.zip, Quarantined, [e595d2a9afccdb5b4f51be14827ff010],
PUP.Optional.Installex, C:\Users\Sirus\Downloads\300.2006.480p.BRRip.QCE.XViD.AC3-Voltage.avi.exe, Quarantined, [601a89f299e2b87e325e0a5340c1c13f],
PUP.Optional.Installex, C:\Users\Sirus\Downloads\300.2006.BluRay.720p.x264.YIFY.mp4.exe, Quarantined, [d1a97803ed8ee254137d98c536cb7888],
PUP.Optional.GoForFiles.A, C:\Users\Sirus\Downloads\snagit_10_full_version_free_downloader.exe, Quarantined, [c4b6cdae5e1d55e188c9998637ca47b9],
PUP.Optional.Bandoo, C:\Users\Sirus\Downloads\iLividSetup-r362-n-bc.exe, Quarantined, [2555b1ca2a5183b340a443ca33cef010],
PUP.Optional.Bandoo, C:\Users\Sirus\Downloads\iLividSetup-r400-n-bc.exe, Quarantined, [fa80c2b984f74ceac3214fbe14ed53ad],
PUP.Optional.Bandoo, C:\Users\Sirus\Downloads\iLividSetup-r446-n-bc.exe, Quarantined, [ea906813ceadf34334b00effbf42dd23],
PUP.Optional.Bandoo, C:\Users\Sirus\Downloads\iLividSetupV1 (1).exe, Quarantined, [403acab1d5a6c96ddd0743ca649dd828],
PUP.Optional.Softonic, C:\Users\Sirus\Downloads\SoftonicDownloader_for_microsoft-outlook.exe, Quarantined, [88f2b3c83b40d4628c58f2163cc5ef11],
PUP.Optional.Softonic.A, C:\Users\Sirus\Downloads\SoftonicDownloader_for_microsoft-powerpoint.exe, Quarantined, [99e14d2ebfbce056d1709f85d22f50b0],
PUP.Optional.OpenCandy, C:\Users\Sirus\Downloads\veetle-0.9.18 (6).exe, Quarantined, [bebcdaa1b3c851e57acb574f21e37789],
PUP.Optional.Simplytech, C:\Windows\Launcher.exe, Quarantined, [dd9d205b7407a3934e26f817ec187e82],
PUP.Optional.FaceMoods.A, C:\Program Files (x86)\Mozilla Firefox\searchplugins\fcmdSrch.xml, Quarantined, [c7b387f46b1090a6f51fe1c90002728e],
PUP.Optional.PCPerformer.A, C:\Windows\System32\roboot64.exe, Quarantined, [68127803d2a9310504cd5d6624de0000],
PUP.Optional.eSafe.A, C:\ProgramData\eSafe\log\eGdpSvc.LOG, Quarantined, [2753a4d72c4fdd599d8d51750002be42],
PUP.Optional.NewTab.A, C:\Users\Sirus\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx, Quarantined, [ec8e017a5823fa3ccdd72f9712f0e51b],
PUP.Optional.BProtector.A, C:\Users\Sirus\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data, Quarantined, [0d6db2c933480b2bf137f1f2fa09bc44],
PUP.Optional.BProtector.A, C:\Users\Sirus\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences, Quarantined, [3149abd009727abcbe6b7a697093847c],
PUP.Optional.TornTV.A, C:\Program Files (x86)\TornTV.com\log\20130813.log, Quarantined, [84f6ec8f8af13bfbf3d4ccc98b7738c8],
PUP.Optional.TornTV.A, C:\Program Files (x86)\TornTV.com\Torrents\.torrent, Quarantined, [84f6ec8f8af13bfbf3d4ccc98b7738c8],
PUP.Optional.Complitly.A, C:\Users\Sirus\AppData\Roaming\Complitly\64\Complitly64.dll, Quarantined, [4d2d2a51e299e45240af5f27dd271de3],
PUP.Optional.Complitly.A, C:\Users\Sirus\AppData\Roaming\Complitly\Complitly.dll, Quarantined, [4d2d2a51e299e45240af5f27dd271de3],
Physical Sectors: 0
(No malicious items detected)
(end)