cjoint

Publicité


Publicité

Format du document : application/octet-stream

Prévisualisation

[code]
HitmanPro 3.7.14.280
www.hitmanpro.com

Computer name . . . . : DESKTOP-ICAB9G0
Windows . . . . . . . : 10.0.0.10586.X86/2
User name . . . . . . : DESKTOP-ICAB9G0\monir
UAC . . . . . . . . . : Enabled
License . . . . . . . : Free

Scan date . . . . . . : 2016-11-04 17:02:09
Scan mode . . . . . . : Normal
Scan duration . . . . : 13m 46s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : No

Threats . . . . . . . : 3
Traces . . . . . . . : 3

Objects scanned . . . : 863 108
Files scanned . . . . : 27 602
Remnants scanned . . : 211 656 files / 623 850 keys

Malware _____________________________________________________________________

C:\AdwCleaner\quarantine\files\cwctikgddzewhodxpdrrroaunguwpmae\QQ\dr\qmdr.dll
Size . . . . . . . : 343 552 bytes
Age . . . . . . . : 1.3 days (2016-11-03 09:07:27)
Entropy . . . . . : 6.6
SHA-256 . . . . . : C89F3960B6773412BC5F9D2D93775DB13A6511F7F3396B5249316E82E5C3F1EC
> Kaspersky . . . . : Trojan.Win32.Obfuscated.bkyg
Fuzzy . . . . . . : 108.0
Forensic Cluster
-0.6s C:\AdwCleaner\quarantine\files\lagzoaqsfdztrrmxcyvpychmpaixohze\
-0.6s C:\AdwCleaner\quarantine\files\lagzoaqsfdztrrmxcyvpychmpaixohze\patch
-0.5s C:\AdwCleaner\quarantine\files\lagzoaqsfdztrrmxcyvpychmpaixohze\QQBrowser.exe
-0.5s C:\AdwCleaner\quarantine\files\lagzoaqsfdztrrmxcyvpychmpaixohze\QQBrowserFrame.dll
-0.1s C:\AdwCleaner\quarantine\files\cwctikgddzewhodxpdrrroaunguwpmae\
-0.0s C:\AdwCleaner\quarantine\files\cwctikgddzewhodxpdrrroaunguwpmae\QQ\
0.0s C:\AdwCleaner\quarantine\files\cwctikgddzewhodxpdrrroaunguwpmae\QQ\dr\
0.0s C:\AdwCleaner\quarantine\files\cwctikgddzewhodxpdrrroaunguwpmae\QQ\dr\qmdr.dll
1.0s C:\AdwCleaner\quarantine\files\gulerjymfrsjzwfichlccbhsmhxpvvtm\
1.0s C:\AdwCleaner\quarantine\files\gulerjymfrsjzwfichlccbhsmhxpvvtm\5.1.0.0\
1.0s C:\AdwCleaner\quarantine\files\gulerjymfrsjzwfichlccbhsmhxpvvtm\5.1.0.0\config.ini
1.0s C:\AdwCleaner\quarantine\files\gulerjymfrsjzwfichlccbhsmhxpvvtm\5.1.0.0\Dump\
1.0s C:\AdwCleaner\quarantine\files\gulerjymfrsjzwfichlccbhsmhxpvvtm\5.1.0.0\Dump\BugReportConfig.ini
1.4s C:\AdwCleaner\quarantine\files\bvodubzvtukqxgeezlnbcwuegymcpnby\
2.2s C:\AdwCleaner\quarantine\files\ltzbgywmuzksonoosvxwvddtapvnhgun\
2.2s C:\AdwCleaner\quarantine\files\ltzbgywmuzksonoosvxwvddtapvnhgun\main
2.2s C:\AdwCleaner\quarantine\files\ltzbgywmuzksonoosvxwvddtapvnhgun\UniKeyNT.exe
3.9s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\
3.9s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\
3.9s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\cert8.db
3.9s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\cookies.sqlite
4.0s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\cookies.sqlite-shm
4.0s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\cookies.sqlite-wal
4.1s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\key3.db
4.2s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\permissions.sqlite
4.3s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\places.sqlite
4.4s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\places.sqlite-shm
4.4s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\places.sqlite-wal
4.5s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\pluginreg.dat
4.5s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\secmod.db
4.6s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\webappsstore.sqlite
4.6s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\webappsstore.sqlite-shm
4.7s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\webappsstore.sqlite-wal
4.8s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\
4.8s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\_CACHE_001_
4.8s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\_CACHE_CLEAN_
4.8s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\_CACHE_002_
4.9s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\_CACHE_003_
5.0s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\_CACHE_MAP_
5.0s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\0\
5.0s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\1\
5.0s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\1\38\
5.0s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\1\38\FEC12d01
5.0s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\2\
5.0s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\2\E1\
5.0s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\2\E1\7F13Fd01
5.1s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\3\78\
5.1s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\3\78\CC99Ed01
5.1s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\3\
5.1s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\4\
5.1s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\5\
5.1s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\6\
5.1s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\6\2F\
5.1s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\6\2F\00AC3d01
5.2s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\6\7B\
5.2s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\6\7B\FEA3Bd01
5.2s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\7\08\
5.2s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\7\08\FEC05d01
5.2s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\7\
5.2s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\8\
5.2s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\9\
5.3s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\9\AF\
5.3s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\9\AF\77D58d01
5.3s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\A\19\
5.3s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\A\
5.3s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\A\19\E5A04d01
5.3s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\A\C5\
5.3s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\A\C5\2EBF4d01
5.3s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\B\F1\
5.3s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\B\F1\1A785d01
5.3s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\B\
5.3s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\C\
5.3s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\D\
5.3s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\F\5E\
5.3s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\F\5E\94E41d01
5.3s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\E\
5.3s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\Cache\F\
5.4s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\startupCache\
5.4s C:\AdwCleaner\quarantine\files\qavuvqpeqehljdtxzuiicbizwvjzohxz\DefaultProfile\startupCache\startupCache.4.little
11.8s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\
11.9s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\addons.json
11.9s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\blocklist.xml
11.9s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\cert8.db
11.9s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\cert_override.txt
11.9s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\compatibility.ini
11.9s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\content-prefs.sqlite
12.0s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\cookies.sqlite
12.0s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\extensions.ini
12.0s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\extensions.json
12.0s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\formhistory.sqlite
12.0s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\key3.db
12.1s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\mimeTypes.rdf
12.1s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\parent.lock
12.1s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\permissions.sqlite
12.1s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\places.sqlite
12.6s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\places.sqlite-shm
12.7s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\places.sqlite-wal
12.8s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\pluginreg.dat
12.8s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\prefs.js
12.8s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\revocations.txt
12.8s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\search-metadata.json
12.8s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\secmod.db
12.8s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\sessionCheckpoints.json
12.8s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\sessionstore.js
12.9s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\SiteSecurityServiceState.txt
12.9s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\times.json
12.9s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\webappsstore.sqlite
13.0s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\xulstore.json
13.0s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\bookmarkbackups\
13.0s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\crashes\events\
13.0s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\datareporting\
13.0s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\crashes\
13.0s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\crashes\store.json.mozlz4
13.0s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\datareporting\archived\2016-06\
13.0s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\datareporting\session-state.json
13.0s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\datareporting\state.json
13.0s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\datareporting\archived\
13.0s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\datareporting\archived\2016-06\1465122146386.232f81da-0b21-4eba-b5b2-dd6f66ce5cc2.main.jsonlz4
13.0s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\datareporting\archived\2016-06\1465123055818.f66a6960-78e6-4252-a499-b8487a53fc7c.main.jsonlz4
13.1s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\datareporting\archived\2016-06\1465123166918.16cdab0e-acac-4c60-80ff-bbd080a05913.main.jsonlz4
13.1s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\datareporting\archived\2016-06\1465123672072.7405a7d4-f654-4a21-97ba-69789757632c.main.jsonlz4
13.1s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\datareporting\archived\2016-06\1465127181311.3fdc16e4-b7be-4c4e-b05d-33e909e5290b.main.jsonlz4
13.1s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\datareporting\archived\2016-06\1465148248318.37c1b90c-54ca-43fc-9bef-63f60e691226.main.jsonlz4
13.2s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\datareporting\archived\2016-06\1465148309911.7301932c-f53e-44a9-a09c-57fd150b71cf.main.jsonlz4
13.2s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\datareporting\archived\2016-06\1465237068953.ddc3c4b7-b3c6-4621-b71c-766ef5a48b33.main.jsonlz4
13.2s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\datareporting\archived\2016-06\1465338058064.8eb0ad58-be95-4b28-a1a8-8a34d015c936.main.jsonlz4
13.3s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\datareporting\archived\2016-06\1465338399997.fbac6cb5-21e2-4694-85a7-5095a402726a.main.jsonlz4
13.3s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\datareporting\archived\2016-06\1465382811799.116ab0ae-4c99-41d3-98d6-bb31d1b4f1b6.main.jsonlz4
13.3s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\datareporting\archived\2016-07\
13.3s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\datareporting\archived\2016-07\1467922976105.8988b5e1-96e5-4336-913b-edd30a976b7e.main.jsonlz4
13.3s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\datareporting\archived\2016-09\
13.3s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\datareporting\archived\2016-09\1473195846991.37a3ba33-8311-4b2a-ab8c-897c4b850130.main.jsonlz4
13.3s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\datareporting\archived\2016-09\1473197778152.edbc9edb-f542-4194-9e40-d3a1ff2e980b.main.jsonlz4
13.4s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\features\{a43c3dac-33fb-4654-98d7-c0a71d6ed9d5}\
13.4s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\features\{a43c3dac-33fb-4654-98d7-c0a71d6ed9d5}\e10srollout@mozilla.org.xpi
13.4s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\features\
13.4s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\extensions\
13.4s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\features\{a43c3dac-33fb-4654-98d7-c0a71d6ed9d5}\firefox@getpocket.com.xpi
13.4s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\features\{a43c3dac-33fb-4654-98d7-c0a71d6ed9d5}\loop@mozilla.org.xpi
13.5s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\gmp\WINNT_x86-msvc\
13.5s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\gmp\
13.5s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\gmp-eme-adobe\
13.6s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\gmp-eme-adobe\17\
13.6s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\gmp-eme-adobe\17\eme-adobe.dll
13.9s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\gmp-eme-adobe\17\eme-adobe.info
13.9s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\gmp-eme-adobe\17\eme-adobe.voucher
13.9s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\gmp-gmpopenh264\
13.9s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\gmp-gmpopenh264\1.5.3\
13.9s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\gmp-gmpopenh264\1.5.3\gmpopenh264.dll
14.0s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\gmp-gmpopenh264\1.5.3\gmpopenh264.info
14.0s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\saved-telemetry-pings\
14.0s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\saved-telemetry-pings\37a3ba33-8311-4b2a-ab8c-897c4b850130
14.0s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\minidumps\
14.0s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\saved-telemetry-pings\8988b5e1-96e5-4336-913b-edd30a976b7e
14.0s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\saved-telemetry-pings\edbc9edb-f542-4194-9e40-d3a1ff2e980b
14.0s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\searchplugins\
14.0s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\sessionstore-backups\
14.0s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\sessionstore-backups\previous.js
14.0s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\storage\default\
14.0s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\sessionstore-backups\upgrade.js-20160502172042
14.0s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\storage\default\https+++lpcdn.lpsnmedia.net\
14.0s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\storage\
14.0s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\storage\default\https+++lpcdn.lpsnmedia.net\idb\
14.0s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\storage\default\https+++lpcdn.lpsnmedia.net\idb\713543746LePgSaercoutrSe.sqlite
14.0s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\storage\default\https+++lpcdn.lpsnmedia.net\.metadata
14.1s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\storage\default\https+++lpcdn.lpsnmedia.net\idb\713543746LePgSaercoutrSe.files\
14.1s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\storage\permanent\
14.1s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\storage\permanent\chrome\idb\
14.1s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\storage\permanent\chrome\idb\2918063365piupsah.sqlite
14.1s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\storage\permanent\chrome\
14.1s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\storage\permanent\chrome\.metadata
14.1s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\storage\permanent\chrome\idb\2918063365piupsah.files\
14.1s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\storage\permanent\moz-safe-about+home\idb\
14.1s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\storage\permanent\moz-safe-about+home\idb\818200132aebmoouht.sqlite
14.1s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\storage\permanent\moz-safe-about+home\
14.1s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\storage\permanent\moz-safe-about+home\.metadata
14.1s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\storage\temporary\
14.1s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\storage\permanent\moz-safe-about+home\idb\818200132aebmoouht.files\
14.2s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\webapps\
14.2s C:\AdwCleaner\quarantine\files\lukewnlweokonymoucscrnkffwlzfzbr\webapps\webapps.json

C:\ProgramData\adgjd\yacqq.exe
Size . . . . . . . : 303 832 bytes
Age . . . . . . . : 6.9 days (2016-10-28 19:44:36)
Entropy . . . . . : 6.0
SHA-256 . . . . . : F86C5938D4ED6860F9EFAB30A1146712505F1216A886A7F36D4809E585CEC754
RSA Key Size . . . : 2048
Authenticode . . . : Valid
> Bitdefender . . . : Gen:Variant.Adware.SupTab.4
> HitmanPro . . . . : Mal/Generic-S
Fuzzy . . . . . . : 101.0

C:\ProgramData\ttff\PPVA.dll
Size . . . . . . . : 592 384 bytes
Age . . . . . . . : 6.9 days (2016-10-28 19:44:42)
Entropy . . . . . : 6.5
SHA-256 . . . . . : 7CFE4CF7DEA0F0E5249B33C4C01A657C3582F913E0DD1736042BD2E16C9D1FBC
> Bitdefender . . . : Gen:Variant.Application.Elex.29
> Kaspersky . . . . : not-a-virus:AdWare.Win32.Elex.aah
Fuzzy . . . . . . : 108.0
Forensic Cluster
-0.0s C:\ProgramData\ttff\
0.0s C:\ProgramData\ttff\PPVA.dll
0.1s C:\ProgramData\ttff\ttff.exe



[/code]

Publicité


Signaler le contenu de ce document

Publicité