Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 8/31/17 Scan Time: 2:53 PM Log File: f4d46c7e-8e42-11e7-9bdc-c45444b759e2.json Administrator: Yes -Software Information- Version: 3.2.2.2018 Components Version: 1.0.0 Update Package Version: 1.0.2696 License: Free -System Information- OS: Windows 10 (Build 10240.17113) CPU: x64 File System: NTFS User: MILANTO\Milanto -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 495244 Threats Detected: 23 Threats Quarantined: 23 Time Elapsed: 9 min, 39 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Detect PUM: Detect -Scan Details- Process: 0 (No malicious items detected) Module: 1 Trojan.Wdfload.TskLnk, C:\PROGRAM FILES\EF COVER CONVERTER\EF COVER CONVERTER.DLL, Quarantined, [4255], [424430],1.0.2696 Registry Key: 14 PUM.Optional.DisabledAVSecurityCerts, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\SYSTEMCERTIFICATES\DISALLOWED\CERTIFICATES\331E2046A1CCA7BFEF766724394BE6112B4CA3F7, Quarantined, [5566], [406773],1.0.2696 PUM.Optional.DisabledAVSecurityCerts, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\SYSTEMCERTIFICATES\DISALLOWED\CERTIFICATES\4C0AF5719009B7C9D85C5EAEDFA3B7F090FE5FFF, Quarantined, [5566], [406783],1.0.2696 PUM.Optional.DisabledAVSecurityCerts, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\SYSTEMCERTIFICATES\DISALLOWED\CERTIFICATES\9132E8B079D080E01D52631690BE18EBC2347C1E, Quarantined, [5566], [406793],1.0.2696 PUM.Optional.DisabledAVSecurityCerts, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\SYSTEMCERTIFICATES\DISALLOWED\CERTIFICATES\AB7E760DA2485EA9EF5A6EEE7647748D4BA6B947, Quarantined, [5566], [406804],1.0.2696 PUM.Optional.DisabledAVSecurityCerts, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\SYSTEMCERTIFICATES\DISALLOWED\CERTIFICATES\E22240E837B52E691C71DF248F12D27F96441C00, Quarantined, [5566], [406797],1.0.2696 PUM.Optional.DisabledAVSecurityCerts, HKLM\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\DISALLOWED\CERTIFICATES\331E2046A1CCA7BFEF766724394BE6112B4CA3F7, Quarantined, [5566], [406773],1.0.2696 PUM.Optional.DisabledAVSecurityCerts, HKLM\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\DISALLOWED\CERTIFICATES\4C0AF5719009B7C9D85C5EAEDFA3B7F090FE5FFF, Quarantined, [5566], [406783],1.0.2696 PUM.Optional.DisabledAVSecurityCerts, HKLM\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\DISALLOWED\CERTIFICATES\9132E8B079D080E01D52631690BE18EBC2347C1E, Quarantined, [5566], [406793],1.0.2696 PUM.Optional.DisabledAVSecurityCerts, HKLM\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\DISALLOWED\CERTIFICATES\AB7E760DA2485EA9EF5A6EEE7647748D4BA6B947, Quarantined, [5566], [406804],1.0.2696 PUM.Optional.DisabledAVSecurityCerts, HKLM\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\DISALLOWED\CERTIFICATES\E22240E837B52E691C71DF248F12D27F96441C00, Quarantined, [5566], [406797],1.0.2696 Trojan.Wdfload.TskLnk, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EF Cover Converter, Quarantined, [4255], [-1],0.0.0 Trojan.Wdfload.TskLnk, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6282FCB1-1DFC-45B3-AD66-1EFB4CC7AC19}, Quarantined, [4255], [-1],0.0.0 Trojan.Wdfload.TskLnk, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{6282FCB1-1DFC-45B3-AD66-1EFB4CC7AC19}, Quarantined, [4255], [-1],0.0.0 Adware.Elex.SHHKRST, HKLM\SOFTWARE\CLASSES\CLSID\{5F51FFFE-7463-4220-B711-E5B9ACB8EDFE}, Quarantined, [9], [357968],1.0.2696 Registry Value: 3 Trojan.Agent.Generic, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE|MILANTO, Quarantined, [458], [408899],1.0.2696 Adware.Tuto4PC.Generic, HKU\S-1-5-21-2074184489-2815443456-4149718103-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|GC9VQVJ0557V0NB, Quarantined, [1305], [392931],1.0.2696 Adware.Elex.SHHKRST, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\SHELLEXECUTEHOOKS|{5F51FFFE-7463-4220-B711-E5B9ACB8EDFE}, Quarantined, [9], [357968],1.0.2696 Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 0 (No malicious items detected) File: 5 Trojan.Agent.Generic, C:\WINDOWS\TEMP\G7F82.TMP.EXE, Quarantined, [458], [408899],1.0.2696 PUP.Optional.FFHijacker, C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\101366968.CFG, Quarantined, [1137], [345408],1.0.2696 Trojan.Wdfload.TskLnk, C:\PROGRAM FILES\EF COVER CONVERTER\EF COVER CONVERTER.DLL, Quarantined, [4255], [424430],1.0.2696 Trojan.Wdfload.TskLnk, C:\WINDOWS\SYSTEM32\TASKS\EF Cover Converter, Quarantined, [4255], [-1],0.0.0 PUP.Optional.FFHijacker, C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\DEFAULTS\PREF\101366968.JS, Quarantined, [1137], [330892],1.0.2696 Physical Sector: 0 (No malicious items detected) (end)