Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 4/18/18 Scan Time: 12:35 PM Log File: cb6c7b8f-42eb-11e8-9963-00247e043889.json Administrator: Yes -Software Information- Version: 3.4.5.2467 Components Version: 1.0.342 Update Package Version: 1.0.4776 License: Free -System Information- OS: Windows 7 Service Pack 1 CPU: x86 File System: NTFS User: User-PC\User -Scan Summary- Scan Type: Threat Scan Scan Initiated By: Manual Result: Completed Objects Scanned: 233167 Threats Detected: 89 Threats Quarantined: 0 (No malicious items detected) Time Elapsed: 24 min, 31 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Detect PUM: Detect -Scan Details- Process: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registry Key: 2 PUP.Optional.DriverPack, HKU\S-1-5-21-1623517632-3426292095-284688614-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\ZONEMAP\DOMAINS\drp.su, No Action By User, [874], [472299],1.0.4776 PUP.Optional.SlimServices, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SlimWareServices, No Action By User, [7798], [452421],1.0.4776 Registry Value: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 0 (No malicious items detected) File: 87 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],1.0.4776 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 MachineLearning/Anomalous.100%, C:\USERS\USER\APPDATA\ROAMING\IDM\M2BOB.EXE, No Action By User, [0], [392687],1.0.4776 Trojan.BitCoinMiner, C:\USERS\USER\APPDATA\ROAMING\LIBRARIES\VCRUNTIME\MICROSOFTVCRUNTIME.EXE, No Action By User, [510], [477462],1.0.4776 MachineLearning/Anomalous.100%, C:\PROGRAM FILES\INTERNET DOWNLOAD MANAGER\M2BOB.EXE, No Action By User, [0], [392687],1.0.4776 PUP.Optional.GameHack, C:\PROGRAM FILES\CHEAT ENGINE 6.4\STANDALONEPHASE1.DAT, No Action By User, [8227], [393793],1.0.4776 MachineLearning/Anomalous.100%, C:\$RECYCLE.BIN\S-1-5-21-1623517632-3426292095-284688614-1000\$RM0XB90.4-\M2BOB.EXE, No Action By User, [0], [392687],1.0.4776 MachineLearning/Anomalous.100%, C:\$RECYCLE.BIN\S-1-5-21-1623517632-3426292095-284688614-1000\$R7Z9HUA.EXE, No Action By User, [0], [392687],1.0.4776 MachineLearning/Anomalous.100%, C:\$RECYCLE.BIN\S-1-5-21-1623517632-3426292095-284688614-1000\$RDC0FQR.EXE, No Action By User, [0], [392687],1.0.4776 MachineLearning/Anomalous.100%, C:\$RECYCLE.BIN\S-1-5-21-1623517632-3426292095-284688614-1000\$RMMU30L.EXE, No Action By User, [0], [392687],1.0.4776 MachineLearning/Anomalous.100%, C:\$RECYCLE.BIN\S-1-5-21-1623517632-3426292095-284688614-1000\$RX62W5P.ZIP, No Action By User, [0], [392687],1.0.4776 RiskWare.DontStealOurSoftware, C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS, No Action By User, [5450], [353143],0.0.0 RiskWare.Tool.CK, C:\WINDOWS\KMSERVICE.EXE, No Action By User, [5967], [133383],1.0.4776 Physical Sector: 0 (No malicious items detected) (end)