Code:
Code:
HitmanPro 3.7.15.281
www.hitmanpro.com
Computer name . . . . : EPONA
Windows . . . . . . . : 10.0.0.14393.X64/8
User name . . . . . . : EPONA\Princhi
UAC . . . . . . . . . : Enabled
License . . . . . . . : Free
Scan date . . . . . . : 2017-03-09 19:39:56
Scan mode . . . . . . : Normal
Scan duration . . . . : 11m 3s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : No
Threats . . . . . . . : 67
Traces . . . . . . . : 75
Objects scanned . . . : 2.258.971
Files scanned . . . . : 102.220
Remnants scanned . . : 718.695 files / 1.438.056 keys
Malware _____________________________________________________________________
C:\AdwCleaner\Quarantine\files\bdbhdpggensejjwczvifunkrvljgzlqw\WinSAP.dll
Size . . . . . . . : 184.832 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:16)
Entropy . . . . . : 6.5
SHA-256 . . . . . : 4B72FCDE3E3A010573A6C147E36643B373A04F33526EE85269BF9A87D2E7FD27
Product . . . . . : Windows
Publisher . . . . : Windows
Description . . . : Windows
Version . . . . . : 1.0.0.1
LanguageID . . . . : 2052
> Kaspersky . . . . : not-a-virus:AdWare.Win32.ELEX.ayq
Fuzzy . . . . . . : 102.0
C:\AdwCleaner\Quarantine\files\fztulhszulhanxgaybuuoyaxkybxzrgd\WinSAP.dll
Size . . . . . . . : 184.832 bytes
Age . . . . . . . : 2.2 days (2017-03-07 15:38:34)
Entropy . . . . . : 6.5
SHA-256 . . . . . : C0BE478ABDE4A102E8BD3FB4C1282106F546E95A6DA2E2572102D4CA69959D35
Product . . . . . : Windows
Publisher . . . . : Windows
Description . . . : Windows
Version . . . . . : 1.0.0.1
LanguageID . . . . : 2052
> Kaspersky . . . . : not-a-virus:AdWare.Win32.ELEX.aym
Fuzzy . . . . . . : 102.0
Forensic Cluster
0.0s C:\AdwCleaner\Quarantine\files\fztulhszulhanxgaybuuoyaxkybxzrgd\
0.0s C:\AdwCleaner\Quarantine\files\fztulhszulhanxgaybuuoyaxkybxzrgd\WinSAP.dll
0.4s C:\AdwCleaner\Quarantine\files\rdjtzmywsbrqfzoarmczyxklxcdeymdo\
0.4s C:\AdwCleaner\Quarantine\files\rdjtzmywsbrqfzoarmczyxklxcdeymdo\amule.conf
0.4s C:\AdwCleaner\Quarantine\files\rdjtzmywsbrqfzoarmczyxklxcdeymdo\clients.met
0.4s C:\AdwCleaner\Quarantine\files\rdjtzmywsbrqfzoarmczyxklxcdeymdo\cryptkey.dat
0.4s C:\AdwCleaner\Quarantine\files\rdjtzmywsbrqfzoarmczyxklxcdeymdo\emfriends.met
0.4s C:\AdwCleaner\Quarantine\files\rdjtzmywsbrqfzoarmczyxklxcdeymdo\ipfilter.dat
0.4s C:\AdwCleaner\Quarantine\files\rdjtzmywsbrqfzoarmczyxklxcdeymdo\ipfilter_static.dat
0.4s C:\AdwCleaner\Quarantine\files\rdjtzmywsbrqfzoarmczyxklxcdeymdo\known.met
0.4s C:\AdwCleaner\Quarantine\files\rdjtzmywsbrqfzoarmczyxklxcdeymdo\known2_64.met
0.4s C:\AdwCleaner\Quarantine\files\rdjtzmywsbrqfzoarmczyxklxcdeymdo\lastversion
0.4s C:\AdwCleaner\Quarantine\files\rdjtzmywsbrqfzoarmczyxklxcdeymdo\logfile
0.4s C:\AdwCleaner\Quarantine\files\rdjtzmywsbrqfzoarmczyxklxcdeymdo\preferences.dat
0.4s C:\AdwCleaner\Quarantine\files\rdjtzmywsbrqfzoarmczyxklxcdeymdo\server.met
0.4s C:\AdwCleaner\Quarantine\files\rdjtzmywsbrqfzoarmczyxklxcdeymdo\shareddir.dat
0.6s C:\AdwCleaner\Quarantine\files\uupqwzgranwctpswsrrmyyrzyznrpejq\
0.6s C:\AdwCleaner\Quarantine\files\uupqwzgranwctpswsrrmyyrzyznrpejq\WinSnare.dll
0.8s C:\AdwCleaner\Quarantine\files\vcuahaftllyzuvxdgnphtrorxoarghhg\
0.9s C:\AdwCleaner\Quarantine\files\mavsvrfscvdlwgpspxkxpoizsivuokbh\
0.9s C:\AdwCleaner\Quarantine\files\mavsvrfscvdlwgpspxkxpoizsivuokbh\Kyubey.exe
1.0s C:\AdwCleaner\Quarantine\files\hrvnzlepwwdhfrdzfbhcrbuimfynpimc\
1.1s C:\AdwCleaner\Quarantine\files\hrvnzlepwwdhfrdzfbhcrbuimfynpimc\aMuleC.lnk
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\curlpp.dll
Size . . . . . . . : 582.144 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:24)
Entropy . . . . . : 6.1
SHA-256 . . . . . : 40B2BF6E50080B681BCEA957B537001BE8D988C9431A3167C9840A050E54A8A9
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : libcurl wrapper
Version . . . . . : 0.7.3.0
LanguageID . . . . : 1033
> Kaspersky . . . . : not-a-virus:HEUR:Downloader.Win32.Elex.gen
Fuzzy . . . . . . : 105.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\iCommon.dll
Size . . . . . . . : 467.024 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:25)
Entropy . . . . . : 6.0
SHA-256 . . . . . : 102687BBD9D2E706498AEE35164D3665CCF004954420582552D3EA8F60F57188
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : iCommon
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\iCommu.dll
Size . . . . . . . : 67.472 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:25)
Entropy . . . . . : 6.8
SHA-256 . . . . . : 55EF23191E3837E2B9E6CF96481205E6F4C377BC6892EDAA911CC5A9FD2DCADF
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : iCommu
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\iImportLib.dll
Size . . . . . . . : 813.056 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:25)
Entropy . . . . . : 6.7
SHA-256 . . . . . : 9503EBCC080FA7D02EBF0A15E7F002F4070406EE1E4E8165389F0BE8CF147B05
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : iImportLib
Version . . . . . : 6,10,495,30853
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Bitdefender . . . : Adware.GenericKD.3813173
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\iSafe.exe
Size . . . . . . . : 618.304 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:25)
Entropy . . . . . : 6.2
SHA-256 . . . . . : A74E1A8E0562182B33496438896A357216F022921087C6FE3EB341BDC72DDC0D
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : YAC
Version . . . . . : 6,11,127,30929
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\isafeadfv.dll
Size . . . . . . . : 449.376 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:25)
Entropy . . . . . : 6.1
SHA-256 . . . . . : A2DC5B1BD97F2A5AA410565F8EEC45D1096C4189B7259784C139CE026AEC4CD4
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : YAC
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\iSafeAdless.dll
Size . . . . . . . : 360.504 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:25)
Entropy . . . . . : 6.4
SHA-256 . . . . . : BC1169D4B0ACD573FD5A4E27A279FB26800D207EF56DF1287054743BB121E78A
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : iSafeAdless
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\isafebase.dll
Size . . . . . . . : 1.055.576 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:25)
Entropy . . . . . : 6.5
SHA-256 . . . . . : 6CC5EF19ABC7A57E8CD7C8060C084A7785CC52FC64534EB6CA629FC23E2FEC38
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : isafebase
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Bitdefender . . . : Adware.GenericKD.3867777
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\isafebs.dll
Size . . . . . . . : 975.080 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:25)
Entropy . . . . . : 6.6
SHA-256 . . . . . : 0443D855020BB9B00CEB1E46A65A558BC63A5D6F8637119DAFF274B0341F10E8
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : iSafebs
Version . . . . . : 6,11,123,30892
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Bitdefender . . . : Adware.GenericKD.4213761
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\isafechlp.dll
Size . . . . . . . : 1.119.056 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:25)
Entropy . . . . . : 6.6
SHA-256 . . . . . : 2DEAE090746D4F7253382585FD7EBF10CDFE520C080DB12F95AC048C9C2FDC55
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : isafechlp
Version . . . . . : 6.0.0.0
Copyright . . . . : Copyright (c) 2011-2014 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\isafeclc.dll
Size . . . . . . . : 254.552 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:25)
Entropy . . . . . : 6.2
SHA-256 . . . . . : 7867CD5DC617E8296EA53F25DE3C31B93BEF0219E2121FC007CE326A3CD0CCC3
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : isafeclc
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\isafeclcv.dll
Size . . . . . . . : 132.432 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:25)
Entropy . . . . . : 5.3
SHA-256 . . . . . : 1D1882DB1E712BB32382E1BAC94AD3C47A82E2D12AF75FAC5622AABBE86D031E
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : isafeclcv
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\iSafeDisp.dll
Size . . . . . . . : 242.536 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:25)
Entropy . . . . . : 5.8
SHA-256 . . . . . : 5008B016D8D5A9C962CCC702913092C591FBD8126F9D55E17D5C8E49F8BA278F
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : iSafeDisp
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\iSafeKrnl.sys
Size . . . . . . . : 262.344 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:25)
Entropy . . . . . : 5.6
SHA-256 . . . . . : 93F737632B51E5BA8142E7F7395BAF22866D5F6D896153DBE6B6AD7BAB7FA82D
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : iSafe Kernel Driver
Version . . . . . : 6.10.449.30619
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\iSafeKrnlCall.dll
Size . . . . . . . : 253.984 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:25)
Entropy . . . . . : 6.2
SHA-256 . . . . . : 4F2D6B05D4050E0DE94F1E9DA8EA14C4DB68435666FA4AD7F59ED7551F33B828
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : iSafe Kernel Driver Caller
Version . . . . . : 6,10,493,30849
RSA Key Size . . . : 2048
LanguageID . . . . : 2052
Authenticode . . . : Valid
> Bitdefender . . . : Adware.GenericKD.3867778
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 98.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\iSafeKrnlKit.sys
Size . . . . . . . : 110.112 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:25)
Entropy . . . . . : 6.4
SHA-256 . . . . . : 1E91C1ECF61EE9FF78FD9644E99880F4443603D764EEC6AFBA12AA7F7F029961
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : iSafe Kernel Kit Driver
Version . . . . . : 6.10.449.30619
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\iSafeKrnlMonCall.dll
Size . . . . . . . : 474.536 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:25)
Entropy . . . . . : 5.9
SHA-256 . . . . . : 9C6FD315A7BCE2AF1D027D73BDBEBD3E3D347E8AAF4E8E2937F9BE3FD0A78DBA
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : iSafe Kernel Monitor Driver Caller
Version . . . . . : 6.10.449.30619
RSA Key Size . . . : 2048
LanguageID . . . . : 2052
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 98.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\iSafeKrnlR3.sys
Size . . . . . . . : 103.904 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:25)
Entropy . . . . . : 6.2
SHA-256 . . . . . : 5826DA2F1BE5AC91219FFD550CD92B9F6124988A6E6F2C9509CF0A6E5F43FF08
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : iSafe Kernel Ring3 Driver
Version . . . . . : 6.10.449.30619
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\isafemadwc.dll
Size . . . . . . . : 464.912 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:25)
Entropy . . . . . : 6.3
SHA-256 . . . . . : 36A0FC541285ACAB02F56E88FFCD92B76F614602C242FF45CDEB11981F5A7091
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : Softmanager
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\isafembp.dll
Size . . . . . . . : 499.248 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:25)
Entropy . . . . . : 6.3
SHA-256 . . . . . : E21D6CB8CC1A8F96315D6555978EBAE23F4EE653D5110E4E251140C973122E52
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : Browser Plugin
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\isafemc.dll
Size . . . . . . . : 43.112 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:25)
Entropy . . . . . : 6.6
SHA-256 . . . . . : AC8F81F0BA0EBF6C1CB188A4059DEC0F6DAF8FE2639AE812DF3226BE66C21796
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : Module Config
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Bitdefender . . . : Adware.GenericKD.3867782
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\isafemclv.dll
Size . . . . . . . : 794.320 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:25)
Entropy . . . . . : 6.4
SHA-256 . . . . . : 95D687234D4B899257849E8E735CC3F97707E820B988C37A0E0FE6C23E5C86EF
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : YAC
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\isafemgc.dll
Size . . . . . . . : 551.168 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:25)
Entropy . . . . . : 6.4
SHA-256 . . . . . : 737673593EC0ACDD53AB41D6C8914B46DD2C7D80828916D17289A61460AF8011
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : Garbage Cleaner
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\iSafeMon.dll
Size . . . . . . . : 301.296 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:25)
Entropy . . . . . : 5.8
SHA-256 . . . . . : 05AD8379CA688D0D771CC3AF8B17BE04503A9570D62C0421D7EE56F2142069AD
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : iSafeMon
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\isafemoptv.dll
Size . . . . . . . : 525.264 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:25)
Entropy . . . . . : 6.2
SHA-256 . . . . . : F68D74A5237AC7AC8BA97D60C9F2CB12800AE9ED087C679BAB94C43944B5E3A3
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : YAC
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\isafemsmv.dll
Size . . . . . . . : 330.384 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:25)
Entropy . . . . . : 6.2
SHA-256 . . . . . : 07894DC69FD83F7AFCF4D64D013082D67A0049662809B1E98C3731368BF65AA5
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : SoftMgr
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\iSafeNetFilter.sys
Size . . . . . . . : 52.392 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:25)
Entropy . . . . . : 6.4
SHA-256 . . . . . : 6597D4994D0D6262B853F64A6E828C5D411225624F137901F6DCF3D3BA81BB80
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : iSafeNetFilter SDK WFP Driver (WPP)
Version . . . . . : 1.4.6.1
Copyright . . . . : Copyright (c) 2011-2013 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:NetTool.Win64.NetFilter.qq
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\iSafenpf.dll
Size . . . . . . . : 223.864 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:25)
Entropy . . . . . : 6.7
SHA-256 . . . . . : E31FE6E63C0E9606697D30E51A94C64C0E139C252B6973EBB0C652EEC870851E
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : iSafenpf
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\isafepxy.dll
Size . . . . . . . : 130.896 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:25)
Entropy . . . . . : 6.5
SHA-256 . . . . . : 89D5BB370C9EFB999A9885D4B74FEFAFD5A5638AD1360148A8B3F7194E2CB28E
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : isafepxy
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\isaferpt.dll
Size . . . . . . . : 129.360 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:25)
Entropy . . . . . : 6.2
SHA-256 . . . . . : DFE91E0C066D1ED9A11D6F5B76024AA4C6F326CEE450FB7048EF8091BBF33502
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : isaferpt
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\isafesmgr.dll
Size . . . . . . . : 629.168 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:25)
Entropy . . . . . : 6.3
SHA-256 . . . . . : 686B20EB95B0D57554EF5C89409064EF2D291FE05FDCB96A3440040099D975FE
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : Softmanager
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\isafesopt.dll
Size . . . . . . . : 475.784 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:25)
Entropy . . . . . : 6.3
SHA-256 . . . . . : D6A58FFC5EE0CF6E8EF6EAA293EC13CD40BA28110B74F0A71F5BC22B52070661
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : System Optimization
Version . . . . . : 6,11,127,30929
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\isafesptv.dll
Size . . . . . . . : 590.168 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:25)
Entropy . . . . . : 6.2
SHA-256 . . . . . : 5A08ADE089F8B986E83433F7BBF743D98C4487883AED5AF9C1EBD960508E35D6
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : YAC
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\isafesv.dll
Size . . . . . . . : 262.864 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:25)
Entropy . . . . . : 5.7
SHA-256 . . . . . : 22FAB420924A99C5562D71247F821FD9D30A98B041D6BC20EB3C8AC832126FFA
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : YAC
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\iSafeSvc.exe
Size . . . . . . . : 131.024 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:26)
Entropy . . . . . : 5.6
SHA-256 . . . . . : F9B616A66CEF8DBDE565D2B79E30C3420B40E1F696D849301C03625E6040F9D4
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : iSafeSvc
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\iSafeSvc2.exe
Size . . . . . . . : 131.024 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:26)
Entropy . . . . . : 5.6
SHA-256 . . . . . : 1B4E2778FEAAA0EF1D64CBC8E60C14C6BEF8F97DF8E6D5E17CD305CCD504FC07
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : iSafeSvc2
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\isafetbv.dll
Size . . . . . . . : 284.728 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:26)
Entropy . . . . . : 6.0
SHA-256 . . . . . : 57B7CDBA62402B14A630F15CC2D99F157CD62A7F6CA4B0E5660CA156D27A9316
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : YAC
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\iSafeTHlp.exe
Size . . . . . . . : 459.672 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:26)
Entropy . . . . . : 6.1
SHA-256 . . . . . : 3482AAB9271FE4268B22BF24C8CA18F899CC307BBACDF77E8F607CD37753AC28
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : iSafeTaskHelper
Version . . . . . : 6,11,127,30929
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Bitdefender . . . : Adware.GenericKD.4397405
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\iSafeTHlp64.exe
Size . . . . . . . : 473.864 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:26)
Entropy . . . . . : 6.1
SHA-256 . . . . . : 731EFDDA85BE9A85A9973B4A6C77F12A6F13EEA68966C9E3AF0E0C89A8F13890
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : iSafeTaskHelper64
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\iSafeTray.exe
Size . . . . . . . : 427.000 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:26)
Entropy . . . . . : 6.1
SHA-256 . . . . . : 82827F2440869222DFF06763075EF0B0E24C85F762952698D13321C0D4F6E21A
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : YACTray
Version . . . . . : 6,10,502,30896
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Bitdefender . . . : Adware.GenericKD.4229071
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\isafeupbiz.dll
Size . . . . . . . : 128.848 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:26)
Entropy . . . . . : 6.1
SHA-256 . . . . . : 80437E99758600229F7D44FE3E2A5497473565A8E687746CC4C1434A90CB7464
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : isafeupbiz
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\iStart.exe
Size . . . . . . . : 314.216 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:26)
Entropy . . . . . : 4.8
SHA-256 . . . . . : B437E07CB74C0FCED30F23591DC0DAB3718379FFA1A10932790065FC6F692F56
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : iStart
Version . . . . . : 6,11,127,30929
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Bitdefender . . . : Adware.GenericKD.4411317
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\iSvc.dll
Size . . . . . . . : 302.832 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:26)
Entropy . . . . . : 6.1
SHA-256 . . . . . : 856B9194D60AE8DD2A26309F3B4700DC265D7EC0F67CDD544387AECD451395B4
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : iSvc
Version . . . . . : 6,10,522,30990
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\iSvc2.dll
Size . . . . . . . : 1.703.520 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:26)
Entropy . . . . . : 6.3
SHA-256 . . . . . : 7F8882D697D521558047BE063CFD9B65ADFC09BF63737EEA30ED3CA8D0F5AD20
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : iSvc2
Version . . . . . : 6,10,502,30896
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\iTPAutoClean.dll
Size . . . . . . . : 122.584 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:26)
Entropy . . . . . : 5.8
SHA-256 . . . . . : 56A6DCFA6E7D39801650EA3D7A608157A111A4DB158D0440A3EFCBFE74848268
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : YACTrayPlugin
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\iTPDesk.dll
Size . . . . . . . : 244.704 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:26)
Entropy . . . . . : 5.9
SHA-256 . . . . . : 4ABC5001CEEA06215A47BD00DDD481349A88A2A9DDEB868D817BA12AFD4D7AE2
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : YACTrayPlugin
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\iTPFloaty.dll
Size . . . . . . . : 709.096 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:26)
Entropy . . . . . : 6.3
SHA-256 . . . . . : 5EA43CC1090E806F4C60CA8E7753534B7FD47973B98E0C471417B5E7312D0368
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : YACTrayPlugin
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\iTPMsgCenter.dll
Size . . . . . . . : 245.672 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:26)
Entropy . . . . . : 5.7
SHA-256 . . . . . : 6520659EF5B82637D47B9DA7BA0373D5BB396A6CF9F7F68340FCC8AC46D84342
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : YACTrayPlugin
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\iTpNodisturb.dll
Size . . . . . . . : 228.536 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:26)
Entropy . . . . . : 5.8
SHA-256 . . . . . : 96171563377B1120C8721AF6A5FAA61F0538DAF4CDBC0336DA60C3F7D6C25453
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : YACTrayPlugin
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\iTPProtect.dll
Size . . . . . . . : 420.736 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:26)
Entropy . . . . . : 5.9
SHA-256 . . . . . : A404077EA638912E92D20144B8F9A83AB7D4FE0477C4C7EFFCF1B89BF4ADF7A9
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : YACTrayPlugin
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\iTPPush.dll
Size . . . . . . . : 266.960 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:26)
Entropy . . . . . : 5.9
SHA-256 . . . . . : 4C32B68A80868E3CA21B95ED3A6AA15A453DD8C7BEF6CE18756878BA7810343B
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : YACTrayPlugin
Version . . . . . : 6,10,493,30849
Copyright . . . . : Copyright (c) 2011-2016 Elex do Brasil Participações Ltda
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 96.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\libeay32.dll
Size . . . . . . . : 1.187.000 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:26)
Entropy . . . . . : 6.8
SHA-256 . . . . . : 97C4F25106F904E808063BB3941C46FDCAA448997832E1784D14DF0EFAA8DFCC
Product . . . . . : The OpenSSL Toolkit
Publisher . . . . : The OpenSSL Project, hxxp://www.openssl.org/
Description . . . : OpenSSL Shared Library
Version . . . . . : 1.0.1j
Copyright . . . . : Copyright ?1998-2005 The OpenSSL Project. Copyright ?1995-1998 Eric A. Young, Tim J. Hudson. All rights reserved.
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 95.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\ouilibx.dll
Size . . . . . . . : 1.926.472 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:26)
Entropy . . . . . : 6.5
SHA-256 . . . . . : 8A96505D25F007431F2AD92ABCDA60B6B8F956DB56C0CD350379DB7929612137
Product . . . . . : OUI
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : ouilib
Version . . . . . : 1.0.248.8837
Copyright
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:AdWare.Win32.ELEX.aax
> HitmanPro . . . . : Troj/Xadupi-A
Fuzzy . . . . . . : 98.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\ssleay32.dll
Size . . . . . . . : 281.648 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:26)
Entropy . . . . . : 6.4
SHA-256 . . . . . : 07B015A70A3371E704630A28173C8800318ACD608A2DF8B0C93247FE1E3C6A96
Product . . . . . : The OpenSSL Toolkit
Publisher . . . . : The OpenSSL Project, hxxp://www.openssl.org/
Description . . . : OpenSSL Shared Library
Version . . . . . : 1.0.1j
Copyright . . . . : Copyright ?1998-2005 The OpenSSL Project. Copyright ?1995-1998 Eric A. Young, Tim J. Hudson. All rights reserved.
RSA Key Size . . . : 2048
LanguageID . . . . : 1033
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 95.0
C:\AdwCleaner\Quarantine\files\gkvhnjorjvclruyxeujjzlcnezrwwser\YAC\uninstall.exe
Size . . . . . . . : 1.081.152 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:26)
Entropy . . . . . : 5.8
SHA-256 . . . . . : 999B00A10A190938A9F5FE0B99F3C10602762435074B232AE160863FDE7A5E82
Product . . . . . : YAC Security Protection
Publisher . . . . : Elex do Brasil Participações Ltda
Description . . . : uninstal
Version . . . . . : 6,11,130,30966
RSA Key Size . . . : 2048
LanguageID . . . . : 9
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.ELEX.gen
Fuzzy . . . . . . : 98.0
C:\AdwCleaner\Quarantine\files\kknmoddgmcoaqnqiqlywyontnvnwqtqf\Kyubey.exe
Size . . . . . . . : 111.104 bytes
Age . . . . . . . : 1.1 days (2017-03-08 16:31:17)
Entropy . . . . . : 6.3
SHA-256 . . . . . : 834B0AF05322BE802ACECFB853B9046DA5C850F42C9608424A44B65D7C8FC481
> Bitdefender . . . : Adware.GenericKD.4542564
> Kaspersky . . . . : not-a-virus:Downloader.Win32.Agent.hrht
Fuzzy . . . . . . : 108.0
C:\AdwCleaner\Quarantine\files\mavsvrfscvdlwgpspxkxpoizsivuokbh\Kyubey.exe
Size . . . . . . . : 115.200 bytes
Age . . . . . . . : 2.2 days (2017-03-07 15:38:35)
Entropy . . . . . : 6.4
SHA-256 . . . . . : 1B081FDAB67DFDE24C0CC18D5CF2A3CBCA36E1BB588EF1FAD8939D75A48CD8F6
> Bitdefender . . . : Trojan.GenericKD.4538419
> Kaspersky . . . . : Trojan-Downloader.Win32.Adload.pwpq
Fuzzy . . . . . . : 108.0
Forensic Cluster
-0.9s C:\AdwCleaner\Quarantine\files\fztulhszulhanxgaybuuoyaxkybxzrgd\
-0.9s C:\AdwCleaner\Quarantine\files\fztulhszulhanxgaybuuoyaxkybxzrgd\WinSAP.dll
-0.5s C:\AdwCleaner\Quarantine\files\rdjtzmywsbrqfzoarmczyxklxcdeymdo\
-0.5s C:\AdwCleaner\Quarantine\files\rdjtzmywsbrqfzoarmczyxklxcdeymdo\amule.conf
-0.5s C:\AdwCleaner\Quarantine\files\rdjtzmywsbrqfzoarmczyxklxcdeymdo\clients.met
-0.5s C:\AdwCleaner\Quarantine\files\rdjtzmywsbrqfzoarmczyxklxcdeymdo\cryptkey.dat
-0.5s C:\AdwCleaner\Quarantine\files\rdjtzmywsbrqfzoarmczyxklxcdeymdo\emfriends.met
-0.5s C:\AdwCleaner\Quarantine\files\rdjtzmywsbrqfzoarmczyxklxcdeymdo\ipfilter.dat
-0.5s C:\AdwCleaner\Quarantine\files\rdjtzmywsbrqfzoarmczyxklxcdeymdo\ipfilter_static.dat
-0.5s C:\AdwCleaner\Quarantine\files\rdjtzmywsbrqfzoarmczyxklxcdeymdo\known.met
-0.5s C:\AdwCleaner\Quarantine\files\rdjtzmywsbrqfzoarmczyxklxcdeymdo\known2_64.met
-0.5s C:\AdwCleaner\Quarantine\files\rdjtzmywsbrqfzoarmczyxklxcdeymdo\lastversion
-0.5s C:\AdwCleaner\Quarantine\files\rdjtzmywsbrqfzoarmczyxklxcdeymdo\logfile
-0.5s C:\AdwCleaner\Quarantine\files\rdjtzmywsbrqfzoarmczyxklxcdeymdo\preferences.dat
-0.5s C:\AdwCleaner\Quarantine\files\rdjtzmywsbrqfzoarmczyxklxcdeymdo\server.met
-0.5s C:\AdwCleaner\Quarantine\files\rdjtzmywsbrqfzoarmczyxklxcdeymdo\shareddir.dat
-0.3s C:\AdwCleaner\Quarantine\files\uupqwzgranwctpswsrrmyyrzyznrpejq\
-0.3s C:\AdwCleaner\Quarantine\files\uupqwzgranwctpswsrrmyyrzyznrpejq\WinSnare.dll
-0.1s C:\AdwCleaner\Quarantine\files\vcuahaftllyzuvxdgnphtrorxoarghhg\
0.0s C:\AdwCleaner\Quarantine\files\mavsvrfscvdlwgpspxkxpoizsivuokbh\
0.0s C:\AdwCleaner\Quarantine\files\mavsvrfscvdlwgpspxkxpoizsivuokbh\Kyubey.exe
0.2s C:\AdwCleaner\Quarantine\files\hrvnzlepwwdhfrdzfbhcrbuimfynpimc\
0.2s C:\AdwCleaner\Quarantine\files\hrvnzlepwwdhfrdzfbhcrbuimfynpimc\aMuleC.lnk
C:\AdwCleaner\Quarantine\files\qtazecleeflohiocxeqckehmbftguxhr\Kyubey.exe
Size . . . . . . . : 111.104 bytes
Age . . . . . . . : 1.0 days (2017-03-08 18:55:39)
Entropy . . . . . : 6.3
SHA-256 . . . . . : 834B0AF05322BE802ACECFB853B9046DA5C850F42C9608424A44B65D7C8FC481
> Bitdefender . . . : Adware.GenericKD.4542564
> Kaspersky . . . . : not-a-virus:Downloader.Win32.Agent.hrht
Fuzzy . . . . . . : 108.0
Forensic Cluster
-0.4s C:\AdwCleaner\Quarantine\files\ovfkkiaswlcewiyblipajhordmifrnqb\
-0.4s C:\AdwCleaner\Quarantine\files\ovfkkiaswlcewiyblipajhordmifrnqb\amule.conf
-0.4s C:\AdwCleaner\Quarantine\files\ovfkkiaswlcewiyblipajhordmifrnqb\clients.met
-0.4s C:\AdwCleaner\Quarantine\files\ovfkkiaswlcewiyblipajhordmifrnqb\cryptkey.dat
-0.4s C:\AdwCleaner\Quarantine\files\ovfkkiaswlcewiyblipajhordmifrnqb\emfriends.met
-0.4s C:\AdwCleaner\Quarantine\files\ovfkkiaswlcewiyblipajhordmifrnqb\ipfilter.dat
-0.4s C:\AdwCleaner\Quarantine\files\ovfkkiaswlcewiyblipajhordmifrnqb\ipfilter_static.dat
-0.4s C:\AdwCleaner\Quarantine\files\ovfkkiaswlcewiyblipajhordmifrnqb\known.met
-0.4s C:\AdwCleaner\Quarantine\files\ovfkkiaswlcewiyblipajhordmifrnqb\known2_64.met
-0.4s C:\AdwCleaner\Quarantine\files\ovfkkiaswlcewiyblipajhordmifrnqb\lastversion
-0.4s C:\AdwCleaner\Quarantine\files\ovfkkiaswlcewiyblipajhordmifrnqb\logfile
-0.4s C:\AdwCleaner\Quarantine\files\ovfkkiaswlcewiyblipajhordmifrnqb\preferences.dat
-0.4s C:\AdwCleaner\Quarantine\files\ovfkkiaswlcewiyblipajhordmifrnqb\server.met
-0.4s C:\AdwCleaner\Quarantine\files\ovfkkiaswlcewiyblipajhordmifrnqb\shareddir.dat
0.0s C:\AdwCleaner\Quarantine\files\qtazecleeflohiocxeqckehmbftguxhr\
0.0s C:\AdwCleaner\Quarantine\files\qtazecleeflohiocxeqckehmbftguxhr\Kyubey.exe
0.5s C:\AdwCleaner\Quarantine\files\nlyatcnykfiunjmmexozbmmjebsrnysv\
0.5s C:\AdwCleaner\Quarantine\files\nlyatcnykfiunjmmexozbmmjebsrnysv\QQLive\
0.5s C:\AdwCleaner\Quarantine\files\nlyatcnykfiunjmmexozbmmjebsrnysv\QQLive\FailRecord.dat
0.9s C:\AdwCleaner\Quarantine\registry\reg_hicklccucqpshnwofsbnrfkeupkvfnhc.reg
1.3s C:\AdwCleaner\Quarantine\registry\reg_rnpuqlwplhzpgvvhjhamehjwbbaasmxj.reg
1.5s C:\AdwCleaner\Quarantine\registry\reg_hbyhsfesjczndyptzjdjvqjobghnspnx.reg
2.0s C:\AdwCleaner\Quarantine\registry\reg_hszfrqlsmtcepwqrsurccdgpvdwlkpny.reg
2.0s C:\AdwCleaner\Quarantine\registry\reg_cfqhpnixaflpffpqqmhhpqryxrvjvguy.reg
2.1s C:\AdwCleaner\Quarantine\registry\reg_zuvtcfoiiybwnkzdgcsbfjehsxjtoltk.reg
2.2s C:\AdwCleaner\Quarantine\registry\reg_vdkoxyoigaymapzelpscpqhxgbwgfsgc.reg
2.5s C:\AdwCleaner\Quarantine\registry\reg_wxfspqgttsqmdlbmbqrhznlclbvnwxmb.reg
C:\AdwCleaner\Quarantine\files\rnkavljixmoptrfxkzrkwjhpxyoqoqxw\WinSAP.dll
Size . . . . . . . : 184.832 bytes
Age . . . . . . . : 1.1 days (2017-03-08 17:17:59)
Entropy . . . . . : 6.5
SHA-256 . . . . . : 4B72FCDE3E3A010573A6C147E36643B373A04F33526EE85269BF9A87D2E7FD27
Product . . . . . : Windows
Publisher . . . . : Windows
Description . . . : Windows
Version . . . . . : 1.0.0.1
LanguageID . . . . : 2052
> Kaspersky . . . . : not-a-virus:AdWare.Win32.ELEX.ayq
Fuzzy . . . . . . : 102.0
Forensic Cluster
-0.3s C:\AdwCleaner\Quarantine\files\gppborzhkigfpkypvvzmffczgmgkwusd\
-0.3s C:\AdwCleaner\Quarantine\files\gppborzhkigfpkypvvzmffczgmgkwusd\LICENSE.txt
-0.3s C:\AdwCleaner\Quarantine\files\gppborzhkigfpkypvvzmffczgmgkwusd\openweb.bat
-0.3s C:\AdwCleaner\Quarantine\files\gppborzhkigfpkypvvzmffczgmgkwusd\SnareWindowsInstallSupport.dll
-0.3s C:\AdwCleaner\Quarantine\files\gppborzhkigfpkypvvzmffczgmgkwusd\stopweb.bat
-0.3s C:\AdwCleaner\Quarantine\files\gppborzhkigfpkypvvzmffczgmgkwusd\s_32.ico
-0.3s C:\AdwCleaner\Quarantine\files\gppborzhkigfpkypvvzmffczgmgkwusd\WinSnare.dll
-0.3s C:\AdwCleaner\Quarantine\files\gppborzhkigfpkypvvzmffczgmgkwusd\WinSnare64.dll
0.0s C:\AdwCleaner\Quarantine\files\rnkavljixmoptrfxkzrkwjhpxyoqoqxw\
0.0s C:\AdwCleaner\Quarantine\files\rnkavljixmoptrfxkzrkwjhpxyoqoqxw\WinSAP.dll
0.3s C:\AdwCleaner\Quarantine\files\pjegakaiiuzgitdoldglleurljjzfnpa\
0.3s C:\AdwCleaner\Quarantine\files\pjegakaiiuzgitdoldglleurljjzfnpa\amule.conf
0.3s C:\AdwCleaner\Quarantine\files\pjegakaiiuzgitdoldglleurljjzfnpa\clients.met
0.3s C:\AdwCleaner\Quarantine\files\pjegakaiiuzgitdoldglleurljjzfnpa\cryptkey.dat
0.3s C:\AdwCleaner\Quarantine\files\pjegakaiiuzgitdoldglleurljjzfnpa\emfriends.met
0.3s C:\AdwCleaner\Quarantine\files\pjegakaiiuzgitdoldglleurljjzfnpa\ipfilter.dat
0.3s C:\AdwCleaner\Quarantine\files\pjegakaiiuzgitdoldglleurljjzfnpa\ipfilter_static.dat
0.3s C:\AdwCleaner\Quarantine\files\pjegakaiiuzgitdoldglleurljjzfnpa\known.met
0.3s C:\AdwCleaner\Quarantine\files\pjegakaiiuzgitdoldglleurljjzfnpa\known2_64.met
0.3s C:\AdwCleaner\Quarantine\files\pjegakaiiuzgitdoldglleurljjzfnpa\lastversion
0.3s C:\AdwCleaner\Quarantine\files\pjegakaiiuzgitdoldglleurljjzfnpa\logfile
0.3s C:\AdwCleaner\Quarantine\files\pjegakaiiuzgitdoldglleurljjzfnpa\preferences.dat
0.3s C:\AdwCleaner\Quarantine\files\pjegakaiiuzgitdoldglleurljjzfnpa\server.met
0.3s C:\AdwCleaner\Quarantine\files\pjegakaiiuzgitdoldglleurljjzfnpa\shareddir.dat
0.4s C:\AdwCleaner\Quarantine\files\cwkyzuwfpensbluwepclbtfpcdvtzfjo\
0.4s C:\AdwCleaner\Quarantine\files\cwkyzuwfpensbluwepclbtfpcdvtzfjo\WinSnare.dll
0.6s C:\AdwCleaner\Quarantine\files\silorkruzwkklhmggvsodfdjjwzehhjb\
0.6s C:\AdwCleaner\Quarantine\files\silorkruzwkklhmggvsodfdjjwzehhjb\Kyubey.exe
0.7s C:\AdwCleaner\Quarantine\files\cuactdtcyuvibtncyrkvfnbrasbtojgx\
0.7s C:\AdwCleaner\Quarantine\files\cuactdtcyuvibtncyrkvfnbrasbtojgx\BikaQ Rss Reader.lnk
0.8s C:\AdwCleaner\Quarantine\files\ynyjnpcdtiqxhrgkiyxuyjxlrpbiryxa\
0.8s C:\AdwCleaner\Quarantine\files\ynyjnpcdtiqxhrgkiyxuyjxlrpbiryxa\app.bikaQ.config
0.8s C:\AdwCleaner\Quarantine\files\ynyjnpcdtiqxhrgkiyxuyjxlrpbiryxa\BikaQ.exe
0.8s C:\AdwCleaner\Quarantine\files\ynyjnpcdtiqxhrgkiyxuyjxlrpbiryxa\BikaQ.exe.config
0.8s C:\AdwCleaner\Quarantine\files\ynyjnpcdtiqxhrgkiyxuyjxlrpbiryxa\bikaQ.ini
0.8s C:\AdwCleaner\Quarantine\files\ynyjnpcdtiqxhrgkiyxuyjxlrpbiryxa\Icon.ico
0.8s C:\AdwCleaner\Quarantine\files\ynyjnpcdtiqxhrgkiyxuyjxlrpbiryxa\Interop.Microsoft.Feeds.Interop.DLL
0.8s C:\AdwCleaner\Quarantine\files\ynyjnpcdtiqxhrgkiyxuyjxlrpbiryxa\MagicLibrary.DLL
0.9s C:\AdwCleaner\Quarantine\files\evsfyeuzcakzhamalwvtlcvrlhqkrsay\QQLive\
0.9s C:\AdwCleaner\Quarantine\files\evsfyeuzcakzhamalwvtlcvrlhqkrsay\QQLive\FailRecord.dat
0.9s C:\AdwCleaner\Quarantine\files\evsfyeuzcakzhamalwvtlcvrlhqkrsay\
1.1s C:\AdwCleaner\Quarantine\files\tabjpqbvdarqgigwqzcjlozuxajjicul\
1.1s C:\AdwCleaner\Quarantine\files\tabjpqbvdarqgigwqzcjlozuxajjicul\MIO.exe
1.1s C:\AdwCleaner\Quarantine\files\tabjpqbvdarqgigwqzcjlozuxajjicul\loader\
1.2s C:\AdwCleaner\Quarantine\files\uckpwuwhbtkrbjftxjewillefbhagvjf.back
1.2s C:\AdwCleaner\Quarantine\files\vebmgbnqanbdhhirxkdmgyqwgeqhmkji.back
1.3s C:\AdwCleaner\Quarantine\registry\reg_ktwtahdpfsysrgtdnkwzypifckvnrufw.reg
1.5s C:\AdwCleaner\Quarantine\registry\reg_uvlrjvppcdstzoqalfwhskwslcxbrqbo.reg
1.5s C:\AdwCleaner\Quarantine\registry\reg_wriqlbpfcrdyokumotgswukkleyofzde.reg
1.7s C:\AdwCleaner\Quarantine\registry\reg_ewfyqcjdnekhwbqrymtjdtafjehatuzw.reg
1.7s C:\AdwCleaner\Quarantine\registry\reg_ognfnetlwxegdivgdtpwkvldpiofbipu.reg
1.8s C:\AdwCleaner\Quarantine\registry\reg_wcmmnrhtaosfmqddqmefzbozbknrvzuz.reg
1.8s C:\AdwCleaner\Quarantine\registry\reg_gwsuluqiypjuljyqazhhxnvsezfdgorn.reg
1.9s C:\AdwCleaner\Quarantine\registry\reg_cvqtvaewyzlnlcgjidnthnhqgbdzcucg.reg
2.0s C:\AdwCleaner\Quarantine\registry\reg_skriaokttsamdvgjgqknmpfweuzkfxhs.reg
2.0s C:\AdwCleaner\Quarantine\registry\reg_zvheadhfosdkaevmcxfjmmqcdujtwmyy.reg
2.0s C:\AdwCleaner\Quarantine\registry\reg_wfcpgzmsegqgwokuqpwrvkavikexyqdw.reg
2.1s C:\AdwCleaner\Quarantine\registry\reg_vxtxicwrqsyccjrhzlbvrnmemaoqlrjs.reg
2.1s C:\AdwCleaner\Quarantine\registry\reg_drojglcvcjscslpkaefihbtflqzcsleu.reg
2.3s C:\AdwCleaner\Quarantine\registry\reg_lqogebnjhgguwovrsxgwfnalzbaxpxjb.reg
2.3s C:\AdwCleaner\Quarantine\registry\reg_rkwkzqrnlexonbgeenmlzjkuozgmvznv.reg
2.3s C:\AdwCleaner\Quarantine\registry\reg_wghdqbrhuxfvwlyplgyselwymgmgodpo.reg
2.3s C:\AdwCleaner\Quarantine\registry\reg_xbzfymcflhehdmporbsqpiesrmpqhbkc.reg
2.4s C:\AdwCleaner\Quarantine\registry\reg_dofvvyywzujbulovririojfkmdybcrgq.reg
2.5s C:\AdwCleaner\Quarantine\registry\reg_renzknldrzyxzfwufvhccprihtfcwzdr.reg
2.5s C:\AdwCleaner\Quarantine\registry\reg_zssrdwcmkfemkfiudqyrejteazqigelk.reg
2.5s C:\AdwCleaner\Quarantine\registry\reg_ndbvdskcyrzydgfllwqmewyhffuxyfem.reg
2.5s C:\AdwCleaner\Quarantine\registry\reg_robdwwehheozobyvlxysuugojffdoosr.reg
2.6s C:\AdwCleaner\Quarantine\registry\reg_jfilwlnyiwgzqcrlyqzfktnzhsmcmsra.reg
2.6s C:\AdwCleaner\Quarantine\registry\reg_nfpsbqwuyjmyiafjyemzmuivyerbxikx.reg
2.6s C:\AdwCleaner\Quarantine\registry\reg_vsfawbadaxdxrjsxoyduuzdpdnquhetd.reg
2.7s C:\AdwCleaner\Quarantine\registry\reg_znehuggdbusilshmtelbgvndthvfxntm.reg
2.7s C:\AdwCleaner\Quarantine\registry\reg_pifdbnxbitspfnxsuoqnbjlfmqpddajw.reg
2.8s C:\AdwCleaner\Quarantine\registry\reg_fnvskenvcxourbzoplcrsprbvdudeufs.reg
2.8s C:\AdwCleaner\Quarantine\registry\reg_yjhvtitcxvmbdvdqxqiscrxqqtszhads.reg
2.9s C:\AdwCleaner\Quarantine\registry\reg_ssijevxesgcixvxvkwnwbhkuczacguuo.reg
3.0s C:\AdwCleaner\Quarantine\registry\reg_rpcsormelopohizhkskrtztzbzoohvab.reg
3.0s C:\AdwCleaner\Quarantine\registry\reg_uoeewndontihkfsotecsqadxwrfbtpxk.reg
3.0s C:\AdwCleaner\Quarantine\registry\reg_qpaqmghjavcsjkdqkzcgbdrcynbbnhof.reg
3.0s C:\AdwCleaner\Quarantine\registry\reg_ntuqwigzizzqzmiqugyckwyczpfnavod.reg
3.0s C:\AdwCleaner\Quarantine\registry\reg_futrmniclsfwnerxhwgcgfeijceanipw.reg
6.9s C:\AdwCleaner\AdwCleaner[C14].txt
9.4s C:\Windows\Prefetch\NVDISPLAY.CONTAINER.EXE-22606B81.pf
9.8s C:\Windows\Prefetch\SEARCHINDEXER.EXE-EF8503D3.pf
10.1s C:\Windows\Prefetch\NVTRAY.EXE-981FA625.pf
C:\AdwCleaner\Quarantine\files\silorkruzwkklhmggvsodfdjjwzehhjb\Kyubey.exe
Size . . . . . . . : 111.104 bytes
Age . . . . . . . : 1.1 days (2017-03-08 17:18:00)
Entropy . . . . . : 6.3
SHA-256 . . . . . : 834B0AF05322BE802ACECFB853B9046DA5C850F42C9608424A44B65D7C8FC481
> Bitdefender . . . : Adware.GenericKD.4542564
> Kaspersky . . . . : not-a-virus:Downloader.Win32.Agent.hrht
Fuzzy . . . . . . : 108.0
Forensic Cluster
-0.8s C:\AdwCleaner\Quarantine\files\gppborzhkigfpkypvvzmffczgmgkwusd\
-0.8s C:\AdwCleaner\Quarantine\files\gppborzhkigfpkypvvzmffczgmgkwusd\LICENSE.txt
-0.8s C:\AdwCleaner\Quarantine\files\gppborzhkigfpkypvvzmffczgmgkwusd\openweb.bat
-0.8s C:\AdwCleaner\Quarantine\files\gppborzhkigfpkypvvzmffczgmgkwusd\SnareWindowsInstallSupport.dll
-0.8s C:\AdwCleaner\Quarantine\files\gppborzhkigfpkypvvzmffczgmgkwusd\stopweb.bat
-0.8s C:\AdwCleaner\Quarantine\files\gppborzhkigfpkypvvzmffczgmgkwusd\s_32.ico
-0.8s C:\AdwCleaner\Quarantine\files\gppborzhkigfpkypvvzmffczgmgkwusd\WinSnare.dll
-0.8s C:\AdwCleaner\Quarantine\files\gppborzhkigfpkypvvzmffczgmgkwusd\WinSnare64.dll
-0.6s C:\AdwCleaner\Quarantine\files\rnkavljixmoptrfxkzrkwjhpxyoqoqxw\
-0.6s C:\AdwCleaner\Quarantine\files\rnkavljixmoptrfxkzrkwjhpxyoqoqxw\WinSAP.dll
-0.3s C:\AdwCleaner\Quarantine\files\pjegakaiiuzgitdoldglleurljjzfnpa\
-0.3s C:\AdwCleaner\Quarantine\files\pjegakaiiuzgitdoldglleurljjzfnpa\amule.conf
-0.3s C:\AdwCleaner\Quarantine\files\pjegakaiiuzgitdoldglleurljjzfnpa\clients.met
-0.3s C:\AdwCleaner\Quarantine\files\pjegakaiiuzgitdoldglleurljjzfnpa\cryptkey.dat
-0.3s C:\AdwCleaner\Quarantine\files\pjegakaiiuzgitdoldglleurljjzfnpa\emfriends.met
-0.3s C:\AdwCleaner\Quarantine\files\pjegakaiiuzgitdoldglleurljjzfnpa\ipfilter.dat
-0.3s C:\AdwCleaner\Quarantine\files\pjegakaiiuzgitdoldglleurljjzfnpa\ipfilter_static.dat
-0.3s C:\AdwCleaner\Quarantine\files\pjegakaiiuzgitdoldglleurljjzfnpa\known.met
-0.3s C:\AdwCleaner\Quarantine\files\pjegakaiiuzgitdoldglleurljjzfnpa\known2_64.met
-0.3s C:\AdwCleaner\Quarantine\files\pjegakaiiuzgitdoldglleurljjzfnpa\lastversion
-0.3s C:\AdwCleaner\Quarantine\files\pjegakaiiuzgitdoldglleurljjzfnpa\logfile
-0.3s C:\AdwCleaner\Quarantine\files\pjegakaiiuzgitdoldglleurljjzfnpa\preferences.dat
-0.3s C:\AdwCleaner\Quarantine\files\pjegakaiiuzgitdoldglleurljjzfnpa\server.met
-0.3s C:\AdwCleaner\Quarantine\files\pjegakaiiuzgitdoldglleurljjzfnpa\shareddir.dat
-0.1s C:\AdwCleaner\Quarantine\files\cwkyzuwfpensbluwepclbtfpcdvtzfjo\
-0.1s C:\AdwCleaner\Quarantine\files\cwkyzuwfpensbluwepclbtfpcdvtzfjo\WinSnare.dll
0.0s C:\AdwCleaner\Quarantine\files\silorkruzwkklhmggvsodfdjjwzehhjb\
0.0s C:\AdwCleaner\Quarantine\files\silorkruzwkklhmggvsodfdjjwzehhjb\Kyubey.exe
0.1s C:\AdwCleaner\Quarantine\files\cuactdtcyuvibtncyrkvfnbrasbtojgx\
0.1s C:\AdwCleaner\Quarantine\files\cuactdtcyuvibtncyrkvfnbrasbtojgx\BikaQ Rss Reader.lnk
0.2s C:\AdwCleaner\Quarantine\files\ynyjnpcdtiqxhrgkiyxuyjxlrpbiryxa\
0.2s C:\AdwCleaner\Quarantine\files\ynyjnpcdtiqxhrgkiyxuyjxlrpbiryxa\app.bikaQ.config
0.2s C:\AdwCleaner\Quarantine\files\ynyjnpcdtiqxhrgkiyxuyjxlrpbiryxa\BikaQ.exe
0.2s C:\AdwCleaner\Quarantine\files\ynyjnpcdtiqxhrgkiyxuyjxlrpbiryxa\BikaQ.exe.config
0.2s C:\AdwCleaner\Quarantine\files\ynyjnpcdtiqxhrgkiyxuyjxlrpbiryxa\bikaQ.ini
0.2s C:\AdwCleaner\Quarantine\files\ynyjnpcdtiqxhrgkiyxuyjxlrpbiryxa\Icon.ico
0.2s C:\AdwCleaner\Quarantine\files\ynyjnpcdtiqxhrgkiyxuyjxlrpbiryxa\Interop.Microsoft.Feeds.Interop.DLL
0.2s C:\AdwCleaner\Quarantine\files\ynyjnpcdtiqxhrgkiyxuyjxlrpbiryxa\MagicLibrary.DLL
0.4s C:\AdwCleaner\Quarantine\files\evsfyeuzcakzhamalwvtlcvrlhqkrsay\QQLive\
0.4s C:\AdwCleaner\Quarantine\files\evsfyeuzcakzhamalwvtlcvrlhqkrsay\QQLive\FailRecord.dat
0.4s C:\AdwCleaner\Quarantine\files\evsfyeuzcakzhamalwvtlcvrlhqkrsay\
0.5s C:\AdwCleaner\Quarantine\files\tabjpqbvdarqgigwqzcjlozuxajjicul\
0.5s C:\AdwCleaner\Quarantine\files\tabjpqbvdarqgigwqzcjlozuxajjicul\MIO.exe
0.5s C:\AdwCleaner\Quarantine\files\tabjpqbvdarqgigwqzcjlozuxajjicul\loader\
0.6s C:\AdwCleaner\Quarantine\files\uckpwuwhbtkrbjftxjewillefbhagvjf.back
0.6s C:\AdwCleaner\Quarantine\files\vebmgbnqanbdhhirxkdmgyqwgeqhmkji.back
0.8s C:\AdwCleaner\Quarantine\registry\reg_ktwtahdpfsysrgtdnkwzypifckvnrufw.reg
0.9s C:\AdwCleaner\Quarantine\registry\reg_uvlrjvppcdstzoqalfwhskwslcxbrqbo.reg
0.9s C:\AdwCleaner\Quarantine\registry\reg_wriqlbpfcrdyokumotgswukkleyofzde.reg
1.1s C:\AdwCleaner\Quarantine\registry\reg_ewfyqcjdnekhwbqrymtjdtafjehatuzw.reg
1.2s C:\AdwCleaner\Quarantine\registry\reg_ognfnetlwxegdivgdtpwkvldpiofbipu.reg
1.2s C:\AdwCleaner\Quarantine\registry\reg_wcmmnrhtaosfmqddqmefzbozbknrvzuz.reg
1.3s C:\AdwCleaner\Quarantine\registry\reg_gwsuluqiypjuljyqazhhxnvsezfdgorn.reg
1.3s C:\AdwCleaner\Quarantine\registry\reg_cvqtvaewyzlnlcgjidnthnhqgbdzcucg.reg
1.4s C:\AdwCleaner\Quarantine\registry\reg_skriaokttsamdvgjgqknmpfweuzkfxhs.reg
1.4s C:\AdwCleaner\Quarantine\registry\reg_zvheadhfosdkaevmcxfjmmqcdujtwmyy.reg
1.5s C:\AdwCleaner\Quarantine\registry\reg_wfcpgzmsegqgwokuqpwrvkavikexyqdw.reg
1.5s C:\AdwCleaner\Quarantine\registry\reg_vxtxicwrqsyccjrhzlbvrnmemaoqlrjs.reg
1.6s C:\AdwCleaner\Quarantine\registry\reg_drojglcvcjscslpkaefihbtflqzcsleu.reg
1.7s C:\AdwCleaner\Quarantine\registry\reg_lqogebnjhgguwovrsxgwfnalzbaxpxjb.reg
1.7s C:\AdwCleaner\Quarantine\registry\reg_rkwkzqrnlexonbgeenmlzjkuozgmvznv.reg
1.7s C:\AdwCleaner\Quarantine\registry\reg_wghdqbrhuxfvwlyplgyselwymgmgodpo.reg
1.8s C:\AdwCleaner\Quarantine\registry\reg_xbzfymcflhehdmporbsqpiesrmpqhbkc.reg
1.8s C:\AdwCleaner\Quarantine\registry\reg_dofvvyywzujbulovririojfkmdybcrgq.reg
1.9s C:\AdwCleaner\Quarantine\registry\reg_renzknldrzyxzfwufvhccprihtfcwzdr.reg
1.9s C:\AdwCleaner\Quarantine\registry\reg_zssrdwcmkfemkfiudqyrejteazqigelk.reg
2.0s C:\AdwCleaner\Quarantine\registry\reg_ndbvdskcyrzydgfllwqmewyhffuxyfem.reg
2.0s C:\AdwCleaner\Quarantine\registry\reg_robdwwehheozobyvlxysuugojffdoosr.reg
2.0s C:\AdwCleaner\Quarantine\registry\reg_jfilwlnyiwgzqcrlyqzfktnzhsmcmsra.reg
2.0s C:\AdwCleaner\Quarantine\registry\reg_nfpsbqwuyjmyiafjyemzmuivyerbxikx.reg
2.1s C:\AdwCleaner\Quarantine\registry\reg_vsfawbadaxdxrjsxoyduuzdpdnquhetd.reg
2.1s C:\AdwCleaner\Quarantine\registry\reg_znehuggdbusilshmtelbgvndthvfxntm.reg
2.2s C:\AdwCleaner\Quarantine\registry\reg_pifdbnxbitspfnxsuoqnbjlfmqpddajw.reg
2.2s C:\AdwCleaner\Quarantine\registry\reg_fnvskenvcxourbzoplcrsprbvdudeufs.reg
2.3s C:\AdwCleaner\Quarantine\registry\reg_yjhvtitcxvmbdvdqxqiscrxqqtszhads.reg
2.3s C:\AdwCleaner\Quarantine\registry\reg_ssijevxesgcixvxvkwnwbhkuczacguuo.reg
2.4s C:\AdwCleaner\Quarantine\registry\reg_rpcsormelopohizhkskrtztzbzoohvab.reg
2.4s C:\AdwCleaner\Quarantine\registry\reg_uoeewndontihkfsotecsqadxwrfbtpxk.reg
2.5s C:\AdwCleaner\Quarantine\registry\reg_qpaqmghjavcsjkdqkzcgbdrcynbbnhof.reg
2.5s C:\AdwCleaner\Quarantine\registry\reg_ntuqwigzizzqzmiqugyckwyczpfnavod.reg
2.5s C:\AdwCleaner\Quarantine\registry\reg_futrmniclsfwnerxhwgcgfeijceanipw.reg
6.3s C:\AdwCleaner\AdwCleaner[C14].txt
8.8s C:\Windows\Prefetch\NVDISPLAY.CONTAINER.EXE-22606B81.pf
9.2s C:\Windows\Prefetch\SEARCHINDEXER.EXE-EF8503D3.pf
9.5s C:\Windows\Prefetch\NVTRAY.EXE-981FA625.pf
C:\AdwCleaner\Quarantine\files\wrwdaaymdpczwwrfkxcyibgztqjvzapg\WinSAP.dll
Size . . . . . . . : 184.832 bytes
Age . . . . . . . : 1.1 days (2017-03-08 17:21:03)
Entropy . . . . . : 6.5
SHA-256 . . . . . : 4B72FCDE3E3A010573A6C147E36643B373A04F33526EE85269BF9A87D2E7FD27
Product . . . . . : Windows
Publisher . . . . : Windows
Description . . . : Windows
Version . . . . . : 1.0.0.1
LanguageID . . . . : 2052
> Kaspersky . . . . : not-a-virus:AdWare.Win32.ELEX.ayq
Fuzzy . . . . . . : 102.0
Forensic Cluster
-6.5s C:\Windows\Logs\dosvc\dosvc.20170308_162056_747.etl
-4.3s C:\Users\Princhi\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\INetCache\XCISGIXW\config[2].json
-1.5s C:\Users\Princhi\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\INetCookies\KVB4XROC.cookie
-0.0s C:\AdwCleaner\Quarantine\files\wrwdaaymdpczwwrfkxcyibgztqjvzapg\
0.0s C:\AdwCleaner\Quarantine\files\wrwdaaymdpczwwrfkxcyibgztqjvzapg\WinSAP.dll
0.5s C:\AdwCleaner\Quarantine\files\sbtpmmeyfhlcljmaploiikjrxasukehh\
0.5s C:\AdwCleaner\Quarantine\files\sbtpmmeyfhlcljmaploiikjrxasukehh\WinSnare.dll
0.6s C:\AdwCleaner\Quarantine\files\kvntknoysjwadbfvaetksftxzlfstsvf\
0.6s C:\AdwCleaner\Quarantine\files\kvntknoysjwadbfvaetksftxzlfstsvf\BikaQ Rss Reader.lnk
0.8s C:\AdwCleaner\Quarantine\files\akuzirhgxdxlelxbjmqphntyfzulpmic\
0.8s C:\AdwCleaner\Quarantine\files\akuzirhgxdxlelxbjmqphntyfzulpmic\app.bikaQ.config
0.8s C:\AdwCleaner\Quarantine\files\akuzirhgxdxlelxbjmqphntyfzulpmic\BikaQ.exe
0.8s C:\AdwCleaner\Quarantine\files\akuzirhgxdxlelxbjmqphntyfzulpmic\BikaQ.exe.config
0.8s C:\AdwCleaner\Quarantine\files\akuzirhgxdxlelxbjmqphntyfzulpmic\bikaQ.ini
0.8s C:\AdwCleaner\Quarantine\files\akuzirhgxdxlelxbjmqphntyfzulpmic\Icon.ico
0.8s C:\AdwCleaner\Quarantine\files\akuzirhgxdxlelxbjmqphntyfzulpmic\Interop.Microsoft.Feeds.Interop.DLL
0.8s C:\AdwCleaner\Quarantine\files\akuzirhgxdxlelxbjmqphntyfzulpmic\MagicLibrary.DLL
0.9s C:\AdwCleaner\Quarantine\files\vtxrsqhnsuataosbmikmwsteelqzcthe\
0.9s C:\AdwCleaner\Quarantine\files\vtxrsqhnsuataosbmikmwsteelqzcthe\MIO.exe
0.9s C:\AdwCleaner\Quarantine\files\vtxrsqhnsuataosbmikmwsteelqzcthe\loader\
1.1s C:\AdwCleaner\Quarantine\registry\reg_smmkwrlvvozopzvdzwxwfgdcfyuzuctz.reg
1.2s C:\AdwCleaner\Quarantine\registry\reg_cyqrnadspdampzjxwsvpninnztlwpcnw.reg
1.3s C:\AdwCleaner\Quarantine\registry\reg_zawauksgbmhxigsgahrmucmiggunqzjh.reg
1.4s C:\AdwCleaner\Quarantine\registry\reg_upytrsgfbwvywfqotnrqiytfsjdfcebe.reg
1.4s C:\AdwCleaner\Quarantine\registry\reg_xrlqxamievdazksgawvigjkzldnlejmv.reg
1.5s C:\AdwCleaner\Quarantine\registry\reg_lqmpmwonzglkeefybkcjtoonlvpgduwj.reg
1.6s C:\AdwCleaner\Quarantine\registry\reg_restvjviqqlslaewxugnllszfwbykjos.reg
1.7s C:\AdwCleaner\Quarantine\registry\reg_tfkypnwxzkjdizjbbcgcjdoaxmhpdizo.reg
1.7s C:\AdwCleaner\Quarantine\registry\reg_kvbelnrowxpjiswvrelykalubbmpznfd.reg
1.9s C:\AdwCleaner\Quarantine\registry\reg_vhjuyqfoowswdggpdfgfitgzucjiouan.reg
2.0s C:\AdwCleaner\Quarantine\registry\reg_erjggulzgydcngpitagpmwmwtxriiiac.reg
2.0s C:\AdwCleaner\Quarantine\registry\reg_btidwxbxcvlzqfzlnwomhhjochwafrck.reg
2.3s C:\AdwCleaner\Quarantine\registry\reg_lwsjrtnvfcgklczkhnphylswulpdaavy.reg
3.5s C:\Windows\Prefetch\NETSH.EXE-59756CAC.pf
4.6s C:\AdwCleaner\AdwCleaner[C15].txt
C:\AdwCleaner\Quarantine\files\yndstoorrhchctuxregtacilqxspofor\bilibili.dll
Size . . . . . . . : 127.488 bytes
Age . . . . . . . : 2.2 days (2017-03-07 15:38:47)
Entropy . . . . . : 6.4
SHA-256 . . . . . : 3D824E968D4E6321D01A9342D5FDAD7911D50FA4419DC46464101C88BF21348E
> Bitdefender . . . : Application.Elex.DA
> Kaspersky . . . . : HEUR:Trojan.Win32.Generic
Fuzzy . . . . . . : 108.0
Forensic Cluster
0.0s C:\AdwCleaner\Quarantine\files\yndstoorrhchctuxregtacilqxspofor\
0.0s C:\AdwCleaner\Quarantine\files\yndstoorrhchctuxregtacilqxspofor\bilibili.dll
1.0s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\
1.0s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\
1.0s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\56.0.2924.87.manifest
1.0s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\chrome.dll
1.0s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\chrome.exe
1.0s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\chrome_100_percent.pak
1.0s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\chrome_200_percent.pak
1.0s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\chrome_child.dll
1.1s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\chrome_elf.dll
1.1s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\chrome_watcher.dll
1.1s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\d3dcompiler_47.dll
1.1s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\icudtl.dat
1.1s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\libegl.dll
1.2s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\libglesv2.dll
1.2s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\natives_blob.bin
1.2s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\resources.pak
1.3s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\bin\
1.3s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\snapshot_blob.bin
1.3s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\Dictionaries\
1.3s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\
1.3s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\am.pak
1.4s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\ar.pak
1.4s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\bg.pak
1.4s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\bn.pak
1.5s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\ca.pak
1.5s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\cs.pak
1.5s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\da.pak
1.5s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\de.pak
1.5s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\el.pak
1.6s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\en-GB.pak
1.6s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\en-US.pak
1.6s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\es-419.pak
1.6s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\es.pak
1.6s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\et.pak
1.6s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\fa.pak
1.6s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\fake-bidi.pak
1.7s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\fi.pak
1.7s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\fil.pak
1.7s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\fr.pak
1.7s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\gu.pak
1.8s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\he.pak
1.8s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\hi.pak
1.8s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\hr.pak
1.8s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\hu.pak
1.8s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\id.pak
1.8s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\it.pak
1.9s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\ja.pak
1.9s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\kn.pak
1.9s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\ko.pak
1.9s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\lt.pak
1.9s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\lv.pak
1.9s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\ml.pak
2.0s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\mr.pak
2.0s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\ms.pak
2.0s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\nb.pak
2.0s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\nl.pak
2.0s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\pl.pak
2.0s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\pt-BR.pak
2.1s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\pt-PT.pak
2.1s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\ro.pak
2.1s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\ru.pak
2.1s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\sk.pak
2.1s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\sl.pak
2.1s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\sr.pak
2.1s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\sv.pak
2.1s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\sw.pak
2.2s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\ta.pak
2.2s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\te.pak
2.2s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\th.pak
2.2s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\tr.pak
2.2s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\uk.pak
2.2s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\vi.pak
2.2s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\zh-CN.pak
2.3s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\locales\zh-TW.pak
2.3s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\VisualElements\
2.3s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\VisualElements\logo.png
2.3s C:\AdwCleaner\Quarantine\files\tzxbtblxjrdjgbszgypgesikywujzuno\Application\VisualElements\smalllogo.png
2.6s C:\AdwCleaner\Quarantine\files\lswypbpmgwsxdoiwqdpscgatuuxvkfij\
2.6s C:\AdwCleaner\Quarantine\files\lswypbpmgwsxdoiwqdpscgatuuxvkfij\app.bikaQ.config
2.6s C:\AdwCleaner\Quarantine\files\lswypbpmgwsxdoiwqdpscgatuuxvkfij\BikaQ.exe
2.6s C:\AdwCleaner\Quarantine\files\lswypbpmgwsxdoiwqdpscgatuuxvkfij\BikaQ.exe.config
2.6s C:\AdwCleaner\Quarantine\files\lswypbpmgwsxdoiwqdpscgatuuxvkfij\bikaQ.ini
2.6s C:\AdwCleaner\Quarantine\files\lswypbpmgwsxdoiwqdpscgatuuxvkfij\Icon.ico
2.6s C:\AdwCleaner\Quarantine\files\lswypbpmgwsxdoiwqdpscgatuuxvkfij\Interop.Microsoft.Feeds.Interop.DLL
2.6s C:\AdwCleaner\Quarantine\files\lswypbpmgwsxdoiwqdpscgatuuxvkfij\MagicLibrary.DLL
2.8s C:\AdwCleaner\Quarantine\files\xfskfehcyqrksuehxcpbkehpqrvudyza\QQLive\
2.8s C:\AdwCleaner\Quarantine\files\xfskfehcyqrksuehxcpbkehpqrvudyza\QQLive\FailRecord.dat
2.8s C:\AdwCleaner\Quarantine\files\xfskfehcyqrksuehxcpbkehpqrvudyza\
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\Accessible.tlb
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\AccessibleMarshal.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-core-console-l1-1-0.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-core-datetime-l1-1-0.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-core-debug-l1-1-0.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-core-errorhandling-l1-1-0.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-core-file-l1-1-0.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-core-file-l1-2-0.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-core-file-l2-1-0.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-core-handle-l1-1-0.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-core-heap-l1-1-0.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-core-interlocked-l1-1-0.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-core-libraryloader-l1-1-0.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-core-localization-l1-2-0.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-core-memory-l1-1-0.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-core-namedpipe-l1-1-0.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-core-processenvironment-l1-1-0.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-core-processthreads-l1-1-0.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-core-processthreads-l1-1-1.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-core-profile-l1-1-0.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-core-rtlsupport-l1-1-0.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-core-string-l1-1-0.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-core-synch-l1-1-0.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-core-synch-l1-2-0.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-core-sysinfo-l1-1-0.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-core-timezone-l1-1-0.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-core-util-l1-1-0.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-crt-conio-l1-1-0.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-crt-convert-l1-1-0.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-crt-environment-l1-1-0.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-crt-filesystem-l1-1-0.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-crt-heap-l1-1-0.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-crt-locale-l1-1-0.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-crt-math-l1-1-0.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-crt-multibyte-l1-1-0.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-crt-private-l1-1-0.dll
3.1s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-crt-process-l1-1-0.dll
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-crt-runtime-l1-1-0.dll
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-crt-stdio-l1-1-0.dll
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-crt-string-l1-1-0.dll
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-crt-time-l1-1-0.dll
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\api-ms-win-crt-utility-l1-1-0.dll
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\application.ini
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\breakpadinjector.dll
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\crashreporter.exe
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\crashreporter.ini
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\d3dcompiler_47.dll
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\dependentlibs.list
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\fbox.bin
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\Firefox.exe
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\firefox.VisualElementsManifest.xml
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\freebl3.chk
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\freebl3.dll
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\IA2Marshal.dll
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\lgpllibs.dll
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\libEGL.dll
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\libGLESv2.dll
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\maintenanceservice.exe
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\maintenanceservice_installer.exe
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\mozavcodec.dll
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\mozavutil.dll
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\mozglue.dll
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\msvcp140.dll
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\nss3.dll
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\nssckbi.dll
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\nssdbm3.chk
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\nssdbm3.dll
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\omni.ja
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\platform.ini
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\plugin-container.exe
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\plugin-hang-ui.exe
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\precomplete
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\removed-files
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\softokn3.chk
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\softokn3.dll
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\ucrtbase.dll
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\update-settings.ini
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\updater.exe
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\updater.ini
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\vcruntime140.dll
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\wow_helper.exe
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\xul.dll
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\bin\
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\bin\FirefoxUpdate.exe
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\browser\
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\browser\blocklist.xml
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\browser\chrome.manifest
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\browser\crashreporter-override.ini
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\browser\features\
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\browser\features\aushelper@mozilla.org.xpi
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\browser\features\e10srollout@mozilla.org.xpi
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\browser\features\firefox@getpocket.com.xpi
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\browser\components\
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\browser\components\browsercomps.dll
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\browser\components\components.manifest
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\browser\extensions\
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi
3.2s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\browser\omni.ja
3.3s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\dictionaries\
3.3s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\dictionaries\en-US.aff
3.3s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\dictionaries\en-US.dic
3.3s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\gmp-clearkey\
3.3s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\browser\features\webcompat@mozilla.org.xpi
3.3s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\gmp-clearkey\0.1\
3.3s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\gmp-clearkey\0.1\clearkey.dll
3.3s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\browser\VisualElements\
3.3s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\browser\VisualElements\VisualElements_150.png
3.3s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\browser\VisualElements\VisualElements_70.png
3.3s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\defaults\
3.3s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\defaults\pref\
3.3s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\defaults\pref\channel-prefs.js
3.3s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\fonts\
3.3s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\fonts\EmojiOneMozilla.ttf
3.3s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\gmp-clearkey\0.1\clearkey.info
3.3s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\uninstall\
3.3s C:\AdwCleaner\Quarantine\files\jszcaitoivtgaurygoptwgcedtxdugbn\uninstall\helper.exe
3.6s C:\AdwCleaner\Quarantine\files\nahubpcvvyunhzvzfmxwtvpwgppzfxdh\
3.6s C:\AdwCleaner\Quarantine\files\nahubpcvvyunhzvzfmxwtvpwgppzfxdh\MIO.exe
3.6s C:\AdwCleaner\Quarantine\files\nahubpcvvyunhzvzfmxwtvpwgppzfxdh\loader\
3.7s C:\AdwCleaner\Quarantine\files\tdaknrqgqrahpmezbgivdrncyiumnoth\
3.7s C:\AdwCleaner\Quarantine\files\tdaknrqgqrahpmezbgivdrncyiumnoth\02cd3cf9-5c3f-43c3-b8aa-965763845b5d.dmp
3.7s C:\AdwCleaner\Quarantine\files\tdaknrqgqrahpmezbgivdrncyiumnoth\2c494a67-5c7d-4f2a-925f-9ad160d98630.dmp
3.8s C:\AdwCleaner\Quarantine\files\tdaknrqgqrahpmezbgivdrncyiumnoth\82955d19-484e-4e13-8464-a7a496738cb9.dmp
3.8s C:\AdwCleaner\Quarantine\files\tdaknrqgqrahpmezbgivdrncyiumnoth\d6e97161-cdae-4025-b8c9-c4458dd85575.dmp
3.8s C:\AdwCleaner\Quarantine\files\tdaknrqgqrahpmezbgivdrncyiumnoth\d9aec98a-f3b3-411d-9cb0-3f79a9036978.dmp
3.8s C:\AdwCleaner\Quarantine\files\tdaknrqgqrahpmezbgivdrncyiumnoth\e3aa4d95-d343-4ffb-943c-60f5f7fb2898.dmp
4.1s C:\AdwCleaner\Quarantine\files\cqhtidxzllzhzglnsmbhytdwfszjprwo\
4.1s C:\AdwCleaner\Quarantine\files\cqhtidxzllzhzglnsmbhytdwfszjprwo\dmr_72.exe
4.1s C:\AdwCleaner\Quarantine\files\cqhtidxzllzhzglnsmbhytdwfszjprwo\Downloads\
4.1s C:\AdwCleaner\Quarantine\files\cqhtidxzllzhzglnsmbhytdwfszjprwo\yshaazdgpgiwmfnu.dat
4.1s C:\AdwCleaner\Quarantine\files\cqhtidxzllzhzglnsmbhytdwfszjprwo\Downloads\152e221a8bef8d2d13c58f995563a1a1\46bd7ff30e89de35f5e2857fdb1690df\
4.1s C:\AdwCleaner\Quarantine\files\cqhtidxzllzhzglnsmbhytdwfszjprwo\Downloads\152e221a8bef8d2d13c58f995563a1a1\46bd7ff30e89de35f5e2857fdb1690df\MouseRecorderSetup-1.0.51.exe
4.1s C:\AdwCleaner\Quarantine\files\cqhtidxzllzhzglnsmbhytdwfszjprwo\Downloads\152e221a8bef8d2d13c58f995563a1a1\
5.0s C:\AdwCleaner\Quarantine\files\bqtkcoqjmmyoveeazexqcpixbsxncdep.back
5.0s C:\AdwCleaner\Quarantine\files\kfoqpzrqppjnjswpxlwldkbpuhqgltlx.back
5.1s C:\AdwCleaner\Quarantine\files\jzpvhfoftmvoxokhwnomaqxputvbtbkj.back
5.1s C:\AdwCleaner\Quarantine\files\goidlqcvcplemngijzjttmsqwwbomfqi.back
5.1s C:\AdwCleaner\Quarantine\files\cdusxwyrqhrqkeibpscrigqemefmsvve.back
5.2s C:\AdwCleaner\Quarantine\files\vqlfkyfafcswsudvbsghitwrgmtofuzv.back
5.2s C:\AdwCleaner\Quarantine\files\nupvhvykdtwskqcspqvbuexpzcpwpsoi.back
5.7s C:\AdwCleaner\Quarantine\registry\reg_ubffxbbsyllmmjxdsqhczffagorydftr.reg
5.9s C:\AdwCleaner\Quarantine\registry\reg_mzqrolgepzsigiwfrqvtqwlbpsydcomn.reg
6.0s C:\AdwCleaner\Quarantine\registry\reg_ythltcjcavsrrrpvzcvslfalrpcztmtu.reg
6.1s C:\AdwCleaner\Quarantine\registry\reg_ckxdvbtnkcnyoptgrjzhaayrjiibpcnw.reg
6.4s C:\AdwCleaner\Quarantine\registry\reg_voanubvtarivcifrewiyxzvalgvlqskx.reg
6.5s C:\AdwCleaner\Quarantine\registry\reg_jswyvwvsaauzrtdjthmalnfpjovhyuhg.reg
6.6s C:\AdwCleaner\Quarantine\registry\reg_vtoflvprzbvpfqytsgxcmjkreubgpeft.reg
6.7s C:\AdwCleaner\Quarantine\registry\reg_wfclgwtbttktcezcgmyuoofpzvbdscfm.reg
7.0s C:\AdwCleaner\Quarantine\registry\reg_ikmhacfulopmqcqqtbdzwwbymezuybgz.reg
7.1s C:\AdwCleaner\Quarantine\registry\reg_alrecaglepdawrmrtipucrbyemuaolne.reg
7.4s C:\AdwCleaner\Quarantine\registry\reg_xqguqzyxanybsuvatuhkfjbvazwcuyzz.reg
7.5s C:\AdwCleaner\Quarantine\registry\reg_zppktzhudqgtzkdgremwgosltiwcnteh.reg
7.7s C:\AdwCleaner\Quarantine\registry\reg_yetnslvkwivnpteopbyepzlkuxnfvrsv.reg
7.8s C:\AdwCleaner\Quarantine\registry\reg_mmmdbilpabnzkhpytxfopjrcvsucseee.reg
7.8s C:\AdwCleaner\Quarantine\registry\reg_brkkxgugjcekhozyhdtijdttmslabcze.reg
7.8s C:\AdwCleaner\Quarantine\registry\reg_rmdwamkotbhzikfawjyfyosfcazzbumx.reg
8.0s C:\AdwCleaner\Quarantine\registry\reg_qjizhysipxdrbntxfibthqibamrpeauh.reg
8.0s C:\AdwCleaner\Quarantine\registry\reg_yksyuaanorsfynzgtkmqzhsqrurqcsfa.reg
8.0s C:\AdwCleaner\Quarantine\registry\reg_aioholtlmudhxpcvhemzrgpojnfsgpba.reg
8.1s C:\AdwCleaner\Quarantine\registry\reg_hghlefktkkszguoknumljdbrmqplcaqa.reg
8.4s C:\AdwCleaner\Quarantine\registry\reg_tezzufvzmkldhrkwabwztsaqgslcbnyy.reg
8.5s C:\AdwCleaner\Quarantine\registry\reg_pqwxjaejtxttsagxwojrdzwlispfrjsy.reg
8.5s C:\AdwCleaner\Quarantine\registry\reg_gecgspeiltsuryvisqxjrxpxkosmsmrz.reg
8.6s C:\AdwCleaner\Quarantine\registry\reg_vppwmtanybecllmqdyskzabwzyoiweaa.reg
8.6s C:\AdwCleaner\Quarantine\registry\reg_cnnanzilvckgvinejultajyexhwrmzaw.reg
8.6s C:\AdwCleaner\Quarantine\registry\reg_ikhoubhqhlvblliiojthocomncdxqmxm.reg
8.6s C:\AdwCleaner\Quarantine\registry\reg_rdrqsgfooomxghksosehepoinarrqazu.reg
8.7s C:\AdwCleaner\Quarantine\registry\reg_gawywypzzjwjhckrdayrhrnlhzheqjpv.reg
8.8s C:\AdwCleaner\Quarantine\registry\reg_epliqhyfghjzlozcqhjzflbwctfbhxtx.reg
8.8s C:\AdwCleaner\Quarantine\registry\reg_fvtvtqwzttnbgwchfnbisrpjwwpadoqk.reg
8.8s C:\AdwCleaner\Quarantine\registry\reg_xqmhigbdzecocijstplywsubbkanqvut.reg
8.9s C:\AdwCleaner\Quarantine\registry\reg_uuwbyrqdnozqawylwojhamhsraysmssi.reg
8.9s C:\AdwCleaner\Quarantine\registry\reg_kfkbzacbqxtndjqwxvpwofzzmuyclltq.reg
9.1s C:\AdwCleaner\Quarantine\registry\reg_pbtjnsmezaqefphqybaqpjwhtcaotpxb.reg
9.1s C:\AdwCleaner\Quarantine\registry\reg_wgifjkkvqfxmxyporqfrtutssnxasaez.reg
9.1s C:\AdwCleaner\Quarantine\registry\reg_zykvojxtbwwczctmirpydmaopgjdnhad.reg
C:\ProgramData\Apple Computer\Installer Cache\setup.dll
Size . . . . . . . : 384.000 bytes
Age . . . . . . . : 23.2 days (2017-02-14 14:06:29)
Entropy . . . . . : 6.3
SHA-256 . . . . . : BD6E5908E8BB639D05C4CC0C40AE118195BFA47C695BB4C0B16C7A92D13B24F3
> Bitdefender . . . : Gen:Variant.Adware.Zusy.219711
> HitmanPro . . . . : App/Generic-LA
Fuzzy . . . . . . : 98.0
Forensic Cluster
0.0s C:\ProgramData\Apple Computer\Installer Cache\setup.dll
0.1s C:\ProgramData\Apple Computer\
0.1s C:\ProgramData\Apple Computer\Installer Cache\
C:\ProgramData\bfibe\regkey.exe
Size . . . . . . . : 102.912 bytes
Age . . . . . . . : 98.2 days (2016-12-01 14:32:30)
Entropy . . . . . : 6.2
SHA-256 . . . . . : FFF2818CAA9040486A634896F329B8AEBAEC9121BDF9982841F0646763A1686B
> Bitdefender . . . : Gen:Variant.Mikey.57768
> Kaspersky . . . . : not-a-virus:AdWare.Win32.ELEX.and
> HitmanPro . . . . : App/Generic-DA
Fuzzy . . . . . . : 98.0
C:\ProgramData\bfibe\yacqq.exe
Size . . . . . . . : 262.144 bytes
Age . . . . . . . : 98.2 days (2016-12-01 14:32:30)
Entropy . . . . . : 5.9
SHA-256 . . . . . : 98AA2A5E01E594F5D71A564EFDAB45967E3A68E313B8E4768EBE344C3EA4F7AF
> Bitdefender . . . : Adware.GenericKD.3799140
> Kaspersky . . . . : not-a-virus:Downloader.Win32.AdLoad.xtzr
Fuzzy . . . . . . : 98.0
Suspicious files ____________________________________________________________
C:\Users\Princhi\Desktop\FRST-OlderVersion\FRST64.exe
Size . . . . . . . : 2.423.808 bytes
Age . . . . . . . : 1.1 days (2017-03-08 17:24:45)
Entropy . . . . . : 7.6
SHA-256 . . . . . : D3F6B73F9517C1058A870B3411AF3A7DDA50A94B76ED0A29D0EF7E55601BCA04
Needs elevation . : Yes
Fuzzy . . . . . . : 24.0
Program has no publisher information but prompts the user for permission elevation.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Time indicates that the file appeared recently on this computer.
C:\Users\Princhi\Desktop\FRST64.exe
Size . . . . . . . : 2.423.808 bytes
Age . . . . . . . : 0.9 days (2017-03-08 21:30:32)
Entropy . . . . . : 7.6
SHA-256 . . . . . : 0C11A0E7E1D7950EAAB54F640609BD62DC8E7F6CCBDD4520ACD6E0A67C252262
Needs elevation . : Yes
Fuzzy . . . . . . : 24.0
Program has no publisher information but prompts the user for permission elevation.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Time indicates that the file appeared recently on this computer.
Forensic Cluster
-0.5s C:\Users\Princhi\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6AF4EE75E3A4ABA658C0087EB9A0BB5B_556BB0FF4D382D90E7703209690E089E
-0.5s C:\Users\Princhi\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6AF4EE75E3A4ABA658C0087EB9A0BB5B_556BB0FF4D382D90E7703209690E089E
0.0s C:\Users\Princhi\Desktop\FRST64.exe
C:\WINDOWS\SysWoW64\GameMon.des
Size . . . . . . . : 3.519.984 bytes
Age . . . . . . . : 368.2 days (2016-03-06 14:46:52)
Entropy . . . . . : 8.0
SHA-256 . . . . . : 7155805F2DE29FBD04950FB08AA75A5C49AAEC3C6AEF645837823D292B8C338D
Product . . . . . : nProtect Game Monitor
Publisher . . . . : INCA Internet Co., Ltd.
Description . . . : nProtect Game Monitor Rev 2376
Version . . . . . : 2016.1.25.1
RSA Key Size . . . : 2048
Service . . . . . : npggsvc
LanguageID . . . . : 1042
Authenticode . . . : Valid
Fuzzy . . . . . . : 25.0
The file name extension of this program is not common.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
The file is located in a folder that contains core operating system files from Windows. This is not typical for most programs and is only common to system tools, drivers and hacking utilities.
Starts automatically as a service during system bootup.
Program is code signed with a valid Authenticode certificate.
Startup
HKLM\SYSTEM\CurrentControlSet\Services\npggsvc\
Potential Unwanted Programs _________________________________________________
HKLM\SOFTWARE\Classes\Interface\{D8CB24E3-DDA3-4B7F-8BA3-871DB7D3D986}\ (YoutubeAdBlock)
HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}\ (CouponBar)
HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\ActiveX Compatibility\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}\ (CouponBar)
HKU\S-1-5-21-88799701-2343346839-193955109-1001\SOFTWARE\IM\ (Sweetpacks)
|