Malwarebytes Anti-Malware
http://www.malwarebytes.org
Scan Date: 17/07/2014
Scan Time: 13:34:44
Logfile:
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.07.17.05
Rootkit Database: v2014.07.14.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Benoit et Sylvie
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 319752
Time Elapsed: 11 min, 4 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 33
Adware.ClickPotato, HKLM\SOFTWARE\CLASSES\APPID\{0D82ACD6-A652-4496-A298-2BDE705F4227}, Quarantined, [a3f6138d4833f64049db84edde2435cb],
Adware.ClickPotato, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{0D82ACD6-A652-4496-A298-2BDE705F4227}, Quarantined, [a3f6138d4833f64049db84edde2435cb],
Adware.ClickPotato, HKLM\SOFTWARE\CLASSES\APPID\{7025E484-D4B0-441a-9F0B-69063BD679CE}, Quarantined, [4f4a049cc2b991a59790ef82e51ddc24],
Adware.ClickPotato, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{7025E484-D4B0-441A-9F0B-69063BD679CE}, Quarantined, [4f4a049cc2b991a59790ef82e51ddc24],
Adware.ClickPotato, HKLM\SOFTWARE\CLASSES\APPID\{8258B35C-05B8-4c0e-9525-9BCCC70F8F2D}, Quarantined, [9306c7d9671457dff03a72ff2bd7e51b],
Adware.ClickPotato, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{8258B35C-05B8-4C0E-9525-9BCCC70F8F2D}, Quarantined, [9306c7d9671457dff03a72ff2bd7e51b],
Adware.ClickPotato, HKLM\SOFTWARE\CLASSES\APPID\{A89256AD-EC17-4a83-BEF5-4B8BC4F39306}, Quarantined, [d8c1643c0b709d992704a9c817eb41bf],
Adware.ClickPotato, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{A89256AD-EC17-4A83-BEF5-4B8BC4F39306}, Quarantined, [d8c1643c0b709d992704a9c817eb41bf],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{68B81CCD-A80C-4060-8947-5AE69ED01199}, Quarantined, [bcddb9e7d4a7b680ce6fd0be8a786a96],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E6B969FB-6D33-48d2-9061-8BBD4899EB08}, Quarantined, [3366386880fbe94def4f0985b84aae52],
PUP.Optional.SweetPacks, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{EEE6C35C-6118-11DC-9C72-001320C79847}, Quarantined, [6c2d6040a6d58da9cd93d487808213ed],
Adware.Hotbar, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{89F88394-3828-4d03-A0CF-8203604C3DA6}, Quarantined, [5b3eecb4c9b2a195c2715a18a45e9070],
Adware.Hotbar, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{D4233F04-1789-483c-A137-731E8F113DD5}, Quarantined, [7722514f8eed76c07ecac1b1d32f45bb],
Adware.ShopperReports, HKLM\SOFTWARE\CLASSES\ShopperReports.IEButtonA, Quarantined, [2e6b4759bdbec175facb470a9f64f709],
Adware.ShopperReports, HKLM\SOFTWARE\CLASSES\ShopperReports.TriggerImmidiate, Quarantined, [3c5dd9c70b707cbaeadbe36e24df14ec],
Adware.ShopperReports, HKLM\SOFTWARE\CLASSES\ShopperReports.TriggerImmidiate.1, Quarantined, [aeeb0799760581b50db83c150cf78f71],
Adware.ShopperReports, HKLM\SOFTWARE\CLASSES\ShopperReports.TriggerImmidiateOrRandomTS, Quarantined, [51485947453645f1c0057cd560a338c8],
Adware.ShopperReports, HKLM\SOFTWARE\CLASSES\ShopperReports.TriggerImmidiateOrRandomTS.1, Quarantined, [5f3aefb199e276c0cafbc9886d9610f0],
Adware.ClickPotato, HKLM\SOFTWARE\CLASSES\APPID\BRNstIE.DLL, Quarantined, [1c7d0c94e794fe38964687c7a75c60a0],
Adware.ClickPotato, HKLM\SOFTWARE\CLASSES\APPID\CmndFF.DLL, Quarantined, [cccd5848a7d4e35317cb0945a1629d63],
Adware.ClickPotato, HKLM\SOFTWARE\CLASSES\APPID\mozillaps.dll, Quarantined, [6a2f237d4a31c4729a8e5bf4a55ed927],
Adware.ClickPotato, HKLM\SOFTWARE\CLASSES\APPID\Pltfrm.DLL, Quarantined, [05948b15146777bf84b5034ca26118e8],
Adware.ShopperReports, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ShopperReports.IEButtonA, Quarantined, [5f3a4c542358a492a91cda7729dab848],
Adware.ShopperReports, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ShopperReports.TriggerImmidiate, Quarantined, [f2a7762accaf9a9c1da8361b8a7955ab],
Adware.ShopperReports, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ShopperReports.TriggerImmidiate.1, Quarantined, [d9c0ffa1abd01e187c495af756ad58a8],
Adware.ShopperReports, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ShopperReports.TriggerImmidiateOrRandomTS, Quarantined, [b4e5b3edd8a3eb4bf4d1c58cdd26827e],
Adware.ShopperReports, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ShopperReports.TriggerImmidiateOrRandomTS.1, Quarantined, [0f8a029ecbb07cba1da8ee633ec535cb],
Adware.ClickPotato, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\BRNstIE.DLL, Quarantined, [6930524ed6a543f30cd0ee60937014ec],
Adware.ClickPotato, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\CmndFF.DLL, Quarantined, [cfca4c5452298ea8984a56f87192f40c],
Adware.ClickPotato, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\mozillaps.dll, Quarantined, [debb10907dfe54e281a751fe6d96cb35],
Adware.ClickPotato, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\Pltfrm.DLL, Quarantined, [7b1e643cd8a34fe7a89177d8778c0bf5],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2598197632-106402267-1668521451-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, Quarantined, [2a6f9f010f6cda5c5e2ed937ee16b848],
PUP.Optional.Pricora.A, HKU\S-1-5-21-2598197632-106402267-1668521451-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Pricora 1.1, Quarantined, [51485b457407f14525060cd5c33fcd33],
Registry Values: 4
PUP.Optional.CertifiedToolBar.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHURI|(Default),
http://search.certified-toolbar.com?si= ... tid=77q=%s, Quarantined, [1b7e910f2d4e48eef779ba0a976bed13]
PUP.Optional.CertifiedToolBar.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|(Default),
http://search.certified-toolbar.com?si= ... tid=77q=%s, Quarantined, [b8e1d5cbf98243f399d8d6eeff037e82]
Adware.HotBar, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\5.0\USER AGENT\POST PLATFORM|ShopperReports 3.0.489.0, Quarantined, [ebae6b35bac10531fa20c0acfe057e82],
Malware.Trace, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\5.0\USER AGENT\POST PLATFORM|SRS_IT_E879027EBC765E5A35A993, Quarantined, [1485940cf2891d19a17ba1cbdd2618e8],
Registry Data: 2
PUP.Optional.SearchCertifiedTB.A, HKU\S-1-5-21-2598197632-106402267-1668521451-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURI|(Default),
http://search.certified-toolbar.com?si= ... tid=77q=%s, Good: (
http://www.google.com), Bad: (
http://search.certified-toolbar.com?si= ... tid=77q=%s),Replaced,[afea3967d8a3fc3a2a233a6b2fd5c13f]
PUP.Optional.SearchCertifiedTB.A, HKU\S-1-5-21-2598197632-106402267-1668521451-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|(Default),
http://search.certified-toolbar.com?si= ... tid=77q=%s, Good: (
http://www.google.com/), Bad: (
http://search.certified-toolbar.com?si= ... tid=77q=%s),Replaced,[ebae2f714d2e45f12c223570cc387987]
Folders: 8
Adware.QuestDns, C:\Program Files (x86)\Mozilla Firefox\extensions\{C91E1C68-B60A-4C9F-B53B-AAAEF0E7EF97}, Quarantined, [6a2f7f217ffc003676a8ecaabf43857b],
Adware.QuestDns, C:\Program Files (x86)\Mozilla Firefox\extensions\{C91E1C68-B60A-4C9F-B53B-AAAEF0E7EF97}\chrome, Quarantined, [6a2f7f217ffc003676a8ecaabf43857b],
Adware.QuestDns, C:\Program Files (x86)\Mozilla Firefox\extensions\{C91E1C68-B60A-4C9F-B53B-AAAEF0E7EF97}\defaults, Quarantined, [6a2f7f217ffc003676a8ecaabf43857b],
Adware.QuestDns, C:\Program Files (x86)\Mozilla Firefox\extensions\{C91E1C68-B60A-4C9F-B53B-AAAEF0E7EF97}\defaults\preferences, Quarantined, [6a2f7f217ffc003676a8ecaabf43857b],
Adware.QuestBrowse, C:\Program Files (x86)\Mozilla Firefox\extensions\{D9ADB0A8-7BFB-498D-9880-EE78A81CCFA0}, Quarantined, [7524e5bb423930069ba07925db275ea2],
Adware.QuestBrowse, C:\Program Files (x86)\Mozilla Firefox\extensions\{D9ADB0A8-7BFB-498D-9880-EE78A81CCFA0}\chrome, Quarantined, [7524e5bb423930069ba07925db275ea2],
Adware.QuestBrowse, C:\Program Files (x86)\Mozilla Firefox\extensions\{D9ADB0A8-7BFB-498D-9880-EE78A81CCFA0}\defaults, Quarantined, [7524e5bb423930069ba07925db275ea2],
Adware.QuestBrowse, C:\Program Files (x86)\Mozilla Firefox\extensions\{D9ADB0A8-7BFB-498D-9880-EE78A81CCFA0}\defaults\preferences, Quarantined, [7524e5bb423930069ba07925db275ea2],
Files: 36
PUP.Optional.PriceMeter.A, C:\Windows\System32\Tasks\pricemeterdownloader, Quarantined, [f8a159470e6db185719edae590727888],
PUP.Optional.PriceMeter.A, C:\Windows\System32\Tasks\pricemetertask, Quarantined, [21785f410972a78fba61467d8c76da26],
PUP.Optional.PriceMeter.A, C:\Windows\System32\Tasks\pricemeterwatcher, Quarantined, [2673d4ccdba0b87e3ce08a390df53ac6],
PUP.Optional.Bubbledock.A, C:\Users\Benoit et Sylvie\AppData\Roaming\Bubble Dock.boostrap.log, Quarantined, [ecadd2ce22596bcb9ef0c223a65c6997],
Adware.QuestDns, C:\Program Files (x86)\Mozilla Firefox\extensions\{C91E1C68-B60A-4C9F-B53B-AAAEF0E7EF97}\chrome.manifest, Quarantined, [6a2f7f217ffc003676a8ecaabf43857b],
Adware.QuestDns, C:\Program Files (x86)\Mozilla Firefox\extensions\{C91E1C68-B60A-4C9F-B53B-AAAEF0E7EF97}\install.rdf, Quarantined, [6a2f7f217ffc003676a8ecaabf43857b],
Adware.QuestDns, C:\Program Files (x86)\Mozilla Firefox\extensions\{C91E1C68-B60A-4C9F-B53B-AAAEF0E7EF97}\chrome\questdns.jar, Quarantined, [6a2f7f217ffc003676a8ecaabf43857b],
Adware.QuestDns, C:\Program Files (x86)\Mozilla Firefox\extensions\{C91E1C68-B60A-4C9F-B53B-AAAEF0E7EF97}\defaults\preferences\prefs.js, Quarantined, [6a2f7f217ffc003676a8ecaabf43857b],
Adware.QuestBrowse, C:\Program Files (x86)\Mozilla Firefox\extensions\{D9ADB0A8-7BFB-498D-9880-EE78A81CCFA0}\chrome.manifest, Quarantined, [7524e5bb423930069ba07925db275ea2],
Adware.QuestBrowse, C:\Program Files (x86)\Mozilla Firefox\extensions\{D9ADB0A8-7BFB-498D-9880-EE78A81CCFA0}\install.rdf, Quarantined, [7524e5bb423930069ba07925db275ea2],
Adware.QuestBrowse, C:\Program Files (x86)\Mozilla Firefox\extensions\{D9ADB0A8-7BFB-498D-9880-EE78A81CCFA0}\defaults\preferences\prefs.js, Quarantined, [7524e5bb423930069ba07925db275ea2],
PUP.Optional.CertifiedTB.A, C:\Users\Benoit et Sylvie\AppData\Local\Google\Chrome\User Data\Default\Preferences, Good: (), Bad: ( "homepage" : "
http://search.certified-toolbar.com?si= ... truetid=77",), Replaced,[79201888bbc0d75ff96d01d3f50fbc44]
PUP.Optional.CrossRider.A, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.crossrider.bic", "1463d364b897ca6242a69cc42c471f95"), Replaced,[66339a069ae1e94d4194755e5ba9af51]
PUP.Optional.Babylon.A, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.BabylonToolbar_i.newTab", true), Replaced,[73267e22d5a6a492faebeae95fa5ea16]
PUP.Optional.Babylon.A, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.BabylonToolbar_i.newTabUrl", "
http://search.babylon.com/?affID=17425t ... src=NT_def"), Replaced,[6c2d2d731f5c1c1a14d111c2d72dcf31]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.admin", false), Replaced,[debb6e327dfe231319ced3019074857b]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.aflt", "babsst"), Replaced,[4c4d257b94e786b03fa8f2e26b9918e8]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.appId", "{37EB75F2-7392-4DBE-B5AD-147EC6D7BF5F}"), Replaced,[9108118f7cff80b644a3f5df49bbbe42]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.autoRvrt", "false"), Replaced,[cecb534d314ab0868364795bd13306fa]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.dfltLng", "fr"), Replaced,[1485bce4205b87af40a7379d56ae52ae]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.excTlbr", false), Replaced,[cacf0b95dba082b4a3444a8aa55f48b8]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.ffxUnstlRst", true), Replaced,[a6f3bae6b4c75ed811d6cc08fa0a9d63]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.id", "e2d62e3000000000000078e4004c2f43"), Replaced,[980119873348e74f22c57e564db72ed2]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.instlDay", "16217"), Replaced,[cfca2f714635d75f7e69f6de7a8a6e92]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.instlRef", "sst"), Replaced,[0c8d227e4932d462f9ee389caa5a49b7]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.newTab", false), Replaced,[d4c58020106b8fa75f88567e768e44bc]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.prdct", "buenosearch"), Replaced,[6c2d99070e6dfd39a4437a5aaa5af907]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.prtnrId", "buenosearch"), Replaced,[e1b8158b334890a6e205548019eb26da]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.rvrt", "false"), Replaced,[afea1a86d1aa66d0dd0aece8ca3a946c]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.smplGrp", "none"), Replaced,[5d3c326ec1ba2d098c5b2ca8f70d758b]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.tb_url", "
http://www.buenosearch.com/?q={searchTe ... 54tsp=5260"), Replaced,[6237643cd1aabe78687f468e956f18e8]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.tlbrId", "base"), Replaced,[5049237dd1aab680f3f40ec6768ea35d]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.tlbrSrchUrl", "
http://www.buenosearch.com/?q={searchTe ... 54tsp=5260"), Replaced,[f9a0f2ae89f266d06e7933a117ed54ac]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.vrsn", "1.8.28.7"), Replaced,[e3b6f3ad1665c07661861bb941c3e11f]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.vrsnTs", "1.8.28.76:50:00"), Replaced,[a8f1e6ba6714fb3b03e429abbd478e72]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.vrsni", "1.8.28.7"), Replaced,[19806a36f982f640895e884ca65e718f]
Physical Sectors: 0
(No malicious items detected)
(end)
Malwarebytes Anti-Malware
http://www.malwarebytes.org
Scan Date: 17/07/2014
Scan Time: 13:34:44
Logfile:
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.07.17.05
Rootkit Database: v2014.07.14.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Benoit et Sylvie
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 319752
Time Elapsed: 11 min, 4 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 33
Adware.ClickPotato, HKLM\SOFTWARE\CLASSES\APPID\{0D82ACD6-A652-4496-A298-2BDE705F4227}, Quarantined, [a3f6138d4833f64049db84edde2435cb],
Adware.ClickPotato, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{0D82ACD6-A652-4496-A298-2BDE705F4227}, Quarantined, [a3f6138d4833f64049db84edde2435cb],
Adware.ClickPotato, HKLM\SOFTWARE\CLASSES\APPID\{7025E484-D4B0-441a-9F0B-69063BD679CE}, Quarantined, [4f4a049cc2b991a59790ef82e51ddc24],
Adware.ClickPotato, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{7025E484-D4B0-441A-9F0B-69063BD679CE}, Quarantined, [4f4a049cc2b991a59790ef82e51ddc24],
Adware.ClickPotato, HKLM\SOFTWARE\CLASSES\APPID\{8258B35C-05B8-4c0e-9525-9BCCC70F8F2D}, Quarantined, [9306c7d9671457dff03a72ff2bd7e51b],
Adware.ClickPotato, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{8258B35C-05B8-4C0E-9525-9BCCC70F8F2D}, Quarantined, [9306c7d9671457dff03a72ff2bd7e51b],
Adware.ClickPotato, HKLM\SOFTWARE\CLASSES\APPID\{A89256AD-EC17-4a83-BEF5-4B8BC4F39306}, Quarantined, [d8c1643c0b709d992704a9c817eb41bf],
Adware.ClickPotato, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{A89256AD-EC17-4A83-BEF5-4B8BC4F39306}, Quarantined, [d8c1643c0b709d992704a9c817eb41bf],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{68B81CCD-A80C-4060-8947-5AE69ED01199}, Quarantined, [bcddb9e7d4a7b680ce6fd0be8a786a96],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E6B969FB-6D33-48d2-9061-8BBD4899EB08}, Quarantined, [3366386880fbe94def4f0985b84aae52],
PUP.Optional.SweetPacks, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{EEE6C35C-6118-11DC-9C72-001320C79847}, Quarantined, [6c2d6040a6d58da9cd93d487808213ed],
Adware.Hotbar, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{89F88394-3828-4d03-A0CF-8203604C3DA6}, Quarantined, [5b3eecb4c9b2a195c2715a18a45e9070],
Adware.Hotbar, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{D4233F04-1789-483c-A137-731E8F113DD5}, Quarantined, [7722514f8eed76c07ecac1b1d32f45bb],
Adware.ShopperReports, HKLM\SOFTWARE\CLASSES\ShopperReports.IEButtonA, Quarantined, [2e6b4759bdbec175facb470a9f64f709],
Adware.ShopperReports, HKLM\SOFTWARE\CLASSES\ShopperReports.TriggerImmidiate, Quarantined, [3c5dd9c70b707cbaeadbe36e24df14ec],
Adware.ShopperReports, HKLM\SOFTWARE\CLASSES\ShopperReports.TriggerImmidiate.1, Quarantined, [aeeb0799760581b50db83c150cf78f71],
Adware.ShopperReports, HKLM\SOFTWARE\CLASSES\ShopperReports.TriggerImmidiateOrRandomTS, Quarantined, [51485947453645f1c0057cd560a338c8],
Adware.ShopperReports, HKLM\SOFTWARE\CLASSES\ShopperReports.TriggerImmidiateOrRandomTS.1, Quarantined, [5f3aefb199e276c0cafbc9886d9610f0],
Adware.ClickPotato, HKLM\SOFTWARE\CLASSES\APPID\BRNstIE.DLL, Quarantined, [1c7d0c94e794fe38964687c7a75c60a0],
Adware.ClickPotato, HKLM\SOFTWARE\CLASSES\APPID\CmndFF.DLL, Quarantined, [cccd5848a7d4e35317cb0945a1629d63],
Adware.ClickPotato, HKLM\SOFTWARE\CLASSES\APPID\mozillaps.dll, Quarantined, [6a2f237d4a31c4729a8e5bf4a55ed927],
Adware.ClickPotato, HKLM\SOFTWARE\CLASSES\APPID\Pltfrm.DLL, Quarantined, [05948b15146777bf84b5034ca26118e8],
Adware.ShopperReports, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ShopperReports.IEButtonA, Quarantined, [5f3a4c542358a492a91cda7729dab848],
Adware.ShopperReports, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ShopperReports.TriggerImmidiate, Quarantined, [f2a7762accaf9a9c1da8361b8a7955ab],
Adware.ShopperReports, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ShopperReports.TriggerImmidiate.1, Quarantined, [d9c0ffa1abd01e187c495af756ad58a8],
Adware.ShopperReports, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ShopperReports.TriggerImmidiateOrRandomTS, Quarantined, [b4e5b3edd8a3eb4bf4d1c58cdd26827e],
Adware.ShopperReports, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ShopperReports.TriggerImmidiateOrRandomTS.1, Quarantined, [0f8a029ecbb07cba1da8ee633ec535cb],
Adware.ClickPotato, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\BRNstIE.DLL, Quarantined, [6930524ed6a543f30cd0ee60937014ec],
Adware.ClickPotato, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\CmndFF.DLL, Quarantined, [cfca4c5452298ea8984a56f87192f40c],
Adware.ClickPotato, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\mozillaps.dll, Quarantined, [debb10907dfe54e281a751fe6d96cb35],
Adware.ClickPotato, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\Pltfrm.DLL, Quarantined, [7b1e643cd8a34fe7a89177d8778c0bf5],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2598197632-106402267-1668521451-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, Quarantined, [2a6f9f010f6cda5c5e2ed937ee16b848],
PUP.Optional.Pricora.A, HKU\S-1-5-21-2598197632-106402267-1668521451-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Pricora 1.1, Quarantined, [51485b457407f14525060cd5c33fcd33],
Registry Values: 4
PUP.Optional.CertifiedToolBar.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHURI|(Default), http://search.certified-toolbar.com?si=38268bs=truetid=77q=%s, Quarantined, [1b7e910f2d4e48eef779ba0a976bed13]
PUP.Optional.CertifiedToolBar.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|(Default), http://search.certified-toolbar.com?si=38268bs=truetid=77q=%s, Quarantined, [b8e1d5cbf98243f399d8d6eeff037e82]
Adware.HotBar, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\5.0\USER AGENT\POST PLATFORM|ShopperReports 3.0.489.0, Quarantined, [ebae6b35bac10531fa20c0acfe057e82],
Malware.Trace, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\5.0\USER AGENT\POST PLATFORM|SRS_IT_E879027EBC765E5A35A993, Quarantined, [1485940cf2891d19a17ba1cbdd2618e8],
Registry Data: 2
PUP.Optional.SearchCertifiedTB.A, HKU\S-1-5-21-2598197632-106402267-1668521451-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURI|(Default), http://search.certified-toolbar.com?si=38268bs=truetid=77q=%s, Good: (http://www.google.com), Bad: (http://search.certified-toolbar.com?si=38268bs=truetid=77q=%s),Replaced,[afea3967d8a3fc3a2a233a6b2fd5c13f]
PUP.Optional.SearchCertifiedTB.A, HKU\S-1-5-21-2598197632-106402267-1668521451-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|(Default), http://search.certified-toolbar.com?si=38268bs=truetid=77q=%s, Good: (http://www.google.com/), Bad: (http://search.certified-toolbar.com?si=38268bs=truetid=77q=%s),Replaced,[ebae2f714d2e45f12c223570cc387987]
Folders: 8
Adware.QuestDns, C:\Program Files (x86)\Mozilla Firefox\extensions\{C91E1C68-B60A-4C9F-B53B-AAAEF0E7EF97}, Quarantined, [6a2f7f217ffc003676a8ecaabf43857b],
Adware.QuestDns, C:\Program Files (x86)\Mozilla Firefox\extensions\{C91E1C68-B60A-4C9F-B53B-AAAEF0E7EF97}\chrome, Quarantined, [6a2f7f217ffc003676a8ecaabf43857b],
Adware.QuestDns, C:\Program Files (x86)\Mozilla Firefox\extensions\{C91E1C68-B60A-4C9F-B53B-AAAEF0E7EF97}\defaults, Quarantined, [6a2f7f217ffc003676a8ecaabf43857b],
Adware.QuestDns, C:\Program Files (x86)\Mozilla Firefox\extensions\{C91E1C68-B60A-4C9F-B53B-AAAEF0E7EF97}\defaults\preferences, Quarantined, [6a2f7f217ffc003676a8ecaabf43857b],
Adware.QuestBrowse, C:\Program Files (x86)\Mozilla Firefox\extensions\{D9ADB0A8-7BFB-498D-9880-EE78A81CCFA0}, Quarantined, [7524e5bb423930069ba07925db275ea2],
Adware.QuestBrowse, C:\Program Files (x86)\Mozilla Firefox\extensions\{D9ADB0A8-7BFB-498D-9880-EE78A81CCFA0}\chrome, Quarantined, [7524e5bb423930069ba07925db275ea2],
Adware.QuestBrowse, C:\Program Files (x86)\Mozilla Firefox\extensions\{D9ADB0A8-7BFB-498D-9880-EE78A81CCFA0}\defaults, Quarantined, [7524e5bb423930069ba07925db275ea2],
Adware.QuestBrowse, C:\Program Files (x86)\Mozilla Firefox\extensions\{D9ADB0A8-7BFB-498D-9880-EE78A81CCFA0}\defaults\preferences, Quarantined, [7524e5bb423930069ba07925db275ea2],
Files: 36
PUP.Optional.PriceMeter.A, C:\Windows\System32\Tasks\pricemeterdownloader, Quarantined, [f8a159470e6db185719edae590727888],
PUP.Optional.PriceMeter.A, C:\Windows\System32\Tasks\pricemetertask, Quarantined, [21785f410972a78fba61467d8c76da26],
PUP.Optional.PriceMeter.A, C:\Windows\System32\Tasks\pricemeterwatcher, Quarantined, [2673d4ccdba0b87e3ce08a390df53ac6],
PUP.Optional.Bubbledock.A, C:\Users\Benoit et Sylvie\AppData\Roaming\Bubble Dock.boostrap.log, Quarantined, [ecadd2ce22596bcb9ef0c223a65c6997],
Adware.QuestDns, C:\Program Files (x86)\Mozilla Firefox\extensions\{C91E1C68-B60A-4C9F-B53B-AAAEF0E7EF97}\chrome.manifest, Quarantined, [6a2f7f217ffc003676a8ecaabf43857b],
Adware.QuestDns, C:\Program Files (x86)\Mozilla Firefox\extensions\{C91E1C68-B60A-4C9F-B53B-AAAEF0E7EF97}\install.rdf, Quarantined, [6a2f7f217ffc003676a8ecaabf43857b],
Adware.QuestDns, C:\Program Files (x86)\Mozilla Firefox\extensions\{C91E1C68-B60A-4C9F-B53B-AAAEF0E7EF97}\chrome\questdns.jar, Quarantined, [6a2f7f217ffc003676a8ecaabf43857b],
Adware.QuestDns, C:\Program Files (x86)\Mozilla Firefox\extensions\{C91E1C68-B60A-4C9F-B53B-AAAEF0E7EF97}\defaults\preferences\prefs.js, Quarantined, [6a2f7f217ffc003676a8ecaabf43857b],
Adware.QuestBrowse, C:\Program Files (x86)\Mozilla Firefox\extensions\{D9ADB0A8-7BFB-498D-9880-EE78A81CCFA0}\chrome.manifest, Quarantined, [7524e5bb423930069ba07925db275ea2],
Adware.QuestBrowse, C:\Program Files (x86)\Mozilla Firefox\extensions\{D9ADB0A8-7BFB-498D-9880-EE78A81CCFA0}\install.rdf, Quarantined, [7524e5bb423930069ba07925db275ea2],
Adware.QuestBrowse, C:\Program Files (x86)\Mozilla Firefox\extensions\{D9ADB0A8-7BFB-498D-9880-EE78A81CCFA0}\defaults\preferences\prefs.js, Quarantined, [7524e5bb423930069ba07925db275ea2],
PUP.Optional.CertifiedTB.A, C:\Users\Benoit et Sylvie\AppData\Local\Google\Chrome\User Data\Default\Preferences, Good: (), Bad: ( "homepage" : "http://search.certified-toolbar.com?si=38268home=truetid=77",), Replaced,[79201888bbc0d75ff96d01d3f50fbc44]
PUP.Optional.CrossRider.A, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.crossrider.bic", "1463d364b897ca6242a69cc42c471f95"), Replaced,[66339a069ae1e94d4194755e5ba9af51]
PUP.Optional.Babylon.A, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.BabylonToolbar_i.newTab", true), Replaced,[73267e22d5a6a492faebeae95fa5ea16]
PUP.Optional.Babylon.A, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.BabylonToolbar_i.newTabUrl", "http://search.babylon.com/?affID=17425tt=5012_1babsrc=NT_def"), Replaced,[6c2d2d731f5c1c1a14d111c2d72dcf31]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.admin", false), Replaced,[debb6e327dfe231319ced3019074857b]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.aflt", "babsst"), Replaced,[4c4d257b94e786b03fa8f2e26b9918e8]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.appId", "{37EB75F2-7392-4DBE-B5AD-147EC6D7BF5F}"), Replaced,[9108118f7cff80b644a3f5df49bbbe42]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.autoRvrt", "false"), Replaced,[cecb534d314ab0868364795bd13306fa]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.dfltLng", "fr"), Replaced,[1485bce4205b87af40a7379d56ae52ae]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.excTlbr", false), Replaced,[cacf0b95dba082b4a3444a8aa55f48b8]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.ffxUnstlRst", true), Replaced,[a6f3bae6b4c75ed811d6cc08fa0a9d63]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.id", "e2d62e3000000000000078e4004c2f43"), Replaced,[980119873348e74f22c57e564db72ed2]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.instlDay", "16217"), Replaced,[cfca2f714635d75f7e69f6de7a8a6e92]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.instlRef", "sst"), Replaced,[0c8d227e4932d462f9ee389caa5a49b7]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.newTab", false), Replaced,[d4c58020106b8fa75f88567e768e44bc]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.prdct", "buenosearch"), Replaced,[6c2d99070e6dfd39a4437a5aaa5af907]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.prtnrId", "buenosearch"), Replaced,[e1b8158b334890a6e205548019eb26da]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.rvrt", "false"), Replaced,[afea1a86d1aa66d0dd0aece8ca3a946c]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.smplGrp", "none"), Replaced,[5d3c326ec1ba2d098c5b2ca8f70d758b]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.tb_url", "http://www.buenosearch.com/?q={searchTerms}babsrc=TB_ssmntrId=E2D678E4004C2F43affID=128854tsp=5260"), Replaced,[6237643cd1aabe78687f468e956f18e8]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.tlbrId", "base"), Replaced,[5049237dd1aab680f3f40ec6768ea35d]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.tlbrSrchUrl", "http://www.buenosearch.com/?q={searchTerms}babsrc=TB_ssmntrId=E2D678E4004C2F43affID=128854tsp=5260"), Replaced,[f9a0f2ae89f266d06e7933a117ed54ac]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.vrsn", "1.8.28.7"), Replaced,[e3b6f3ad1665c07661861bb941c3e11f]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.vrsnTs", "1.8.28.76:50:00"), Replaced,[a8f1e6ba6714fb3b03e429abbd478e72]
PUP.Optional.BuenoSearch, C:\Users\Benoit et Sylvie\AppData\Roaming\Mozilla\Firefox\Profiles\y28iusdr.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.vrsni", "1.8.28.7"), Replaced,[19806a36f982f640895e884ca65e718f]
Physical Sectors: 0
(No malicious items detected)
(end)