Usually, when a virus hits my computer, I tend to know how to search for solutions because the virus usually attacks something specific or leaves a trail of sorts. For this one, I have no idea what it's doing on/to my computer or where I got it from. In fact, I got it when I was AFK so I definitely don't know how I got it. All I know of it are 2 things:
1. It got rid of my System Restore option. It doesn't just turn off System Restore, it literally got rid of the tab in System Properties.
2. When I boot up Windows normally, it gives me a black screen. I'm not sure if it's freezing or doing something to my graphics, I don't know. However, I can load up Safe Mode (with networking) perfectly fine. Albeit with a much longer than usual load time.
Anyway, here are my logs:
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Database version: v2013.09.11.04
Windows Vista Service Pack 2 x64 NTFS (Safe Mode/Networking)
Internet Explorer 9.0.8112.16421
Bernard :: BERNARD-PC [administrator]
11/09/2013 6:10:42 AM
mbam-log-2013-09-11 (06-10-42).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 286972
Time elapsed: 26 minute(s), 15 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 37
HKLM\SYSTEM\CurrentControlSet\Services\WajamUpdater (PUP.Optional.Wajam.A) -> No action taken.
HKCR\CLSID\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2} (PUP.Optional.Wajam.A) -> No action taken.
HKCR\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2} (PUP.Optional.Wajam.A) -> No action taken.
HKCR\TypeLib\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D} (PUP.Optional.Wajam.A) -> No action taken.
HKCR\CLSID\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam.A) -> No action taken.
HKCR\wajam.WajamBHO.1 (PUP.Optional.Wajam.A) -> No action taken.
HKCR\wajam.WajamBHO (PUP.Optional.Wajam.A) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam.A) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam.A) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam.A) -> No action taken.
HKCR\AppID\{1DD31B76-C57E-49ba-94BC-BF53F0C82CD4} (PUP.Funshion) -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1DD31B76-C57E-49ba-94BC-BF53F0C82CD4} (PUP.Funshion) -> No action taken.
HKCR\AppID\{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634} (PUP.Optional.Wajam.A) -> No action taken.
HKCR\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17} (PUP.Optional.Wajam.A) -> No action taken.
HKCR\CLSID\{11CC93E4-0BE6-4f8f-82AA-D577FB955B05} (PUP.Funshion) -> No action taken.
HKCR\TypeLib\{F9BC0421-BB5C-447d-8547-BB45AFA80A4D} (PUP.Funshion) -> No action taken.
HKCR\Interface\{4D89001B-5B5B-4E76-A1F5-638E49DB7A58} (PUP.Funshion) -> No action taken.
HKCR\AddressSearch.JsObject.1 (PUP.Funshion) -> No action taken.
HKCR\AddressSearch.JsObject (PUP.Funshion) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11CC93E4-0BE6-4F8F-82AA-D577FB955B05} (PUP.Funshion) -> No action taken.
HKCR\CLSID\{5D64294B-1341-4FE7-B6D8-7C36828D4DD5} (PUP.Optional.Wajam.A) -> No action taken.
HKCR\wajam.WajamDownloader.1 (PUP.Optional.Wajam.A) -> No action taken.
HKCR\wajam.WajamDownloader (PUP.Optional.Wajam.A) -> No action taken.
HKCR\CLSID\{91878E42-FC03-4785-B513-1F9E613D1027} (PUP.Funshion) -> No action taken.
HKCR\TypeLib\{D02E3AB9-7796-40cb-BDFC-20D834FE1F75} (PUP.Funshion) -> No action taken.
HKCR\Interface\{FCB380C4-D350-44BE-8791-50216F4747AC} (PUP.Funshion) -> No action taken.
HKCR\ASBarBroker.BDBroker.1 (PUP.Funshion) -> No action taken.
HKCR\ASBarBroker.BDBroker (PUP.Funshion) -> No action taken.
HKCR\CLSID\{FBEDBA6C-44A2-43b9-BD49-20EB6E0C4E86} (PUP.Funshion) -> No action taken.
HKCR\AddressSearch.SnavHttpProtocol.1 (PUP.Funshion) -> No action taken.
HKCR\AddressSearch.SnavHttpProtocol (PUP.Funshion) -> No action taken.
HKLM\SYSTEM\CurrentControlSet\Services\CltMngSvc (PUP.Optional.SearchProtect.A) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect (PUP.Optional.SearchProtect.A) -> No action taken.
HKCR\AppID\priam_bho.DLL (PUP.Optional.Wajam.A) -> No action taken.
HKCU\SOFTWARE\WAJAM (PUP.Optional.Wajam.A) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Wajam (PUP.Optional.Wajam.A) -> No action taken.
HKCR\thunder (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Values Detected: 3
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|SearchProtectAll (PUP.Optional.SearchProtect.A) -> Data: "C:\Program Files (x86)\SearchProtect\bin\cltmng.exe" -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|SearchProtect (PUP.Optional.SearchProtect.A) -> Data: C:\Users\Bernard\AppData\Roaming\SearchProtect\bin\cltmng.exe -> No action taken.
HKCU\Software\Wajam|affiliate_id (PUP.Optional.Wajam.A) -> Data: 5921 -> No action taken.
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 19
C:\Program Files (x86)\SEARCHPROTECT\bin (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\lib (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spbd (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spbd\images (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spsd (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spsd\images (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\bin (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\lib (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spbd (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spbd\images (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spsd (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spsd\images (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\Wajam (PUP.Optional.Wajam.A) -> No action taken.
C:\Program Files (x86)\Wajam\Firefox (PUP.Optional.Wajam.A) -> No action taken.
C:\Program Files (x86)\Wajam\IE (PUP.Optional.Wajam.A) -> No action taken.
C:\Program Files (x86)\Wajam\Updater (PUP.Optional.Wajam.A) -> No action taken.
C:\Recycle.Bin (Trojan.Spyeyes) -> Quarantined and deleted successfully.
Files Detected: 77
C:\Program Files (x86)\Wajam\Updater\WAJAMUPDATER.EXE (PUP.Optional.Wajam.A) -> No action taken.
C:\Program Files (x86)\Wajam\IE\PRIAM_BHO.DLL (PUP.Optional.Wajam.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SearchProtect\Res\SPSetup.exe (PUP.Optional.Conduit) -> No action taken.
C:\Users\Bernard\AppData\Local\Temp\0YudRA7T.exe.part (PUP.Optional.SweetIM) -> No action taken.
C:\Users\Bernard\AppData\Local\Temp\MyBabylonTB.exe (PUP.Optional.Babylon.A) -> No action taken.
C:\Users\Bernard\AppData\Local\Temp\OptimizerPro.exe (PUP.Optional.OptimizePro.A) -> No action taken.
C:\Users\Bernard\AppData\Local\Temp\QuickShare1.exe (PUP.Optional.QuickShare.A) -> No action taken.
C:\Users\Bernard\AppData\Local\Temp\SPStub.exe (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Bernard\AppData\Local\Temp\wajam_install.exe (PUP.Optional.Wajam.A) -> No action taken.
C:\Users\Bernard\AppData\Local\Temp\ct2737658\ffLogic.exe (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Bernard\AppData\Local\Temp\ct2737658\ieLogic.exe (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Bernard\AppData\Local\Temp\ct2737658\spff.exe (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Bernard\AppData\Local\Temp\ct2737658\statisticsStub.exe (PUP.Optional.Conduit.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\bin\FIREFOXMODULE.DLL (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\bin\ChromeModule.dll (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\bin\cltmng.exe (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\bin\CltMngSvc.exe (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\bin\InternetExplorerModule.dll (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\bin\msvcp100.dll (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\bin\msvcr100.dll (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\bin\SPHook32.dll (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\bin\uninstall.exe (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\DIALOGSAPI.JS (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\lib\jquery.min.js (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\lib\json2.js (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spbd\bubble.css (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spbd\bubble.js (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spbd\main.html (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spbd\images\information.png (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spbd\images\x-default-LTR.png (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spbd\images\x-default-RTL.png (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spbd\images\x-mouseover-LTR.png (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spbd\images\x-mouseover-RTL.png (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spsd\main.html (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spsd\SearchProtector.css (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spsd\settings.js (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spsd\images\ok-button.png (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spsd\images\separation-line.png (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spsd\images\warning.png (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\bin\FIREFOXMODULE.DLL (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\bin\ChromeModule.dll (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\bin\cltmng.exe (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\bin\CltMngSvc.exe (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\bin\InternetExplorerModule.dll (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\bin\msvcp100.dll (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\bin\msvcr100.dll (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\bin\rep.dat (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\bin\SPHook32.dll (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\DIALOGSAPI.JS (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\lib\jquery.min.js (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\lib\json2.js (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spbd\bubble.css (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spbd\bubble.js (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spbd\main.html (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spbd\images\information.png (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spbd\images\x-default-LTR.png (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spbd\images\x-default-RTL.png (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spbd\images\x-mouseover-LTR.png (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spbd\images\x-mouseover-RTL.png (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spsd\main.html (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spsd\SearchProtector.css (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spsd\settings.js (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spsd\images\ok-button.png (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spsd\images\separation-line.png (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spsd\images\warning.png (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\Wajam\uninstall.exe (PUP.Optional.Wajam.A) -> No action taken.
C:\Program Files (x86)\Wajam\Firefox\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}.xpi (PUP.Optional.Wajam.A) -> No action taken.
C:\Program Files (x86)\Wajam\IE\favicon.ico (PUP.Optional.Wajam.A) -> No action taken.
C:\Program Files (x86)\Wajam\IE\wajamLogo.bmp (PUP.Optional.Wajam.A) -> No action taken.
C:\Program Files (x86)\Wajam\Updater\update.exe (PUP.Optional.Wajam.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\Microsoft\6884\9396.tmp (Trojan.Dropper.PE4) -> Quarantined and deleted successfully.
C:\Users\Bernard\AppData\Local\Temp\C164.tmp (Trojan.Phex.THAGen6) -> Quarantined and deleted successfully.
C:\Users\Bernard\AppData\Local\Temp\D67E.tmp (Spyware.Agent) -> Quarantined and deleted successfully.
C:\Users\Bernard\AppData\Local\Temp\FAA3.tmp (Trojan.Dropper.PE4) -> Quarantined and deleted successfully.
C:\Users\Bernard\AppData\Local\Temp\pricepeep_130001_1001.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\ProgramData\lsass.exe (Trojan.Delf) -> Quarantined and deleted successfully.
C:\Users\Bernard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk (Trojan.Ransom.Gen) -> Quarantined and deleted successfully.
(end)
1. It got rid of my System Restore option. It doesn't just turn off System Restore, it literally got rid of the tab in System Properties.
2. When I boot up Windows normally, it gives me a black screen. I'm not sure if it's freezing or doing something to my graphics, I don't know. However, I can load up Safe Mode (with networking) perfectly fine. Albeit with a much longer than usual load time.
Anyway, here are my logs:
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Database version: v2013.09.11.04
Windows Vista Service Pack 2 x64 NTFS (Safe Mode/Networking)
Internet Explorer 9.0.8112.16421
Bernard :: BERNARD-PC [administrator]
11/09/2013 6:10:42 AM
mbam-log-2013-09-11 (06-10-42).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 286972
Time elapsed: 26 minute(s), 15 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 37
HKLM\SYSTEM\CurrentControlSet\Services\WajamUpdater (PUP.Optional.Wajam.A) -> No action taken.
HKCR\CLSID\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2} (PUP.Optional.Wajam.A) -> No action taken.
HKCR\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2} (PUP.Optional.Wajam.A) -> No action taken.
HKCR\TypeLib\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D} (PUP.Optional.Wajam.A) -> No action taken.
HKCR\CLSID\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam.A) -> No action taken.
HKCR\wajam.WajamBHO.1 (PUP.Optional.Wajam.A) -> No action taken.
HKCR\wajam.WajamBHO (PUP.Optional.Wajam.A) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam.A) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam.A) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam.A) -> No action taken.
HKCR\AppID\{1DD31B76-C57E-49ba-94BC-BF53F0C82CD4} (PUP.Funshion) -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1DD31B76-C57E-49ba-94BC-BF53F0C82CD4} (PUP.Funshion) -> No action taken.
HKCR\AppID\{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634} (PUP.Optional.Wajam.A) -> No action taken.
HKCR\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17} (PUP.Optional.Wajam.A) -> No action taken.
HKCR\CLSID\{11CC93E4-0BE6-4f8f-82AA-D577FB955B05} (PUP.Funshion) -> No action taken.
HKCR\TypeLib\{F9BC0421-BB5C-447d-8547-BB45AFA80A4D} (PUP.Funshion) -> No action taken.
HKCR\Interface\{4D89001B-5B5B-4E76-A1F5-638E49DB7A58} (PUP.Funshion) -> No action taken.
HKCR\AddressSearch.JsObject.1 (PUP.Funshion) -> No action taken.
HKCR\AddressSearch.JsObject (PUP.Funshion) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11CC93E4-0BE6-4F8F-82AA-D577FB955B05} (PUP.Funshion) -> No action taken.
HKCR\CLSID\{5D64294B-1341-4FE7-B6D8-7C36828D4DD5} (PUP.Optional.Wajam.A) -> No action taken.
HKCR\wajam.WajamDownloader.1 (PUP.Optional.Wajam.A) -> No action taken.
HKCR\wajam.WajamDownloader (PUP.Optional.Wajam.A) -> No action taken.
HKCR\CLSID\{91878E42-FC03-4785-B513-1F9E613D1027} (PUP.Funshion) -> No action taken.
HKCR\TypeLib\{D02E3AB9-7796-40cb-BDFC-20D834FE1F75} (PUP.Funshion) -> No action taken.
HKCR\Interface\{FCB380C4-D350-44BE-8791-50216F4747AC} (PUP.Funshion) -> No action taken.
HKCR\ASBarBroker.BDBroker.1 (PUP.Funshion) -> No action taken.
HKCR\ASBarBroker.BDBroker (PUP.Funshion) -> No action taken.
HKCR\CLSID\{FBEDBA6C-44A2-43b9-BD49-20EB6E0C4E86} (PUP.Funshion) -> No action taken.
HKCR\AddressSearch.SnavHttpProtocol.1 (PUP.Funshion) -> No action taken.
HKCR\AddressSearch.SnavHttpProtocol (PUP.Funshion) -> No action taken.
HKLM\SYSTEM\CurrentControlSet\Services\CltMngSvc (PUP.Optional.SearchProtect.A) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect (PUP.Optional.SearchProtect.A) -> No action taken.
HKCR\AppID\priam_bho.DLL (PUP.Optional.Wajam.A) -> No action taken.
HKCU\SOFTWARE\WAJAM (PUP.Optional.Wajam.A) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Wajam (PUP.Optional.Wajam.A) -> No action taken.
HKCR\thunder (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Values Detected: 3
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|SearchProtectAll (PUP.Optional.SearchProtect.A) -> Data: "C:\Program Files (x86)\SearchProtect\bin\cltmng.exe" -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|SearchProtect (PUP.Optional.SearchProtect.A) -> Data: C:\Users\Bernard\AppData\Roaming\SearchProtect\bin\cltmng.exe -> No action taken.
HKCU\Software\Wajam|affiliate_id (PUP.Optional.Wajam.A) -> Data: 5921 -> No action taken.
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 19
C:\Program Files (x86)\SEARCHPROTECT\bin (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\lib (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spbd (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spbd\images (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spsd (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spsd\images (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\bin (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\lib (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spbd (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spbd\images (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spsd (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spsd\images (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\Wajam (PUP.Optional.Wajam.A) -> No action taken.
C:\Program Files (x86)\Wajam\Firefox (PUP.Optional.Wajam.A) -> No action taken.
C:\Program Files (x86)\Wajam\IE (PUP.Optional.Wajam.A) -> No action taken.
C:\Program Files (x86)\Wajam\Updater (PUP.Optional.Wajam.A) -> No action taken.
C:\Recycle.Bin (Trojan.Spyeyes) -> Quarantined and deleted successfully.
Files Detected: 77
C:\Program Files (x86)\Wajam\Updater\WAJAMUPDATER.EXE (PUP.Optional.Wajam.A) -> No action taken.
C:\Program Files (x86)\Wajam\IE\PRIAM_BHO.DLL (PUP.Optional.Wajam.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SearchProtect\Res\SPSetup.exe (PUP.Optional.Conduit) -> No action taken.
C:\Users\Bernard\AppData\Local\Temp\0YudRA7T.exe.part (PUP.Optional.SweetIM) -> No action taken.
C:\Users\Bernard\AppData\Local\Temp\MyBabylonTB.exe (PUP.Optional.Babylon.A) -> No action taken.
C:\Users\Bernard\AppData\Local\Temp\OptimizerPro.exe (PUP.Optional.OptimizePro.A) -> No action taken.
C:\Users\Bernard\AppData\Local\Temp\QuickShare1.exe (PUP.Optional.QuickShare.A) -> No action taken.
C:\Users\Bernard\AppData\Local\Temp\SPStub.exe (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Bernard\AppData\Local\Temp\wajam_install.exe (PUP.Optional.Wajam.A) -> No action taken.
C:\Users\Bernard\AppData\Local\Temp\ct2737658\ffLogic.exe (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Bernard\AppData\Local\Temp\ct2737658\ieLogic.exe (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Bernard\AppData\Local\Temp\ct2737658\spff.exe (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\Bernard\AppData\Local\Temp\ct2737658\statisticsStub.exe (PUP.Optional.Conduit.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\bin\FIREFOXMODULE.DLL (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\bin\ChromeModule.dll (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\bin\cltmng.exe (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\bin\CltMngSvc.exe (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\bin\InternetExplorerModule.dll (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\bin\msvcp100.dll (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\bin\msvcr100.dll (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\bin\SPHook32.dll (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\bin\uninstall.exe (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\DIALOGSAPI.JS (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\lib\jquery.min.js (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\lib\json2.js (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spbd\bubble.css (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spbd\bubble.js (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spbd\main.html (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spbd\images\information.png (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spbd\images\x-default-LTR.png (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spbd\images\x-default-RTL.png (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spbd\images\x-mouseover-LTR.png (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spbd\images\x-mouseover-RTL.png (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spsd\main.html (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spsd\SearchProtector.css (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spsd\settings.js (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spsd\images\ok-button.png (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spsd\images\separation-line.png (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\SEARCHPROTECT\Dialogs\spsd\images\warning.png (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\bin\FIREFOXMODULE.DLL (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\bin\ChromeModule.dll (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\bin\cltmng.exe (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\bin\CltMngSvc.exe (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\bin\InternetExplorerModule.dll (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\bin\msvcp100.dll (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\bin\msvcr100.dll (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\bin\rep.dat (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\bin\SPHook32.dll (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\DIALOGSAPI.JS (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\lib\jquery.min.js (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\lib\json2.js (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spbd\bubble.css (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spbd\bubble.js (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spbd\main.html (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spbd\images\information.png (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spbd\images\x-default-LTR.png (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spbd\images\x-default-RTL.png (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spbd\images\x-mouseover-LTR.png (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spbd\images\x-mouseover-RTL.png (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spsd\main.html (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spsd\SearchProtector.css (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spsd\settings.js (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spsd\images\ok-button.png (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spsd\images\separation-line.png (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\SEARCHPROTECT\Dialogs\spsd\images\warning.png (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Program Files (x86)\Wajam\uninstall.exe (PUP.Optional.Wajam.A) -> No action taken.
C:\Program Files (x86)\Wajam\Firefox\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}.xpi (PUP.Optional.Wajam.A) -> No action taken.
C:\Program Files (x86)\Wajam\IE\favicon.ico (PUP.Optional.Wajam.A) -> No action taken.
C:\Program Files (x86)\Wajam\IE\wajamLogo.bmp (PUP.Optional.Wajam.A) -> No action taken.
C:\Program Files (x86)\Wajam\Updater\update.exe (PUP.Optional.Wajam.A) -> No action taken.
C:\Users\Bernard\AppData\Roaming\Microsoft\6884\9396.tmp (Trojan.Dropper.PE4) -> Quarantined and deleted successfully.
C:\Users\Bernard\AppData\Local\Temp\C164.tmp (Trojan.Phex.THAGen6) -> Quarantined and deleted successfully.
C:\Users\Bernard\AppData\Local\Temp\D67E.tmp (Spyware.Agent) -> Quarantined and deleted successfully.
C:\Users\Bernard\AppData\Local\Temp\FAA3.tmp (Trojan.Dropper.PE4) -> Quarantined and deleted successfully.
C:\Users\Bernard\AppData\Local\Temp\pricepeep_130001_1001.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\ProgramData\lsass.exe (Trojan.Delf) -> Quarantined and deleted successfully.
C:\Users\Bernard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk (Trojan.Ransom.Gen) -> Quarantined and deleted successfully.
(end)