www.malwarebytes.org
Database version:
main: v2017.03.30.09
rootkit: v2017.03.11.01
Windows 10 x64 NTFS
Internet Explorer 11.713.10586.0
Primitive :: RANY [administrator]
3/30/2017 7:11:27 PM
mbar-log-2017-03-30 (19-11-27).txt
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 367281
Time elapsed: 15 minute(s), 30 second(s)
Memory Processes Detected: 8
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\svcvmx.exe (Adware.Yelloader) -> 8312 -> Delete on reboot. [85acb41cccdcc76fe1eda2d93bc601ff]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe (Adware.Yelloader) -> 5764 -> Delete on reboot. [63ceab25495f6acc4b2ab2c5e71ad12f]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe (Adware.Yelloader) -> 2384 -> Delete on reboot. [63ceab25495f6acc4b2ab2c5e71ad12f]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe (Adware.Yelloader) -> 860 -> Delete on reboot. [63ceab25495f6acc4b2ab2c5e71ad12f]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe (Adware.Yelloader) -> 6888 -> Delete on reboot. [63ceab25495f6acc4b2ab2c5e71ad12f]
C:\Users\Primitive\AppData\Local\microlabs\ct.exe (Trojan.Clicker) -> 3392 -> Delete on reboot. [ab8657798226cb6becc44406d72b34cc]
C:\Program Files (x86)\3b4f51ef-73de-4277-a2f6-3e687129283e1490563447\kns3C43.tmp (Adware.ConvertAd.Generic) -> 1568 -> Delete on reboot. [230ed7f9beeab284868aa2b32ed45ca4]
C:\Program Files (x86)\3b4f51ef-73de-4277-a2f6-3e687129283e1490563447\prot3b4f51ef-73de-4277-a2f6-3e687129283e.tmpfs (Adware.ConvertAd.Generic) -> 1832 -> Delete on reboot. [230ed7f9beeab284868aa2b32ed45ca4]
Memory Modules Detected: 12
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\d3dcompiler_47.dll (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\dbghelp.dll (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\dbghelp.dll (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\dbghelp.dll (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\dbghelp.dll (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\dbghelp.dll (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\libcef.dll (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\libcef.dll (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\libcef.dll (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\libcef.dll (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\libEGL.dll (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\libGLESv2.dll (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
Registry Keys Detected: 21
HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Dataup (Adware.Yelloader) -> Delete on reboot. [2011af21495f58dec2ab8aed2ad7d62a]
HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\windowsmanagementservice (Trojan.Clicker) -> Delete on reboot. [ab8657798226cb6becc44406d72b34cc]
HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\servervo (Adware.ConvertAd.Generic) -> Delete on reboot. [230ed7f9beeab284868aa2b32ed45ca4]
HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\gemeloki (Adware.ConvertAd.Generic) -> Delete on reboot. [230ed7f9beeab284868aa2b32ed45ca4]
HKLM\SOFTWARE\RunBooster (Adware.RunBooster) -> Delete on reboot. [f83923ad9a0ec67080bc6394f30dfb05]
HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\drmkpro64 (Rootkit.Agent.PUA) -> Delete on reboot. [d25fede3981050e654c4407f1ee3738d]
HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\Dataup (Trojan.Clicker) -> Delete on reboot. [ff32ce029117e452753d512bf20fa45c]
HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E7BC34A3-BA86-11CF-84B1-CBC2DA68BF6C} (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
HKLM\SOFTWARE\CLASSES\TYPELIB\{E7BC34A0-BA86-11CF-84B1-CBC2DA68BF6C} (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
HKLM\SOFTWARE\CLASSES\INTERFACE\{E7BC34A1-BA86-11CF-84B1-CBC2DA68BF6C} (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
HKLM\SOFTWARE\CLASSES\INTERFACE\{E7BC34A2-BA86-11CF-84B1-CBC2DA68BF6C} (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E7BC34A1-BA86-11CF-84B1-CBC2DA68BF6C} (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E7BC34A2-BA86-11CF-84B1-CBC2DA68BF6C} (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{E7BC34A1-BA86-11CF-84B1-CBC2DA68BF6C} (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{E7BC34A2-BA86-11CF-84B1-CBC2DA68BF6C} (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{E7BC34A0-BA86-11CF-84B1-CBC2DA68BF6C} (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{E7BC34A0-BA86-11CF-84B1-CBC2DA68BF6C} (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
HKLM\SOFTWARE\CLASSES\NTService.Control.1 (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
HKLM\SOFTWARE\WOW6432NODE\CLASSES\NTService.Control.1 (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
HKLM\SOFTWARE\CLASSES\WOW6432NODE\NTService.Control.1 (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{E7BC34A3-BA86-11CF-84B1-CBC2DA68BF6C} (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
Registry Values Detected: 6
HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|svcvmx (Adware.Yelloader) -> Data: "C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\svcvmx.exe" -starup -> Delete on reboot. [85acb41cccdcc76fe1eda2d93bc601ff]
HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|cpx (Trojan.Clicker) -> Data: "C:\Users\Primitive\AppData\Local\ntuserlitelist\cpx\cpx.exe" -starup -> Delete on reboot. [cd6404cceeba3cfa984ae77050b2f40c]
HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\gemeloki|ImagePath (Adware.ConvertAd.Generic) -> Data: C:\Program Files (x86)\3b4f51ef-73de-4277-a2f6-3e687129283e1490563447\prot3b4f51ef-73de-4277-a2f6-3e687129283e.tmpfs -> Delete on reboot. [ab86339d7b2d1f17864bab2e5ca4728e]
HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\servervo|ImagePath (Adware.ConvertAd.Generic) -> Data: C:\Program Files (x86)\3b4f51ef-73de-4277-a2f6-3e687129283e1490563447\kns3C43.tmp -> Delete on reboot. [67ca616f8127d462ce03518831cff20e]
HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\DATAUP|ImagePath (Trojan.Clicker) -> Data: C:\Users\PRIMIT~1\AppData\Local\NTUSER~1\dataup\dataup.exe -> Delete on reboot. [b67b5779e2c64ceaf7b9e6970ff2659b]
HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WINDOWSMANAGEMENTSERVICE|ImagePath (Trojan.Clicker) -> Data: "C:\Users\Primitive\AppData\Local\microlabs\ct.exe" /svc -> Delete on reboot. [e849d7f9cfd990a640fa4413c73b6a96]
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 28
C:\Windows\src_srv (Adware.DotDo.PrxySvrRST) -> Delete on reboot. [1a17e8e8961283b3486b2a48cb351ae6]
C:\Users\Primitive\AppData\Local\microlabs (Trojan.Clicker) -> Delete on reboot. [ab8657798226cb6becc44406d72b34cc]
C:\Program Files (x86)\3b4f51ef-73de-4277-a2f6-3e687129283e1490563447 (Adware.ConvertAd.Generic) -> Delete on reboot. [230ed7f9beeab284868aa2b32ed45ca4]
C:\Users\Primitive\AppData\Local\llssoft\winvmx (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data603 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data603\GPUCache (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data614 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data614\GPUCache (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data618 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data618\GPUCache (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data638 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data638\GPUCache (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data673 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data673\GPUCache (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data680 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data680\GPUCache (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data685 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data685\GPUCache (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data691 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data691\GPUCache (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\dump (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\ntuserlitelist (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\dataup (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\qdcomsvc (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\regtool (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\locales (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\winscr (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
Files Detected: 252
C:\WINDOWS\SYSTEM32\drivers\1d160a49fc8ecb3cfce1289a40c9b4dc.sys (Adware.Social2Search) -> Delete on reboot. [23232dccce49afc4102e7ec4d879efd0]
C:\WINDOWS\SYSTEM32\drivers\ndistpr64.sys (Rootkit.Agent.PUA) -> Delete on reboot. [b82af19ea4f351ab70ceeeec014dcc62]
C:\Users\Primitive\AppData\Local\ntuserlitelist\dataup\dataup.exe (Adware.Yelloader) -> Delete on reboot. [2011af21495f58dec2ab8aed2ad7d62a]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\svcvmx.exe (Adware.Yelloader) -> Delete on reboot. [85acb41cccdcc76fe1eda2d93bc601ff]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe (Adware.Yelloader) -> Delete on reboot. [63ceab25495f6acc4b2ab2c5e71ad12f]
c:\windows\system32\tprdpw32.exe (Rootkit.Agent.PUA) -> Delete on reboot. [e64b3e926c3cd85ed6727fcebd45f808]
C:\Windows\SysWOW64\SurfShield.exe (Trojan.MalPack) -> Delete on reboot. [6ec3f0e050587fb7f7f8f551837f946c]
C:\Users\Primitive\AppData\Local\Temp\1490577405\s5-20150702.exe (Rootkit.Agent.PUA) -> Delete on reboot. [ea47923e1f892a0cc7687cd545bde719]
C:\Users\Primitive\AppData\Local\Temp\172776218\RunBoosterSetup64_3231.exe (Adware.RunBooster) -> Delete on reboot. [55dcdef254542e0881a03b5853adc937]
C:\Windows\Temp\9279.tmp (Adware.ConvertAd) -> Delete on reboot. [8ca5a42c8325cf6785d1d0fcc23fdf21]
C:\Windows\Temp\927F.tmp (Trojan.Agent) -> Delete on reboot. [2f0280506147ce68b53d5aa7ce34ba46]
C:\Windows\Temp\928B.tmp (Trojan.Bunitu) -> Delete on reboot. [b879527e099f5fd737b2e076a55dfe02]
C:\Users\Primitive\AppData\Local\ntuserlitelist\qdcomsvc\kpiumycw.exe (Rootkit.Agent.PUA) -> Delete on reboot. [d65b11bf367245f114c871daf111c63a]
C:\Users\Primitive\AppData\Local\ntuserlitelist\winscr\winscr.exe (Adware.Yelloader) -> Delete on reboot. [37faae226543cb6b6e0697e0c23f9d63]
C:\Windows\src_srv\Trusted.Web.Proxy.dll (Adware.DotDo.PrxySvrRST) -> Delete on reboot. [1a17e8e8961283b3486b2a48cb351ae6]
C:\Windows\src_srv\accept_cert.exe (Adware.DotDo.PrxySvrRST) -> Delete on reboot. [1a17e8e8961283b3486b2a48cb351ae6]
C:\Windows\src_srv\Ionic.Zip.dll (Adware.DotDo.PrxySvrRST) -> Delete on reboot. [1a17e8e8961283b3486b2a48cb351ae6]
C:\Windows\src_srv\rootCert.pfx (Adware.DotDo.PrxySvrRST) -> Delete on reboot. [1a17e8e8961283b3486b2a48cb351ae6]
C:\Windows\src_srv\winsrcsrv.exe (Adware.DotDo.PrxySvrRST) -> Delete on reboot. [1a17e8e8961283b3486b2a48cb351ae6]
C:\Users\Primitive\AppData\Local\microlabs\ct.exe (Trojan.Clicker) -> Delete on reboot. [ab8657798226cb6becc44406d72b34cc]
C:\Program Files (x86)\3b4f51ef-73de-4277-a2f6-3e687129283e1490563447\kns2411.tmp (Adware.ConvertAd.Generic) -> Delete on reboot. [230ed7f9beeab284868aa2b32ed45ca4]
C:\Program Files (x86)\3b4f51ef-73de-4277-a2f6-3e687129283e1490563447\kns3C43.tmp (Adware.ConvertAd.Generic) -> Delete on reboot. [230ed7f9beeab284868aa2b32ed45ca4]
C:\Program Files (x86)\3b4f51ef-73de-4277-a2f6-3e687129283e1490563447\knsF876.tmp (Adware.ConvertAd.Generic) -> Delete on reboot. [230ed7f9beeab284868aa2b32ed45ca4]
C:\Program Files (x86)\3b4f51ef-73de-4277-a2f6-3e687129283e1490563447\pro175E.tmp (Adware.ConvertAd.Generic) -> Delete on reboot. [230ed7f9beeab284868aa2b32ed45ca4]
C:\Program Files (x86)\3b4f51ef-73de-4277-a2f6-3e687129283e1490563447\pro1BE4.tmp (Adware.ConvertAd.Generic) -> Delete on reboot. [230ed7f9beeab284868aa2b32ed45ca4]
C:\Program Files (x86)\3b4f51ef-73de-4277-a2f6-3e687129283e1490563447\pro3C53.tmp (Adware.ConvertAd.Generic) -> Delete on reboot. [230ed7f9beeab284868aa2b32ed45ca4]
C:\Program Files (x86)\3b4f51ef-73de-4277-a2f6-3e687129283e1490563447\pro9729.tmp (Adware.ConvertAd.Generic) -> Delete on reboot. [230ed7f9beeab284868aa2b32ed45ca4]
C:\Program Files (x86)\3b4f51ef-73de-4277-a2f6-3e687129283e1490563447\proB94D.tmp (Adware.ConvertAd.Generic) -> Delete on reboot. [230ed7f9beeab284868aa2b32ed45ca4]
C:\Program Files (x86)\3b4f51ef-73de-4277-a2f6-3e687129283e1490563447\proD661.tmp (Adware.ConvertAd.Generic) -> Delete on reboot. [230ed7f9beeab284868aa2b32ed45ca4]
C:\Program Files (x86)\3b4f51ef-73de-4277-a2f6-3e687129283e1490563447\proF5B7.tmp (Adware.ConvertAd.Generic) -> Delete on reboot. [230ed7f9beeab284868aa2b32ed45ca4]
C:\Program Files (x86)\3b4f51ef-73de-4277-a2f6-3e687129283e1490563447\proF6FE.tmp (Adware.ConvertAd.Generic) -> Delete on reboot. [230ed7f9beeab284868aa2b32ed45ca4]
C:\Program Files (x86)\3b4f51ef-73de-4277-a2f6-3e687129283e1490563447\prot3b4f51ef-73de-4277-a2f6-3e687129283e.tmpfs (Adware.ConvertAd.Generic) -> Delete on reboot. [230ed7f9beeab284868aa2b32ed45ca4]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data603\Cookies (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data603\Cookies-journal (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data603\data_0 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data603\data_1 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data603\data_2 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data603\data_3 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data603\index (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data603\Visited Links (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data603\GPUCache\data_0 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data603\GPUCache\data_1 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data603\GPUCache\data_2 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data603\GPUCache\data_3 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data603\GPUCache\index (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data614\Cookies (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data614\Cookies-journal (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data614\data_0 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data614\data_1 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data614\data_2 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data614\data_3 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data614\index (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data614\Visited Links (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data614\GPUCache\data_0 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data614\GPUCache\data_1 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data614\GPUCache\data_2 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data614\GPUCache\data_3 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data614\GPUCache\index (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data618\Cookies (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data618\Cookies-journal (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data618\data_0 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data618\data_1 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data618\data_2 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data618\data_3 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data618\index (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data618\Visited Links (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data618\GPUCache\data_0 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data618\GPUCache\data_1 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data618\GPUCache\data_2 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data618\GPUCache\data_3 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data618\GPUCache\index (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data638\Cookies (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data638\Cookies-journal (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data638\data_0 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data638\data_1 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data638\data_2 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data638\data_3 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data638\index (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data638\Visited Links (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data638\GPUCache\data_0 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data638\GPUCache\data_1 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data638\GPUCache\data_2 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data638\GPUCache\data_3 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data638\GPUCache\index (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data673\Cookies (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data673\Cookies-journal (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data673\data_0 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data673\data_1 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data673\data_2 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data673\data_3 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data673\index (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data673\Visited Links (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data673\GPUCache\data_0 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data673\GPUCache\data_1 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data673\GPUCache\data_2 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data673\GPUCache\data_3 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data673\GPUCache\index (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data680\Cookies (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data680\Cookies-journal (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data680\data_0 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data680\data_1 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data680\data_2 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data680\data_3 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data680\index (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data680\Visited Links (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data680\GPUCache\data_0 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data680\GPUCache\data_1 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data680\GPUCache\data_2 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data680\GPUCache\data_3 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data680\GPUCache\index (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data685\Cookies (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data685\Cookies-journal (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data685\data_0 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data685\data_1 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data685\data_2 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data685\data_3 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data685\index (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data685\Visited Links (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data685\GPUCache\data_0 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data685\GPUCache\data_1 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data685\GPUCache\data_2 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data685\GPUCache\data_3 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data685\GPUCache\index (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data691\Cookies (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data691\Cookies-journal (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data691\data_0 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data691\data_1 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data691\data_2 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data691\data_3 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data691\index (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data691\Visited Links (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data691\GPUCache\data_0 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data691\GPUCache\data_1 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data691\GPUCache\data_2 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data691\GPUCache\data_3 (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\llssoft\winvmx\data691\GPUCache\index (Trojan.Clicker.D) -> Delete on reboot. [41f08c44baee35014013ad31b34de51b]
C:\Users\Primitive\AppData\Local\ntuserlitelist\dataup\dataup.ini (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\dataup\help_dll.dll (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\dataup\NTSVC.ocx (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\regtool\regtool.exe (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\cef.pak (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\cef_100_percent.pak (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\cef_200_percent.pak (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\cef_extensions.pak (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\d3dcompiler_47.dll (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\dbghelp.dll (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\debug.log (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\icudtl.dat (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\libcef.dll (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\libEGL.dll (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\libGLESv2.dll (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\natives_blob.bin (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\pepflashplayer.dll (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\snapshot_blob.bin (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\svcvmx.log (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\widevinecdm.dll (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\widevinecdmadapter.dll (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\locales\en-US.pak (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Users\Primitive\AppData\Local\ntuserlitelist\svcvmx\locales\zh-CN.pak (Trojan.Clicker) -> Delete on reboot. [71c087492f79d3631616f45137cbfc04]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: ( 92.53.119.169 469ba60d9681f961064c-3cca6631dac1b4997db921c060b712f6.r30.cf2.rackcdn.com) Good: () -> Replace on reboot. [979acf01a305c96d6ef35121936e59a7]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (ac1b4997db921c060b712f6.r30.cf2.rackcdn.co) Good: () -> Replace on reboot. [b0816f61891fda5c461b7cf6778ab44c]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (
92.53.119.169 469ba60d9681f961064c-3cca6631dac) Good: () -> Replace on reboot. [5bd6a729c1e741f5540d7cf6a9582dd3]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (3.119.169 469ba60d9681f961064c-3cca6631dac1b499) Good: () -> Replace on reboot. [70c112be8424aa8cb3ae621051b034cc]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (53.119.169 469ba60d9681f961064c-3cca6631dac1b4) Good: () -> Replace on reboot. [f73a933d377174c25f02beb456abbc44]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (.53.119.169 469ba60d9681f961064c-3cca6631dac1b4997d) Good: () -> Replace on reboot. [7fb20ac68325b383b3ae591923de649c]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (19.169 469ba60d9681f961064c-3cca6631dac1b4997d) Good: () -> Replace on reboot. [cc657957901842f49ec3abc730d18779]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (.53.119.169 469ba60d9681f961064c-3cca6631) Good: () -> Replace on reboot. [1a175e720f99cf67c8998de5fd04ff01]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (
92.53.119.169 469ba60d9681f961064c-3cca6631) Good: () -> Replace on reboot. [d061a22eb6f2f145d8899ad812eff010]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (.53.119.169 469ba60d9681f961064c-3cca6631da) Good: () -> Replace on reboot. [c0719e325c4c132374ed4a2805fc02fe]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: ( 92.53.119.169 469ba60d9681f961064c-3cca6631da) Good: () -> Replace on reboot. [a78aa22e53555ed8174a383a877ad62a]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (.53.119.169 469ba60d9681f961064c-3cca6631dac1) Good: () -> Replace on reboot. [77ba1cb401a7360094cd2b47b8496799]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (2.53.119.169 469ba60d9681f961064c-3cca6631dac1b) Good: () -> Replace on reboot. [fd343a96a40488ae461bbab8b74a55ab]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (53.119.169 469ba60d9681f961064c-3cca6631dac1b499) Good: () -> Replace on reboot. [2011fad646623ff72d34135fea17946c]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (3.119.169 469ba60d9681f961064c-3cca6631dac1b4997d) Good: () -> Replace on reboot. [d061c60abdebf640cb963939ae533ac6]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (.119.169 469ba60d9681f961064c-3cca6631dac1b4997db) Good: () -> Replace on reboot. [56dbad23e5c3fd3994cd92e00cf59a66]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (.119.169 469ba60d9681f961064c-3cca6631dac1b) Good: () -> Replace on reboot. [55dc0cc49414b0862f326a089c6536ca]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: ( 92.53.119.169 469ba60d9681f961064c-3cca6) Good: () -> Replace on reboot. [6ec34888931504323a271959c53c1ee2]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (
92.53.119.169 469ba60d9681f961064c-3cca6631dac1b) Good: () -> Replace on reboot. [3bf6e2ee773195a148194d25e31edd23]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (19.169 469ba60d9681f961064c-3cca6631dac1) Good: () -> Replace on reboot. [38f98947b0f81d193d24a8ca71903ac6]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (
92.53.119.169 469ba60d9681f961064c-3cca6631dac1b49) Good: () -> Replace on reboot. [5ad708c8288037ff412085edfe03ae52]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (169 469ba60d9681f961064c-3cca6631dac1b4997db9) Good: () -> Replace on reboot. [2f028b45b3f5bb7b2f32b4bec23fda26]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (53.119.169 469ba60d9681f961064c-3cca6631dac1b4997) Good: () -> Replace on reboot. [042db020e4c48caa86db0270f60bb749]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: ( 92.53.119.169 469ba60d9681f961064c-3cca6631) Good: () -> Replace on reboot. [db56c10f3276013519487ff3ab5632ce]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (92.53.119.169 469ba60d9681f961064c-3cca6631) Good: () -> Replace on reboot. [c76a3b958f1976c028395220e918e41c]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: ( 92.53.119.169 469ba60d9681f961064c-3cca6631d) Good: () -> Replace on reboot. [53de7a563e6a033329388fe3b1504bb5]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (2.53.119.169 469ba60d9681f961064c-3cca6631d) Good: () -> Replace on reboot. [56db58785553bd79bba6650dc43dcd33]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (92.53.119.169 469ba60d9681f961064c-3cca6631dac1b499) Good: () -> Replace on reboot. [171ab9174068ee487de4ec865ba650b0]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (19.169 469ba60d9681f961064c-3cca6631dac1b49) Good: () -> Replace on reboot. [af8216ba8226b3835809cba77e830af6]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (92.53.119.169 469ba60d9681f961064c-3cca6631dac) Good: () -> Replace on reboot. [35fcc907396fdd593b26d99961a08f71]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (2.53.119.169 469ba60d9681f961064c-3cca6631dac) Good: () -> Replace on reboot. [e150d000a10754e24021dd95ed14e917]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: ( 92.53.119.169 469ba60d9681f961064c-3cca663) Good: () -> Replace on reboot. [ae832da3e3c56dc97ce597db30d13cc4]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: ( 92.53.119.169 469ba60d9681f961064c-3cca6631dac) Good: () -> Replace on reboot. [c46d0ec207a146f0e879cea438c902fe]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (53.119.169 469ba60d9681f961064c-3cca6631da) Good: () -> Replace on reboot. [70c1725e54545adccd943f33e120d52b]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (
92.53.119.169 469ba60d9681f961064c-3cca6631d) Good: () -> Replace on reboot. [18196a661b8d2e0870f1f97927da24dc]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (.53.119.169 469ba60d9681f961064c-3cca6631dac1b4997) Good: () -> Replace on reboot. [161b8e427137bf770f52274bf50c5ba5]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (119.169 469ba60d9681f961064c-3cca6631dac1b499) Good: () -> Replace on reboot. [62cf2aa6f4b4dd59adb49dd535cc06fa]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (2.53.119.169 469ba60d9681f961064c-3cca6631dac1) Good: () -> Replace on reboot. [c76a4c844b5dd26481e04d25748dac54]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (.53.119.169 469ba60d9681f961064c-3cca6631dac1b) Good: () -> Replace on reboot. [1a172da3e0c8a09682df81f1ba475fa1]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (.53.119.169 469ba60d9681f961064c-3cca6631dac1b49) Good: () -> Replace on reboot. [ea47d6fa2484bc7a68f9d79b976a837d]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (.119.169 469ba60d9681f961064c-3cca6631dac1b49) Good: () -> Replace on reboot. [a28f458b48609d99a8b95c16a8594ab6]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (53.119.169 469ba60d9681f961064c-3cca6631dac1b49) Good: () -> Replace on reboot. [013020b0684049edbaa78fe3a25fdb25]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (.119.169 469ba60d9681f961064c-3cca6631dac1b4997d) Good: () -> Replace on reboot. [48e92ba54c5cc2746ef3b9b9f30e9a66]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (3.119.169 469ba60d9681f961064c-3cca6631dac1b4997db921c0) Good: () -> Replace on reboot. [52df755bb7f11026b1b0f47ed52c2bd5]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (69 469ba60d9681f961064c-3cca6631dac1b4997db921c060b712f) Good: () -> Replace on reboot. [e84902cea7013afc86dbbcb64fb2f010]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (69 469ba60d9681f961064c-3cca6631dac1b4997db9) Good: () -> Replace on reboot. [4fe220b02e7a142287daf67c946d53ad]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (92.53.119.169 469ba60d9681f961064c-3cca6631d) Good: () -> Replace on reboot. [f63b25abccdc83b377eabfb3fb0606fa]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (92.53.119.169 469ba60d9681f961064c-3cca6631dac1b) Good: () -> Replace on reboot. [9b96ede3e4c45cdaf26fb0c2e51cfa06]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (3.119.169 469ba60d9681f961064c-3cca6631dac1b4) Good: () -> Replace on reboot. [ea474789beead95d540d9cd67889f808]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (2.53.119.169 469ba60d9681f961064c-3cca6631dac1b4997) Good: () -> Replace on reboot. [c36ee7e9d6d2d363abb6d99942bf8e72]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (53.119.169 469ba60d9681f961064c-3cca6631dac1b4997db9) Good: () -> Replace on reboot. [51e000d0783072c4045d462c0af7f60a]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (9.169 469ba60d9681f961064c-3cca6631dac1b49) Good: () -> Replace on reboot. [86ab06ca8c1c082e4e136c06d0319868]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (
92.53.119.169 469ba60d9681f961064c-3cca6631dac1) Good: () -> Replace on reboot. [b08107c9dfc95dd9a7ba2f43966b827e]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (.119.169 469ba60d9681f961064c-3cca6631dac1b499) Good: () -> Replace on reboot. [2011369accdcda5c01601b577e83e41c]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (2.53.119.169 469ba60d9681f961064c-3cca66) Good: () -> Replace on reboot. [3cf5e7e9f1b72412441de48e1ae75aa6]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (
92.53.119.169 469ba60d9681f961064c-3cca) Good: () -> Replace on reboot. [fd34ac24396fb284d78ae58d42bf5da3]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: ( 92.53.119.169 469ba60d9681f961064c-3cca6631dac1b) Good: () -> Replace on reboot. [65cc478997113006adb4264c08f9738d]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (.119.169 469ba60d9681f961064c-3cca6631dac1b4997) Good: () -> Replace on reboot. [161b11bf0e9a67cf20412f43a25f02fe]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (53.119.169 469ba60d9681f961064c-3cca6631dac) Good: () -> Replace on reboot. [ce635080fbadc373134ecfa3c9387b85]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (2.53.119.169 469ba60d9681f961064c-3cca6631dac1b4) Good: () -> Replace on reboot. [f0416e62f2b6ef47bda4027043be3bc5]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (3.119.169 469ba60d9681f961064c-3cca6631dac1b4997db92) Good: () -> Replace on reboot. [85ac4a86b1f7fb3b322f9ed45ca55da3]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (9.169 469ba60d9681f961064c-3cca6631dac1b499) Good: () -> Replace on reboot. [c56c5d7343658ea8fa671c562ad78f71]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: ( 92.53.119.169 469ba60d9681f961064c-3cca) Good: () -> Replace on reboot. [072a9c346345df575a071e543bc6639d]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (
92.53.119.169 469ba60d9681f961064c-3cca6631) Good: () -> Replace on reboot. [76bb01cf268258de461b363c4eb39070]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (3.119.169 469ba60d9681f961064c-3cca6631dac1b49) Good: () -> Replace on reboot. [1a1701cf4a5e2e08b8a93f3305fc49b7]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (.53.119.169 469ba60d9681f961064c-3cca6631dac1b4997db92) Good: () -> Replace on reboot. [01307a566e3a78be88d988ead42dc33d]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (169 469ba60d9681f961064c-3cca6631dac1b4997d) Good: () -> Replace on reboot. [022f9c34e0c845f1f170244e7a87ed13]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: ( 92.53.119.169 469ba60d9681f961064c-3cca6631dac1b4997db) Good: () -> Replace on reboot. [86ab339dc1e789ad1150640e37ca26da]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (69 469ba60d9681f961064c-3cca6631dac1b4997db921c060b7) Good: () -> Replace on reboot. [072aa03030781c1ae978254d10f105fb]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (9.169 469ba60d9681f961064c-3cca6631dac1b4997) Good: () -> Replace on reboot. [89a8cf016444ec4aa0c1304228d946ba]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (92.53.119.169 469ba60d9681f961064c-3cca66) Good: () -> Replace on reboot. [2d043b95693f76c0f56c3042e0219868]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (
92.53.119.169 469ba60d9681f961064c-3cca6) Good: () -> Replace on reboot. [90a14f81a6022b0b86dbf082f908eb15]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (
92.53.119.169 469ba60d9681f961064c-3cca6631da) Good: () -> Replace on reboot. [5ad7f0e0a9ff56e08fd2c4ae8f728977]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (3.119.169 469ba60d9681f961064c-3cca6631dac1b4997) Good: () -> Replace on reboot. [cb666e62b9efcc6a89d86a08bd449967]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (2.53.119.169 469ba60d9681f961064c-3cca6631dac1b499) Good: () -> Replace on reboot. [0829824e990f7bbb263b551dd52c60a0]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (119.169 469ba60d9681f961064c-3cca6631dac) Good: () -> Replace on reboot. [da5799373f6981b5e57cf37fee1355ab]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (
92.53.119.169 469ba60d9681f961064c-3cca6) Good: () -> Replace on reboot. [6dc46b658523f93d3b260c66010056aa]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (92.53.119.169 469ba60d9681f961064c-3cca6631dac1b4997) Good: () -> Replace on reboot. [d160cb051d8b78be90d1f082f20fb947]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (3.119.169 469ba60d9681f961064c-3cca6631dac1b4997db921) Good: () -> Replace on reboot. [85acffd1c5e3c2741c454c262ed3a858]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (.169 469ba60d9681f961064c-3cca6631dac1b4997db921c060b) Good: () -> Replace on reboot. [6bc69739ffa9ac8a68f9076b887924dc]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (.169 469ba60d9681f961064c-3cca6631dac1b4997db9) Good: () -> Replace on reboot. [c968a22e6147cc6ac69b284a5ca5da26]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (.53.119.169 469ba60d9681f961064c-3cca6631dac1b4997db921c) Good: () -> Replace on reboot. [a48d527ef4b441f50859531f29d8ca36]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (9 469ba60d9681f961064c-3cca6631dac1b4997db921) Good: () -> Replace on reboot. [e150a12fa20692a48fd288ea05fc9868]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (119.169 469ba60d9681f961064c-3cca6631dac1b4997db92) Good: () -> Replace on reboot. [ef422ba54662b97d86db6909a35ed22e]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (119.169 469ba60d9681f961064c-3cca6631dac1b4) Good: () -> Replace on reboot. [5bd63c94aff99d990d545c1645bcfb05]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (.119.169 469ba60d9681f961064c-3cca6631dac1b4) Good: () -> Replace on reboot. [74bd9b355b4d2f07055cc3afa0610ef2]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (
92.53.119.169 469ba60d9681f961064c-3cca6631dac) Good: () -> Replace on reboot. [57da15bbaafe9a9c1051c5adb150b947]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: ( 92.53.119.169 469ba60d9681f961064c-3cca6631dac1b499) Good: () -> Replace on reboot. [f33e913f81279e98d38ee191e31ec33d]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (9.169 469ba60d9681f961064c-3cca6631dac1b4997db921) Good: () -> Replace on reboot. [4ae7f0e0e3c5989e352c0270d130b050]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (53.119.169 469ba60d9681f961064c-3cca6631dac1b) Good: () -> Replace on reboot. [250c755bd2d6171fc69bf1815da4e719]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (9.169 469ba60d9681f961064c-3cca6631dac1b4997db921c06) Good: () -> Replace on reboot. [8da46769387075c18ad7452d59a88878]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (9.169 469ba60d9681f961064c-3cca6631dac1b4997d) Good: () -> Replace on reboot. [8aa75a76ecbc8bab97ca2f4327da4eb2]
C:\Windows\System32\drivers\etc\hosts (Hijack.HostFile) -> Bad: (3.119.169 469ba60d9681f961064c-3cca6631dac1) Good: () -> Replace on reboot. [87aa339d53552c0af170bdb5e02139c7]
Physical Sectors Detected: 0
(No malicious items detected)
(end)