You are on page 1of 8

Malwarebytes

www.malwarebytes.com

-Log Details-
Scan Date: 11/21/21
Scan Time: 1:03 AM
Log File: c70a5586-4a38-11ec-82d6-b4b5b67f1fba.json

-Software Information-
Version: 4.4.11.149
Components Version: 1.0.1513
Update Package Version: 1.0.47421
License: Trial

-System Information-
OS: Windows 10 (Build 19043.1348)
CPU: x64
File System: NTFS
User: Jigensh-PC\TASK MASTER

-Scan Summary-
Scan Type: Custom Scan
Scan Initiated By: Manual
Result: Cancelled
Objects Scanned: 939903
Threats Detected: 118
Threats Quarantined: 118
Time Elapsed: 6 hr, 1 min, 44 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 15
Spyware.PasswordStealer, HKU\S-1-5-21-3213672408-90157873-1817760974-1001\SOFTWARE\
ffdroider, Quarantined, 540, 954910, 1.0.47421, , ame, , ,
Trojan.Glupteba.E, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\
TASKCACHE\TASKS\{7DD7EB27-14BE-4A25-BA26-641A63AAF5F4}, Quarantined, 501, 781232, ,
, , , ,
Trojan.Glupteba.E, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\
TASKCACHE\LOGON\{7DD7EB27-14BE-4A25-BA26-641A63AAF5F4}, Quarantined, 501, 781232, ,
, , , ,
Trojan.Glupteba.E, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\
TASKCACHE\TREE\csrss, Quarantined, 501, 781232, 1.0.47421, , ame, , ,
Trojan.Glupteba.E, HKU\S-1-5-21-3213672408-90157873-1817760974-1001\SOFTWARE\
MICROSOFT\7a465d07, Quarantined, 501, 821174, 1.0.47421, , ame, , ,
Trojan.Downloader.E, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\
TASKCACHE\TREE\PowerControl HR, Quarantined, 2836, 982507, , , , , ,
Trojan.Downloader.E, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\
TASKCACHE\TASKS\{F69F257C-D0FC-4DC6-8F4D-123F5631059F}, Quarantined, 2836,
982507, , , , , ,
Trojan.Downloader.E, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\
TASKCACHE\PLAIN\{F69F257C-D0FC-4DC6-8F4D-123F5631059F}, Quarantined, 2836,
982507, , , , , ,
Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\
TREE\services32, Quarantined, 499, 988375, , , , , ,
Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\
TASKS\{C8E49926-ADA2-4069-B3F5-AB5BCB7D74BE}, Quarantined, 499, 988375, , , , , ,
Trojan.Agent, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\
LOGON\{C8E49926-ADA2-4069-B3F5-AB5BCB7D74BE}, Quarantined, 499, 988375, , , , , ,
Trojan.Downloader.E, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\
TASKCACHE\TREE\PowerControl LG, Quarantined, 2836, 982508, , , , , ,
Trojan.Downloader.E, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\
TASKCACHE\TASKS\{4B9CB6B9-70B7-476A-9F1A-D77B312FF326}, Quarantined, 2836,
982508, , , , , ,
Trojan.Downloader.E, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\
TASKCACHE\LOGON\{4B9CB6B9-70B7-476A-9F1A-D77B312FF326}, Quarantined, 2836,
982508, , , , , ,
Backdoor.Bifrose, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\
UNINSTALL\NewProduct 1.00, Quarantined, 1045, 172663, , , , , ,

Registry Value: 3
Trojan.Glupteba.E, HKU\S-1-5-21-3213672408-90157873-1817760974-1001\SOFTWARE\
MICROSOFT\7a465d07|CAMPAIGNID, Quarantined, 501, 821174, 1.0.47421, , ame, , ,
Trojan.Glupteba.E, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\
TASKCACHE\TASKS\{7DD7EB27-14BE-4A25-BA26-641A63AAF5F4}|PATH, Quarantined, 501,
781231, 1.0.47421, , ame, , ,
Trojan.Glupteba.E, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SHAREDACCESS\PARAMETERS\
FIREWALLPOLICY\FIREWALLRULES|{7EC4A79B-2039-4A04-ACD5-F0013E19B5AB}, Quarantined,
501, 795081, 1.0.47421, , ame, , ,

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 16
Backdoor.Bifrose, C:\Program Files (x86)\Company\NewProduct, Quarantined, 1045,
172663, 1.0.47421, , ame, , ,
Spyware.StolenData.E, C:\ProgramData\S4K3R8590NJFTFROAW2A9YW24\files\Wallets\
ElectronCash, Quarantined, 969, 697276, , , , , ,
Spyware.StolenData.E, C:\ProgramData\S4K3R8590NJFTFROAW2A9YW24\files\Wallets\
ElectrumLTC, Quarantined, 969, 697276, , , , , ,
Spyware.StolenData.E, C:\ProgramData\S4K3R8590NJFTFROAW2A9YW24\files\Wallets\
MultiDoge, Quarantined, 969, 697276, , , , , ,
Spyware.StolenData.E, C:\ProgramData\S4K3R8590NJFTFROAW2A9YW24\files\Wallets\
Electrum, Quarantined, 969, 697276, , , , , ,
Spyware.StolenData.E, C:\ProgramData\S4K3R8590NJFTFROAW2A9YW24\files\Wallets\
Jaxx_New, Quarantined, 969, 697276, , , , , ,
Spyware.StolenData.E, C:\ProgramData\S4K3R8590NJFTFROAW2A9YW24\files\Wallets\
Binance, Quarantined, 969, 697276, , , , , ,
Spyware.StolenData.E, C:\ProgramData\S4K3R8590NJFTFROAW2A9YW24\files\Wallets\
Coinomi, Quarantined, 969, 697276, , , , , ,
Spyware.StolenData.E, C:\ProgramData\S4K3R8590NJFTFROAW2A9YW24\files\Wallets\
Atomic, Quarantined, 969, 697276, , , , , ,
Spyware.StolenData.E, C:\ProgramData\S4K3R8590NJFTFROAW2A9YW24\files\Wallets\
Exodus, Quarantined, 969, 697276, , , , , ,
Spyware.StolenData.E, C:\ProgramData\S4K3R8590NJFTFROAW2A9YW24\files\Wallets\
Monero, Quarantined, 969, 697276, , , , , ,
Spyware.StolenData.E, C:\ProgramData\S4K3R8590NJFTFROAW2A9YW24\files\Wallets\JAXX,
Quarantined, 969, 697276, , , , , ,
Spyware.StolenData.E, C:\ProgramData\S4K3R8590NJFTFROAW2A9YW24\files\Wallets,
Quarantined, 969, 697276, 1.0.47421, , ame, , ,
Trojan.Ranumbot, C:\Users\TASK MASTER\AppData\Local\Temp\csrss\injector,
Quarantined, 3613, 995472, , , , , ,
Trojan.Ranumbot, C:\Users\TASK MASTER\AppData\Local\Temp\csrss, Quarantined, 3613,
995472, 1.0.47421, , ame, , ,
Trojan.Dropper, C:\Users\TASK MASTER\Documents\VlcpVideoV1.0.1, Quarantined, 590,
974953, 1.0.47421, , ame, , ,

File: 84
Trojan.Glupteba.E, C:\WINDOWS\SYSTEM32\TASKS\CSRSS, Quarantined, 501, 781232, , , ,
, F4CE396A3EC75A0120472D2FEB2EAA5D,
2E9A7D5EEC51D8BB627259C7A63C43BEB39AA79E1EFAA98C56BD3071EEA83FD8
Trojan.Downloader.E, C:\WINDOWS\SYSTEM32\TASKS\PowerControl HR, Quarantined, 2836,
982507, 1.0.47421, , ame, , 3580BF2BB6BC23C7286D759E0D7650B2,
4C59E6C617BEE3AB1EE6A288E363BC386B42853B35100D166DCCAB904EBF40FA
Trojan.Agent, C:\WINDOWS\SYSTEM32\TASKS\services32, Quarantined, 499, 988375, , , ,
, 2AF3CB67FBE47672DA4FB4FC3F1FAE62,
7866EF692CBFCDBB2024311967493BC5F8FBD80325CF9579F3A9B1F1A0241D6F
Trojan.Agent, C:\WINDOWS\SYSTEM32\SERVICES32.EXE, Delete-on-Reboot, 499, 988375,
1.0.47421, CFC572FBB9B17916C1867559, dds, 01518724,
41F68B65D2AF9150B1069B9A94F41E5A,
9DE683234BB62DD2A89D9A24B9139852FFE87A1A7F5FD0227E7D7D82E0E96248
Trojan.Downloader.E, C:\WINDOWS\SYSTEM32\TASKS\PowerControl LG, Quarantined, 2836,
982508, 1.0.47421, , ame, , D179B66EA4BABD4791227014E92FBBCB,
846E7B9C9F13199C3C4AAA08627E75843F15176D1EF8A5E91ACD8FFE9233EAF8
Backdoor.Bifrose, C:\Program Files (x86)\Company\NewProduct\d, Quarantined, 1045,
172663, , , , , ,
Backdoor.Bifrose, C:\Program Files (x86)\Company\NewProduct\d.INTEG.RAW,
Quarantined, 1045, 172663, , , , , ADEF430EB4A1049523DACA1A37BD5323,
7773B6D96E4C4F5CF50EF376B5160B65FA46A2D0924B5C401CE1462FB798C2D3
Backdoor.Bifrose, C:\Program Files (x86)\Company\NewProduct\d.jfm, Quarantined,
1045, 172663, , , , , 0B49149479EC279E78E7B9E6B2150498,
B0AA0A806B18A3AE40AA55C00081480A586FF31D727B16FCCACF8226C87ACD85
Backdoor.Bifrose, C:\Program Files (x86)\Company\NewProduct\p, Quarantined, 1045,
172663, , , , , 7FD775EEEF667E35DF70D694DD2E0962,
AFF914350B155D696D6E2921922E772608D4B7111C61F39F9A63D385EB0C5F7B
Backdoor.Bifrose, C:\Program Files (x86)\Company\NewProduct\rtst1039.exe, Delete-
on-Reboot, 1045, 172663, , , , , EDC2848872DCF17DA85C09279F524593,
4398DB0875261E516245B0B88959346305966440E943C06616DAAFD6351802EC
Backdoor.Bifrose, C:\Program Files (x86)\Company\NewProduct\Uninstall.exe, Delete-
on-Reboot, 1045, 172663, , , , , 56B3225C7B1D6F05B4BA4BA7B4CE2202,
B3A3C03A2B140D4FBE9BAC4416866210D014DA4C64355B395715F2D4C2506C46
Backdoor.Bifrose, C:\Program Files (x86)\Company\NewProduct\Uninstall.ini,
Quarantined, 1045, 172663, , , , , 1CC0C521F892B1E21A2CBA4A8764E5C9,
8F9010E6519A6A06FEB6524B6A0487441B14127D3F9C00C4EE2BB1F9C255D3AC
Trojan.Ranumbot, C:\Users\TASK MASTER\AppData\Local\Temp\csrss\injector\
NtQuerySystemInformationHook.dll, Delete-on-Reboot, 3613, 995472, , , , ,
09031A062610D77D685C9934318B4170,
778BD69AF403DF3C4E074C31B3850D71BF0E64524BEA4272A802CA9520B379DD
Trojan.Dropper, C:\Users\TASK MASTER\Documents\VlcpVideoV1.0.1\jg1_1faf.exe,
Delete-on-Reboot, 590, 974953, , , , , B1341B5094E9776B7ADBE69B2E5BD52B,
2B1AC64B2551B41CDA56FB0B072E9C9F303163FBB7F9D85E7313E193ECF75605
Adware.Csdimonetize, C:\PROGRAM FILES (X86)\BY DECEPTICON\DOFUKEKESU.EXE, Delete-
on-Reboot, 2929, 999235, 1.0.47421, , ame, , 2C175C596F60FCA676E7C8E1A9C1E638,
3BC2A2AAF899ED766179252CF084F7BD40F1944C8A608D21527E9F6012CC5B8A
Adware.Csdimonetize, C:\PROGRAM FILES (X86)\MCAFEE\CIMAMAXOHAE.EXE, Delete-on-
Reboot, 2929, 999235, 1.0.47421, , ame, , 2C175C596F60FCA676E7C8E1A9C1E638,
3BC2A2AAF899ED766179252CF084F7BD40F1944C8A608D21527E9F6012CC5B8A
RiskWare.MisusedLegit.E, C:\PROGRAMDATA\FREEBL3.DLL, Delete-on-Reboot, 3830,
820418, 1.0.47421, , ame, , EF2834AC4EE7D6724F255BEAF527E635,
A770ECBA3B08BBABD0A567FC978E50615F8B346709F8EB3CFACF3FAAB24090BA
RiskWare.MisusedLegit.E, C:\PROGRAMDATA\SOFTOKN3.DLL, Delete-on-Reboot, 3830,
820420, 1.0.47421, , ame, , A2EE53DE9167BF0D6C019303B7CA84E5,
43536ADEF2DDCC811C28D35FA6CE3031029A2424AD393989DB36169FF2995083
RiskWare.MisusedLegit.E, C:\PROGRAMDATA\VCRUNTIME140.DLL, Delete-on-Reboot, 3830,
820419, 1.0.47421, , ame, , 7587BF9CB4147022CD5681B015183046,
C40BB03199A2054DABFC7A8E01D6098E91DE7193619EFFBD0F142A7BF031C14D
RiskWare.MisusedLegit.E, C:\PROGRAMDATA\MSVCP140.DLL, Delete-on-Reboot, 3830,
820423, 1.0.47421, , ame, , 109F0F02FD37C84BFC7508D4227D7ED5,
334E69AC9367F708CE601A6F490FF227D6C20636DA5222F148B25831D22E13D4
RiskWare.MisusedLegit.E, C:\PROGRAMDATA\NSS3.DLL, Delete-on-Reboot, 3830, 820421,
1.0.47421, , ame, , BFAC4E3C5908856BA17D41EDCD455A51,
E2935B5B28550D47DC971F456D6961F20D1633B4892998750140E0EAA9AE9D78
RiskWare.MisusedLegit.E, C:\PROGRAMDATA\MOZGLUE.DLL, Delete-on-Reboot, 3830,
820422, 1.0.47421, , ame, , 8F73C08A9660691143661BF7332C3C27,
3FE6B1C54B8CF28F571E0C5D6636B4069A8AB00B4F11DD842CFEC00691D0C9CD
MachineLearning/Anomalous.100%, C:\USERS\TASK MASTER\APPDATA\LOCAL\MICROSOFT\
WINDOWS\INETCACHE\IE\IHMCLQZQ\FILE2[1].EXE, Delete-on-Reboot, 0, 392687, 1.0.47421,
, shuriken, , 1589564FFF006B127687D737A9CAFF76,
06838E246D98121DE289765A9DDFBD08927ABE1D946DA36C56BBDAD8E742902B
Trojan.MalPack.GS, C:\USERS\TASK MASTER\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCACHE\
IE\IJ3JOKW4\LOAD3[1].EXE, Delete-on-Reboot, 8032, 999306, 1.0.47421, , ame, ,
52A4AAB96984B740210CE3B0D39B7B1C,
C60DCA9B2972F1B24381E5BE94425981F38D98B817D2DD86C4A8F729C70C95E9
Generic.Malware/Suspicious, C:\USERS\TASK MASTER\APPDATA\LOCAL\MICROSOFT\WINDOWS\
INETCACHE\IE\F3CLL3AA\OUEST[1].EXE, Delete-on-Reboot, 0, 392686, 1.0.47421, ,
shuriken, , AA4ED5C8C8382938B17A5E7F29153320,
F7FDE2C53835B923D1FA60CFC8D2CB6EF71FCF4C94BE3450E7FDB4B37E8F99F0
Spyware.Socelars, C:\USERS\TASK MASTER\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCACHE\
IE\IJ3JOKW4\ASKINSTALL59[1].EXE, Delete-on-Reboot, 814, 831557, 1.0.47421, , ame, ,
BA34753B0D6ECC7D91B09F8B47BBB69D,
2CFF17660A9690F88C699456B097FA3496D542372E45373F7DC5EBB724AD3765
Trojan.Crypt.MSIL, C:\USERS\TASK MASTER\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCACHE\
IE\IJ3JOKW4\FILE3[1].EXE, Delete-on-Reboot, 5769, 993574, 1.0.47421, , ame, ,
801701713D269F94CF3431952A086410,
34CEEF759442B197A407FFA1D986C34F1BC617FAAEAEE36A14AA357CEC9C693A
Trojan.MalPack.GS, C:\USERS\TASK MASTER\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCACHE\
IE\IJ3JOKW4\UDPTEST[1].EXE, Delete-on-Reboot, 8032, 999306, 1.0.47421, , ame, ,
731325E2815F80053985CB49DCB78A73,
77F65F685F65F0496B9DE2936A1668C3463E13B9C9965F304887094F62177B85
Trojan.Injector, C:\USERS\TASK MASTER\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCACHE\IE\
F3CLL3AA\NICEPROCESSX64[1].BMP, Delete-on-Reboot, 726, 985021, 1.0.47421, , ame, ,
3F22BD82EE1B38F439E6354C60126D6D,
265C2DDC8A21E6FA8DFAA38EF0E77DF8A2E98273A1ABFB575AEF93C0CC8EE96A
MachineLearning/Anomalous.100%, C:\USERS\TASK MASTER\APPDATA\LOCAL\MICROSOFT\
WINDOWS\INETCACHE\IE\IJ3JOKW4\FILE1[1].EXE, Delete-on-Reboot, 0, 392687, 1.0.47421,
, shuriken, , 4437C351A4460C94E5A9F4C262635B0D,
B679ECB9FAEA4E95EEB356110AA5AE5307CAE20AFA2AA01BE673A59DCFEA1066
Trojan.Crypt.MSIL, C:\USERS\TASK MASTER\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCACHE\
IE\F3CLL3AA\FILE5[1].EXE, Delete-on-Reboot, 5769, 993574, 1.0.47421, , ame, ,
1BBE146EA055F970ACE17E0AFF3E9606,
835E496AFABAA0A2D8FBE0B8116D4F89C1C35485DB18D4F6EF6E2B093252A81E
Trojan.MalPack, C:\USERS\TASK MASTER\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCACHE\IE\
IHMCLQZQ\NULL[1], Delete-on-Reboot, 529, 998538, 1.0.47421, , ame, ,
F77D01F7E1D94598B490CA7A346BFD6F,
17F9B102C470CBB8AABAD5345FC5FE85B4448B2B3B9AED07DE437B15C9A28430
Trojan.Downloader, C:\USERS\TASK MASTER\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCACHE\
IE\IJ3JOKW4\SERVICE[1].BMP, Delete-on-Reboot, 528, 997803, 1.0.47421, , ame, ,
503A913A1C1F9EE1FD30251823BEAF13,
2C18D41DFF60FD0EF4BD2BC9F6346C6F6E0DE229E872E05B30CD3E7918CA4E5E
Trojan.MalPack.GS, C:\USERS\TASK MASTER\APPDATA\LOCAL\MICROSOFT\WINDOWS\INETCACHE\
IE\IJ3JOKW4\TOOLSPAB2[1].EXE, Delete-on-Reboot, 8032, 999306, 1.0.47421, , ame, ,
49B216188CD2F11A1D719A7B5CAD34A0,
68198296E77B2D1FC7F1554BC06B96DB90D5E82AF3C47EA50363B33F73DF7262
Trojan.SmokeLoader, C:\USERS\TASK MASTER\APPDATA\LOCAL\TEMP\OTW10TLK.OEB\ANY.EXE,
Delete-on-Reboot, 1175, 998512, 1.0.47421, 6E8916A1D461A40BEDA33935, dds, 01518724,
66264214F1B0368C2AA45D78030EFE5D,
CE811DE62F845811E767D18C64E32D7ED6DE68B18DDC689F9A1D12C511A13022
Spyware.Stealer, C:\USERS\TASK MASTER\APPDATA\LOCAL\TEMP\RRQDCFER.5YD\GCLEANER.EXE,
Delete-on-Reboot, 7295, 999198, 1.0.47421, 4BCD3D5BB1FEB216A19E682F, dds, 01518724,
D06FBB20A011E919FCB302184887137E,
5AFCC5898CF92278D9990AEDC236F1A174A4C91D8EB8F52C0330E8CA7E2312C0
Malware.Sandbox.1, C:\USERS\TASK MASTER\APPDATA\LOCAL\TEMP\RAR$EXB2820.41709\
SETUP.EXE, Delete-on-Reboot, 1, 0, 1.0.47421, 1, dds, 01518724,
436127406E05EF44A3565F3D0E09504F,
7F0B3FB7148C3A631CF0F67043F3EF72A382C0D4F1EBDB3251821B0A0DDE9AA4
Trojan.Crypt, C:\USERS\TASK MASTER\APPDATA\LOCAL\TEMP\
PIDHTSIGEI8DRAMAYU9K8GHN89.DLL, Delete-on-Reboot, 512, 985025, 1.0.47421,
A45A095A635CA9783DC49C43, dds, 01518724, F07AC9ECB112C1DD62AC600B76426BD3,
28859FA0E72A262E2479B3023E17EE46E914001D7F97C0673280A1473B07A8C0
Adware.Csdimonetize, C:\USERS\TASK MASTER\APPDATA\LOCAL\TEMP\42-7164C-0BE-CC1A5-
BCDEBCDA21B4F\QIPIJAEXYME.EXE, Delete-on-Reboot, 2929, 987441, 1.0.47421, , ame, ,
FFC2D01DBFDCFAE3EA2683CBA1D23145,
B34C0CDC7D961EF71DBCADC1A16F14B14BBC98452EBBA64718B1912FA6987373
Trojan.SmokeLoader, C:\USERS\TASK MASTER\APPDATA\LOCAL\TEMP\QJJ2JLZ4.0MV\ANY.EXE,
Delete-on-Reboot, 1175, 998512, 1.0.47421, 6E8916A1D461A40BEDA33935, dds, 01518724,
66264214F1B0368C2AA45D78030EFE5D,
CE811DE62F845811E767D18C64E32D7ED6DE68B18DDC689F9A1D12C511A13022
Adware.Csdimonetize, C:\USERS\TASK MASTER\APPDATA\LOCAL\TEMP\99-11BDC-48E-ECE84-
E2F0BEBA5148D\ZHOGYJAETOHU.EXE, Delete-on-Reboot, 2929, 987441, 1.0.47421, , ame, ,
FFC2D01DBFDCFAE3EA2683CBA1D23145,
B34C0CDC7D961EF71DBCADC1A16F14B14BBC98452EBBA64718B1912FA6987373
Trojan.Dropper.SFX, C:\USERS\TASK MASTER\APPDATA\LOCAL\TEMP\FL.EXE, Delete-on-
Reboot, 7146, 998536, 1.0.47421, 43488EBCEA994572EEDC0FD4, dds, 01518724,
E50C245E0EA8AF20E4D3553A2A547890,
5E7F30FDBF3D44387F28126D875B0EB24F7542C26317641CA97C886CB0677E30
Trojan.Crypt, C:\USERS\TASK MASTER\APPDATA\LOCAL\TEMP\WINLOGSON.EXE, Delete-on-
Reboot, 512, 998537, 1.0.47421, 2FD5740C268DE7E0A39AD67E, dds, 01518724,
88F7552E76576A0FAC58EAC38AFA47FA,
B17C4902A348727376C5E6B7877045D9BE5C7A31D5F06AE0AED89CB6A4855F97
Malware.Sandbox.1, C:\USERS\TASK MASTER\APPDATA\LOCAL\TEMP\IDHEJTHI.BPM\
BUMPERWW.EXE, Delete-on-Reboot, 1, 0, 1.0.47421, 1, dds, 01518724,
1F2783D940465CA818EEFD5C520F998A,
9DA006C01B502660745A2E7CB52C790368F376F7A2743AFEA10B89AD3713DEFE
Adware.Csdimonetize, C:\USERS\TASK MASTER\APPDATA\LOCAL\TEMP\06-99245-860-BD3B9-
5B27F0293B276\XAXEHADYSHY.EXE, Delete-on-Reboot, 2929, 991305, 1.0.47421, , ame, ,
0E0D42C0458316BD7693B442251D7FF2,
D8F09CEB5F0956277B36AF5B751C353891420250FC5AAB01538E8D78F5861934
MachineLearning/Anomalous.100%, C:\USERS\TASK MASTER\APPDATA\LOCAL\TEMP\MYPC.EXE,
Quarantined, 0, 392687, 1.0.47421, , shuriken, , 6DB2FF67ED0910A0A5855CA8E11313AC,
93FCF148E3E197B8B47F998645F9CBDC5492C2F11271AEA3BBAF3C0EEE9BD93D
Trojan.Dropper.NSIS, C:\USERS\TASK MASTER\APPDATA\LOCAL\TEMP\2BJ0ZKN3.TTV\
AUTOSUBPLAYER.EXE, Delete-on-Reboot, 7099, 994089, 1.0.47421, , ame, ,
8AA61FA9A80CABB15C66424259A10886,
C3438B068B728FED33B89357BD4CE88A11AEF841E96C7DEAB6099868391611A5
Trojan.Dropper.NSIS, C:\USERS\TASK MASTER\APPDATA\LOCAL\TEMP\PZ04GT5Y.AK0\
AUTOSUBPLAYER.EXE, Delete-on-Reboot, 7099, 994089, 1.0.47421, , ame, ,
8AA61FA9A80CABB15C66424259A10886,
C3438B068B728FED33B89357BD4CE88A11AEF841E96C7DEAB6099868391611A5
Malware.AI.4275287271, C:\USERS\TASK MASTER\APPDATA\LOCAL\TEMP\RWV4YYKF.WOZ\
RTST1045.EXE, Delete-on-Reboot, 1000000, 0, 1.0.47421, A683A7E598B17ACFFED3B4E7,
dds, 01518724, A8D3943A8DA4717BB569474900DBC703,
A026D098163797C17FF2C9E6B61464B4DFE8DEFEB1DC557CC20B99CE5B4F9EA5
Trojan.MalPack.GS, C:\USERS\TASK MASTER\APPDATA\LOCAL\TEMP\7D13.EXE, Delete-on-
Reboot, 8032, 999306, 1.0.47421, , ame, , 49B216188CD2F11A1D719A7B5CAD34A0,
68198296E77B2D1FC7F1554BC06B96DB90D5E82AF3C47EA50363B33F73DF7262
Legit.MisusedLegit, C:\USERS\TASK MASTER\APPDATA\LOCALLOW\QO7QM6FA3\MOZGLUE.DLL,
Delete-on-Reboot, 3703, 965519, 1.0.47421, , ame, ,
EAE9273F8CDCF9321C6C37C244773139,
A0C6630D4012AE0311FF40F4F06911BCF1A23F7A4762CE219B8DFFA012D188CC
Trojan.Crypt.MSIL.Generic, C:\USERS\TASK MASTER\APPDATA\LOCAL\TEMP\ECC8.EXE,
Delete-on-Reboot, 7142, 979714, 1.0.47421, 5012550B4DFF51BDB8819C57, dds, 01518724,
5E34695C9F46F1E69CE731D3B7359C88,
97F96815D81F9C1C8EDE31F1C21FDA2BEE7CBAB3490184EF833D9D2E8C17E6FC
Adware.Csdimonetize, C:\USERS\TASK MASTER\APPDATA\LOCAL\TEMP\A9-7B9F1-D8F-EFE80-
88A281DE856AD\TOMIBETOQI.EXE, Delete-on-Reboot, 2929, 991305, 1.0.47421, , ame, ,
0E0D42C0458316BD7693B442251D7FF2,
D8F09CEB5F0956277B36AF5B751C353891420250FC5AAB01538E8D78F5861934
Trojan.Crypt.MSIL.Generic, C:\USERS\TASK MASTER\APPDATA\LOCAL\TEMP\727.EXE, Delete-
on-Reboot, 7142, 998987, 1.0.47421, 0000000000000000000003EB, dds, 01518724,
AE5D96E92ED87FF6C2FDD52C7F3C6160,
4186DB92AEBADC350B2B991F5EA2430F4AB9901FA1A581BA8661887294D74351
Trojan.MalPack.Themida, C:\USERS\TASK MASTER\APPDATA\LOCAL\TEMP\D920.EXE, Delete-
on-Reboot, 7097, 999255, 1.0.47421, 0000000000000000000003EB, dds, 01518724,
264C695E55BDDC219ECD5EEDA48A2120,
EAFD85C5721D9FD40847EE9CB954A153506E190E6933514DDD2CFD835CA252E9
Legit.MisusedLegit, C:\USERS\TASK MASTER\APPDATA\LOCALLOW\QO7QM6FA3\NSS3.DLL,
Delete-on-Reboot, 3703, 965520, 1.0.47421, , ame, ,
02CC7B8EE30056D5912DE54F1BDFC219,
1989526553FD1E1E49B0FEA8036822CA062D3D39C4CAB4A37846173D0F1753D5
Trojan.ClipBanker, C:\USERS\TASK MASTER\APPDATA\ROAMING\6708401.EXE, Delete-on-
Reboot, 4282, 982300, 1.0.47421, 0000000000000000000003EB, dds, 01518724,
23A3EB5908354BC3BD9CE9AC45F31A1E,
9336FDD90856DD2C65BB187EBE90AF827C50207487BCA27EB54B6D0E6C9E1D56
Trojan.Agent, C:\USERS\TASK MASTER\APPDATA\ROAMING\MONITOR.EXE, Delete-on-Reboot,
499, 988375, 1.0.47421, CFC572FBB9B17916C1867559, dds, 01518724,
41F68B65D2AF9150B1069B9A94F41E5A,
9DE683234BB62DD2A89D9A24B9139852FFE87A1A7F5FD0227E7D7D82E0E96248
Spyware.PasswordStealer, C:\USERS\TASK MASTER\APPDATA\ROAMING\844943.EXE, Delete-
on-Reboot, 540, 999160, 1.0.47421, 0000000000000000000003EB, dds, 01518724,
2D3671A83EDF40422FD7751BC635C880,
3AB65D82225552864419B544B5A8132DBD7BFF7E319D925939E99F42CC4C27CA
Trojan.MalPack.Themida, C:\USERS\TASK MASTER\APPDATA\ROAMING\6456721.EXE, Delete-
on-Reboot, 7097, 999255, 1.0.47421, 0000000000000000000003EB, dds, 01518724,
C38AC9DAA40FB83A8DFB7492498FFAFB,
F203D1D54823E1B2FDA8D8A2EC4D0EEFF28ECB81C48EF9569A49EB69D8A46CEC
Spyware.PasswordStealer.MSIL, C:\USERS\TASK MASTER\APPDATA\ROAMING\6154036.EXE,
Delete-on-Reboot, 7466, 999143, 1.0.47421, 0000000000000000000003EB, dds, 01518724,
B1F858297D47188BC4A324B29E978CFA,
74C40A2DD32CBCBED962E881FDDEA6A359F4D4B71CAB690C37AA4B09275F19FA
Spyware.PasswordStealer, C:\USERS\TASK MASTER\APPDATA\ROAMING\HENO.EXE, Delete-on-
Reboot, 540, 995551, 1.0.47421, 5827C7141AAE11EDC28AB2BE, dds, 01518724,
5988B5E6BC658EADCDD1318C0C3C0D91,
B8A97E6BC7F8FD4A3C3F1CDC4183CBAE2A48262B8E352E5169C2B647696AB1B8
Trojan.Downloader, C:\USERS\TASK MASTER\APPDATA\ROAMING\2232050.EXE, Delete-on-
Reboot, 528, 990119, 1.0.47421, 0000000000000000000003EB, dds, 01518724,
C0D4102BC530B466D82C95834CF47F6C,
BC20F615E19EA37E51E1A98A0E3CE84534DA7B9B352E288921B1C171D6F3728D
Trojan.MalPack.Themida, C:\USERS\TASK MASTER\APPDATA\ROAMING\8906560.EXE, Delete-
on-Reboot, 7097, 999255, 1.0.47421, 0000000000000000000003EB, dds, 01518724,
2F261A88DF5A4E82AD94158B48934898,
B88EBAF19290ABD97D8240E17802023C6489D351AEBA47F25970BFD2131FBD27
Trojan.Crypt.MSIL, C:\USERS\TASK MASTER\APPDATA\ROAMING\FORE.EXE, Delete-on-Reboot,
5769, 993574, 1.0.47421, , ame, , 9C615B6B1E28E42040B618FB634ADAD7,
76BB47A862406207A8E60779AB38A7A335B54AA893384C5F3A275059FDDFCF55
Generic.Malware/Suspicious, C:\USERS\TASK MASTER\PICTURES\ADOBE FILMS\
_2IWMTK21GNRCE_BF3AYJOBE.EXE, Delete-on-Reboot, 0, 392686, 1.0.47421, , shuriken, ,
AA4ED5C8C8382938B17A5E7F29153320,
F7FDE2C53835B923D1FA60CFC8D2CB6EF71FCF4C94BE3450E7FDB4B37E8F99F0
Trojan.Crypt.MSIL, C:\USERS\TASK MASTER\PICTURES\ADOBE FILMS\
AWNWC7J8FW6UOXF3WSXCCXP4.EXE, Delete-on-Reboot, 5769, 993574, 1.0.47421, , ame, ,
801701713D269F94CF3431952A086410,
34CEEF759442B197A407FFA1D986C34F1BC617FAAEAEE36A14AA357CEC9C693A
Trojan.Downloader, C:\USERS\TASK MASTER\PICTURES\ADOBE FILMS\
SOJOP8HE_FRTGDGFKROXEBOM.EXE, Delete-on-Reboot, 528, 997803, 1.0.47421,
96883FBA31973EA745446863, dds, 01518724, 503A913A1C1F9EE1FD30251823BEAF13,
2C18D41DFF60FD0EF4BD2BC9F6346C6F6E0DE229E872E05B30CD3E7918CA4E5E
Trojan.MalPack.Themida, C:\USERS\TASK MASTER\PICTURES\ADOBE FILMS\
5J8HCJQJJT_E7XP0M2ID44FN.EXE, Delete-on-Reboot, 7097, 999255, 1.0.47421,
0000000000000000000003EB, dds, 01518724, 600D0D33CCF36FD5A6A12749C4AB858A,
18180971E55C15C559D1458FF404D84AAFEEC1918F45B1FCD350A7CF9D865AFD
Trojan.MalPack.Themida, C:\USERS\TASK MASTER\PICTURES\ADOBE FILMS\
LYRXSCHL0KGDEFE35RCWZ_VS.EXE, Delete-on-Reboot, 7097, 999255, 1.0.47421,
0000000000000000000003EB, dds, 01518724, E8B102F18B4C7F66467E361012D2F679,
68B1319AC921BCD9E7C30E55687116DF9B76158F907EF4A4440E77F44C49D603
Spyware.Socelars, C:\USERS\TASK MASTER\PICTURES\ADOBE FILMS\
BEPRUF9GSXBF6JYBDAFXR8SE.EXE, Delete-on-Reboot, 814, 831557, 1.0.47421,
24CFE6160890562D9AE92A0F, dds, 01518724, BA34753B0D6ECC7D91B09F8B47BBB69D,
2CFF17660A9690F88C699456B097FA3496D542372E45373F7DC5EBB724AD3765
Trojan.MalPack.Themida, C:\USERS\TASK MASTER\PICTURES\ADOBE FILMS\
PZRXFEYNCSJZV63UE9USKAD6.EXE, Delete-on-Reboot, 7097, 999255, 1.0.47421,
0000000000000000000003EB, dds, 01518724, E8B102F18B4C7F66467E361012D2F679,
68B1319AC921BCD9E7C30E55687116DF9B76158F907EF4A4440E77F44C49D603
Trojan.MalPack.GS, C:\USERS\TASK MASTER\PICTURES\ADOBE FILMS\
XBOA2B88_ZCIKFC2IRFPCGKU.EXE, Delete-on-Reboot, 8032, 999306, 1.0.47421, , ame, ,
52A4AAB96984B740210CE3B0D39B7B1C,
C60DCA9B2972F1B24381E5BE94425981F38D98B817D2DD86C4A8F729C70C95E9
Malware.AI.4275287271, C:\USERS\TASK MASTER\PICTURES\ADOBE FILMS\
O6AONA_M067Y3R6TS_0IGDNI.EXE, Delete-on-Reboot, 1000000, 0, 1.0.47421,
A683A7E598B17ACFFED3B4E7, dds, 01518724, 18B59E79AC40C081B719C1B8D6C6CF32,
7A0FB647C62E46B48095BB37E4A4750288AD5D062F34121769ACD94CB864A478
Trojan.MalPack.GS, C:\USERS\TASK MASTER\PICTURES\ADOBE FILMS\
T_GUS1SU0GHKGITKIKU_I9E0.EXE, Delete-on-Reboot, 8032, 999306, 1.0.47421, , ame, ,
57040C6E10E3D2F1CFEF511107540D78,
75640178A295D9C64991B727380D79EC641918BACD5778496E8C831F2774D5E1
Trojan.Crypt.MSIL, C:\USERS\TASK MASTER\PICTURES\ADOBE FILMS\
_ZXONBXOWS1BALO6HB4E9R3K.EXE, Delete-on-Reboot, 5769, 993574, 1.0.47421, , ame, ,
1BBE146EA055F970ACE17E0AFF3E9606,
835E496AFABAA0A2D8FBE0B8116D4F89C1C35485DB18D4F6EF6E2B093252A81E
Trojan.Injector, C:\USERS\TASK MASTER\PICTURES\ADOBE FILMS\
MTYMN9UCKGPNBQFBWA9K2E9C.EXE, Delete-on-Reboot, 726, 985021, 1.0.47421,
A45A095A635CA9783DC49C43, dds, 01518724, 3F22BD82EE1B38F439E6354C60126D6D,
265C2DDC8A21E6FA8DFAA38EF0E77DF8A2E98273A1ABFB575AEF93C0CC8EE96A
Trojan.Downloader, C:\USERS\TASK MASTER\PICTURES\ADOBE FILMS\
RGMAESAQ68CE1HJXTBCPWGLV.EXE, Delete-on-Reboot, 528, 990119, 1.0.47421,
0000000000000000000003EB, dds, 01518724, 7CDF8D9CE9BADD1BD1EA5DE381D7FA87,
E895409CD5BCE9948A05378750604C6749270C47D96452B1FF881C073A104E1B
Trojan.MalPack, C:\USERS\TASK MASTER\PICTURES\ADOBE FILMS\
0ZHRLEN6VRJY1FBKJVSWBKSK.EXE, Delete-on-Reboot, 529, 998538, 1.0.47421,
0000000000000000000003EB, dds, 01518724, C8F92704CDEEA742BAFFDD2850C6447F,
944788DC55E273F39EE26C7EE8B11193030188E4A78A79CDC560856E1817D7AD
Spyware.PasswordStealer, C:\USERS\TASK MASTER\PICTURES\ADOBE FILMS\
BL3LU3WWBFCWIBEXZRKBPKX6.EXE, Delete-on-Reboot, 540, 998493, 1.0.47421,
0000000000000000000003EB, dds, 01518724, 851D245E2D7BC792C2A0E0500311346C,
AC26113D4703CE8B938D160886F652F9C692A3C4EC101E0456671BEFD6B6983A
Trojan.MalPack.GS, C:\USERS\TASK MASTER\PICTURES\ADOBE FILMS\
U93GQ2DWAWVPM959XBO5M4RX.EXE, Delete-on-Reboot, 8032, 999306, 1.0.47421, , ame, ,
E124902132723C55B212D5A68E287B61,
5E97B7317444AE61103A3ED13CB90118D0D7E92153EC3694A41BE8FA6F497832
Trojan.MalPack.GS, C:\USERS\TASK MASTER\PICTURES\ADOBE FILMS\
1VP76OAOCKKDFMDXJPNVEPG7.EXE, Delete-on-Reboot, 8032, 999306, 1.0.47421, , ame, ,
731325E2815F80053985CB49DCB78A73,
77F65F685F65F0496B9DE2936A1668C3463E13B9C9965F304887094F62177B85
Trojan.MalPack.GS, C:\USERS\TASK MASTER\PICTURES\ADOBE FILMS\
DF1G1CK9TCKRGHQCBERVFMON.EXE, Delete-on-Reboot, 8032, 999306, 1.0.47421, , ame, ,
0B85CFAAE0A2ACB127720A3BA710D477,
0F250D6B17EA5ABBE5D9F0E0904058876024F5A0F462552FB1CCE35C43F40883
Trojan.MalPack.Themida, C:\USERS\TASK MASTER\PICTURES\ADOBE FILMS\
WZX3FKAF7J2XJVYRQNZEMFHX.EXE, Delete-on-Reboot, 7097, 999255, 1.0.47421,
0000000000000000000003EB, dds, 01518724, 73EFE178D604CB4CA7DBC799869A6D8B,
3C10B83666B2C8A4875C3F0A6D6C08099C4749975F321C2CC035D49C77C2B248

Physical Sector: 0
(No malicious items detected)

WMI: 0
(No malicious items detected)

(end)

You might also like