[RESOLVED] Freshy Services / Tightrope
Hi,
Followed instructions and posted files requested.
Thanks in advance for your time and your help!
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 11/12/2014
Scan Time: 8:48:32 PM
Logfile: mbam scan 11-12-14.txt
Administrator: Yes
Version: 2.00.3.1025
Malware Database: v2014.11.13.01
Rootkit Database: v2014.11.12.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Kathy
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 337145
Time Elapsed: 24 min, 24 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Warn
PUM: Enabled
Processes: 4
Adware.PremierOpinion, C:\Program Files (x86)\PremierOpinion\pmservice.exe, 2144, Delete-on-Reboot, [a89d46f52a5261d56be7ccfa58a88f71]
Adware.PremierOpinion, C:\Program Files (x86)\PremierOpinion\pmropn.exe, 4116, Delete-on-Reboot, [fb4af04b9ae24de91c363a8c22de758b]
Adware.PremierOpinion, C:\Program Files (x86)\PremierOpinion\pmropn32.exe, 4496, Delete-on-Reboot, [72d3a09b6f0d54e2f45e20a635cb2fd1]
Adware.PremierOpinion, C:\Program Files (x86)\PremierOpinion\pmropn64.exe, 6068, Delete-on-Reboot, [49fc47f4ed8f81b5b1a1e7dfed137e82]
Modules: 1
Adware.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\pmnx.dll, Delete-on-Reboot, [1f26122994e8b08659f9d5f133cddc24],
Registry Keys: 10
PUP.Optional.SweetIM.A, HKU\S-1-5-21-61633527-4084290942-2707624099-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{DEDAF650-12B8-48F5-A843-BBA100716106}, No Action By User, [fd48cb70413b66d043b9d4e7b74baa56],
PUP.Optional.SearchYah.A, HKLM\SOFTWARE\CLASSES\esrv.searchyaESrvc, No Action By User, [133257e479036acca202203ed23134cc],
PUP.Optional.SearchYah.A, HKLM\SOFTWARE\CLASSES\esrv.searchyaESrvc.1, No Action By User, [67ded6654d2f023460441a448f7446ba],
PUP.Optional.FunMoods.A, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\cjpglkicenollcignonpgiafdgfeehoj, No Action By User, [093c86b5bfbd95a10efaf17336ced62a],
PUP.Optional.SearchYah.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.searchyaESrvc, No Action By User, [232263d857250e2871335608fe05946c],
PUP.Optional.SearchYah.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.searchyaESrvc.1, No Action By User, [a79e43f8c4b8f640b2f2b4aa7a89e818],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-61633527-4084290942-2707624099-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, No Action By User, [90b53803304ce254ce8f9305917338c8],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-61633527-4084290942-2707624099-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, No Action By User, [87be3b00df9de84efd27067e05ffe31d],
Adware.PremierOpinion, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\PremierOpinion, Quarantined, [a89d46f52a5261d56be7ccfa58a88f71],
Adware.PremierOpinion, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{eeb86aef-4a5d-4b75-9d74-f16d438fc286}, Quarantined, [fb4af04b9ae24de91c363a8c22de758b],
Registry Values: 2
PUP.Optional.OpinionSquare.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|{C7AE725D-FA5C-4027-BB4C-787EF9F8248A}, C:\Program Files (x86)\PremierOpinion\firefox, No Action By User, [f154ef4ceb910f27c36ece8440c31ce4]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-61633527-4084290942-2707624099-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0D1L2S2X1M1M0O1J1O2R1N, No Action By User, [87be3b00df9de84efd27067e05ffe31d]
Registry Data: 0
(No malicious items detected)
Folders: 39
PUP.Optional.Updater.A, C:\Users\Kathy\AppData\Roaming\DSite\UpdateProc, No Action By User, [87bedb6095e770c67720a37cb84b4ab6],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion, Delete-on-Reboot, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\components, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox, Delete-on-Reboot, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\defaults, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\defaults\preferences, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\addon, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\console, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\content, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\core, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\events, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\traits, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\dom, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\event, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\io, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\l10n, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\lang, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\loader, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\net, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\page-mod, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\platform, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\preferences, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\private-browsing, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\private-browsing\window, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\system, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\util, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\window, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\windows, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\toolkit, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\dpjs, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\dpjs\data, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\dpjs\lib, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Adware.PremierOpinion, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PremierOpinion, Quarantined, [80c5de5df28ac670a25d7981758d36ca],
Files: 127
PUP.Optional.InstallCore, C:\Users\Kathy\Downloads\PDFReaderSetup.exe, No Action By User, [9aab47f49ae2aa8c7413c4613fc2ce32],
PUP.Optional.GoForFiles.A, C:\Users\Kathy\Downloads\Van_Halen-Ice_Cream_Man_mp3_downloader_us_98975(1).exe, No Action By User, [87be90abf28ae551200473c179888080],
PUP.Optional.GoForFiles.A, C:\Users\Kathy\Downloads\Van_Halen-Ice_Cream_Man_mp3_downloader_us_98975.exe, No Action By User, [49fc3cff265683b33de77eb6be4353ad],
PUP.Optional.Updater.A, C:\Users\Kathy\AppData\Roaming\DSite\UpdateProc\prod.dat, No Action By User, [87bedb6095e770c67720a37cb84b4ab6],
PUP.Optional.CrossRider.A, C:\Users\Kathy\AppData\Roaming\Mozilla\Firefox\Profiles\rsrsrm2w.default\prefs.js, Good: (), Bad: (user_pref("extensions.crossrider.bic", "13ce5789f07ff858c89bd171bdf6bd1c");), No Action By User,[a5a096a5324a79bd88bd5b21a65f6898]
Adware.PremierOpinion, C:\Program Files (x86)\PremierOpinion\pmservice.exe, Delete-on-Reboot, [a89d46f52a5261d56be7ccfa58a88f71],
Adware.PremierOpinion, C:\Program Files (x86)\PremierOpinion\pmropn.exe, Delete-on-Reboot, [fb4af04b9ae24de91c363a8c22de758b],
Adware.PremierOpinion, C:\Program Files (x86)\PremierOpinion\pmropn32.exe, Delete-on-Reboot, [72d3a09b6f0d54e2f45e20a635cb2fd1],
Adware.PremierOpinion, C:\Program Files (x86)\PremierOpinion\pmropn64.exe, Delete-on-Reboot, [49fc47f4ed8f81b5b1a1e7dfed137e82],
Adware.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\pmnx.dll, Delete-on-Reboot, [1f26122994e8b08659f9d5f133cddc24],
Adware.PremierOpinion, C:\Program Files (x86)\PremierOpinion\pmls.dll, Quarantined, [a89d1724e993ea4c99b9e7dfbc44ab55],
Adware.PremierOpinion, C:\Program Files (x86)\PremierOpinion\pmls64.dll, Quarantined, [6bdaae8d8bf1181edc76c8fe06faae52],
Adware.PremierOpinion, C:\Program Files (x86)\PremierOpinion\pmph.dll, Quarantined, [63e20338215bb3838cc60bbb966ae31d],
Adware.PremierOpinion, C:\Program Files (x86)\PremierOpinion\pmxf.dll, Quarantined, [71d44bf086f667cfd87aa91da0607e82],
Adware.PremierOpinion, C:\Windows\System32\pmls64.dll, Delete-on-Reboot, [77ce5dde4c3066d022302c9af10f748c],
Adware.PremierOpinion, C:\Windows\SysWOW64\pmls.dll, Delete-on-Reboot, [b39272c9b3c9082e5200a71f986821df],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\chrome.manifest, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\install.rdf, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\nscf.dat, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\pmcm.crx, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\pmcm.txt, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\pmoci.bin, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\readme.txt, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\components\pmxg.dll, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\bootstrap.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\harness-options.json, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\install.rdf, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\locales.json, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\defaults\preferences\prefs.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\chrome.manifest, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\base64.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\page-mod.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\private-browsing.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\self.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\system.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\timers.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\url.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\windows.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\addon\runner.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\console\plain-text.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\console\traceback.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\content\content-proxy.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\content\content-worker.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\content\loader.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\content\thumbnail.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\content\worker.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\core\heritage.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\core\namespace.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\core\promise.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\api-utils.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\cortex.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\errors.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\events.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\light-traits.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\list.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\memory.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\observer-service.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\traits.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\window-utils.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\events\assembler.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\traits\core.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\dom\events.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\event\core.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\event\target.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\io\byte-streams.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\io\data.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\io\file.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\io\text-streams.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\l10n\core.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\l10n\html.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\l10n\loader.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\l10n\locale.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\l10n\prefs.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\lang\functional.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\loader\cuddlefish.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\loader\sandbox.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\net\url.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\page-mod\match-pattern.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\platform\xpcom.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\preferences\service.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\private-browsing\utils.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\private-browsing\window\utils.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\system\environment.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\system\events.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\system\globals.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\system\runtime.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\system\unload.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\system\xul-app.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\common.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\events.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\helpers.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\namespace.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\observer.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\tab-fennec.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\tab-firefox.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\tab.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\tabs-firefox.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\tabs.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\utils.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\worker.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\util\array.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\util\deprecate.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\util\list.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\util\object.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\util\registry.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\util\uuid.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\window\browser.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\window\namespace.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\window\utils.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\windows\dom.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\windows\fennec.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\windows\firefox.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\windows\loader.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\windows\observer.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\windows\tabs-fennec.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\windows\tabs-firefox.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\toolkit\loader.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\dpjs\data\content.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\dpjs\lib\dompilot.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\dpjs\lib\dputil.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Trojan.Agent, C:\Program Files (x86)\PremierOpinion\firefox\resources\dpjs\lib\main.js, Quarantined, [a2a30b3065171e183d87c82f758d936d],
Adware.PremierOpinion, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PremierOpinion\About PremierOpinion.lnk, Quarantined, [80c5de5df28ac670a25d7981758d36ca],
Adware.PremierOpinion, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PremierOpinion\Member of GRID - Goodware Repository Information Database.lnk, Quarantined, [80c5de5df28ac670a25d7981758d36ca],
Adware.PremierOpinion, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PremierOpinion\Privacy Policy and User License Agreement.lnk, Quarantined, [80c5de5df28ac670a25d7981758d36ca],
Adware.PremierOpinion, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PremierOpinion\Support.lnk, Quarantined, [80c5de5df28ac670a25d7981758d36ca],
Adware.PremierOpinion, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PremierOpinion\Uninstall Instructions.lnk, Quarantined, [80c5de5df28ac670a25d7981758d36ca],
Physical Sectors: 0
(No malicious items detected)
(end)
Not enough coffee yet this morning....
Hi Again
Not sure if the report under each tab of the scan is different or not. Let me know please. Thanks again! :)
RogueKiller V10.0.6.0 [Nov 13 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com
Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : Kathy [Administrator]
Mode : Delete -- Date : 11/16/2014 07:20:16
¤¤¤ Processes : 0 ¤¤¤
¤¤¤ Registry : 26 ¤¤¤
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0068001354159123mcinstcleanup (C:\Users\Kathy\AppData\Local\Temp\006800~1.EXE -cleanup -nolog) -> Not selected
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\0068001354159123mcinstcleanup (C:\Users\Kathy\AppData\Local\Temp\006800~1.EXE -cleanup -nolog) -> Not selected
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\0068001354159123mcinstcleanup (C:\Users\Kathy\AppData\Local\Temp\006800~1.EXE -cleanup -nolog) -> Not selected
[PUM.Proxy] (X64) HKEY_USERS\S-1-5-21-61633527-4084290942-2707624099-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1 -> Not selected
[PUM.Proxy] (X86) HKEY_USERS\S-1-5-21-61633527-4084290942-2707624099-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1 -> Not selected
[PUM.Proxy] (X64) HKEY_USERS\S-1-5-21-61633527-4084290942-2707624099-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1 -> Not selected
[PUM.Proxy] (X86) HKEY_USERS\S-1-5-21-61633527-4084290942-2707624099-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1 -> Not selected
[PUM.Proxy] (X64) HKEY_USERS\S-1-5-21-61633527-4084290942-2707624099-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : localhost:21320 -> Not selected
[PUM.Proxy] (X86) HKEY_USERS\S-1-5-21-61633527-4084290942-2707624099-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : localhost:21320 -> Not selected
[PUM.Proxy] (X64) HKEY_USERS\S-1-5-21-61633527-4084290942-2707624099-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : localhost:21320 -> Not selected
[PUM.Proxy] (X86) HKEY_USERS\S-1-5-21-61633527-4084290942-2707624099-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : localhost:21320 -> Not selected
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-61633527-4084290942-2707624099-1000\Software\Microsoft\Internet Explorer\Main | Start Page : http://google.com/ -> Not selected
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-61633527-4084290942-2707624099-1000\Software\Microsoft\Internet Explorer\Main | Start Page : http://google.com/ -> Not selected
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-61633527-4084290942-2707624099-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main | Start Page : http://google.com/ -> Not selected
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-61633527-4084290942-2707624099-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main | Start Page : http://google.com/ -> Not selected
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 192.168.1.1 68.105.28.11 68.105.29.11 68.105.28.12 [UNITED STATES (US)][UNITED STATES (US)][UNITED STATES (US)] -> Not selected
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 192.168.1.1 68.105.28.11 68.105.29.11 68.105.28.12 [UNITED STATES (US)][UNITED STATES (US)][UNITED STATES (US)] -> Not selected
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{37718098-9F8D-4873-8604-2F510CF089D8} | DhcpNameServer : 192.168.1.1 68.105.28.11 68.105.29.11 68.105.28.12 [UNITED STATES (US)][UNITED STATES (US)][UNITED STATES (US)] -> Not selected
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C933AF2F-A6BB-4C6D-BE57-0767DE394CD0} | DhcpNameServer : 10.40.47.1 [(Private Address) (XX)] -> Not selected
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{37718098-9F8D-4873-8604-2F510CF089D8} | DhcpNameServer : 192.168.1.1 68.105.28.11 68.105.29.11 68.105.28.12 [UNITED STATES (US)][UNITED STATES (US)][UNITED STATES (US)] -> Not selected
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{C933AF2F-A6BB-4C6D-BE57-0767DE394CD0} | DhcpNameServer : 10.40.47.1 [(Private Address) (XX)] -> Not selected
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{C933AF2F-A6BB-4C6D-BE57-0767DE394CD0} | DhcpNameServer : 10.40.47.1 [(Private Address) (XX)] -> Not selected
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Not selected
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Not selected
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Not selected
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Not selected
¤¤¤ Tasks : 2 ¤¤¤
[Suspicious.Path] \\4694 -- wscript.exe (C:\Users\Kathy\AppData\Local\Temp\launchie.vbs //B) -> ERROR [0]
[Suspicious.Path] \\Searchya -- C:\Users\Kathy\AppData\Roaming\Searchya\UPDATE~1\UPDATE~1.EXE (/Check) -> ERROR [0]
¤¤¤ Files : 0 ¤¤¤
¤¤¤ Hosts File : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Not loaded [0xc000036b]) ¤¤¤
¤¤¤ Web browsers : 1 ¤¤¤
[PUM.HomePage][FIREFX:Config] rsrsrm2w.default : user_pref("browser.startup.homepage", "http://services.freshy.com/general/newhometab.php?hometab=home&partner=11075&guid={4E0071CA-C3CC-4634-BB3D-0B5BD9E47D70}&i="); -> Not selected
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: Hitachi HTS547575A9E384 +++++
--- User ---
[MBR] 3ab187af51244b8bdfe7579e7a6a17a3
[BSP] 742e9e8b59aa945a00b791c81a09f483 : Empty MBR Code
Partition table:
0 - [XXXXXX] UNKNOWN (0x0) [VISIBLE] Offset (sectors): 1 | Size: 2097151 MB
User = LL1 ... OK
User = LL2 ... OK
============================================
RKreport_SCN_11162014_071319.log - RKreport_DEL_11162014_071937.log - RKreport_DEL_11162014_072001.log