HitmanPro 3.7.2.188
www.hitmanpro.com
Computer name . . . . : USER-PC
Windows . . . . . . . : 6.1.0.7600.X64/2
User name . . . . . . : User-PC\User
UAC . . . . . . . . . : Enabled
License . . . . . . . : Free
Scan date . . . . . . : 2013-02-21 19:44:51
Scan mode . . . . . . : Normal
Scan duration . . . . : 8m 2s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : No
Threats . . . . . . . : 25
Traces . . . . . . . : 81
Objects scanned . . . : 1,373,044
Files scanned . . . . : 34,813
Remnants scanned . . : 395,363 files / 942,868 keys
Malware _____________________________________________________________________
C:\Windows\mshtfo32.dll
Size . . . . . . . : 74,752 bytes
Age . . . . . . . : 87.4 days (2012-11-26 10:21:22)
Entropy . . . . . : 6.3
SHA-256 . . . . . : 26CF45BABC4541254E14F5418D8794455EF5ABA03BD502C9C65E27A18D625108
Product . . . . . : Pound grass practical applied pitch.
Publisher . . . . : UNICOOP TIRRENO
Description . . . : Pound grass practical applied pitch.
Version . . . . . : 2,3,7,1
Copyright . . . . : Copyright (C) 2010
> G Data . . . . . . : Trojan.Generic.8246940 (Engine A)
> Ikarus . . . . . . : Trojan-Spy.Win32.Ursnif!IK
Fuzzy . . . . . . : 102.0
C:\Windows\mshtfo3264.dll
Size . . . . . . . : 81,920 bytes
Age . . . . . . . : 87.4 days (2012-11-26 11:04:28)
Entropy . . . . . : 6.3
SHA-256 . . . . . : 683FC652FB84F9DB58AD6B43C8C2A385531930FC7BD51E3EA8BC1B3F65DEEDB0
Product . . . . . : Limited, yours leant ordinary.
Publisher . . . . : PENNSYLVANIA
Description . . . : Limited, yours leant ordinary.
Version . . . . . : 6,0,8,6
Copyright . . . . : Copyright (C) 2010
> G Data . . . . . . : Win32:Dropper-gen [Drp]
> Ikarus . . . . . . : Trojan-Spy.Win64!IK
Fuzzy . . . . . . : 102.0
C:\Windows\system32\mshtfo3264.dll
Size . . . . . . . : 81,920 bytes
Age . . . . . . . : 87.4 days (2012-11-26 10:21:22)
Entropy . . . . . : 6.3
SHA-256 . . . . . : 683FC652FB84F9DB58AD6B43C8C2A385531930FC7BD51E3EA8BC1B3F65DEEDB0
Product . . . . . : Limited, yours leant ordinary.
Publisher . . . . : PENNSYLVANIA
Description . . . : Limited, yours leant ordinary.
Version . . . . . : 6,0,8,6
Copyright . . . . : Copyright (C) 2010
> G Data . . . . . . : Win32:Dropper-gen [Drp]
> Ikarus . . . . . . : Trojan-Spy.Win64!IK
Fuzzy . . . . . . : 102.0
Malware remnants ____________________________________________________________
C:\Program Files (x86)\PricePeep\ (Adware.ClickPotato)
C:\Program Files (x86)\PricePeep\installer.ico (Adware.ClickPotato)
C:\Program Files (x86)\PricePeep\pricepeep.crx (Adware.ClickPotato)
C:\Program Files (x86)\PricePeep\pricepeep.dll (Adware.ClickPotato)
Size . . . . . . . : 497,008 bytes
Age . . . . . . . : 73.5 days (2012-12-10 08:23:18)
Entropy . . . . . : 6.2
SHA-256 . . . . . : 3F7383407B729554610A6E67F0D7560B9459B4AA1638FD43E19AEDDFF60CCFDC
Product . . . . . : PricePeep
Publisher . . . . : PricePeep
Description . . . : PricePeep
Version . . . . . : 2.1.355.0
RSA Key Size . . . : 2048
Authenticode . . . : Valid
Fuzzy . . . . . . : -11.0
Startup
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}\
References
HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}\
HKLM\SOFTWARE\Wow6432Node\Classes\PricePeep.PricePeepBho.1\
HKLM\SOFTWARE\Wow6432Node\Classes\PricePeep.PricePeepBho\
HKLM\SOFTWARE\Wow6432Node\Classes\TypeLib\{3BF3DED5-0FC8-4207-AC09-AA7B5AF4E408}\
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}\
HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}\
HKU\S-1-5-21-2488982566-3392821603-1833236861-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}\
C:\Program Files (x86)\PricePeep\uninstall.exe (Adware.ClickPotato)
Size . . . . . . . : 86,391 bytes
Age . . . . . . . : 73.5 days (2012-12-10 08:23:18)
Entropy . . . . . : 7.1
SHA-256 . . . . . : CB17E95EFA15A6DB1C447CD55FB35DEA92F6F442FA35B47A95053F0C135E955E
Fuzzy . . . . . . : -2.0
HKLM\SOFTWARE\Classes\AppID\{38A066B0-DD5F-4226-AC4F-6A27C1BFB892}\ (Adware.ClickPotato)
HKLM\SOFTWARE\Classes\Interface\{1B97A696-5576-43AC-A73B-E1D2C78F21E8}\ (Adware.ClickPotato)
HKLM\SOFTWARE\Classes\Interface\{75BF416E-4326-45B5-8A2D-AE32D05B930B}\ (Adware.ClickPotato)
HKLM\SOFTWARE\Classes\PricePeep.PricePeepBho.1\ (Adware.ClickPotato)
HKLM\SOFTWARE\Classes\PricePeep.PricePeepBho\ (Adware.ClickPotato)
HKLM\SOFTWARE\Classes\TypeLib\{3BF3DED5-0FC8-4207-AC09-AA7B5AF4E408}\ (Adware.ClickPotato)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{38A066B0-DD5F-4226-AC4F-6A27C1BFB892}\ (Adware.ClickPotato)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}\ (Adware.ClickPotato)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{1B97A696-5576-43AC-A73B-E1D2C78F21E8}\ (Adware.ClickPotato)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{75BF416E-4326-45B5-8A2D-AE32D05B930B}\ (Adware.ClickPotato)
HKLM\SOFTWARE\Classes\Wow6432Node\TypeLib\{3BF3DED5-0FC8-4207-AC09-AA7B5AF4E408}\ (Adware.ClickPotato)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}\ (Adware.ClickPotato)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PricePeep\ (Adware.ClickPotato)
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}\ (Adware.ClickPotato)
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}\ (Adware.ClickPotato)
HKU\S-1-5-21-2488982566-3392821603-1833236861-1000\Software\AppDataLow\Software\PricePeep\ (Adware.ClickPotato)
HKU\S-1-5-21-2488982566-3392821603-1833236861-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}\ (Adware.ClickPotato)
Potential Unwanted Programs _________________________________________________
C:\Program Files (x86)\Yontoo\ (Yontoo)
C:\Program Files (x86)\Yontoo\OptChrome.exe (Yontoo)
Size . . . . . . . : 133,632 bytes
Age . . . . . . . : 73.5 days (2012-12-10 08:23:19)
Entropy . . . . . : 6.4
SHA-256 . . . . . : 829D936424BF6598883B8913505942BBC64F739A2FCECA493CA1C5FD42A90B66
Fuzzy . . . . . . : 6.0
C:\Program Files (x86)\Yontoo\YontooIEClient.dll (Yontoo)
Size . . . . . . . : 194,928 bytes
Age . . . . . . . : 73.5 days (2012-12-10 08:23:19)
Entropy . . . . . : 6.3
SHA-256 . . . . . : 37A3A24A2F115AE7571086399C64A7335186F1AF67160B5D022519E454A69AE9
Product . . . . . : Yontoo Runtime
Publisher . . . . : Yontoo LLC
Description . . . : Yontoo Runtime
Version . . . . . : 1.10.01
Copyright . . . . : Copyright (c) 2011 Yontoo LLC. All rights reserved.
RSA Key Size . . . : 1024
Authenticode . . . : Valid
Fuzzy . . . . . . : -3.0
Startup
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\
References
HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\
HKLM\SOFTWARE\Wow6432Node\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}\
HKLM\SOFTWARE\Wow6432Node\Classes\YontooIEClient.Layers.1\
HKLM\SOFTWARE\Wow6432Node\Classes\YontooIEClient.Layers\
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\
HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\
HKU\S-1-5-21-2488982566-3392821603-1833236861-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\
C:\Program Files (x86)\Yontoo\YontooLayers.crx (Yontoo)
HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL\ (Yontoo)
HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}\ (Yontoo)
HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}\ (Yontoo)
HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}\ (Yontoo)
HKLM\SOFTWARE\Classes\s\ (Softonic)
HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\YontooIEClient.DLL\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{80922ee0-8a76-46ae-95d5-bd3c3fe0708d}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{99066096-8989-4612-841F-621A01D54AD7}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{FE9271F2-6EFD-44b0-A826-84C829536E93}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}\ (Yontoo)
HKLM\SOFTWARE\Classes\YontooIEClient.Api.1\ (Yontoo)
HKLM\SOFTWARE\Classes\YontooIEClient.Api\ (Yontoo)
HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1\ (Yontoo)
HKLM\SOFTWARE\Classes\YontooIEClient.Layers\ (Yontoo)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\ (Yontoo)
HKLM\SOFTWARE\Tarma Installer\Components\{8D8654CD-7FBC-4C7E-84E9-371BFA8DB04E}\ (Yontoo)
HKLM\SOFTWARE\Tarma Installer\Components\{9307081B-7444-494C-8CF6-2FA7C0E92BFB}\ (Yontoo)
HKLM\SOFTWARE\Tarma Installer\Components\{9D9785E5-3424-40B6-A287-BA143AD53109}\ (Yontoo)
HKLM\SOFTWARE\Tarma Installer\Components\{B6783DFA-B8C8-4CB6-AB9F-EF1A1F7F7AE8}\ (Yontoo)
HKLM\SOFTWARE\Tarma Installer\Components\{F5F971A9-DBF8-4EEC-81E3-5F1660573E6C}\ (Yontoo)
HKLM\SOFTWARE\Tarma Installer\Products\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\ (Yontoo)
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc\ (Yontoo)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\ (Yontoo)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}\ (Yontoo)
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\ (Yontoo)
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\ (Yontoo)
HKU\S-1-5-21-2488982566-3392821603-1833236861-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}\ (Yontoo)
HKU\S-1-5-21-2488982566-3392821603-1833236861-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\ (Yontoo)
Cookies _____________________________________________________________________
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.yieldmanager.com
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Cookies:doubleclick.net
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Cookies:ext.myshopres.com
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Cookies:invitemedia.com
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\PIP5RJ9M.txt
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:a1.interclick.com
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:ad.yieldmanager.com
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:adinterax.com
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:apmebf.com
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:atdmt.com
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:collective-media.net
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:doubleclick.net
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:interclick.com
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:invitemedia.com
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:mediaplex.com
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:questionmarket.com
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:statse.webtrendslive.com
:Files
C:\ProgramData\mshtfo3264.dll
C:\ProgramData\mshtfo32.dll
C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\runctf.lnk
C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
:Commands
[EmptyTemp]
[EmptyFlash]
[EmptyJava]
[Reboot]
HitmanPro 3.7.2.188
www.hitmanpro.com
Computer name . . . . : USER-PC
Windows . . . . . . . : 6.1.0.7600.X64/2
User name . . . . . . : User-PC\User
UAC . . . . . . . . . : Enabled
License . . . . . . . : Trial (31 days left)
Scan date . . . . . . : 2013-02-21 19:44:51
Scan mode . . . . . . : Normal
Scan duration . . . . : 8m 2s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : Yes
Threats . . . . . . . : 25
Traces . . . . . . . : 81
Objects scanned . . . : 1,373,044
Files scanned . . . . : 34,813
Remnants scanned . . : 395,363 files / 942,868 keys
Malware _____________________________________________________________________
C:\Windows\mshtfo32.dll -> Deleted
Size . . . . . . . : 74,752 bytes
Age . . . . . . . : 87.4 days (2012-11-26 10:21:22)
Entropy . . . . . : 6.3
SHA-256 . . . . . : 26CF45BABC4541254E14F5418D8794455EF5ABA03BD502C9C65E27A18D625108
Product . . . . . : Pound grass practical applied pitch.
Publisher . . . . : UNICOOP TIRRENO
Description . . . : Pound grass practical applied pitch.
Version . . . . . : 2,3,7,1
Copyright . . . . : Copyright (C) 2010
> G Data . . . . . . : Trojan.Generic.8246940 (Engine A)
> Ikarus . . . . . . : Trojan-Spy.Win32.Ursnif!IK
Fuzzy . . . . . . : 102.0
C:\Windows\mshtfo3264.dll -> Deleted
Size . . . . . . . : 81,920 bytes
Age . . . . . . . : 87.4 days (2012-11-26 11:04:28)
Entropy . . . . . : 6.3
SHA-256 . . . . . : 683FC652FB84F9DB58AD6B43C8C2A385531930FC7BD51E3EA8BC1B3F65DEEDB0
Product . . . . . : Limited, yours leant ordinary.
Publisher . . . . : PENNSYLVANIA
Description . . . : Limited, yours leant ordinary.
Version . . . . . : 6,0,8,6
Copyright . . . . : Copyright (C) 2010
> G Data . . . . . . : Win32:Dropper-gen [Drp]
> Ikarus . . . . . . : Trojan-Spy.Win64!IK
Fuzzy . . . . . . : 102.0
C:\Windows\system32\mshtfo3264.dll -> Deleted
Size . . . . . . . : 81,920 bytes
Age . . . . . . . : 87.4 days (2012-11-26 10:21:22)
Entropy . . . . . : 6.3
SHA-256 . . . . . : 683FC652FB84F9DB58AD6B43C8C2A385531930FC7BD51E3EA8BC1B3F65DEEDB0
Product . . . . . : Limited, yours leant ordinary.
Publisher . . . . : PENNSYLVANIA
Description . . . : Limited, yours leant ordinary.
Version . . . . . : 6,0,8,6
Copyright . . . . : Copyright (C) 2010
> G Data . . . . . . : Win32:Dropper-gen [Drp]
> Ikarus . . . . . . : Trojan-Spy.Win64!IK
Fuzzy . . . . . . : 102.0
Malware remnants ____________________________________________________________
C:\Program Files (x86)\PricePeep\ (Adware.ClickPotato) -> Deleted
C:\Program Files (x86)\PricePeep\installer.ico (Adware.ClickPotato) -> Deleted
C:\Program Files (x86)\PricePeep\pricepeep.crx (Adware.ClickPotato) -> Deleted
C:\Program Files (x86)\PricePeep\pricepeep.dll (Adware.ClickPotato) -> Deleted
Size . . . . . . . : 497,008 bytes
Age . . . . . . . : 73.5 days (2012-12-10 08:23:18)
Entropy . . . . . : 6.2
SHA-256 . . . . . : 3F7383407B729554610A6E67F0D7560B9459B4AA1638FD43E19AEDDFF60CCFDC
Product . . . . . : PricePeep
Publisher . . . . : PricePeep
Description . . . : PricePeep
Version . . . . . : 2.1.355.0
RSA Key Size . . . : 2048
Authenticode . . . : Valid
Fuzzy . . . . . . : -11.0
Startup
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}\
References
HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}\
HKLM\SOFTWARE\Wow6432Node\Classes\PricePeep.PricePeepBho.1\
HKLM\SOFTWARE\Wow6432Node\Classes\PricePeep.PricePeepBho\
HKLM\SOFTWARE\Wow6432Node\Classes\TypeLib\{3BF3DED5-0FC8-4207-AC09-AA7B5AF4E408}\
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}\
HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}\
HKU\S-1-5-21-2488982566-3392821603-1833236861-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}\
C:\Program Files (x86)\PricePeep\uninstall.exe (Adware.ClickPotato) -> Deleted
Size . . . . . . . : 86,391 bytes
Age . . . . . . . : 73.5 days (2012-12-10 08:23:18)
Entropy . . . . . : 7.1
SHA-256 . . . . . : CB17E95EFA15A6DB1C447CD55FB35DEA92F6F442FA35B47A95053F0C135E955E
Fuzzy . . . . . . : -2.0
HKLM\SOFTWARE\Classes\AppID\{38A066B0-DD5F-4226-AC4F-6A27C1BFB892}\ (Adware.ClickPotato) -> Deleted
HKLM\SOFTWARE\Classes\Interface\{1B97A696-5576-43AC-A73B-E1D2C78F21E8}\ (Adware.ClickPotato) -> Deleted
HKLM\SOFTWARE\Classes\Interface\{75BF416E-4326-45B5-8A2D-AE32D05B930B}\ (Adware.ClickPotato) -> Deleted
HKLM\SOFTWARE\Classes\PricePeep.PricePeepBho.1\ (Adware.ClickPotato) -> Deleted
HKLM\SOFTWARE\Classes\PricePeep.PricePeepBho\ (Adware.ClickPotato) -> Deleted
HKLM\SOFTWARE\Classes\TypeLib\{3BF3DED5-0FC8-4207-AC09-AA7B5AF4E408}\ (Adware.ClickPotato) -> PendingDelete
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{38A066B0-DD5F-4226-AC4F-6A27C1BFB892}\ (Adware.ClickPotato) -> PendingDelete
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}\ (Adware.ClickPotato) -> PendingDelete
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{1B97A696-5576-43AC-A73B-E1D2C78F21E8}\ (Adware.ClickPotato) -> Deleted
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{75BF416E-4326-45B5-8A2D-AE32D05B930B}\ (Adware.ClickPotato) -> Deleted
HKLM\SOFTWARE\Classes\Wow6432Node\TypeLib\{3BF3DED5-0FC8-4207-AC09-AA7B5AF4E408}\ (Adware.ClickPotato) -> PendingDelete
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}\ (Adware.ClickPotato) -> PendingDelete
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PricePeep\ (Adware.ClickPotato) -> Deleted
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}\ (Adware.ClickPotato) -> PendingDelete
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}\ (Adware.ClickPotato) -> PendingDelete
HKU\S-1-5-21-2488982566-3392821603-1833236861-1000\Software\AppDataLow\Software\PricePeep\ (Adware.ClickPotato) -> Deleted
HKU\S-1-5-21-2488982566-3392821603-1833236861-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}\ (Adware.ClickPotato) -> PendingDelete
Potential Unwanted Programs _________________________________________________
C:\Program Files (x86)\Yontoo\ (Yontoo)
C:\Program Files (x86)\Yontoo\OptChrome.exe (Yontoo)
Size . . . . . . . : 133,632 bytes
Age . . . . . . . : 73.5 days (2012-12-10 08:23:19)
Entropy . . . . . : 6.4
SHA-256 . . . . . : 829D936424BF6598883B8913505942BBC64F739A2FCECA493CA1C5FD42A90B66
Fuzzy . . . . . . : 6.0
C:\Program Files (x86)\Yontoo\YontooIEClient.dll (Yontoo)
Size . . . . . . . : 194,928 bytes
Age . . . . . . . : 73.5 days (2012-12-10 08:23:19)
Entropy . . . . . : 6.3
SHA-256 . . . . . : 37A3A24A2F115AE7571086399C64A7335186F1AF67160B5D022519E454A69AE9
Product . . . . . : Yontoo Runtime
Publisher . . . . : Yontoo LLC
Description . . . : Yontoo Runtime
Version . . . . . : 1.10.01
Copyright . . . . : Copyright (c) 2011 Yontoo LLC. All rights reserved.
RSA Key Size . . . : 1024
Authenticode . . . : Valid
Fuzzy . . . . . . : -3.0
Startup
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\
References
HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\
HKLM\SOFTWARE\Wow6432Node\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}\
HKLM\SOFTWARE\Wow6432Node\Classes\YontooIEClient.Layers.1\
HKLM\SOFTWARE\Wow6432Node\Classes\YontooIEClient.Layers\
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\
HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\
HKU\S-1-5-21-2488982566-3392821603-1833236861-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\
C:\Program Files (x86)\Yontoo\YontooLayers.crx (Yontoo)
HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL\ (Yontoo)
HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}\ (Yontoo)
HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}\ (Yontoo)
HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}\ (Yontoo)
HKLM\SOFTWARE\Classes\s\ (Softonic)
HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\YontooIEClient.DLL\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{80922ee0-8a76-46ae-95d5-bd3c3fe0708d}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{99066096-8989-4612-841F-621A01D54AD7}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{FE9271F2-6EFD-44b0-A826-84C829536E93}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}\ (Yontoo)
HKLM\SOFTWARE\Classes\YontooIEClient.Api.1\ (Yontoo)
HKLM\SOFTWARE\Classes\YontooIEClient.Api\ (Yontoo)
HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1\ (Yontoo)
HKLM\SOFTWARE\Classes\YontooIEClient.Layers\ (Yontoo)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\ (Yontoo)
HKLM\SOFTWARE\Tarma Installer\Components\{8D8654CD-7FBC-4C7E-84E9-371BFA8DB04E}\ (Yontoo)
HKLM\SOFTWARE\Tarma Installer\Components\{9307081B-7444-494C-8CF6-2FA7C0E92BFB}\ (Yontoo)
HKLM\SOFTWARE\Tarma Installer\Components\{9D9785E5-3424-40B6-A287-BA143AD53109}\ (Yontoo)
HKLM\SOFTWARE\Tarma Installer\Components\{B6783DFA-B8C8-4CB6-AB9F-EF1A1F7F7AE8}\ (Yontoo)
HKLM\SOFTWARE\Tarma Installer\Components\{F5F971A9-DBF8-4EEC-81E3-5F1660573E6C}\ (Yontoo)
HKLM\SOFTWARE\Tarma Installer\Products\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\ (Yontoo)
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc\ (Yontoo)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\ (Yontoo)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}\ (Yontoo)
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\ (Yontoo)
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\ (Yontoo)
HKU\S-1-5-21-2488982566-3392821603-1833236861-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}\ (Yontoo)
HKU\S-1-5-21-2488982566-3392821603-1833236861-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\ (Yontoo)
Cookies _____________________________________________________________________
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.yieldmanager.com
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Cookies:doubleclick.net
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Cookies:ext.myshopres.com
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Cookies:invitemedia.com
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\PIP5RJ9M.txt
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:a1.interclick.com
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:ad.yieldmanager.com
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:adinterax.com
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:apmebf.com
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:atdmt.com
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:collective-media.net
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:doubleclick.net
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:interclick.com
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:invitemedia.com
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:mediaplex.com
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:questionmarket.com
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:statse.webtrendslive.com
HitmanPro 3.7.2.188
www.hitmanpro.com
Computer name . . . . : USER-PC
Windows . . . . . . . : 6.1.0.7600.X64/2
User name . . . . . . : User-PC\User
UAC . . . . . . . . . : Enabled
License . . . . . . . : Trial (31 days left)
Scan date . . . . . . : 2013-02-21 19:44:51
Scan mode . . . . . . : Normal
Scan duration . . . . : 8m 2s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : Yes
Threats . . . . . . . : 25
Traces . . . . . . . : 81
Objects scanned . . . : 1,373,044
Files scanned . . . . : 34,813
Remnants scanned . . : 395,363 files / 942,868 keys
Malware _____________________________________________________________________
C:\Windows\mshtfo32.dll -> Deleted
Size . . . . . . . : 74,752 bytes
Age . . . . . . . : 87.4 days (2012-11-26 10:21:22)
Entropy . . . . . : 6.3
SHA-256 . . . . . : 26CF45BABC4541254E14F5418D8794455EF5ABA03BD502C9C65E27A18D625108
Product . . . . . : Pound grass practical applied pitch.
Publisher . . . . : UNICOOP TIRRENO
Description . . . : Pound grass practical applied pitch.
Version . . . . . : 2,3,7,1
Copyright . . . . : Copyright (C) 2010
> G Data . . . . . . : Trojan.Generic.8246940 (Engine A)
> Ikarus . . . . . . : Trojan-Spy.Win32.Ursnif!IK
Fuzzy . . . . . . : 102.0
C:\Windows\mshtfo3264.dll -> Deleted
Size . . . . . . . : 81,920 bytes
Age . . . . . . . : 87.4 days (2012-11-26 11:04:28)
Entropy . . . . . : 6.3
SHA-256 . . . . . : 683FC652FB84F9DB58AD6B43C8C2A385531930FC7BD51E3EA8BC1B3F65DEEDB0
Product . . . . . : Limited, yours leant ordinary.
Publisher . . . . : PENNSYLVANIA
Description . . . : Limited, yours leant ordinary.
Version . . . . . : 6,0,8,6
Copyright . . . . : Copyright (C) 2010
> G Data . . . . . . : Win32:Dropper-gen [Drp]
> Ikarus . . . . . . : Trojan-Spy.Win64!IK
Fuzzy . . . . . . : 102.0
C:\Windows\system32\mshtfo3264.dll -> Deleted
Size . . . . . . . : 81,920 bytes
Age . . . . . . . : 87.4 days (2012-11-26 10:21:22)
Entropy . . . . . : 6.3
SHA-256 . . . . . : 683FC652FB84F9DB58AD6B43C8C2A385531930FC7BD51E3EA8BC1B3F65DEEDB0
Product . . . . . : Limited, yours leant ordinary.
Publisher . . . . : PENNSYLVANIA
Description . . . : Limited, yours leant ordinary.
Version . . . . . : 6,0,8,6
Copyright . . . . : Copyright (C) 2010
> G Data . . . . . . : Win32:Dropper-gen [Drp]
> Ikarus . . . . . . : Trojan-Spy.Win64!IK
Fuzzy . . . . . . : 102.0
Malware remnants ____________________________________________________________
C:\Program Files (x86)\PricePeep\ (Adware.ClickPotato) -> Deleted
C:\Program Files (x86)\PricePeep\installer.ico (Adware.ClickPotato) -> Deleted
C:\Program Files (x86)\PricePeep\pricepeep.crx (Adware.ClickPotato) -> Deleted
C:\Program Files (x86)\PricePeep\pricepeep.dll (Adware.ClickPotato) -> Deleted
Size . . . . . . . : 497,008 bytes
Age . . . . . . . : 73.5 days (2012-12-10 08:23:18)
Entropy . . . . . : 6.2
SHA-256 . . . . . : 3F7383407B729554610A6E67F0D7560B9459B4AA1638FD43E19AEDDFF60CCFDC
Product . . . . . : PricePeep
Publisher . . . . : PricePeep
Description . . . : PricePeep
Version . . . . . : 2.1.355.0
RSA Key Size . . . : 2048
Authenticode . . . : Valid
Fuzzy . . . . . . : -11.0
Startup
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}\
References
HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}\
HKLM\SOFTWARE\Wow6432Node\Classes\PricePeep.PricePeepBho.1\
HKLM\SOFTWARE\Wow6432Node\Classes\PricePeep.PricePeepBho\
HKLM\SOFTWARE\Wow6432Node\Classes\TypeLib\{3BF3DED5-0FC8-4207-AC09-AA7B5AF4E408}\
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}\
HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}\
HKU\S-1-5-21-2488982566-3392821603-1833236861-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}\
C:\Program Files (x86)\PricePeep\uninstall.exe (Adware.ClickPotato) -> Deleted
Size . . . . . . . : 86,391 bytes
Age . . . . . . . : 73.5 days (2012-12-10 08:23:18)
Entropy . . . . . : 7.1
SHA-256 . . . . . : CB17E95EFA15A6DB1C447CD55FB35DEA92F6F442FA35B47A95053F0C135E955E
Fuzzy . . . . . . : -2.0
HKLM\SOFTWARE\Classes\AppID\{38A066B0-DD5F-4226-AC4F-6A27C1BFB892}\ (Adware.ClickPotato) -> Deleted
HKLM\SOFTWARE\Classes\Interface\{1B97A696-5576-43AC-A73B-E1D2C78F21E8}\ (Adware.ClickPotato) -> Deleted
HKLM\SOFTWARE\Classes\Interface\{75BF416E-4326-45B5-8A2D-AE32D05B930B}\ (Adware.ClickPotato) -> Deleted
HKLM\SOFTWARE\Classes\PricePeep.PricePeepBho.1\ (Adware.ClickPotato) -> Deleted
HKLM\SOFTWARE\Classes\PricePeep.PricePeepBho\ (Adware.ClickPotato) -> Deleted
HKLM\SOFTWARE\Classes\TypeLib\{3BF3DED5-0FC8-4207-AC09-AA7B5AF4E408}\ (Adware.ClickPotato) -> PendingDelete
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{38A066B0-DD5F-4226-AC4F-6A27C1BFB892}\ (Adware.ClickPotato) -> PendingDelete
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}\ (Adware.ClickPotato) -> PendingDelete
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{1B97A696-5576-43AC-A73B-E1D2C78F21E8}\ (Adware.ClickPotato) -> Deleted
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{75BF416E-4326-45B5-8A2D-AE32D05B930B}\ (Adware.ClickPotato) -> Deleted
HKLM\SOFTWARE\Classes\Wow6432Node\TypeLib\{3BF3DED5-0FC8-4207-AC09-AA7B5AF4E408}\ (Adware.ClickPotato) -> PendingDelete
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}\ (Adware.ClickPotato) -> PendingDelete
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PricePeep\ (Adware.ClickPotato) -> Deleted
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}\ (Adware.ClickPotato) -> PendingDelete
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}\ (Adware.ClickPotato) -> PendingDelete
HKU\S-1-5-21-2488982566-3392821603-1833236861-1000\Software\AppDataLow\Software\PricePeep\ (Adware.ClickPotato) -> Deleted
HKU\S-1-5-21-2488982566-3392821603-1833236861-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}\ (Adware.ClickPotato) -> PendingDelete
Potential Unwanted Programs _________________________________________________
C:\Program Files (x86)\Yontoo\ (Yontoo)
C:\Program Files (x86)\Yontoo\OptChrome.exe (Yontoo)
Size . . . . . . . : 133,632 bytes
Age . . . . . . . : 73.5 days (2012-12-10 08:23:19)
Entropy . . . . . : 6.4
SHA-256 . . . . . : 829D936424BF6598883B8913505942BBC64F739A2FCECA493CA1C5FD42A90B66
Fuzzy . . . . . . : 6.0
C:\Program Files (x86)\Yontoo\YontooIEClient.dll (Yontoo)
Size . . . . . . . : 194,928 bytes
Age . . . . . . . : 73.5 days (2012-12-10 08:23:19)
Entropy . . . . . : 6.3
SHA-256 . . . . . : 37A3A24A2F115AE7571086399C64A7335186F1AF67160B5D022519E454A69AE9
Product . . . . . : Yontoo Runtime
Publisher . . . . : Yontoo LLC
Description . . . : Yontoo Runtime
Version . . . . . : 1.10.01
Copyright . . . . : Copyright (c) 2011 Yontoo LLC. All rights reserved.
RSA Key Size . . . : 1024
Authenticode . . . : Valid
Fuzzy . . . . . . : -3.0
Startup
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\
References
HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\
HKLM\SOFTWARE\Wow6432Node\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}\
HKLM\SOFTWARE\Wow6432Node\Classes\YontooIEClient.Layers.1\
HKLM\SOFTWARE\Wow6432Node\Classes\YontooIEClient.Layers\
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\
HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\
HKU\S-1-5-21-2488982566-3392821603-1833236861-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\
C:\Program Files (x86)\Yontoo\YontooLayers.crx (Yontoo)
HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL\ (Yontoo)
HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}\ (Yontoo)
HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}\ (Yontoo)
HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}\ (Yontoo)
HKLM\SOFTWARE\Classes\s\ (Softonic)
HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\YontooIEClient.DLL\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{80922ee0-8a76-46ae-95d5-bd3c3fe0708d}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{99066096-8989-4612-841F-621A01D54AD7}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{FE9271F2-6EFD-44b0-A826-84C829536E93}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}\ (Yontoo)
HKLM\SOFTWARE\Classes\Wow6432Node\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}\ (Yontoo)
HKLM\SOFTWARE\Classes\YontooIEClient.Api.1\ (Yontoo)
HKLM\SOFTWARE\Classes\YontooIEClient.Api\ (Yontoo)
HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1\ (Yontoo)
HKLM\SOFTWARE\Classes\YontooIEClient.Layers\ (Yontoo)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\ (Yontoo)
HKLM\SOFTWARE\Tarma Installer\Components\{8D8654CD-7FBC-4C7E-84E9-371BFA8DB04E}\ (Yontoo)
HKLM\SOFTWARE\Tarma Installer\Components\{9307081B-7444-494C-8CF6-2FA7C0E92BFB}\ (Yontoo)
HKLM\SOFTWARE\Tarma Installer\Components\{9D9785E5-3424-40B6-A287-BA143AD53109}\ (Yontoo)
HKLM\SOFTWARE\Tarma Installer\Components\{B6783DFA-B8C8-4CB6-AB9F-EF1A1F7F7AE8}\ (Yontoo)
HKLM\SOFTWARE\Tarma Installer\Components\{F5F971A9-DBF8-4EEC-81E3-5F1660573E6C}\ (Yontoo)
HKLM\SOFTWARE\Tarma Installer\Products\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\ (Yontoo)
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc\ (Yontoo)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\ (Yontoo)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}\ (Yontoo)
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\ (Yontoo)
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\ (Yontoo)
HKU\S-1-5-21-2488982566-3392821603-1833236861-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}\ (Yontoo)
HKU\S-1-5-21-2488982566-3392821603-1833236861-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\ (Yontoo)
Cookies _____________________________________________________________________
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.yieldmanager.com
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Cookies:doubleclick.net
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Cookies:ext.myshopres.com
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Cookies:invitemedia.com
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\PIP5RJ9M.txt
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:a1.interclick.com
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:ad.yieldmanager.com
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:adinterax.com
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:apmebf.com
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:atdmt.com
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:collective-media.net
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:doubleclick.net
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:interclick.com
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:invitemedia.com
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:mediaplex.com
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:questionmarket.com
C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\j5rcxobi.default\cookies.sqlite:statse.webtrendslive.com
kuttus said:STEP 1: Run the below OTL fix
<ol><li>Start <>OTL.exe</></li>
<li>Copy/paste the following text written <>inside of the code box</> into the <>Custom Scans/Fixes</> box located at the bottom of OTL
Code::Files C:\ProgramData\mshtfo3264.dll C:\ProgramData\mshtfo32.dll C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\runctf.lnk C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini :Commands [EmptyTemp] [EmptyFlash] [EmptyJava] [Reboot]
<>NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system</></li>
<li>Then click the <>Run Fix</> button at the top</li>
<li>Let the program run unhindered, reboot when it is done</li>
<li>Attach the new log produced by OTL (C:\_OTL)</li>
</ol>
<hr />