HitmanPro 3.7.3.194
www.hitmanpro.com
Computer name . . . . : JONATHANS
Windows . . . . . . . : 6.1.1.7601.X86/2
Safe Mode Boot . . . : NETWORK
User name . . . . . . : Jonathans\Jona
UAC . . . . . . . . . : Disabled
License . . . . . . . : Trial (30 days left)
Scan date . . . . . . : 2013-05-13 22:51:02
Scan mode . . . . . . : Normal
Scan duration . . . . : 5m 3s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : Yes
Threats . . . . . . . : 2
Traces . . . . . . . : 5
Objects scanned . . . : 1,213,214
Files scanned . . . . : 23,512
Remnants scanned . . : 352,254 files / 837,448 keys
Malware _____________________________________________________________________
C:\ProgramData\Microsoft\Media Tools\MediaIconsOverlays.dll -> Quarantined
Size . . . . . . . : 225,280 bytes
Age . . . . . . . : 5.0 days (2013-05-08 22:18:09)
Entropy . . . . . : 6.4
SHA-256 . . . . . : E6A37A94CF4998E0DA0EFAAABB179899B445F1453CF355EA729D1DCD2B8B63FE
Needs elevation . : Yes
Product . . . . . : Online files icon's overlay
Publisher . . . . : Microsoft
Description . . . : Online files icon's overlay
Version . . . . . : 1.0.2.5
Copyright . . . . : Microsoft
Gossip . . . . . . : crosoft
> Emsisoft . . . . . : Trojan.Win32.Agent.amn!A2
Fuzzy . . . . . . : 117.0
One or more antivirus vendors have indicated that the file is malicious.
This file was most recently added as automatic startup.
Program starts automatically without user intervention.
Time indicates that the file appeared recently on this computer.
The file is in use by one or more active processes.
The file appears to be part of an installation package or setup program. This is typical for most programs.
Startup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\ShellIconOverlayIdentifiers\1MediaIconsOverlay\
References
HKLM\SOFTWARE\Classes\CLSID\{1EC23CFF-4C58-458f-924C-8519AEF61B32}\
Forensic Cluster
-0.0s C:\ProgramData\Microsoft\Media Tools\
0.0s C:\ProgramData\Microsoft\Media Tools\MediaIconsOverlays.dll
3.0s C:\ProgramData\Microsoft\Media Tools\temp\
7.0s C:\ProgramData\Microsoft\Media Tools\plugins\
Malware remnants ____________________________________________________________
HKU\S-1-5-21-3659869320-2491200586-312378291-1000\Software\Microsoft\Internet Explorer\LowRegistry\Extensions\CmdMapping\{B58926D6-CFB0-45d2-9C28-4B5A0F0368AE} (Adware.ClickPotato) -> Deleted