Open MalwareTips from your Home Screen or desktop. Follow discussions, find answers and pick up where you left off.
If you cannot find an install option, update your browser or use its bookmark option to keep MalwareTips close.
After installation, open the app and sign in. Enable push notifications in Preferences if you want alerts. On iPhone and iPad, push requires a Home Screen web app and iOS or iPadOS 16.4 or later.
Sign in to manage notificationsInstallation is optional. Your notification settings stay under your control.
HitmanPro 3.7.3.194
www.hitmanpro.com
Computer name . . . . : JONATHANS
Windows . . . . . . . : 6.1.1.7601.X86/2
Safe Mode Boot . . . : NETWORK
User name . . . . . . : Jonathans\Jona
UAC . . . . . . . . . : Disabled
License . . . . . . . : Trial (30 days left)
Scan date . . . . . . : 2013-05-13 22:51:02
Scan mode . . . . . . : Normal
Scan duration . . . . : 5m 3s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : Yes
Threats . . . . . . . : 2
Traces . . . . . . . : 5
Objects scanned . . . : 1,213,214
Files scanned . . . . : 23,512
Remnants scanned . . : 352,254 files / 837,448 keys
Malware _____________________________________________________________________
C:\ProgramData\Microsoft\Media Tools\MediaIconsOverlays.dll -> Quarantined
Size . . . . . . . : 225,280 bytes
Age . . . . . . . : 5.0 days (2013-05-08 22:18:09)
Entropy . . . . . : 6.4
SHA-256 . . . . . : E6A37A94CF4998E0DA0EFAAABB179899B445F1453CF355EA729D1DCD2B8B63FE
Needs elevation . : Yes
Product . . . . . : Online files icon's overlay
Publisher . . . . : Microsoft
Description . . . : Online files icon's overlay
Version . . . . . : 1.0.2.5
Copyright . . . . : Microsoft
Gossip . . . . . . : crosoft
> Emsisoft . . . . . : Trojan.Win32.Agent.amn!A2
Fuzzy . . . . . . : 117.0
One or more antivirus vendors have indicated that the file is malicious.
This file was most recently added as automatic startup.
Program starts automatically without user intervention.
Time indicates that the file appeared recently on this computer.
The file is in use by one or more active processes.
The file appears to be part of an installation package or setup program. This is typical for most programs.
Startup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\ShellIconOverlayIdentifiers\1MediaIconsOverlay\
References
HKLM\SOFTWARE\Classes\CLSID\{1EC23CFF-4C58-458f-924C-8519AEF61B32}\
Forensic Cluster
-0.0s C:\ProgramData\Microsoft\Media Tools\
0.0s C:\ProgramData\Microsoft\Media Tools\MediaIconsOverlays.dll
3.0s C:\ProgramData\Microsoft\Media Tools\temp\
7.0s C:\ProgramData\Microsoft\Media Tools\plugins\
Malware remnants ____________________________________________________________
HKU\S-1-5-21-3659869320-2491200586-312378291-1000\Software\Microsoft\Internet Explorer\LowRegistry\Extensions\CmdMapping\{B58926D6-CFB0-45d2-9C28-4B5A0F0368AE} (Adware.ClickPotato) -> Deleted
Members who viewed this thread in the last 5 minutes