HitmanPro 3.6.2.173
www.hitmanpro.com Computer name . . . . : PCSGURGOLA
Windows . . . . . . . : 6.1.1.7601.X86/4
User name . . . . . . : PCSGURGOLA\Usuario
UAC . . . . . . . . . : Disabled
License . . . . . . . : Free
Scan date . . . . . . : 2012-11-11 06:16:45
Scan mode . . . . . . : Normal
Scan duration . . . . : 8m 2s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : No
Threats . . . . . . . : 2
Traces . . . . . . . : 14
Objects scanned . . . : 1.135.326
Files scanned . . . . : 21.951
Remnants scanned . . : 193.461 files / 919.914 keys
Malware _____________________________________________________________________
C:\Users\Usuario\AppData\Local\Temp\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbar4ie.exe
Size . . . . . . . : 997.768 bytes
Age . . . . . . . : 348.6 days (2011-11-28 14:48:41)
Entropy . . . . . : 8.0
SHA-256 . . . . . : 14F842F731671CC45DA1611BF3FCA33EBA5FF44F82251E2C7886CB04F5517CB7
Product . . . . . : BabylonToolbar
Publisher . . . . : BabylonToolbar
Version . . . . . : 1.5.3.17
RSA Key Size . . . : 2048
Authenticode . . . : Self-signed
> DrWeb . . . . . . : Infected
Fuzzy . . . . . . : 111.0
C:\Users\Usuario\Documents\2012-08-21 Escritorio\yo\Brothersoftdownloader_for_German_Truck_Simulator_English_Patch.exe
Size . . . . . . . : 367.950 bytes
Age . . . . . . . : 276.8 days (2012-02-08 11:38:12)
Entropy . . . . . : 7.9
SHA-256 . . . . . : 8EB726CCA24346AD84003C5282F63BE248537DF9D35665E5C4F2D7E582269D46
Product . . . . . : Brothersoft Download Manager
Publisher . . . . : Conduit
Description . . . : Brothersoft Download Manager
Version . . . . . : 1.0.0
Copyright . . . . : © Conduit
> DrWeb . . . . . . : Trojan.DownLoader4.31749
Fuzzy . . . . . . : 108.0
References
C:\Users\Usuario\Documents\2012-08-21 Escritorio\yo\Finish Downloading Brothersoft Download Manager.lnk
Suspicious files ____________________________________________________________
C:\Windows\system32\drivers\iqmhvmfu.sys
Size . . . . . . . : 43.600 bytes
Age . . . . . . . : 34.8 days (2012-10-07 11:56:45)
Entropy . . . . . : 6.7
SHA-256 . . . . . : C94C7F88477F740BDA08CE68EAFAC2599E2B45025C8F302CD42985B270185F03
Product . . . . . : Microsoft Malware Protection
Publisher . . . . : Microsoft Corporation
Description . . . : Boot Time Removal Tool
Version . . . . . : 1.1.0020.0
Copyright . . . . : © Microsoft Corporation. All rights reserved.
Service . . . . . : iqmhvmfu
Fuzzy . . . . . . : 27.0
The file is completely hidden from view and most antivirus products. It may belong to a rootkit.
Starts automatically as a service during system bootup.
Program starts automatically without user intervention.
The file is located in a folder that contains core operating system files from Windows. This is not typical for most programs and is only common to system tools, drivers and hacking utilities.
The file is a device driver. Device drivers run as trusted (highly privileged) code.
Startup
HKLM\SYSTEM\ControlSet001\Services\iqmhvmfu\
C:\Windows\system32\drivers\lbhiujis.sys
Size . . . . . . . : 43.600 bytes
Age . . . . . . . : 34.0 days (2012-10-08 07:21:14)
Entropy . . . . . : 6.7
SHA-256 . . . . . : C94C7F88477F740BDA08CE68EAFAC2599E2B45025C8F302CD42985B270185F03
Product . . . . . : Microsoft Malware Protection
Publisher . . . . : Microsoft Corporation
Description . . . : Boot Time Removal Tool
Version . . . . . : 1.1.0020.0
Copyright . . . . : © Microsoft Corporation. All rights reserved.
Service . . . . . : lbhiujis
Fuzzy . . . . . . : 27.0
The file is completely hidden from view and most antivirus products. It may belong to a rootkit.
Starts automatically as a service during system bootup.
Program starts automatically without user intervention.
The file is located in a folder that contains core operating system files from Windows. This is not typical for most programs and is only common to system tools, drivers and hacking utilities.
The file is a device driver. Device drivers run as trusted (highly privileged) code.
Startup
HKLM\SYSTEM\ControlSet001\Services\lbhiujis\
Potential Unwanted Programs _________________________________________________
HKLM\SOFTWARE\Classes\AppID\escort.DLL\ (Funmoods)
HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}\ (Funmoods)
HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\ (Babylon)
HKU\S-1-5-21-2827143398-4206964840-745579886-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ (Babylon)
HKU\S-1-5-21-2827143398-4206964840-745579886-1000\Software\Softonic\ (Softonic)
Cookies _____________________________________________________________________
C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Cookies\L2AUTI45.txt
C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Cookies\RKZCKY7W.txt