Malwarebytes Anti-Malware 1.75.0.1300
Database version: v2013.09.23.08
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 10.0.9200.16660
user :: USER-PC [administrator]
17/11/34 05:08:52 م
mbam-log-2013-09-23 (17-08-52).txt
Scan type: Full scan (C:\|D:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | PUP | PUM
Scan options disabled: Heuristics/Shuriken | P2P
Objects scanned: 453534
Time elapsed: 4 hour(s), 22 minute(s), 21 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 25
HKCR\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB} (PUP.Optional.BabylonToolBar.A) -> Quarantined and deleted successfully.
HKCR\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} (PUP.Optional.Delta.A) -> Quarantined and deleted successfully.
HKCR\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} (PUP.Optional.BrowseFox.A) -> Quarantined and deleted successfully.
HKCR\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23} (PUP.Optional.BrowseFox.A) -> Quarantined and deleted successfully.
HKCR\CLSID\{DF84E609-C3A4-49CB-A160-61767DAF8899} (PUP.Optional.WebCake.A) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{055AF109-DE93-4160-BCFC-7DA70ECAA020} (PUP.Optional.Diamonddata) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055AF109-DE93-4160-BCFC-7DA70ECAA020} (PUP.Optional.Diamonddata) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C} (PUP.Optional.OptimzerPro.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
Lyrics@LyricsContainer.co (PUP.Optional.LyricsAd) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1F0F184F-9C12-4E67-AC8C-D430C4EC3AB9} (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D04E53D7-AD00-48EE-AA05-E5220BAD7121} (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7F58F24E-1D53-1E33-4AE8-F3A63EF2FF98} (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6D872AA3-6474-7814-F90C-5745CAD3BC93} (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\BabylonToolbar (PUP.Optional.BabylonToolBar.A) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\DataMngr_Toolbar (PUP.Optional.DataMngr.A) -> Quarantined and deleted successfully.
HKCU\Software\1ClickDownload (PUP.Optional.1ClickDownload.A) -> Quarantined and deleted successfully.
HKCU\Software\DataMngr (PUP.Optional.DataMngr.A) -> Quarantined and deleted successfully.
HKCU\Software\diamondata (PUP.Optional.diamondata.A) -> Quarantined and deleted successfully.
HKCU\Software\AppDataLow\SProtector (PUP.Optional.SProtector.A) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\SWEETIM (PUP.Optional.SweetIM.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\babylontoolbar (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Google\Chrome\Extensions\pfmopbbadnfoelckkcmjjeaaegjpjjbk (PUP.Optional.Gophoto.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\SWEETIM (PUP.Optional.SweetIM.A) -> Quarantined and deleted successfully.
HKCR\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755} (PUP.Optional.SearchNewTab) -> Quarantined and deleted successfully.
HKCR\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F} (PUP.Optional.SearchNewTab) -> Quarantined and deleted successfully.
Registry Values Detected: 2
HKCU\Software\SweetIM|simapp_id (PUP.Optional.SweetIM.A) -> Data: 11111111 -> Quarantined and deleted successfully.
HKLM\Software\SweetIM|simapp_id (PUP.Optional.SweetIM.A) -> Data: 11111111 -> Quarantined and deleted successfully.
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 10
C:\Users\user\AppData\Roaming\Babylon (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
C:\Program Files\LyricsContainer (PUP.Optional.LyricsContainer.A) -> Quarantined and deleted successfully.
C:\Program Files\LemurLeap (PUP.Optional.LemurLeap.A) -> Quarantined and deleted successfully.
C:\Program Files\Gophoto.it (PUP.Optional.Gophoto.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504} (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Cache (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\Users\user\AppData\Roaming\BabSolution (PUP.Optional.BabSolution.A) -> Quarantined and deleted successfully.
C:\Users\user\AppData\Roaming\BabSolution\Shared (PUP.Optional.BabSolution.A) -> Quarantined and deleted successfully.
C:\ProgramData\SearchNewTab (PUP.Optional.SearchNewTab) -> Quarantined and deleted successfully.
Files Detected: 38
C:\Users\user\AppData\Local\Apps\2.0\0H6PTYWV.Y0A\3P6N8W3Y.147\inst...exe_c3955e569709176b_0001.0005_none_90e029059443a254\CleanCoGen.rar (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\user\AppData\Local\Apps\2.0\0H6PTYWV.Y0A\3P6N8W3Y.147\inst..tion_c3955e569709176b_0001.0005_2260807ffd178e96\CleanCoGen.rar (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\user\Desktop\برامج م\Navicat.Premium.11.0.8.rar (PUP.Hacktool.Patcher) -> Quarantined and deleted successfully.
C:\Users\user\Desktop\برامج م\Patch-MPT.zip (PUP.Hacktool.Patcher) -> Quarantined and deleted successfully.
C:\Users\user\Downloads\MyEgY.CoM_IDM_6.17_Build_9_By.MaHeR.rar (PUP.Hacktool.Patcher) -> Quarantined and deleted successfully.
C:\Program Files\LyricsContainer\122.dll (PUP.Optional.LyricsAd) -> Quarantined and deleted successfully.
C:\Program Files\LyricsContainer\Uninstall.exe (PUP.Optional.LyricsAd) -> Quarantined and deleted successfully.
C:\ProgramData\MUIQWG\DJR.01 (Trojan.Monder) -> Quarantined and deleted successfully.
C:\ProgramData\MUIQWG\DJR.02 (PUP.Ardamax) -> Quarantined and deleted successfully.
C:\ProgramData\InstallMate\{1F0F184F-9C12-4E67-AC8C-D430C4EC3AB9}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\InstallMate\{1F0F184F-9C12-4E67-AC8C-D430C4EC3AB9}\TsuDll.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\InstallMate\{D04E53D7-AD00-48EE-AA05-E5220BAD7121}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\InstallMate\{D04E53D7-AD00-48EE-AA05-E5220BAD7121}\TsuDll.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\InstallMate\{D0C899E7-FE32-4E8D-AC66-B6100B2BBB11}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\InstallMate\{D0C899E7-FE32-4E8D-AC66-B6100B2BBB11}\TsuDll.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\InstallMate\{F0F169AE-13B0-4DAF-AF44-5B922B124B58}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\InstallMate\{F0F169AE-13B0-4DAF-AF44-5B922B124B58}\TsuDll.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
D:\svhnu.pif (Trojan.Agent) -> Quarantined and deleted successfully.
D:\anhmnl.pif (Trojan.Agent) -> Quarantined and deleted successfully.
D:\ShadowCo Client\1031.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Users\user\AppData\Roaming\logs.dat (Bifrose.Trace) -> Quarantined and deleted successfully.
C:\Windows\schost.exe (Backdoor.IRCBot) -> Quarantined and deleted successfully.
C:\Users\user\AppData\Roaming\userv1.18.0 - Trial versionlog.dat (Stolen.Data) -> Quarantined and deleted successfully.
C:\Users\user\AppData\Roaming\Babylon\log_file.txt (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
C:\Program Files\LyricsContainer\sqlite3.dll (PUP.Optional.LyricsContainer.A) -> Quarantined and deleted successfully.
C:\Program Files\LyricsContainer\122.xpi (PUP.Optional.LyricsContainer.A) -> Quarantined and deleted successfully.
C:\Windows\Tasks\LyricsContainer Update.job (PUP.Optional.LyricsContainer.A) -> Quarantined and deleted successfully.
C:\Program Files\LemurLeap\updateLemurLeap.InstallState (PUP.Optional.LemurLeap.A) -> Quarantined and deleted successfully.
C:\Program Files\LemurLeap\jlnfdbbladgcmhhamgkioifhbobjaoof.crx (PUP.Optional.LemurLeap.A) -> Quarantined and deleted successfully.
C:\Program Files\diamondata\updatediamondata.exe (PUP.Optional.DiamonData.A) -> Quarantined and deleted successfully.
C:\Program Files\Gophoto.it\gophotoit14.crx (PUP.Optional.Gophoto.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.dat (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.ico (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setup.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\SearchNewTab\51b1ec80981dd.tlb (PUP.Optional.SearchNewTab) -> Quarantined and deleted successfully.
C:\ProgramData\SearchNewTab\settings.ini (PUP.Optional.SearchNewTab) -> Quarantined and deleted successfully.
(end)