Malwarebytes
www.malwarebytes.com
-Log Details-
Scan Date: 6/4/20
Scan Time: 2:38 AM
Log File: 44608e6a-a5f3-11ea-9867-000000000000.json
-Software Information-
Version: 4.1.0.56
Components Version: 1.0.920
Update Package Version: 1.0.24966
License: Trial
-System Information-
OS: Windows 10 (Build 18362.476)
CPU: x64
File System: NTFS
User: SERHAT\Serhat
-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 324548
Threats Detected: 27
Threats Quarantined: 27
Time Elapsed: 3 min, 9 sec
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect
-Scan Details-
Process: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registry Key: 10
PUP.Optional.InstallCore, HKU\S-1-5-21-1656262597-3878234489-254850471-1001\SOFTWARE\CSASTATS\ic, Quarantined, 500, 586068, 1.0.24966, , ame,
Trojan.Agent.PrxySvrRST, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Re-attempt Adobe® Flash Player Install, Quarantined, 1178, 694061, , , ,
Trojan.Agent.PrxySvrRST, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{0C088BD4-0B42-4FBD-AF65-B4CCE7DBBD4D}, Quarantined, 1178, 694061, , , ,
Trojan.Agent.PrxySvrRST, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{0C088BD4-0B42-4FBD-AF65-B4CCE7DBBD4D}, Quarantined, 1178, 694061, , , ,
Trojan.Agent.PrxySvrRST, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NLASVC\PARAMETERS\INTERNET\MANUALPROXIES, Quarantined, 1178, -1, 0.0.0, , action,
Trojan.Agent.PrxySvrRST, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{B3C3EB9A-8C77-47C7-B740-BFAB31215159}, Quarantined, 1178, 694062, , , ,
Trojan.Agent.PrxySvrRST, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{B3C3EB9A-8C77-47C7-B740-BFAB31215159}, Quarantined, 1178, 694062, , , ,
Trojan.Agent.PrxySvrRST, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Inno Setup® Software Update Scheduler, Quarantined, 1178, 694062, 1.0.24966, , ame,
PUP.Optional.ByteFence, HKLM\SOFTWARE\MICROSOFT\TRACING\ByteFence_RASAPI32, Quarantined, 1005, 823187, 1.0.24966, , ame,
PUP.Optional.ByteFence, HKLM\SOFTWARE\MICROSOFT\TRACING\ByteFence_RASMANCS, Quarantined, 1005, 823187, 1.0.24966, , ame,
Registry Value: 15
Trojan.Agent.PrxySvrRST, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Quarantined, 1178, -1, 0.0.0, , action,
Trojan.Agent.PrxySvrRST, HKU\S-1-5-21-1656262597-3878234489-254850471-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Quarantined, 1178, -1, 0.0.0, , action,
Trojan.Agent.PrxySvrRST, HKU\S-1-5-21-1656262597-3878234489-254850471-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYSERVER, Quarantined, 1178, -1, 0.0.0, , action,
Trojan.Agent.PrxySvrRST, HKU\S-1-5-21-1656262597-3878234489-254850471-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYOVERRIDE, Quarantined, 1178, -1, 0.0.0, , action,
Trojan.Agent.PrxySvrRST, HKU\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Quarantined, 1178, -1, 0.0.0, , action,
Trojan.Agent.PrxySvrRST, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Quarantined, 1178, -1, 0.0.0, , action,
Trojan.Agent.PrxySvrRST, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Quarantined, 1178, -1, 0.0.0, , action,
Trojan.Agent.PrxySvrRST, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYSERVER, Quarantined, 1178, -1, 0.0.0, , action,
Trojan.Agent.PrxySvrRST, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYSERVER, Quarantined, 1178, -1, 0.0.0, , action,
Trojan.Agent.PrxySvrRST, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYOVERRIDE, Quarantined, 1178, -1, 0.0.0, , action,
Trojan.Agent.PrxySvrRST, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYOVERRIDE, Quarantined, 1178, -1, 0.0.0, , action,
Trojan.Agent.PrxySvrRST, HKLM\SOFTWARE\POLICIES\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYSETTINGSPERUSER, Quarantined, 1178, -1, 0.0.0, , action,
Trojan.Agent.PrxySvrRST, HKLM\SOFTWARE\WOW6432NODE\POLICIES\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYSETTINGSPERUSER, Quarantined, 1178, -1, 0.0.0, , action,
Trojan.Agent.PrxySvrRST, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{0C088BD4-0B42-4FBD-AF65-B4CCE7DBBD4D}|PATH, Quarantined, 1178, 694059, 1.0.24966, , ame,
Trojan.Agent.PrxySvrRST, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{B3C3EB9A-8C77-47C7-B740-BFAB31215159}|PATH, Quarantined, 1178, 694063, 1.0.24966, , ame,
Registry Data: 0
(No malicious items detected)
Data Stream: 0
(No malicious items detected)
Folder: 0
(No malicious items detected)
File: 2
Trojan.Agent.PrxySvrRST, C:\WINDOWS\SYSTEM32\TASKS\Re-attempt Adobe® Flash Player Install, Quarantined, 1178, 694061, 1.0.24966, , ame,
Trojan.Agent.PrxySvrRST, C:\WINDOWS\SYSTEM32\TASKS\INNO SETUP® SOFTWARE UPDATE SCHEDULER, Quarantined, 1178, 694062, , , ,
Physical Sector: 0
(No malicious items detected)
WMI: 0
(No malicious items detected)
(end)