Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 7/27/2016
Scan Time: 8:31 PM
Logfile:
Administrator: Yes
Version: 2.2.1.1043
Malware Database: v2016.07.27.11
Rootkit Database: v2016.05.27.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Bud Parker
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 357373
Time Elapsed: 28 min, 40 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 2
Backdoor.Agent.PGen, C:\Users\Bud Parker\AppData\Roaming\Ronzafind\Ronzafind.exe, 3480, , [a067b9702e6c91a56333a1aa936e738d]
PUP.Optional.Linkury.ACMB1, C:\ProgramData\Lamzap\Lamzap.exe, 4160, , [f71081a83367ab8b83454ab200033cc4]
Modules: 1
PUP.Optional.Linkury, C:\ProgramData\Lamzap\Lotstock.dll, , [b354bd6cd7c387af2b83bafca75aed13],
Registry Keys: 10
Backdoor.Agent.PGen, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Ronzafind, , [a067b9702e6c91a56333a1aa936e738d],
PUP.Optional.Linkury.ACMB1, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Lamzap, , [f71081a83367ab8b83454ab200033cc4],
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\LAMZAP.EXE, , [f71081a83367ab8b83454ab200033cc4],
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\LAMZAP.EXE, , [f71081a83367ab8b83454ab200033cc4],
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\mtLamzap, , [0403b0798812ba7c9835ae4e4eb5916f],
PUP.Optional.Linkury, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\IELNKSRCH, , [8f78bc6d6337f0466d0fba3ae320d52b],
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\Lamzap_RASAPI32, , [20e737f27723b185c80325d78c7745bb],
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\Lamzap_RASMANCS, , [67a039f03367b581a823c834ed163ec2],
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SILENTPROCESSEXIT\Lamzap.exe, , [8780b871fc9e092d9f2df20aac573fc1],
PUP.Optional.Linkury, HKU\S-1-5-21-2712942507-1312882600-3786330889-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{IELNKSRCH}, , [689fe14864360135f289d222798a8d73],
Registry Values: 7
PUP.Optional.Linkury, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\ielnksrch|DisplayName, Search the web, , [8f78bc6d6337f0466d0fba3ae320d52b]
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\ielnksrch|URL, http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBFnYN5R-SRTQR4zPSPhuTaZ17vJ3frYn59HrL-X3ClkPrJO7VoWVZ3t7tPNQGvKjF72C367JmhiWsudzFrQPH9hVxOGkdTp9-MDd2zs5uzDEDtGzS4DPOk4v-3JEy6wXan7Zt58nF2gcyl6BCXVvhpGeBEWbGd1kxW9kLxWxpeyNCVXm3OpW9yl1gT&q={searchTerms}, , [49be59d04d4db87e031c46b147bc18e8]
PUP.Optional.Linkury.ACMB1, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\LAMZAP|ImagePath, C:\ProgramData\\Lamzap\\Lamzap.exe shuz -f "C:\ProgramData\\Lamzap\\Lamzap.dat" -l -a, , [bb4ce5445941e84e547aec109b68e21e]
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-2712942507-1312882600-3786330889-1001\ENVIRONMENT|SNP, http://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F%6D?publisher=APSFClickMeIn&co=US&userid=e5295532-cfef-2cfc-b916-e5ddde5765fe&searchtype=sc&installDate=27/07/2016&barcodeid=51107003&channelid=3&av=windows, , [8f78f633a7f34cea113748adaf548c74]
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-2712942507-1312882600-3786330889-1001\ENVIRONMENT|SNF, C:\ProgramData\Lamzaps\snp.sc, , [13f4de4bd1c9cf67ed5ae90c2bd847b9]
PUP.Optional.Linkury, HKU\S-1-5-21-2712942507-1312882600-3786330889-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{ielnksrch}|DisplayName, Search the web, , [689fe14864360135f289d222798a8d73]
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-2712942507-1312882600-3786330889-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{ielnksrch}|URL, http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBFnYN5R-SRTQR4zPSPhuTaZ17vJ3frYn59HrL-X3ClkPrJO7VoWVZ3t7tPNQGvKjF72C367JmhiWsudzFrQPH9hVxOGkdTp9-MDd2zs5uzDEDtGzS4DPOk4v-3JEy6wXan7Zt58nF2gcyl6BCXVvhpGeBEWbGd1kxW9kLxWxpeyNCVXm3OpW9yl1gT&q={searchTerms}, , [7196d1584456d4621eff1dda9b685ea2]
Registry Data: 4
PUP.Optional.Linkury, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\ProgramData\Lamzap\Lotstock.dll, Good: (), Bad: (C:\ProgramData\Lamzap\Lotstock.dll),,[b354bd6cd7c387af2b83bafca75aed13]
PUP.Optional.Linkury, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\ProgramData\Lamzap\Vaialab.dll, Good: (), Bad: (C:\ProgramData\Lamzap\Vaialab.dll),,[fa0d13166139f640d3bca944946da35d]
PUP.Optional.Linkury, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {ielnksrch}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({ielnksrch}),,[e62186a33763e353fed3f287d331916f]
PUP.Optional.Linkury, HKU\S-1-5-21-2712942507-1312882600-3786330889-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {ielnksrch}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({ielnksrch}),,[bb4cc36605950b2be1ef7afff80cbd43]
Folders: 4
PUP.Optional.Linkury, C:\Windows\Temp\Smartbar, , [b0576ebb1486ad894634b0441ae9718f],
PUP.Optional.Linkury.ACMB1, C:\ProgramData\Lamzap, , [f71081a83367ab8b83454ab200033cc4],
PUP.Optional.Linkury.ACMB1, C:\ProgramData\Lamzap\ondemand, , [f71081a83367ab8b83454ab200033cc4],
PUP.Optional.Linkury.ACMB1, C:\ProgramData\Lamzaps, , [47c0aa7f1b7f8aac211c435a21e337c9],
Files: 32
PUP.Optional.Linkury, C:\ProgramData\Lamzap\Lotstock.dll, , [b354bd6cd7c387af2b83bafca75aed13],
Backdoor.Agent.PGen, C:\Users\Bud Parker\AppData\Roaming\Ronzafind\Ronzafind.exe, , [a067b9702e6c91a56333a1aa936e738d],
PUP.Optional.Linkury, C:\ProgramData\Lamzap\Vaialab.dll, , [fa0d13166139f640d3bca944946da35d],
PUP.Optional.Linkury, C:\ProgramData\Lamzap\Insoft.exe, , [cf38b673a0fab1859000fcf14db440c0],
PUP.Optional.Linkury, C:\ProgramData\Lamzap\Statquadkix.exe, , [ff083cedf2a8a5914baff694c33e7d83],
PUP.Optional.Linkury, C:\Windows\Temp\Smartbar\NewLam.ico, , [b0576ebb1486ad894634b0441ae9718f],
PUP.Optional.Linkury, C:\Windows\Temp\Smartbar\VoyaZaming.ico, , [b0576ebb1486ad894634b0441ae9718f],
PUP.Optional.Linkury.ACMB1, C:\ProgramData\Lamzap\Canlatcof.dat, , [f71081a83367ab8b83454ab200033cc4],
PUP.Optional.Linkury.ACMB1, C:\ProgramData\Lamzap\Ozergofan.bin, , [f71081a83367ab8b83454ab200033cc4],
PUP.Optional.Linkury.ACMB1, C:\ProgramData\Lamzap\conf.config, , [f71081a83367ab8b83454ab200033cc4],
PUP.Optional.Linkury.ACMB1, C:\ProgramData\Lamzap\Config.xml, , [f71081a83367ab8b83454ab200033cc4],
PUP.Optional.Linkury.ACMB1, C:\ProgramData\Lamzap\Dongtam.dat, , [f71081a83367ab8b83454ab200033cc4],
PUP.Optional.Linkury.ACMB1, C:\ProgramData\Lamzap\Insoft.exe.config, , [f71081a83367ab8b83454ab200033cc4],
PUP.Optional.Linkury.ACMB1, C:\ProgramData\Lamzap\Isplus.bin, , [f71081a83367ab8b83454ab200033cc4],
PUP.Optional.Linkury.ACMB1, C:\ProgramData\Lamzap\Kayis.bin, , [f71081a83367ab8b83454ab200033cc4],
PUP.Optional.Linkury.ACMB1, C:\ProgramData\Lamzap\Lamzap.d.dat, , [f71081a83367ab8b83454ab200033cc4],
PUP.Optional.Linkury.ACMB1, C:\ProgramData\Lamzap\Lamzap.dat, , [f71081a83367ab8b83454ab200033cc4],
PUP.Optional.Linkury.ACMB1, C:\ProgramData\Lamzap\Lamzap.exe, , [f71081a83367ab8b83454ab200033cc4],
PUP.Optional.Linkury.ACMB1, C:\ProgramData\Lamzap\md.xml, , [f71081a83367ab8b83454ab200033cc4],
PUP.Optional.Linkury.ACMB1, C:\ProgramData\Lamzap\Nam-Fax.dat, , [f71081a83367ab8b83454ab200033cc4],
PUP.Optional.Linkury.ACMB1, C:\ProgramData\Lamzap\SailCore.exe, , [f71081a83367ab8b83454ab200033cc4],
PUP.Optional.Linkury.ACMB1, C:\ProgramData\Lamzap\SailCore.exe.config, , [f71081a83367ab8b83454ab200033cc4],
PUP.Optional.Linkury.ACMB1, C:\ProgramData\Lamzap\Sangotip.bin, , [f71081a83367ab8b83454ab200033cc4],
PUP.Optional.Linkury.ACMB1, C:\ProgramData\Lamzap\Statquadkix.exe.config, , [f71081a83367ab8b83454ab200033cc4],
PUP.Optional.Linkury.ACMB1, C:\ProgramData\Lamzap\Stiming.bin, , [f71081a83367ab8b83454ab200033cc4],
PUP.Optional.Linkury.ACMB1, C:\ProgramData\Lamzap\Techhome.bin, , [f71081a83367ab8b83454ab200033cc4],
PUP.Optional.Linkury.ACMB1, C:\ProgramData\Lamzap\uninstall.dat, , [f71081a83367ab8b83454ab200033cc4],
PUP.Optional.Linkury.ACMB1, C:\ProgramData\Lamzap\Villacore.bin, , [f71081a83367ab8b83454ab200033cc4],
PUP.Optional.Linkury.ACMB1, C:\ProgramData\Lamzaps\ff.HP, , [47c0aa7f1b7f8aac211c435a21e337c9],
PUP.Optional.Linkury.ACMB1, C:\ProgramData\Lamzaps\ff.NT, , [47c0aa7f1b7f8aac211c435a21e337c9],
PUP.Optional.Linkury.ACMB1, C:\ProgramData\Lamzaps\snp.sc, , [47c0aa7f1b7f8aac211c435a21e337c9],
PUP.Optional.Linkury.ACMB1, C:\Users\Bud Parker\AppData\Roaming\Mozilla\Firefox\Profiles\kjqunreh.default\prefs.js, Good: (user_pref("browser.startup.homepage", "https://www.malwareb...storebrowser/),Bad: (user_pref("browser.startup.homepage", "C:\\ProgramData\\Lamzaps\\ff.HP), ,[c93ec762980293a30f1d00a0e71d5aa6]
Physical Sectors: 0
(No malicious items detected)
(end)