Virus Total link -
https://www.virustotal.com/en/file/...d3330d4f02fae7de1919549e513238864c4/analysis/
============================================================================================
Malwarebytes Scan - This found some of my Nikon RAW photograph files. Possibly because the file name started with an underscore. I cleaned them regardless
============================================================================================
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 25/03/2014
Scan Time: 16:26:26
Logfile:
Administrator: Yes
Version: 2.00.0.1000
Malware Database: v2014.03.25.04
Rootkit Database: v2014.03.18.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Chameleon: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Ricky
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 331405
Time Elapsed: 44 min, 59 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 6
PUP.Optional.FunMoods.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}, Quarantined, [98e0bb4c0e6d6bcb6ddc62b20bf717e9],
PUP.Optional.FunMoods.A, HKU\S-1-5-21-752273353-578144960-589867486-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}, Quarantined, [98e0bb4c0e6d6bcb6ddc62b20bf717e9],
PUP.Optional.FunMoods.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}, Quarantined, [98e0bb4c0e6d6bcb6ddc62b20bf717e9],
PUP.Optional.FunMoods.A, HKU\S-1-5-21-752273353-578144960-589867486-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}, Quarantined, [98e0bb4c0e6d6bcb6ddc62b20bf717e9],
PUP.Optional.Funmoods.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}, Quarantined, [5325d6314a31db5bd3c6260fa45e946c],
PUP.Optional.Funmoods.A, HKU\S-1-5-21-752273353-578144960-589867486-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}, Quarantined, [5325d6314a31db5bd3c6260fa45e946c],
Registry Values: 1
Trojan.Downloader, HKU\S-1-5-21-752273353-578144960-589867486-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Audio HD Driver, C:\Users\Guest\AppData\Local\Temp\guitarpro.exe, Quarantined, [91e77b8c83f89b9b74717c561ee4e11f]
Registry Data: 0
(No malicious items detected)
Folders: 4
Trojan.Agent, C:\Users\Ricky\20131226, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131229, Quarantined, [6711db2cdd9ea5917dd8d972fb0720e0],
Trojan.Agent, C:\Users\Ricky\20140104, Quarantined, [91e7c641f784aa8cada88cbfcc36f10f],
Trojan.Agent, C:\Users\Ricky\20140105, Quarantined, [591f23e49eddfc3a9db81d2ec1415ba5],
Files: 94
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4865.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4850.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4851.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4852.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4853.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4854.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4855.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4856.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4857.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4858.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4859.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4860.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4861.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4862.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4863.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4864.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4866.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4867.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4868.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4869.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4870.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4871.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4872.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4873.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4874.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4875.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4876.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4877.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4878.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4879.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4880.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4881.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4882.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4883.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4884.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4885.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4886.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4887.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4888.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4889.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4890.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4891.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4892.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131226\_DSC4893.NEF, Quarantined, [4533f90ec4b778be9abb430844be6898],
Trojan.Agent, C:\Users\Ricky\20131229\_DSC4902.NEF, Quarantined, [6711db2cdd9ea5917dd8d972fb0720e0],
Trojan.Agent, C:\Users\Ricky\20131229\_DSC4903.NEF, Quarantined, [6711db2cdd9ea5917dd8d972fb0720e0],
Trojan.Agent, C:\Users\Ricky\20131229\_DSC4904.NEF, Quarantined, [6711db2cdd9ea5917dd8d972fb0720e0],
Trojan.Agent, C:\Users\Ricky\20131229\_DSC4905.NEF, Quarantined, [6711db2cdd9ea5917dd8d972fb0720e0],
Trojan.Agent, C:\Users\Ricky\20131229\_DSC4906.NEF, Quarantined, [6711db2cdd9ea5917dd8d972fb0720e0],
Trojan.Agent, C:\Users\Ricky\20131229\_DSC4907.NEF, Quarantined, [6711db2cdd9ea5917dd8d972fb0720e0],
Trojan.Agent, C:\Users\Ricky\20131229\_DSC4908.NEF, Quarantined, [6711db2cdd9ea5917dd8d972fb0720e0],
Trojan.Agent, C:\Users\Ricky\20131229\_DSC4909.NEF, Quarantined, [6711db2cdd9ea5917dd8d972fb0720e0],
Trojan.Agent, C:\Users\Ricky\20131229\_DSC4910.NEF, Quarantined, [6711db2cdd9ea5917dd8d972fb0720e0],
Trojan.Agent, C:\Users\Ricky\20131229\_DSC4911.NEF, Quarantined, [6711db2cdd9ea5917dd8d972fb0720e0],
Trojan.Agent, C:\Users\Ricky\20131229\_DSC4912.NEF, Quarantined, [6711db2cdd9ea5917dd8d972fb0720e0],
Trojan.Agent, C:\Users\Ricky\20131229\_DSC4913.NEF, Quarantined, [6711db2cdd9ea5917dd8d972fb0720e0],
Trojan.Agent, C:\Users\Ricky\20131229\_DSC4914.NEF, Quarantined, [6711db2cdd9ea5917dd8d972fb0720e0],
Trojan.Agent, C:\Users\Ricky\20131229\_DSC4915.NEF, Quarantined, [6711db2cdd9ea5917dd8d972fb0720e0],
Trojan.Agent, C:\Users\Ricky\20131229\_DSC4916.NEF, Quarantined, [6711db2cdd9ea5917dd8d972fb0720e0],
Trojan.Agent, C:\Users\Ricky\20131229\_DSC4917.NEF, Quarantined, [6711db2cdd9ea5917dd8d972fb0720e0],
Trojan.Agent, C:\Users\Ricky\20131229\_DSC4918.NEF, Quarantined, [6711db2cdd9ea5917dd8d972fb0720e0],
Trojan.Agent, C:\Users\Ricky\20131229\_DSC4919.NEF, Quarantined, [6711db2cdd9ea5917dd8d972fb0720e0],
Trojan.Agent, C:\Users\Ricky\20140104\_DSC4920.NEF, Quarantined, [91e7c641f784aa8cada88cbfcc36f10f],
Trojan.Agent, C:\Users\Ricky\20140104\_DSC4921.NEF, Quarantined, [91e7c641f784aa8cada88cbfcc36f10f],
Trojan.Agent, C:\Users\Ricky\20140104\_DSC4922.NEF, Quarantined, [91e7c641f784aa8cada88cbfcc36f10f],
Trojan.Agent, C:\Users\Ricky\20140104\_DSC4923.NEF, Quarantined, [91e7c641f784aa8cada88cbfcc36f10f],
Trojan.Agent, C:\Users\Ricky\20140104\_DSC4924.NEF, Quarantined, [91e7c641f784aa8cada88cbfcc36f10f],
Trojan.Agent, C:\Users\Ricky\20140104\_DSC4925.NEF, Quarantined, [91e7c641f784aa8cada88cbfcc36f10f],
Trojan.Agent, C:\Users\Ricky\20140104\_DSC4926.NEF, Quarantined, [91e7c641f784aa8cada88cbfcc36f10f],
Trojan.Agent, C:\Users\Ricky\20140104\_DSC4927.NEF, Quarantined, [91e7c641f784aa8cada88cbfcc36f10f],
Trojan.Agent, C:\Users\Ricky\20140104\_DSC4928.NEF, Quarantined, [91e7c641f784aa8cada88cbfcc36f10f],
Trojan.Agent, C:\Users\Ricky\20140104\_DSC4929.NEF, Quarantined, [91e7c641f784aa8cada88cbfcc36f10f],
Trojan.Agent, C:\Users\Ricky\20140104\_DSC4930.NEF, Quarantined, [91e7c641f784aa8cada88cbfcc36f10f],
Trojan.Agent, C:\Users\Ricky\20140104\_DSC4931.NEF, Quarantined, [91e7c641f784aa8cada88cbfcc36f10f],
Trojan.Agent, C:\Users\Ricky\20140104\_DSC4932.NEF, Quarantined, [91e7c641f784aa8cada88cbfcc36f10f],
Trojan.Agent, C:\Users\Ricky\20140104\_DSC4933.NEF, Quarantined, [91e7c641f784aa8cada88cbfcc36f10f],
Trojan.Agent, C:\Users\Ricky\20140104\_DSC4934.NEF, Quarantined, [91e7c641f784aa8cada88cbfcc36f10f],
Trojan.Agent, C:\Users\Ricky\20140104\_DSC4935.NEF, Quarantined, [91e7c641f784aa8cada88cbfcc36f10f],
Trojan.Agent, C:\Users\Ricky\20140104\_DSC4936.NEF, Quarantined, [91e7c641f784aa8cada88cbfcc36f10f],
Trojan.Agent, C:\Users\Ricky\20140104\_DSC4937.NEF, Quarantined, [91e7c641f784aa8cada88cbfcc36f10f],
Trojan.Agent, C:\Users\Ricky\20140104\_DSC4938.NEF, Quarantined, [91e7c641f784aa8cada88cbfcc36f10f],
Trojan.Agent, C:\Users\Ricky\20140105\_DSC4939.NEF, Quarantined, [591f23e49eddfc3a9db81d2ec1415ba5],
Trojan.Agent, C:\Users\Ricky\20140105\_DSC4940.NEF, Quarantined, [591f23e49eddfc3a9db81d2ec1415ba5],
Trojan.Agent, C:\Users\Ricky\20140105\_DSC4941.NEF, Quarantined, [591f23e49eddfc3a9db81d2ec1415ba5],
Trojan.Agent, C:\Users\Ricky\20140105\_DSC4942.NEF, Quarantined, [591f23e49eddfc3a9db81d2ec1415ba5],
Trojan.Agent, C:\Users\Ricky\20140105\_DSC4943.NEF, Quarantined, [591f23e49eddfc3a9db81d2ec1415ba5],
Trojan.Agent, C:\Users\Ricky\20140105\_DSC4944.NEF, Quarantined, [591f23e49eddfc3a9db81d2ec1415ba5],
Trojan.Agent, C:\Users\Ricky\20140105\_DSC4945.NEF, Quarantined, [591f23e49eddfc3a9db81d2ec1415ba5],
Trojan.Agent, C:\Users\Ricky\20140105\_DSC4946.NEF, Quarantined, [591f23e49eddfc3a9db81d2ec1415ba5],
Trojan.Agent, C:\Users\Ricky\20140105\_DSC4947.NEF, Quarantined, [591f23e49eddfc3a9db81d2ec1415ba5],
Trojan.Agent, C:\Users\Ricky\20140105\_DSC4948.NEF, Quarantined, [591f23e49eddfc3a9db81d2ec1415ba5],
Trojan.Agent, C:\Users\Ricky\20140105\_DSC4949.NEF, Quarantined, [591f23e49eddfc3a9db81d2ec1415ba5],
Trojan.Agent, C:\Users\Ricky\20140105\_DSC4950.NEF, Quarantined, [591f23e49eddfc3a9db81d2ec1415ba5],
Trojan.Agent, C:\Users\Ricky\20140105\_DSC4951.NEF, Quarantined, [591f23e49eddfc3a9db81d2ec1415ba5],
Physical Sectors: 0
(No malicious items detected)
(end)
ESETSCAN
===========================================================================================================
C:\FRST\Quarantine\C\Users\Guest\AppData\Local\Temp\guitarpro.exe.xBAD MSIL/Arcdoor.AK worm
C:\FRST\Quarantine\C\Users\Ricky\AppData\Local\Google\Chrome\User Data\Default\Extensions\klibnahbojhkanfgaglnlalfkgpcppfi\10.26.9.505_0\APISupport\APISupport.dll a variant of Win32/Toolbar.Conduit.Z potentially unwanted application
C:\FRST\Quarantine\C\Users\Ricky\AppData\Local\Temp\Windows-Auth-Host-Service.exe.xBAD MSIL/Arcdoor.AK worm
C:\FRST\Quarantine\C\Users\Ryan\AppData\Local\Temp\Windows-Auth-Host-Service.exe.xBAD MSIL/Arcdoor.AK worm
C:\Program Files\Common Files\Windows-Auth-Host-Service.exe MSIL/Arcdoor.AK worm
C:\Program Files (x86)\Dell DataSafe Local Backup\hstart.exe a variant of Win32/HiddenStart.A potentially unsafe application
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe a variant of Win32/HiddenStart.A potentially unsafe application
C:\Users\Guest\AppData\Roaming\guitarpro.exe MSIL/Arcdoor.AK worm
C:\Users\Guest\Downloads\Never_Blue04_8668_319894.exe Win32/InstallMonetizer.AG potentially unwanted application
C:\Users\Public\Documents\FoxitReader614.0217_enu_Setup.exe a variant of Win32/OpenCandy.A potentially unsafe application
C:\Users\Ricky\AppData\Roaming\Audio-HD-Service.exe MSIL/Arcdoor.AK worm
C:\Users\Ricky\AppData\Roaming\GooglePlug\genius.exe MSIL/Arcdoor.AK worm
C:\Users\Ricky\Downloads\BickhamScriptFancy2_Font_Installer.exe a variant of Win32/OpenInstall potentially unwanted application
C:\Users\Ricky\Downloads\Core-Temp-setup.exe probably a variant of Win32/Complitly.A potentially unwanted application
C:\Users\Ricky\Downloads\CrK.rar a variant of MSIL/HackKMS.A potentially unsafe application
C:\Users\Ricky\Downloads\orionsetup.exe a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\Users\Ricky\Downloads\pal_install_r109888.exe a variant of Win32/Bundled.Toolbar.Ask.D potentially unsafe application
C:\Users\Ricky\Downloads\Unlockroot\Unlockroot\unlockroot.exe Win32/UnlockRoot potentially unsafe application
C:\Users\Ryan\AppData\Roaming\Audio-HD-Service.exe MSIL/Arcdoor.AK worm
C:\Users\Ryan\Downloads\WinZip180.exe a variant of Win32/OpenInstall potentially unwanted application
D:\My Documents\Downloads\easetup.exe a variant of Win32/Toolbar.Conduit.I potentially unwanted application
D:\NewsBin\Amateur_Photographer_-_January_4_2014__UK.zip MSIL/TrojanDownloader.Agent.NZ trojan
D:\RICKY-PC\Backup Set 2014-03-02 202708\Backup Files 2014-03-02 202708\Backup files 10.zip a variant of Win32/OpenInstall potentially unwanted application
D:\RICKY-PC\Backup Set 2014-03-02 202708\Backup Files 2014-03-02 202708\Backup files 14.zip a variant of Win32/Toolbar.Conduit.H potentially unwanted application
D:\RICKY-PC\Backup Set 2014-03-02 202708\Backup Files 2014-03-02 202708\Backup files 18.zip multiple threats
D:\RICKY-PC\Backup Set 2014-03-02 202708\Backup Files 2014-03-02 202708\Backup files 19.zip MSIL/Arcdoor.AK worm
D:\RICKY-PC\Backup Set 2014-03-02 202708\Backup Files 2014-03-02 202708\Backup files 27.zip a variant of Win32/Toolbar.Conduit.Z potentially unwanted application
D:\RICKY-PC\Backup Set 2014-03-23 190004\Backup Files 2014-03-23 190004\Backup files 1.zip a variant of Win32/OpenCandy.A potentially unsafe application
D:\RICKY-PC\Backup Set 2014-03-23 190004\Backup Files 2014-03-23 190004\Backup files 11.zip a variant of Win32/OpenInstall potentially unwanted application
D:\RICKY-PC\Backup Set 2014-03-23 190004\Backup Files 2014-03-23 190004\Backup files 15.zip a variant of Win32/Toolbar.Conduit.H potentially unwanted application
D:\RICKY-PC\Backup Set 2014-03-23 190004\Backup Files 2014-03-23 190004\Backup files 20.zip Win32/UnlockRoot potentially unsafe application
D:\RICKY-PC\Backup Set 2014-03-23 190004\Backup Files 2014-03-23 190004\Backup files 21.zip MSIL/Arcdoor.AK worm
WINZIP180.exe - File Upload Manager refused to allow upload saying it was an invalid file
Did you speak too soon? These scans appear to have been productive. The beer's the being kept cold.
