Malwarebytes Anti-Rootkit BETA 1.10.3.1001 www.malwarebytes.org Database version: main: v2021.05.31.07 rootkit: v2021.05.31.07 Windows 10 x64 NTFS (Safe Mode/Networking) Internet Explorer 11.789.19041.0 josev :: DESKTOP-MKTF2H5 [administrator] 31/5/2021 1:07:51 p. m. mbar-log-2021-05-31 (13-07-51).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: Kernel memory modifications detected. Deep Anti-Rootkit Scan engaged. Objects scanned: 49315 Time elapsed: 12 minute(s), 33 second(s) [aborted] Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 1 HKU\S-1-5-21-2251894981-3858074833-453683670-1001\SOFTWARE\WOW6432NODE\MICROSOFT\ACTIVE SETUP\INSTALLED COMPONENTS\{Y479C6D0-OTRW-U5GH-S1EE-E0AC10B4E666} (Trojan.Agent) -> Delete on reboot. [ac076dbadc0a50e6d4ec2ac65ca4817f] Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 2 C:\Users\josev\AppData\Roaming\tdbtwcr (Trojan.MalPack) -> Delete on reboot. [a60d6dba4a9c36004f5daab822e325db] C:\Users\josev\Desktop\Malwarebytes.Premium.4.2.0.82\LicenseMalwareBytes.exe (RiskWare.DontStealOurSoftware) -> Delete on reboot. [a60db96ec620ed494198233cb0510ff1] Physical Sectors Detected: 1 Master Boot Record on Drive #0 (Bootkit.Pitou.MBR) -> Replace on reboot. [5237b8cacfd6ee7975cc82d9213313b1] (end)