Malwarebytes Anti-Malware 1.60.0.1800 www.malwarebytes.org Database version: v2012.01.18.03 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Cathy :: CATHY-PC [administrator] 1/18/2012 10:13:20 AM mbam-log-2012-01-18 (10-13-20).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 250947 Time elapsed: 7 minute(s), 8 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 4 HKCR\AppID\GamevanceText.DLL (Adware.GameVance) -> Quarantined and deleted successfully. HKCU\Software\voomuusa (Adware.HotBar.VM) -> Quarantined and deleted successfully. HKCU\Software\AppDataLow\gvtl (Adware.GameVance) -> Quarantined and deleted successfully. HKLM\SOFTWARE\VooMuu (Adware.HotBar.VM) -> Quarantined and deleted successfully. Registry Values Detected: 1 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Microsoft® Windows® Operating System (Backdoor.Messa) -> Data: C:\Users\Cathy\AppData\Roaming\Microsoft\Protect\Credentials -> Quarantined and deleted successfully. Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 16 C:\Users\Cathy\Downloads\oi_setup.exe (PUP.BundleInstaller.OI) -> No action taken. C:\Users\Cathy\Downloads\IWON(2).exe (Adware.FunWeb) -> Quarantined and deleted successfully. C:\Users\Cathy\Downloads\IWON(3).exe (Adware.FunWeb) -> Quarantined and deleted successfully. C:\Users\Cathy\Downloads\IWON(4).exe (Adware.FunWeb) -> Quarantined and deleted successfully. C:\Users\Cathy\Downloads\IWON(5).exe (Adware.FunWeb) -> Quarantined and deleted successfully. C:\Users\Cathy\Downloads\IWON(6).exe (Adware.FunWeb) -> Quarantined and deleted successfully. C:\Users\Cathy\Downloads\IWON(7).exe (Adware.FunWeb) -> Quarantined and deleted successfully. C:\Users\Cathy\Downloads\IWON(8).exe (Adware.FunWeb) -> Quarantined and deleted successfully. C:\Users\Cathy\Downloads\IWON.exe (Adware.FunWeb) -> Quarantined and deleted successfully. C:\Users\Cathy\Downloads\MusicConverterSetup(2).exe (Adware.InstallCore) -> Quarantined and deleted successfully. C:\Users\Cathy\Downloads\MusicConverterSetup.exe (Adware.InstallCore) -> Quarantined and deleted successfully. C:\Users\Janice\Downloads\FLVPlayerSetup.exe (Adware.Agent) -> Quarantined and deleted successfully. C:\Users\june\Downloads\Codec-C.exe (Affiliate.Downloader) -> Quarantined and deleted successfully. C:\Users\june\Downloads\CursorMania.exe (Adware.FunWeb) -> Quarantined and deleted successfully. C:\Users\june\Downloads\IWON(2).exe (Adware.FunWeb) -> Quarantined and deleted successfully. C:\Users\june\Downloads\IWON.exe (Adware.FunWeb) -> Quarantined and deleted successfully. (end)