Malwarebytes Anti-Malware (Trial) 1.61.0.1400 www.malwarebytes.org Database version: v2012.04.04.08 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 hannah :: HANNAH-HP [administrator] Protection: Enabled 4/19/2012 7:23:09 AM mbam-log-2012-04-19 (07-23-09).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 197107 Time elapsed: 2 minute(s), 59 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 4 HKLM\SYSTEM\CurrentControlSet\Services\BasicScan Service (Adware.QuestBasic) -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33524C00-63FB-43DB-A6BF-0A4E14B24649} (Adware.Zwangi) -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{23B38049-323F-443D-9732-F454E5B15B72} (PUP.MyWebSearch) -> Quarantined and deleted successfully. HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\BASICSCAN (Adware.Zwangi) -> Quarantined and deleted successfully. Registry Values Detected: 3 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|KangoBoxSA (Adware.HotBar.CP) -> Data: "C:\Users\hannah\AppData\Local\KangoBoxSA\bin\1.0.3.0\KangoBoxSA.exe" -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BasicScan|DisplayName (Adware.Zwangi) -> Data: BasicScan 1.0 build 115 -> Quarantined and deleted successfully. HKLM\SYSTEM\CurrentControlSet\Services\BasicScan Service|ImagePath (Adware.Zwangi) -> Data: "C:\Program Files (x86)\BasicScan\basicscan.exe" "C:\Program Files (x86)\BasicScan\basicscan.dll" vivujora hodapuja -> Quarantined and deleted successfully. Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 6 C:\Users\hannah\AppData\Local\KangoBoxSA\bin\1.0.3.0\KangoBoxSA.exe (Adware.HotBar.CP) -> Quarantined and deleted successfully. C:\Program Files (x86)\BasicScan\basicscan.exe (Adware.QuestBasic) -> Quarantined and deleted successfully. C:\ProgramData\BasicScan\basicscan115.exe (Adware.QuestBasic) -> Quarantined and deleted successfully. C:\Program Files (x86)\2pUninstall Coupon Alert.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully. C:\Users\hannah\Local Settings\Temporary Internet Files\Content.IE5\VWXFJ0MO\XvidSetup.exe (Adware.AdBundle) -> Quarantined and deleted successfully. C:\Program Files (x86)\BasicScan\basicscan.dll (Adware.Zwangi) -> Quarantined and deleted successfully. (end)