Malwarebytes Anti-Malware (Trial) 1.65.0.1400 www.malwarebytes.org Database version: v2012.09.07.13 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 Owner :: USER-PC [administrator] Protection: Enabled 8/18/2012 5:54:21 PM mbam-log-2012-08-18 (17-54-21).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 197556 Time elapsed: 6 minute(s), 50 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 22 HKCR\Typelib\{B035BA6B-57CD-4F72-B545-65BE465FCAF6} (Adware.ShoppingReport2) -> Quarantined and deleted successfully. HKCR\Typelib\{D44FD6F0-9746-484E-B5C4-C66688393872} (Adware.ShoppingReport2) -> Quarantined and deleted successfully. HKCR\Interface\{0EB3F101-224A-4B2B-9E5B-DF720857529C} (Adware.ShoppingReport2) -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (PUP.MyWebSearch) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A078F691-9C07-4AF2-BF43-35E79EECF8B7} (Adware.Softomate) -> Quarantined and deleted successfully. HKCR\HBLiteAx.Info (Adware.HotBar) -> Quarantined and deleted successfully. HKCR\HBLiteAx.Info.1 (Adware.HotBar) -> Quarantined and deleted successfully. HKCR\HBLiteAX.UserProfiles (Adware.HotBar) -> Quarantined and deleted successfully. HKCR\HBLiteAX.UserProfiles.1 (Adware.HotBar) -> Quarantined and deleted successfully. HKCR\ShoppingReport2.HbAx (Adware.ShopperReports) -> Quarantined and deleted successfully. HKCR\ShoppingReport2.HbAx.1 (Adware.ShopperReports) -> Quarantined and deleted successfully. HKCR\ShoppingReport2.HbInfoBand (Adware.ShopperReports) -> Quarantined and deleted successfully. HKCR\ShoppingReport2.HbInfoBand.1 (Adware.ShopperReports) -> Quarantined and deleted successfully. HKCR\ShoppingReport2.IEButton (Adware.ShopperReports) -> Quarantined and deleted successfully. HKCR\ShoppingReport2.IEButton.1 (Adware.ShopperReports) -> Quarantined and deleted successfully. HKCR\ShoppingReport2.IEButtonA (Adware.ShopperReports) -> Quarantined and deleted successfully. HKCR\ShoppingReport2.IEButtonA.1 (Adware.ShopperReports) -> Quarantined and deleted successfully. HKCR\ShoppingReport2.RprtCtrl (Adware.ShopperReports) -> Quarantined and deleted successfully. HKCR\ShoppingReport2.RprtCtrl.1 (Adware.ShopperReports) -> Quarantined and deleted successfully. HKCU\Software\hblitesa (Adware.HotBar) -> Quarantined and deleted successfully. HKLM\SOFTWARE\HBLite (Adware.HotBar) -> Quarantined and deleted successfully. HKLM\SOFTWARE\ResultBar (Adware.ResultBar) -> Quarantined and deleted successfully. Registry Values Detected: 2 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|HBLiteSA (Adware.HotBar) -> Data: "C:\Program Files\HBLite\bin\11.0.264.0\HBLiteSA.exe" -> Quarantined and deleted successfully. HKLM\SOFTWARE\Mozilla\Firefox\extensions|HBLite@HBLite.com (Adware.HotBar) -> Data: C:\Program Files\HBLite\bin\11.0.264.0\firefox\extensions -> Quarantined and deleted successfully. Registry Data Items Detected: 1 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowSearch (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully. Folders Detected: 12 C:\ProgramData\92316425 (Rogue.Multiple) -> Quarantined and deleted successfully. C:\ProgramData\2ACA5CC3-0F83-453D-A079-1076FE1A8B65 (Adware.Seekmo) -> Quarantined and deleted successfully. C:\Users\Owner\AppData\Roaming\HBLite (Adware.Hotbar) -> Quarantined and deleted successfully. C:\ProgramData\HBLiteSA (Adware.Hotbar) -> Quarantined and deleted successfully. C:\ProgramData\ResultBar (Adware.ResultBar) -> Quarantined and deleted successfully. C:\Program Files\HBLite (Adware.Hotbar) -> Quarantined and deleted successfully. C:\Program Files\HBLite\bin (Adware.Hotbar) -> Quarantined and deleted successfully. C:\Program Files\HBLite\bin\11.0.264.0 (Adware.Hotbar) -> Quarantined and deleted successfully. C:\Program Files\HBLite\bin\11.0.264.0\firefox (Adware.Hotbar) -> Quarantined and deleted successfully. C:\Program Files\HBLite\bin\11.0.264.0\firefox\extensions (Adware.Hotbar) -> Quarantined and deleted successfully. C:\Program Files\HBLite\bin\11.0.264.0\firefox\extensions\plugins (Adware.Hotbar) -> Quarantined and deleted successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hotbar (Adware.Hotbar) -> Quarantined and deleted successfully. Files Detected: 13 C:\Users\Owner\AppData\Roaming\Adobe\shed\thr1.chm (Malware.Trace) -> Quarantined and deleted successfully. C:\ProgramData\HBLiteSA\HBLiteSA.dat (Adware.Hotbar) -> Quarantined and deleted successfully. C:\ProgramData\HBLiteSA\HBLiteSAAbout.mht (Adware.Hotbar) -> Quarantined and deleted successfully. C:\ProgramData\HBLiteSA\HBLiteSAau.dat (Adware.Hotbar) -> Quarantined and deleted successfully. C:\ProgramData\HBLiteSA\HBLiteSAEULA.mht (Adware.Hotbar) -> Quarantined and deleted successfully. C:\ProgramData\HBLiteSA\HBLiteSA_kyf.dat (Adware.Hotbar) -> Quarantined and deleted successfully. C:\ProgramData\HBLiteSA\HBLiteSA_kyf_update.dat (Adware.Hotbar) -> Quarantined and deleted successfully. C:\Program Files\HBLite\bin\11.0.264.0\firefox\extensions\chrome.manifest (Adware.Hotbar) -> Quarantined and deleted successfully. C:\Program Files\HBLite\bin\11.0.264.0\firefox\extensions\install.rdf (Adware.Hotbar) -> Quarantined and deleted successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hotbar\About Hotbar.lnk (Adware.Hotbar) -> Quarantined and deleted successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hotbar\Hotbar Customer Support Center.lnk (Adware.Hotbar) -> Quarantined and deleted successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hotbar\Hotbar Uninstall Instructions.lnk (Adware.Hotbar) -> Quarantined and deleted successfully. C:\Users\Owner\Desktop\explorer.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully. (end)