Malwarebytes Anti-Rootkit BETA 1.9.3.1001 www.malwarebytes.org Database version: main: v2017.10.29.04 rootkit: v2017.10.14.01 Windows Vista Service Pack 2 x64 NTFS (Safe Mode/Networking) Internet Explorer 9.0.8112.16421 Hayes 2 :: HAYES2-PC [administrator] 10/29/2017 3:06:34 PM mbar-log-2017-10-29 (15-06-34).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: Objects scanned: 322235 Time elapsed: 31 minute(s), 55 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 1 HKLM\SOFTWARE\Tarma Installer (Adware.Yontoo) -> Delete on reboot. [8cacf6eb06a3b086e7d3c6811ee3fb05] Registry Values Detected: 2 HKU\S-1-5-21-1094520485-351602351-698667415-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} (Trojan.BHO.Generic) -> Data: -> Delete on reboot. [76c2c918cddc7abc4819991a16ebcb35] HKU\S-1-5-21-1094520485-351602351-698667415-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} (Trojan.BHO.Generic) -> Data: *ÃK`€–Ñ@šÆàk#¡ºL -> Delete on reboot. [76c2c918cddc7abc4819991a16ebcb35] Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) Physical Sectors Detected: 0 (No malicious items detected) (end)