
Quote: Originally Posted by
MadforitSteve
I have done a scan with MBAM,,,here is the log.
I have to restart now so will let yo unow if anything changes when i get back on.
Malwarebytes Anti-Malware (Trial) 1.61.0.1400
Malwarebytes : Free anti-malware, anti-virus and spyware removal download
Database version: v2012.04.18.05
Windows 7 x64 NTFS
Internet Explorer 9.0.8112.16421
Steve :: STEVE-PC [administrator]
Protection: Enabled
18/04/2012 12:59:13
mbam-log-2012-04-18 (12-59-13).txt
Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 443761
Time elapsed: 1 hour(s), 39 minute(s), 29 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 11
HKCR\CLSID\{11111111-1111-1111-1111-110011041135} (PUP.Codec.PR) -> Quarantined and deleted successfully.
HKCR\TypeLib\{44444444-4444-4444-4444-440044044435} (PUP.Codec.PR) -> Quarantined and deleted successfully.
HKCR\Interface\{55555555-5555-5555-5555-550055045535} (PUP.Codec.PR) -> Quarantined and deleted successfully.
HKCR\CrossriderApp0000435.BHO.1 (PUP.Codec.PR) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110011041135} (PUP.Codec.PR) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110011041135} (PUP.Codec.PR) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110011041135} (PUP.Codec.PR) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011041135} (PUP.Codec.PR) -> Quarantined and deleted successfully.
HKCR\CrossriderApp0000435.BHO (PUP.Codec.PR) -> Quarantined and deleted successfully.
HKCU\Software\voomuusa (Adware.HotBar.VM) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\VooMuu (Adware.HotBar.VM) -> Quarantined and deleted successfully.
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 5
C:\ProgramData\2ACA5CC3-0F83-453D-A079-1076FE1A8B65 (Adware.Seekmo) -> Quarantined and deleted successfully.
C:\Program Files (x86)\VooMuu (Adware.HotBar.VM) -> Quarantined and deleted successfully.
C:\Program Files (x86)\VooMuu\bin (Adware.HotBar.VM) -> Quarantined and deleted successfully.
C:\Program Files (x86)\VooMuu\bin\1.0.36.0 (Adware.HotBar.VM) -> Quarantined and deleted successfully.
C:\ProgramData\VooMuuSA (Adware.HotBar.VM) -> Quarantined and deleted successfully.
Files Detected: 11
D:\Users\Steve\Downloads\Remove WAT v2.2.5.2 - Windows 7 Activation\Remove WAT v2.2.5.2 - Windows 7 Activation\RemoveWAT.exe (HackTool.Wpakill) -> No action taken.
D:\Users\Steve\Downloads\Remove WAT v2.2.5.2 - Windows 7 Activation\Remove WAT v2.2.5.2 - Windows 7 Activation\RemoveWAT_2.exe (HackTool.Wpakill) -> No action taken.
C:\Program Files (x86)\Premiumplay Codec-C\Premiumplay Codec-C.dll (PUP.Codec.PR) -> Quarantined and deleted successfully.
C:\Program Files (x86)\VooMuu\bin\1.0.36.0\VooMuuSAHook.dll (Adware.HotBar.VM) -> Quarantined and deleted successfully.
C:\Users\Steve\Downloads\32Red(1).exe (PUP.Casino.Gen) -> Quarantined and deleted successfully.
C:\Users\Steve\Downloads\32Red.exe (PUP.Casino.Gen) -> Quarantined and deleted successfully.
C:\Program Files (x86)\VooMuu\bin\1.0.36.0\copyright.txt (Adware.HotBar.VM) -> Quarantined and deleted successfully.
C:\ProgramData\VooMuuSA\VooMuuSA.dat (Adware.HotBar.VM) -> Quarantined and deleted successfully.
C:\ProgramData\VooMuuSA\VooMuuSAau.dat (Adware.HotBar.VM) -> Quarantined and deleted successfully.
C:\ProgramData\VooMuuSA\VooMuuSA_hpk.dat (Adware.HotBar.VM) -> Quarantined and deleted successfully.
C:\ProgramData\VooMuuSA\VooMuuSA_kyf.dat (Adware.HotBar.VM) -> Quarantined and deleted successfully.
(end)