[RESOLVED] Conduit - Visual Bee Search
The Chrome, Internet Explorer and Firefox browers on my WinXP computer have suddenly show up with the Conduit Toolbar and Visual Bee Search page instead of my usual default 'Google' search.
I have looked into this problem and had followed several suggestions on how to remove them, including the following:-
- removing the Conduit components using the Add/Remove Programs
- removing the Conduit apps from Chrome
- removing the Trusted Toolbar component using the Add/Remove Program
I do not think this hated Conduit stuff had been totally eradicated using the above methods; and sadly the System Restore function does not work** (cannot restore to a previous state no matter which restore point I choose). [** this problem had not been resolved, and I am not thinking of doing anything about it because I am thinking of moving to Win 7, although I like Win XP].
Firefox - I do not use it often. My most-often used browser is IE (Version 8.0.6001.18702).
The priority right now for me is to get rid of this hated Conduit and Visual Bee thing.
Please help. I appreciate your help.
Conduit - Visual Bee Search
Hi Broni,
I have used the "Remove Selected" after scanning. Here is the log.
=======
Malwarebytes Anti-Malware 1.70.0.1100
www.malwarebytes.org
Database version: v2013.04.01.03
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
ADMIN :: TEST-0EDA6CF69E [administrator]
4/2/2013 7:50:01 AM
mbam-log-2013-04-02 (07-50-01).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 239934
Time elapsed: 47 minute(s), 51 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 19
HKCR\AppID\{1DD31B76-C57E-49ba-94BC-BF53F0C82CD4} (PUP.Funshion) -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1DD31B76-C57E-49ba-94BC-BF53F0C82CD4} (PUP.Funshion) -> No action taken.
HKCR\CLSID\{91878E42-FC03-4785-B513-1F9E613D1027} (PUP.Funshion) -> No action taken.
HKCR\TypeLib\{D02E3AB9-7796-40CB-BDFC-20D834FE1F75} (PUP.Funshion) -> No action taken.
HKCR\Interface\{FCB380C4-D350-44BE-8791-50216F4747AC} (PUP.Funshion) -> No action taken.
HKCR\ASBarBroker.BDBroker.1 (PUP.Funshion) -> No action taken.
HKCR\ASBarBroker.BDBroker (PUP.Funshion) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{11CC93E4-0BE6-4F8F-82AA-D577FB955B05} (PUP.Funshion) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SETUP.EXE (PUP.BundleInstaller.VG) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{77FEF28E-EB96-44FF-B511-3185DEA48697} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{77FEF28E-EB96-44FF-B511-3185DEA48697} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{B580CF65-E151-49C3-B73F-70B13FCA8E86} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{B580CF65-E151-49C3-B73F-70B13FCA8E86} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A7F05EE4-0426-454F-8013-C41E3596E9E9} (Trojan.Cinmus) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E5D5D4A1-17F0-41D7-B1C6-0979F91E6F46} (Adware.BDSearch) -> Quarantined and deleted successfully.
HKCR\SogouExplorerHTML (Adware.Sogou) -> Delete on reboot.
HKCR\thunder (Trojan.Agent) -> Quarantined and deleted successfully.
HKCU\Software\SogouExplorer (Adware.Sogou) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Clients\StartMenuInternet\SogouExplorer.exe (Adware.Sogou) -> Quarantined and deleted successfully.
Registry Values Detected: 2
HKCU\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser|{B580CF65-E151-49C3-B73F-70B13FCA8E86} (Trojan.Cinmus) -> Data: eÏ€µQáÃI·?p±?ÊŽ* -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{B580CF65-E151-49C3-B73F-70B13FCA8E86} (Trojan.Cinmus) -> Data: -> Quarantined and deleted successfully.
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 20
C:\Program Files\Coopen (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\conf (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009 (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675 (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Photo (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Photo\local Photo (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Share (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Share\coopen share (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Share\coopen share\image_100 (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Wallpaper (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Wallpaper\coopen wallpaper (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Wallpaper\local wallpaper (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Resource (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Resource\res (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Resource\res\BMP (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Resource\SkinNormal (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Templete (Trojan.Agent) -> Quarantined and deleted successfully.
Files Detected: 186
C:\Program Files\Baidu\{17C2069B-BBFB-D78F-E94E-D089291F2150}\ASBarBroker.exe (PUP.Funshion) -> No action taken.
C:\Documents and Settings\ADMIN\My Documents\Downloads\setup.exe (PUP.BundleInstaller.VG) -> No action taken.
C:\Documents and Settings\ADMIN\Local Settings\TempDIR\BetterInstaller.exe (PUP.BundleInstaller.Somoto) -> No action taken.
C:\Documents and Settings\ADMIN\Application Data\SogouExplorer\sogou_explorer_silent_3.2.0.4716_2170.exe (Adware.Sogou) -> Quarantined and deleted successfully.
C:\Documents and Settings\ADMIN\Local Settings\Temp\12740125.Uninstall\Uninstall.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\ADMIN\Local Settings\Temp\coopen_setup_100155.exe (Adware.Coopen) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\CoopenModeB.cop (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\CoopenClient.cop (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\CoopenDeskIcon.cop (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\CoopenDownloader.cop (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\CoopenModeA.cop (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\CoopenModeC.cop (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\CoopenModeD.cop (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\CoopenPlayer.cop (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\CoopenUI.cop (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\CoopenUpdate.cop (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\licence.txt (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\temp.html (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\conf\ChannelListReal.txt (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\conf\ChannelListReal.txt.bak (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\conf\Debug (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\conf\DownImageList (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\conf\Log.txt (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\conf\MainParams (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\conf\ModeAChannelList.txt (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\conf\ModeAChannelList.txt.bak (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\conf\ModeAChannelListReal.txt (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\conf\ModeAChannelSetup.txt (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\conf\ModeASelectChannel.txt (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\conf\ServerList.txt (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\CoopenWallpaper.bmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746959926.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746926646.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746926646.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746926726.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746926726.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746926796.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746926796.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746926886.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746926886.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746926976.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746926976.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746927056.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746927056.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746959766.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746959766.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746959846.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746959846.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746959926.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\212.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\226.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\2472.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\252.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\255.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\258.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\259.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\p-100009-326.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\p-100009-330.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\p-100009-331.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\p-100009-332.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\p-100009-333.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\p-100009-334.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746960016.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746960016.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746960106.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746960106.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746960206.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746960206.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746961096.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746961096.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746961386.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746961386.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746961596.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746961596.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746961676.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746961676.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746961766.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746961766.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746963546.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_100009\12746963556.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12523977442.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12523977612.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12523977622.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12523977952.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12524765092.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12524765122.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12524765152.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12524765182.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12524765202.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12524765272.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12524765302.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12538562092.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12538562122.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12538562152.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12538562202.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12538562232.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12538562412.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12538562442.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12538562462.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12538562522.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12538562552.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\20090925172908.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\20090925174025.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\633880229608750000ad.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\633880237512812500ad.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\633880250656875000ad.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\633891499670468750ad.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\633894300871406250ad.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\633894965225781250ad.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12524765352.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12524765382.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12524765412.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12524765432.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12524765462.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12524765492.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12524765522.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12524765542.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12524765612.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12524765632.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12524765662.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12524765692.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12524765722.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12524765752.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\125308966416.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12531742162.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12531789482.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12536031572.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12536031602.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12536031652.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12536909952.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12536909972.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12538559422.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12538559452.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12538559472.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12538559502.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12538559522.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12538559582.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12538561942.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12538561972.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12538562002.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12538562012.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12538562032.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12524765322.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\12538562062.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\633894972007656250ad.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\8573320090924225316.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\8580720090921110242.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\8586220090921110524.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\8651920090924230156.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\8702220090926224733.xml (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Illustrated\coopen illustrated\image_109675\DefaultCoopenWallpaper.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Photo\local Photo\B_0.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Photo\local Photo\B_1.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Share\coopen share\image_100\B_0.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Share\coopen share\image_100\B_1.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Wallpaper\coopen wallpaper\DefaultCoopenWallpaper.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\image\Wallpaper\local wallpaper\DefaultCoopenWallpaper.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Resource\res\BMP\cancel.bmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Resource\res\BMP\close.bmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Resource\res\BMP\Myphoto.bmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Resource\res\BMP\MyShare.bmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Resource\res\BMP\MyWallpaper.bmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Resource\res\BMP\play.bmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Resource\SkinNormal\Button_Play.bmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Resource\SkinNormal\Background.bmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Resource\SkinNormal\Button_Close.bmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Resource\SkinNormal\Button_IconHide.bmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Resource\SkinNormal\Button_IconShow.bmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Resource\SkinNormal\Button_ModeMenu.bmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Resource\SkinNormal\Button_ModeSel.bmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Resource\SkinNormal\Button_next.bmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Resource\SkinNormal\Button_Pause.bmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Resource\SkinNormal\Button_Prev.bmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Resource\SkinNormal\Button_ScreenSaver.bmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Resource\SkinNormal\Button_Setting.bmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Resource\SkinNormal\Button_Weblogo.bmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Resource\SkinNormal\Notify_BG.bmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Resource\SkinNormal\Notify_Close.bmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Resource\SkinNormal\Progress_download.bmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Resource\SkinNormal\Progress_download1.bmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Resource\SkinNormal\Separator.bmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Templete\CoopenPhoto.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Templete\DefaultCoopenWallpaper.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Templete\ModeB.tpl (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Templete\ModeB_logo.jpg (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Coopen\Templete\ModeC.tpl (Trojan.Agent) -> Quarantined and deleted successfully.
(end)
======
Conduit - Visual Bee Search
Hi Broni,
All highlighted items in the Scan had been removed.
Here is the log.
= = = =
Malwarebytes Anti-Malware 1.70.0.1100
www.malwarebytes.org
Database version: v2013.04.01.03
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
ADMIN :: TEST-0EDA6CF69E [administrator]
4/2/2013 5:46:32 PM
mbam-log-2013-04-02 (17-46-32).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 239459
Time elapsed: 37 minute(s), 51 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 9
HKCR\AppID\{1DD31B76-C57E-49ba-94BC-BF53F0C82CD4} (PUP.Funshion) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1DD31B76-C57E-49ba-94BC-BF53F0C82CD4} (PUP.Funshion) -> Quarantined and
deleted successfully.
HKCR\CLSID\{91878E42-FC03-4785-B513-1F9E613D1027} (PUP.Funshion) -> Quarantined and deleted successfully.
HKCR\TypeLib\{D02E3AB9-7796-40CB-BDFC-20D834FE1F75} (PUP.Funshion) -> Quarantined and deleted successfully.
HKCR\Interface\{FCB380C4-D350-44BE-8791-50216F4747AC} (PUP.Funshion) -> Quarantined and deleted successfully.
HKCR\ASBarBroker.BDBroker.1 (PUP.Funshion) -> Quarantined and deleted successfully.
HKCR\ASBarBroker.BDBroker (PUP.Funshion) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{11CC93E4-0BE6-4F8F-82AA-D577FB955B05} (PUP.Funshion) -> Quarantined and deleted
successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SETUP.EXE (PUP.BundleInstaller.VG) -> Quarantined and deleted
successfully.
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 3
C:\Program Files\Baidu\{17C2069B-BBFB-D78F-E94E-D089291F2150}\ASBarBroker.exe (PUP.Funshion) -> Quarantined and deleted successfully.
C:\Documents and Settings\ADMIN\My Documents\Downloads\setup.exe (PUP.BundleInstaller.VG) -> Quarantined and deleted successfully.
C:\Documents and Settings\ADMIN\Local Settings\TempDIR\BetterInstaller.exe (PUP.BundleInstaller.Somoto) -> Quarantined and deleted successfully.
(end)
= = = =