I need help - I ran malwarebytes and detected Minibar.A


Using my Laptop.


Last night I ran Malwarebytes after my cousin used my laptop. Malwarebytes detected 13 PUP all under MiniBar.A.

Because it was late already, I decided to shut down my laptop and deal with it later. 


This morning I ran again Malwarebytes and to my surprise, it detected 192 PUPs all under MiniBar.A


I ran my Anti-virus afterwards and detected nothing. 

I'm Using Microsoft Security Essentials.


I have the option with checking the PUP in Malwarebytes and remove it but I'm not quite sure because some of it are files, folders and registry. I'm afraid that i might mess my laptop up.


I also noticed the sometimes after i typed google.com it takes longer than the usual. I'm not sure whether it is an effect of the malware detected but it was the only culprit that the Malwarebytes detected so i think it's safe to say that it might.


I'm not so good with computer.


Please help me. 

Hello Marz18 and :welcome:! My name is Borislav and I will be glad to help you solve your malware problem.

Please note:

  • If you are a paying customer, you have the privilege to contact the help desk at Consumer Support. If you choose this option to get help, please let me know.
  • I recommend you to keep the instructions I will be giving you so that they are available to you at any time. You can save them in a text file or print them.
  • Make sure you read all of the instructions and fixes thoroughly before continuing with them.
  • Follow my instructions strictly and don’t hesitate to stop and ask me if you have any questions.
  • Post your log files, don't attach them. Every log file should be copy/pasted in your next reply.
  • Do not perform any kind of scanning and fixing without my instructions. If you want to proceed on your own, please let me know.
Please follow the instructions here and then post the log files in your next reply.


hello maniac,

thank you for the quick response.


here is the dss and attach files:



Step 1

Please uninstall the following applications:


Search Protection

Step 2

Please download Junkware Removal Tool to your desktop.

  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
Step 3

Please download AdwCleaner by Xplode onto your desktop.

  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Clean.
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[s1].txt as well.
Step 4
  • Launch Malwarebytes' Anti-Malware
  • Go to Update tab and select Check for Updates. If an update is found, it will download and install the latest version.
  • Go to Scanner tab and select Perform Quick Scan, then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer,please do so immediately.

In your next reply, post the following log files:

  • Junkware Removal Tool log
  • AdwCleaner log
  • Malwarebytes' Anti-Malware log
Ok, I'm posting Jrt.txt, AdwCleaner[s0].txt and Malwarebytes' Anti-Malware log



Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.0 (09.12.2013:1)
OS: Windows 7 Home Basic x64
Ran by Marissa on Fri 09/13/2013 at 19:44:41.36
~~~ Services
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\sdp
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\anchorfree
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\bi
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\optimizer pro
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\softonic
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\somoto
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_for_google-chrome_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_for_google-chrome_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_for_google-chrome_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_for_google-chrome_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA74D58F-ACD0-450D-A85E-6C04B171C044}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Users\Marissa\AppData\Roaming\optimizer pro"
Successfully deleted: [Folder] "C:\Users\Marissa\appdata\local\filesfrog update checker"
Successfully deleted: [Folder] "C:\Users\Marissa\appdata\local\minibar"
Successfully deleted: [Folder] "C:\Users\Marissa\appdata\locallow\minibar"
Successfully deleted: [Folder] "C:\Program Files (x86)\minibar"
Successfully deleted: [Folder] "C:\Users\Marissa\AppData\Roaming\microsoft\windows\start menu\programs\filesfrog update checker"
Successfully deleted: [Empty Folder] C:\Users\Marissa\appdata\local\{05494DA7-7438-4630-B1C4-60473C6FAFBE}
Successfully deleted: [Empty Folder] C:\Users\Marissa\appdata\local\{27E7F51D-3855-47E8-B9A8-A305B12DF182}
Successfully deleted: [Empty Folder] C:\Users\Marissa\appdata\local\{3796564D-AFD4-49D8-80F5-EC5423DB3B8D}
Successfully deleted: [Empty Folder] C:\Users\Marissa\appdata\local\{3FD75315-FD27-47E1-A95B-EF3F246BCFEA}
Successfully deleted: [Empty Folder] C:\Users\Marissa\appdata\local\{496A6935-0870-47E3-BBB3-E3EE6B1173B7}
Successfully deleted: [Empty Folder] C:\Users\Marissa\appdata\local\{49D92800-2842-402E-92F1-A43DB6C3C383}
Successfully deleted: [Empty Folder] C:\Users\Marissa\appdata\local\{77241356-FB3B-4C24-9E44-8977F2E945B9}
Successfully deleted: [Empty Folder] C:\Users\Marissa\appdata\local\{7B11ED52-C334-4F1A-BB04-A8EB19E24A8A}
Successfully deleted: [Empty Folder] C:\Users\Marissa\appdata\local\{94CA0024-E1B9-4998-B271-4F8D71A54CD4}
Successfully deleted: [Empty Folder] C:\Users\Marissa\appdata\local\{9A5136E1-0A2B-4545-8AFF-6E3CA0AFC5CC}
Successfully deleted: [Empty Folder] C:\Users\Marissa\appdata\local\{9B8FDD53-F1F1-4828-A65E-A01DA6D67DE2}
Successfully deleted: [Empty Folder] C:\Users\Marissa\appdata\local\{9CBE225A-B374-46B5-A0E6-A2EF4EFAC776}
Successfully deleted: [Empty Folder] C:\Users\Marissa\appdata\local\{9DDA9E35-EE3D-497E-9B9D-28D2D06F3E0E}
Successfully deleted: [Empty Folder] C:\Users\Marissa\appdata\local\{9F88582C-AFB3-49F7-8825-65E2FF01D4C8}
Successfully deleted: [Empty Folder] C:\Users\Marissa\appdata\local\{A9A1117D-682C-4940-9F7E-4FC01BCD4AB6}
Successfully deleted: [Empty Folder] C:\Users\Marissa\appdata\local\{BF4DCC47-7B53-468B-8BD6-7934ED57E1B8}
Successfully deleted: [Empty Folder] C:\Users\Marissa\appdata\local\{D1477131-C1C9-44B5-BD8F-20CCBD490B7D}
Successfully deleted: [Empty Folder] C:\Users\Marissa\appdata\local\{D59F0F4F-9D98-4A89-A170-277FAE2D74FC}
Successfully deleted: [Empty Folder] C:\Users\Marissa\appdata\local\{DAD125F6-D24B-4BF7-8381-AA10794A7865}
Successfully deleted: [Empty Folder] C:\Users\Marissa\appdata\local\{F3526612-6B6B-4F3C-A622-9EEC9C03B031}
~~~ FireFox
Successfully deleted the following from C:\Users\Marissa\AppData\Roaming\mozilla\firefox\profiles\9c3m8ezf.default\prefs.js
user_pref("extensions.kango.storage.ui.button.iconCache", "\"
Emptied folder: C:\Users\Marissa\AppData\Roaming\mozilla\firefox\profiles\9c3m8ezf.default\minidumps [119 files]
~~~ Chrome
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome\extensioninstallforcelist [blacklisted Policy]
~~~ Event Viewer Logs were cleared
Scan was completed on Fri 09/13/2013 at 19:55:43.48
End of JRT log
# AdwCleaner v3.003 - Report created 13/09/2013 at 20:00:18
# Updated 07/09/2013 by Xplode
# Operating System : Windows 7 Home Basic Service Pack 1 (64 bits)
# Username : Marissa - MARISSA-PC
# Running from : C:\Users\Marissa\Downloads\AdwCleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Users\Marissa\AppData\Local\Bundled software uninstaller
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{539F76FD-084E-4858-86D5-62F02F54AE86}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AA74D58F-ACD0-450D-A85E-6C04B171C044}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AAA38851-3CFF-475F-B5E0-720D3645E4A5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{26E7211D-0650-43CF-8498-4C81E83AEAAA}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{F13D3582-1359-4F8F-9A48-EF3AE9F5701C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AA74D58F-ACD0-450D-A85E-6C04B171C044}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AA74D58F-ACD0-450D-A85E-6C04B171C044}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{AAA38851-3CFF-475F-B5E0-720D3645E4A5}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{539F76FD-084E-4858-86D5-62F02F54AE86}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Deleted : HKLM\Software\Minibar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bi_uninstaller
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16686
-\\ Mozilla Firefox v24.0 (en-US)
[ File : C:\Users\Marissa\AppData\Roaming\Mozilla\Firefox\Profiles\9c3m8ezf.default\prefs.js ]
Line Deleted : user_pref("extensions.kango.storage.m2_k1", "0");
Line Deleted : user_pref("extensions.kango.storage.m2_k2", "0");
Line Deleted : user_pref("extensions.kango.storage.m2_k3", "0");
Line Deleted : user_pref("extensions.kango.storage.m2_k4", "1378423750186");
Line Deleted : user_pref("extensions.kango.storage.m2_k5", "1378404458102");
Line Deleted : user_pref("extensions.kango.storage.nero_options", "\"{\\\"m1\\\":{\\\"ads\\\":{\\\"n1\\\":{\\\"url\\\":\\\"//ulayout.com/nero/hatter/google_post_results_728x90.html?aff_slug=appshat\\\",\\\"width\\\"[...]
Line Deleted : user_pref("extensions.kango.storage.ui.button.iconCache", "\"[...]
-\\ Google Chrome v29.0.1547.66
[ File : C:\Users\Marissa\AppData\Local\Google\Chrome\User Data\Default\preferences ]
AdwCleaner[R0].txt - [3394 octets] - [13/09/2013 19:59:20]
AdwCleaner[s0].txt - [3357 octets] - [13/09/2013 20:00:18]
########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [3417 octets] ##########
Malwarebytes Anti-Malware
Database version: v2013.09.13.05
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16686
Marissa :: MARISSA-PC [administrator]
9/13/2013 8:05:26 PM
mbam-log-2013-09-13 (20-05-26).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 245106
Time elapsed: 5 minute(s), 48 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 1
HKCR\CLSID\{60EACC1A-33FA-443D-9846-17B28E2C9BDB} (PUP.Optional.MiniBar.A) -> Quarantined and deleted successfully.
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
Please tell me what's next or if it's done. And if it's ok to download and install the utorrent because my daughter will be looking for it.. thanks
hi, i did a full scan and this is the log:


Malwarebytes Anti-Malware
Database version: v2013.09.13.11
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16686
Marissa :: MARISSA-PC [administrator]
9/14/2013 7:44:04 AM
mbam-log-2013-09-14 (07-44-04).txt
Scan type: Full scan (C:\|E:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 447040
Time elapsed: 1 hour(s), 21 minute(s), 4 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
Yes, it is done. Glad I could help! :)

Step 1

  • Download OTC to your desktop and run it
  • Click Yes to beginning the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. Choose Yes.
Step 2
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Uninstall
  • Confirm with Yes
Step 3

Some malware prevention tips:


Safe surfing! :)

  • Root Admin

Glad we could help. :)

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

