#### Hotbar removal - help required

I got a colourful message from a friend and a link at the bottom which took
me to Hotbar.com

At no cost (suspicious) the visitor can download and install of an extension
to MS Outlook, adding colours, stationeries etc.

It was supposed to be compatible with MS Outlook and I had (na�ve) an
impression that it had to be somehow endorsed by Microsoft.

Immediately after the installation I saw that I got more than I bargained
for.

For one, it seems to be a spyware. It has also embedded itself quite deep
and there is no uninstall option.

What bugs me the most is that it has replaced my Copernic Search Agent and
it did it really brutally.

It has just replaced the addresses and the buttons on the Copernic toolbar.
That toolbar is still called Copernic but now it links me to an impostor.

My question to the group: Have you seen something like this before? Do you
know a remedy?
I have already scanned the registry for all the traces of hotbar and removed
every mention of it.
It doe not appear in my task manager anymore. It there anything else I
should look?

Ciao,
Andy


You are right about what Hotbar is.  Trash/Spyware/Malaware/Etc.  The
easiest way to get rid of it is to get Adaware and SpyBot S&D (both free).
They are tools to remove spyware.  Get both, install and update them and run
them, you'll be amazed how much spyware you have.  I suggest you run Adaware
first, then SpyBot.  Use care with Spybot, it can be overly aggressive.
When it gives you the list of things found, read it carefully and make sure
there isn't something in there you don't want to delete.  If your unsure or
concerned, just use Adaware.  It does a good job and gets probably 99% of
the trash.

There are instructions on how to uninstall Hotbar completely on their page -
you just have to be really diligent.

From Pest Patrol's Page:

Find and remove these entries:

Manual Removal: Removable from "Add/Remove Programs" on the Control
Panel. However it leaves two copies of its installer and other files and a
number of registry entries. You may remove these items manually, if you
wish.

In the registry, which you can clean up by running regedit if you
want. Keys you can delete:

HKEY_CLASSES_ROOT\clsid\{da603411-0593-11d5-a46b-00508b5ba2df}
HKEY_CLASSES_ROOT\hbhostie.hbbho.1
HKEY_CLASSES_ROOT\hotbar.hbmain.1
HKEY_CLASSES_ROOT\interface\{7e33bc81-0818-11d5-b50d-00d0b77f0a6d}
HKEY_CLASSES_ROOT\typelib\{60f63095-41ec-11d5-b558-00d0b77f0a6d}
HKEY_CLASSES_ROOT\appid\hbsrv.exe
HKEY_CLASSES_ROOT\appid\{b701a705-f828-11d4-a466-00508b5ba2df}
HKEY_CLASSES_ROOT\clsid\{1038dd23-8ae8-451b-a134-4db8a49aa519}
HKEY_CLASSES_ROOT\clsid\{3103e312-e1bb-49ab-80eb-0a92fca78746}
HKEY_CLASSES_ROOT\clsid\{46417afd-7a15-4ed1-b764-cb72cd4d904f}
HKEY_CLASSES_ROOT\clsid\{4bf4fafa-186e-4e36-8f74-525290438d7b}
HKEY_CLASSES_ROOT\clsid\{4dbcfaf7-62e1-4811-8acc-6511e7192cb4}
HKEY_CLASSES_ROOT\clsid\{60b25924-c865-11d2-b0c1-000000000000}
HKEY_CLASSES_ROOT\clsid\{60f63095-41ec-11d5-b558-00d0b77f0a6d}
HKEY_CLASSES_ROOT\clsid\{60f630a2-41ec-11d5-b558-00d0b77f0a6d}
HKEY_CLASSES_ROOT\clsid\{69fd62b1-0216-4c31-8d55-840ed86b7c8f}
HKEY_CLASSES_ROOT\clsid\{6a6ebae8-8c66-4675-b423-95b3ba530940}
HKEY_CLASSES_ROOT\clsid\{6d6d1580-5b74-40ea-97f4-3c2b46c5abdd}
HKEY_CLASSES_ROOT\clsid\{6f885f52-b45f-45bc-8642-fe3d56155a3a}
HKEY_CLASSES_ROOT\clsid\{6fe00b71-7251-4e00-9186-ed89bbb946b8}
HKEY_CLASSES_ROOT\clsid\{75d2080b-4857-4b96-9b7d-732634fbd01f}
HKEY_CLASSES_ROOT\clsid\{7e33bc81-0818-11d5-b50d-00d0b77f0a6d}
HKEY_CLASSES_ROOT\clsid\{8f59f897-6923-4b3b-8156-4e55d19de99a}
HKEY_CLASSES_ROOT\clsid\{9ee87a26-b2c8-4130-83f6-e8511d939976}
HKEY_CLASSES_ROOT\clsid\{a80347d3-f757-11d4-a466-00508b5ba2df}
HKEY_CLASSES_ROOT\clsid\{a80347df-f757-11d4-a466-00508b5ba2df}
HKEY_CLASSES_ROOT\clsid\{a80347e0-f757-11d4-a466-00508b5ba2df}
HKEY_CLASSES_ROOT\clsid\{b195b3a5-8a05-11d3-97a4-0004aca6948e}
HKEY_CLASSES_ROOT\clsid\{b195b3b2-8a05-11d3-97a4-0004aca6948e}
HKEY_CLASSES_ROOT\clsid\{b195b3b3-8a05-11d3-97a4-0004aca6948e}
HKEY_CLASSES_ROOT\clsid\{b701a704-f828-11d4-a466-00508b5ba2df}
HKEY_CLASSES_ROOT\clsid\{b701a705-f828-11d4-a466-00508b5ba2df}
HKEY_CLASSES_ROOT\clsid\{becafc17-baf9-11d4-b492-00d0b77f0a6d}
HKEY_CLASSES_ROOT\clsid\{da603411-0593-11d5-a46b-10101b1b1111}
HKEY_CLASSES_ROOT\clsid\{da603411-0593-11d5-a46b-10101ddd1111}
HKEY_CLASSES_ROOT\clsid\{f4132b7b-1576-41b6-abd8-39c6c53047f7}
HKEY_CLASSES_ROOT\clsid\{f64b26c1-07de-11d5-b50d-00d0b77f0a6d}
HKEY_CLASSES_ROOT\clsid\{f7a1bf21-1d7d-4f5f-a201-0ca35a5cd68f}
HKEY_CLASSES_ROOT\hbcoresrv.hbcoreservices
HKEY_CLASSES_ROOT\hbcoresrv.hbcoreservices.1
HKEY_CLASSES_ROOT\hbhostol.hbmailanim
HKEY_CLASSES_ROOT\hbhostol.hbmailanim.1
HKEY_CLASSES_ROOT\hbinstie.hbinstobj
HKEY_CLASSES_ROOT\hbinstie.hbinstobj.1
HKEY_CLASSES_ROOT\hbsrv.hbcoreservices
HKEY_CLASSES_ROOT\hbsrv.hbcoreservices.1
HKEY_CLASSES_ROOT\hbtoolbar.hbtoolbarctl
HKEY_CLASSES_ROOT\hbtoolbar.hbtoolbarctl.1
HKEY_CLASSES_ROOT\hotbar.hbbho
HKEY_CLASSES_ROOT\hotbar.hbcommband
HKEY_CLASSES_ROOT\hotbar.hbcommband.1
HKEY_CLASSES_ROOT\hotbar.hbcommmband.1
HKEY_CLASSES_ROOT\hotbar.hbmain
HKEY_CLASSES_ROOT\interface\{3103e312-e1bb-49ab-80eb-0a92fca78746}
HKEY_CLASSES_ROOT\interface\{46417afd-7a15-4ed1-b764-cb72cd4d904f}
HKEY_CLASSES_ROOT\interface\{4bf4fafa-186e-4e36-8f74-525290438d7b}
HKEY_CLASSES_ROOT\interface\{6a6ebae8-8c66-4675-b423-95b3ba530940}
HKEY_CLASSES_ROOT\interface\{6f885f52-b45f-45bc-8642-fe3d56155a3a}
HKEY_CLASSES_ROOT\interface\{8f59f897-6923-4b3b-8156-4e55d19de99a}
HKEY_CLASSES_ROOT\interface\{9ee87a26-b2c8-4130-83f6-e8511d939976}
HKEY_CLASSES_ROOT\interface\{a80347df-f757-11d4-a466-00508b5ba2df}
HKEY_CLASSES_ROOT\interface\{b195b3b2-8a05-11d3-97a4-0004aca6948e}
HKEY_CLASSES_ROOT\interface\{da603411-0593-11d5-a46b-00508b5ba2df}
HKEY_CLASSES_ROOT\interface\{da603411-0593-11d5-a46b-10101b1b1111}
HKEY_CLASSES_ROOT\interface\{da603411-0593-11d5-a46b-10101ddd1111}
HKEY_CLASSES_ROOT\interface\{f4132b7b-1576-41b6-abd8-39c6c53047f7}
HKEY_CLASSES_ROOT\interface\{f64b26c1-07de-11d5-b50d-00d0b77f0a6d}
HKEY_CLASSES_ROOT\interface\{f7a1bf21-1d7d-4f5f-a201-0ca35a5cd68f}

HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser
helper objects\{b195b3b3-8a05-11d3-97a4-0004aca6948e}
HKEY_CLASSES_ROOT\typelib\{6d6d1580-5b74-40ea-97f4-3c2b46c5abdd}
HKEY_CLASSES_ROOT\typelib\{a80347d3-f757-11d4-a466-00508b5ba2df}
HKEY_CLASSES_ROOT\typelib\{b195b3a5-8a05-11d3-97a4-0004aca6948e}
HKEY_CLASSES_ROOT\typelib\{b701a704-f828-11d4-a466-00508b5ba2df}
HKEY_CLASSES_ROOT\{69fd62b1-0216-4c31-8d55-840ed86b7c8f}
HKEY_CURRENT_USER\software\""
HKEY_CURRENT_USER\software\hotbar
HKEY_CURRENT_USER\software\microsoft\internet explorer\explorer
bars\{becafc17-baf9-11d4-b492-00d0b77f0a6d}
HKEY_CURRENT_USER\software\microsoft\internet
explorer\toolbar\webbrowser{b195b3b3-8a05-11d3-97a4-0004aca6948e}
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet
settings\user agenthotbar 3.0

HKEY_LOCAL_MACHINE\software\classes\appid\{b701a705-f828-11d4-a466-00508b5ba
2df}

HKEY_LOCAL_MACHINE\software\classes\clsid\{1038dd23-8ae8-451b-a134-4db8a49aa
519}

f3b}

HKEY_LOCAL_MACHINE\software\classes\clsid\{4dbcfaf7-62e1-4811-8acc-6511e7192
cb4}

HKEY_LOCAL_MACHINE\software\classes\clsid\{60f630a2-41ec-11d5-b558-00d0b77f0
a6d}

HKEY_LOCAL_MACHINE\software\classes\clsid\{69fd62b1-0216-4c31-8d55-840ed86b7
c8f}

HKEY_LOCAL_MACHINE\software\classes\clsid\{6fe00b71-7251-4e00-9186-ed89bbb94
6b8}

HKEY_LOCAL_MACHINE\software\classes\clsid\{75d2080b-4857-4b96-9b7d-732634fbd
01f}

HKEY_LOCAL_MACHINE\software\classes\clsid\{a80347e0-f757-11d4-a466-00508b5ba
2df}

HKEY_LOCAL_MACHINE\software\classes\clsid\{b195b3b3-8a05-11d3-97a4-0004aca69
48e}

HKEY_LOCAL_MACHINE\software\classes\clsid\{becafc17-baf9-11d4-b492-00d0b77f0
a6d}

b5ba2df}

b5ba2df}

HKEY_LOCAL_MACHINE\software\classes\interface\{3103e312-e1bb-49ab-80eb-0a92f
ca78746}

HKEY_LOCAL_MACHINE\software\classes\interface\{31321312-e1bb-49ab-80eb-13212
ca78746}

HKEY_LOCAL_MACHINE\software\classes\interface\{46417afd-7a15-4ed1-b764-cb72c
d4d904f}

HKEY_LOCAL_MACHINE\software\classes\interface\{4bf4fafa-186e-4e36-8f74-52529
0438d7b}

HKEY_LOCAL_MACHINE\software\classes\interface\{6a6ebae8-8c66-4675-b423-95b3b
a530940}

HKEY_LOCAL_MACHINE\software\classes\interface\{6f885f52-b45f-45bc-8642-fe3d5
6155a3a}

HKEY_LOCAL_MACHINE\software\classes\interface\{7e33bc81-0818-11d5-b50d-00d0b
77f0a6d}

HKEY_LOCAL_MACHINE\software\classes\interface\{8f59f897-6923-4b3b-8156-4e55d
19de99a}

c11841f}

HKEY_LOCAL_MACHINE\software\classes\interface\{9ee87a26-b2c8-4130-83f6-e8511
d939976}

HKEY_LOCAL_MACHINE\software\classes\interface\{a80347df-f757-11d4-a466-00508
b5ba2df}

77f0a6d}

93ceb86}

HKEY_LOCAL_MACHINE\software\classes\interface\{b195b3b2-8a05-11d3-97a4-0004a
ca6948e}

HKEY_LOCAL_MACHINE\software\classes\interface\{c8539bfe-8fd7-405c-8eef-d9af4
8dc6ba4}

HKEY_LOCAL_MACHINE\software\classes\interface\{da603411-0593-11d5-a46b-00508
b5ba2df}

HKEY_LOCAL_MACHINE\software\classes\interface\{da603411-0593-11d5-a46b-10101
b1b1111}

HKEY_LOCAL_MACHINE\software\classes\interface\{da603411-0593-11d5-a46b-10101
ddd1111}

HKEY_LOCAL_MACHINE\software\classes\interface\{f4132b7b-1576-41b6-abd8-39c6c
53047f7}

HKEY_LOCAL_MACHINE\software\classes\interface\{f64b26c1-07de-11d5-b50d-00d0b
77f0a6d}

HKEY_LOCAL_MACHINE\software\classes\interface\{f7a1bf21-1d7d-4f5f-a201-0ca35
a5cd68f}

HKEY_LOCAL_MACHINE\software\classes\typelib\{60f63095-41ec-11d5-b558-00d0b77
f0a6d}

HKEY_LOCAL_MACHINE\software\classes\typelib\{6d6d1580-5b74-40ea-97f4-3c2b46c
5abdd}

409c0}

HKEY_LOCAL_MACHINE\software\classes\typelib\{a80347d3-f757-11d4-a466-00508b5
ba2df}

HKEY_LOCAL_MACHINE\software\classes\typelib\{b195b3a5-8a05-11d3-97a4-0004aca
6948e}

HKEY_LOCAL_MACHINE\software\classes\typelib\{b701a704-f828-11d4-a466-00508b5
ba2df}
HKEY_LOCAL_MACHINE\software\""
HKEY_LOCAL_MACHINE\software\hotbar
HKEY_LOCAL_MACHINE\software\microsoft\code store
database\distribution units\{69fd62b1-0216-4c31-8d55-840ed86b7c8f}
HKEY_LOCAL_MACHINE\software\microsoft\internet
explorer\toolbar{b195b3b3-8a05-11d3-97a4-0004aca6948e}
HKEY_LOCAL_MACHINE\software\microsoft\internet
explorer\toolbar\b195b3b3-8a05-11d3-97a4-0004aca6948e

nim

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorerbrowser
helper

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browse
r helper objects\{b195b3b3-8a05-11d3-97a4-0004aca6948e}

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\internet
settings\user agent\post platformhotbar 3.0

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\internet
settings\user agent\post platformhotbar 4.2.13.0

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\internet
settings\user agent\post platform\hotbar 3.0

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runhotbar

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\""

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\hotba
r uninstall

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\deviceclasses\{fd0a5af4-
b41d-11d2-9c95-00c04f7971e0}

HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\sw\{03884cb6-e89a-4deb-b69e
-8dc621686e6a}

HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\sw\{8e60217d-a2ee-47f8-b0c5
-0f44c55f66dc}

HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\sw\{96e080c7-143c-11d1-b40f
-00a0c9223196}

HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\sw\{b7eafdc0-a680-11d0-96d8
-00aa0051e51d}
HKEY_USERS\.default\software\hotbar

HKEY_USERS\s-1-5-21-329068152-1677128483-854245398-500\software\microsoft\in
ternet explorer\explorer bars\{becafc17-baf9-11d4-b492-00d0b77f0a6d}

HKEY_USERS\s-1-5-21-725345543-1078145449-1343024091-500\software\microsoft\i
nternet explorer\explorer bars\{becafc17-baf9-11d4-b492-00d0b77f0a6d}

Remove these files:

c:\hotbar\hotbar new files\hotbar.log
profilepath+\local settings\temp\hbinst.exe
programfilesdir+\hotbar\bin\4.3.1.0\dbenderc.dll
programfilesdir+\hotbar\bin\4.3.1.0\hbcoresrv.dll
programfilesdir+\hotbar\bin\4.3.1.0\hbhostie.dll
programfilesdir+\hotbar\bin\4.3.1.0\hbhostoe.dll
programfilesdir+\hotbar\bin\4.3.1.0\hbhostol.dll
programfilesdir+\hotbar\bin\4.3.1.0\hbinst.exe
programfilesdir+\hotbar\bin\4.3.1.0\hbinstie.dll
programfilesdir+\hotbar\bin\4.3.1.0\hbsrv.exe
programfilesdir+\hotbar\bin\4.3.1.0\hbtoolbar.dll
programfilesdir+\hotbar\bin\hbinst.exe
programfilesdir+\hotbar\bin\hbinstie.dll
programfilesdir+\hotbar\hotbar.log
systemroot+\system32\hbinst.exe

Remove these directories:

profilepath+\application data\hotbar
programfilesdir+\hotbar

Milly Staples [MVP - Outlook]

Post all replies to the group to keep the discussion intact.

