WiredWX Hobby Weather ToolsLog in

 


descriptiontango toolbar??? Emptytango toolbar???

more_horiz
I have just noticed on my ie a tango tool bar, i have tried to unistall and disable with no joy. I have scanned with microsoft essentials and so far find nothing, just downloaded malwarebytes to try following googling and hopefully that will work, if not any suggestions xx Thank You!

descriptiontango toolbar??? EmptyRe: tango toolbar???

more_horiz
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4172

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

06/06/2010 12:05:38
mbam-log-2010-06-06 (12-05-38).txt

Scan type: Quick scan
Objects scanned: 132166
Time elapsed: 15 minute(s), 11 second(s)

Memory Processes Infected: 2
Memory Modules Infected: 1
Registry Keys Infected: 13
Registry Values Infected: 4
Registry Data Items Infected: 3
Folders Infected: 2
Files Infected: 11

Memory Processes Infected:
C:\Users\Parent\AppData\Roaming\GabPath\gabpath.exe (Adware.GabPath) -> Unloaded process successfully.
C:\Users\Parent\AppData\Roaming\Microsoft\Windows\jnipmo.exe (Trojan.Downloader) -> Unloaded process successfully.

Memory Modules Infected:
C:\Windows\System32\0c78.dll (Adware.Mirar) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{917df574-74e2-4f75-85c9-ce4a9d8ed4bc} (Adware.Mirar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{917df574-74e2-4f75-85c9-ce4a9d8ed4bc} (Adware.Mirar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{917df574-74e2-4f75-85c9-ce4a9d8ed4bc} (Adware.Mirar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{917df574-74e2-4f75-85c9-ce4a9d8ed4bc} (Adware.Mirar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{917df575-74e2-4f75-85c9-ce4a9d8ed4bc} (Adware.Mirar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{917df575-74e2-4f75-85c9-ce4a9d8ed4bc} (Adware.Mirar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{917df575-74e2-4f75-85c9-ce4a9d8ed4bc} (Adware.Mirar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{917df575-74e2-4f75-85c9-ce4a9d8ed4bc} (Adware.Mirar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\gabpath (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\AppDataLow\Software\MarketPrecision (Adware.Adparatus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\GabPath (Adware.Adparatus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\IEBarProperties (Adware.Mirar) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\gabpath (Adware.GabPath) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{917df574-74e2-4f75-85c9-ce4a9d8ed4bc} (Adware.Mirar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{917df574-74e2-4f75-85c9-ce4a9d8ed4bc} (Adware.Mirar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sfkg6wipusp (Trojan.Downloader) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Search Bar (Hijack.SearchPage) -> Bad: (http://www.tangosearch.com/?useie5=1&q=) Good: (http://www.google.com) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Search Bar (Hijack.SearchPage) -> Bad: (http://www.tangosearch.com/?useie5=1&q=) Good: (http://www.google.com) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page (Hijack.StartPage) -> Bad: (http://home.tangotoolbar.com/) Good: (http://www.google.com) -> Quarantined and deleted successfully.

Folders Infected:
C:\Users\Parent\AppData\Roaming\GabPath (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Comet (Adware.Comet) -> Quarantined and deleted successfully.

Files Infected:
C:\Users\Parent\AppData\Roaming\GabPath\gabpath.exe (Adware.GabPath) -> Quarantined and deleted successfully.
C:\Windows\System32\0c78.dll (Adware.Mirar) -> Delete on reboot.
C:\Users\Parent\AppData\Local\Temp\1.exe (Adware.GabPath) -> Quarantined and deleted successfully.
C:\Users\Parent\AppData\Local\Temp\4.exe (Adware.TangoBar) -> Quarantined and deleted successfully.
C:\Users\Parent\AppData\Local\Temp\stub-9945.exe (Adware.Adparatus) -> Quarantined and deleted successfully.
C:\Users\Parent\AppData\Roaming\GabPath\config.cfg (Adware.Agent) -> Quarantined and deleted successfully.
C:\Users\Parent\AppData\Roaming\GabPath\GPUninstall.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Comet\AcademicSelect2009StudentLicenseAgr(UK Home Access)(Oct2009)(IU) - Comet.docx (Adware.Comet) -> Quarantined and deleted successfully.
C:\Users\Parent\AppData\Roaming\Microsoft\Windows\jnipmo.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Public\Desktop\Streaming Music - MediaPass.lnk (Adware.Trace) -> Quarantined and deleted successfully.
C:\Users\Parent\AppData\Local\Temp\adparatus.installer.log (Adware.Adparatus) -> Quarantined and deleted successfully.



malwarebytes just finished does this mean its clean????????

descriptiontango toolbar??? EmptyRe: tango toolbar???

more_horiz
it worked yay x

descriptiontango toolbar??? EmptyRe: tango toolbar???

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum