This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer Running Very Slow and Freezing Up [Closed]

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

The system that is on this computer is Windows Xp this is a older very older computer that was given to my son he only uses it for internet and game play but since it was given to me it has been just running very so, I know the it is not the best as far as processor spend but wanted to see about clean it up and maybe it would work a lot better…Here is the High Jack on it


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:31:49 PM, on 4/13/2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\MYWEBS~1\bar\2.bin\m3SrchMn.exe
C:\WINDOWS\system32\ANIWConnService.exe
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\XxCoolNessxX\My Documents\Downloads\HiJackThis(1).exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mystart.incredibar.com/mb128?a=6PQydq5qrj&i=26
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpro.com/hypercam/{5340BF…F-8426AC17FE50}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe" //mailurl:mailto:?body=http%3A%2F%2Ffc03.deviantart.net%2Ffs46%2Ff%2F2009%2F221%2F6%2Fc%2FPokemon_Ranch__Lapras_by_Pokelova.jpg&subject=
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\2.bin\MWSSRCAS.DLL
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\2.bin\MWSSRCAS.DLL
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Web Assistant Helper - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension32.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll
O2 - BHO: Incredibar.com Helper Object - {6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} - C:\Program Files\Incredibar.com\incredibar\1.5.11.14\bh\incredibar.dll
O2 - BHO: Zango - {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - C:\Program Files\Zango\bin\10.3.75.0\HostIE.dll (file missing)
O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Zango - {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - C:\Program Files\Zango\bin\10.3.75.0\HostIE.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll
O3 - Toolbar: Incredibar Toolbar - {F9639E4A-801B-4843-AEE3-03D9DA199E77} - C:\Program Files\Incredibar.com\incredibar\1.5.11.14\incredibarTlbr.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\2.bin\m3SrchMn.exe" /m=2 /w /h
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O9 - Extra button: (no name) - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - (no file)
O9 - Extra button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {925DAB62-F9AC-4221-806A-057BFB1014AA} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…etup1.0.1.1.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\11.2.0\ViProtocol.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ANIWConn Service (ANIWConnService) - Unknown owner - C:\WINDOWS\system32\ANIWConnService.exe
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Wireless Service - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe

–
End of file - 7481 bytes
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!



Run Hijack This
  • Double click on the icon on your desktop to launch Hijack This
  • Click on the Scan button
  • When the scan has finished, please put a check in the box next to the following item:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mystart.incredibar.com/mb128?a=6PQydq5qrj&i=26
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpro.com/hypercam/{5340BF…F-8426AC17FE50}
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\2.bin\MWSSRCAS.DLL
    O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\2.bin\MWSSRCAS.DLL
    O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL
    O2 - BHO: Web Assistant Helper - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension32.dll
    O2 - BHO: Incredibar.com Helper Object - {6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} - C:\Program Files\Incredibar.com\incredibar\1.5.11.14\bh\incredibar.dll
    O2 - BHO: Zango - {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - C:\Program Files\Zango\bin\10.3.75.0\HostIE.dll (file missing)
    O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    O3 - Toolbar: Zango - {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - C:\Program Files\Zango\bin\10.3.75.0\HostIE.dll (file missing)
    O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL
    O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    O3 - Toolbar: Incredibar Toolbar - {F9639E4A-801B-4843-AEE3-03D9DA199E77} - C:\Program Files\Incredibar.com\incredibar\1.5.11.14\incredibarTlbr.dll
    O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\2.bin\m3SrchMn.exe" /m=2 /w /h
    O9 - Extra button: (no name) - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - (no file)
    O9 - Extra button: (no name) - {925DAB62-F9AC-4221-806A-057BFB1014AA} - (no file)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…etup1.0.1.1.cab
  • Make sure all other windows, including your browser are closed, and then click on the Fix Checked button
If you are not prompted to do so, please reboot your computer after the fix has completed.



[external image: Posted Image] Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

You should now be seeing some definite improvement in the speed of your browser.


HijackThis has largely been replaced by other tools. Since being acquired by TrendMicro, HijackThis has not been regularly updated. Many infections are now able to hide partly, or completely from a HijackThis scan. DDS includes all the scan locations of HijackThis and more.


Download and Run DDS by sUBs

Now that we've cleared up some basic browser items, we need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
    • DDS.com
    • DDS.pif
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 4.8.3 (04.05.2013:1) OS: Microsoft Windows XP x86 Ran by [removed] on Mon 04/15/2013 at 19:32:04.54 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services Successfully stopped: [Service] mywebsearchservice Successfully deleted: [Service] mywebsearchservice Successfully stopped: [Service] web assistant updater Successfully deleted: [Service] web assistant updater ~~~ Registry Values Successfully deleted: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\toolbar\\{95b7759c-8c7f-4bf1-b163-73684a933233} Successfully deleted: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\toolbar\\{ef99bd32-c1fb-11d2-892f-0090271d4f88} Successfully repaired: [Registry Value] hkey_current_user\software\microsoft\internet explorer\searchscopes\{0633ee93-d776-472f-a0ff-e1416b8b2e3a}\\DisplayName Successfully repaired: [Registry Value] hkey_current_user\software\microsoft\internet explorer\searchscopes\{0633ee93-d776-472f-a0ff-e1416b8b2e3a}\\URL Successfully repaired: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\searchscopes\{0633ee93-d776-472f-a0ff-e1416b8b2e3a}\\DisplayName Successfully repaired: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\searchscopes\{0633ee93-d776-472f-a0ff-e1416b8b2e3a}\\URL Successfully repaired: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\abouturls\\Tabs Successfully deleted: [Registry Value] hkey_current_user\software\microsoft\internet explorer\toolbar\webbrowser\\{d4027c7f-154a-4066-a1ad-4243d8127440} ~~~ Registry Keys Successfully deleted: [Registry Key] hkey_classes_root\escort.escortiepane Successfully deleted: [Registry Key] hkey_classes_root\escort.escortiepane.1 Successfully deleted: [Registry Key] hkey_classes_root\esrv.incredibaresrvc Successfully deleted: [Registry Key] hkey_classes_root\esrv.incredibaresrvc.1 Successfully deleted: [Registry Key] hkey_classes_root\hbcoresrv.dynamicprop Successfully deleted: [Registry Key] hkey_classes_root\hbcoresrv.dynamicprop.1 Successfully deleted: [Registry Key] hkey_classes_root\wallpaper.wallpapermanager Successfully deleted: [Registry Key] hkey_classes_root\wallpaper.wallpapermanager.1 Successfully deleted: [Registry Key] hkey_current_user\software\1clickdownload Successfully deleted: [Registry Key] hkey_local_machine\software\freeze.com Successfully deleted: [Registry Key] hkey_local_machine\software\funwebproducts Successfully deleted: [Registry Key] hkey_current_user\software\im Successfully deleted: [Registry Key] hkey_local_machine\software\iminent Successfully deleted: [Registry Key] hkey_current_user\software\iminstaller Successfully deleted: [Registry Key] hkey_local_machine\software\iminstaller Successfully deleted: [Registry Key] hkey_current_user\software\incredibar.com Successfully deleted: [Registry Key] hkey_local_machine\software\incredibar.com Successfully deleted: [Registry Key] hkey_local_machine\software\mywebsearch Successfully deleted: [Registry Key] hkey_current_user\software\sweetim Successfully deleted: [Registry Key] hkey_local_machine\software\sweetim Successfully deleted: [Registry Key] hkey_local_machine\software\tarma installer Successfully deleted: [Registry Key] hkey_current_user\software\web assistant Successfully deleted: [Registry Key] hkey_local_machine\software\web assistant Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\escort.dll Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\escortapp.dll Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\escorteng.dll Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\escortlbr.dll Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\esrv.exe Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\extension.dll Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\genericasktoolbar.dll Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\scripthelper.exe Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\tbcommonutils.dll Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\tbhelper.exe Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\viprotocol.dll Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\yontooieclient.dll Successfully deleted: [Registry Key] hkey_local_machine\software\classes\bbylntlbr.bbylntlbrhlpr Successfully deleted: [Registry Key] hkey_local_machine\software\classes\bbylntlbr.bbylntlbrhlpr.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\cntntcntr.cntntdic Successfully deleted: [Registry Key] hkey_local_machine\software\classes\cntntcntr.cntntdic.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\cntntcntr.cntntdisp Successfully deleted: [Registry Key] hkey_local_machine\software\classes\cntntcntr.cntntdisp.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\conduit.engine Successfully deleted: [Registry Key] hkey_local_machine\software\classes\coresrv.coreservices Successfully deleted: [Registry Key] hkey_local_machine\software\classes\coresrv.coreservices.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\coresrv.lfgax Successfully deleted: [Registry Key] hkey_local_machine\software\classes\coresrv.lfgax.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\extension.extensionhelperobject Successfully deleted: [Registry Key] hkey_local_machine\software\classes\extension.extensionhelperobject.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\funwebproducts.datacontrol Successfully deleted: [Registry Key] hkey_local_machine\software\classes\funwebproducts.datacontrol.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\funwebproducts.historykillerscheduler Successfully deleted: [Registry Key] hkey_local_machine\software\classes\funwebproducts.historykillerscheduler.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\funwebproducts.historyswattercontrolbar Successfully deleted: [Registry Key] hkey_local_machine\software\classes\funwebproducts.historyswattercontrolbar.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\funwebproducts.htmlmenu Successfully deleted: [Registry Key] hkey_local_machine\software\classes\funwebproducts.htmlmenu.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\funwebproducts.htmlmenu.2 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\funwebproducts.iecookiesmanager Successfully deleted: [Registry Key] hkey_local_machine\software\classes\funwebproducts.iecookiesmanager.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\funwebproducts.killerobjmanager Successfully deleted: [Registry Key] hkey_local_machine\software\classes\funwebproducts.killerobjmanager.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\funwebproducts.popswatterbarbutton Successfully deleted: [Registry Key] hkey_local_machine\software\classes\funwebproducts.popswatterbarbutton.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\funwebproducts.popswattersettingscontrol Successfully deleted: [Registry Key] hkey_local_machine\software\classes\funwebproducts.popswattersettingscontrol.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\genericasktoolbar.toolbarwnd Successfully deleted: [Registry Key] hkey_local_machine\software\classes\genericasktoolbar.toolbarwnd.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\hbmain.commband Successfully deleted: [Registry Key] hkey_local_machine\software\classes\hbmain.commband.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\hbr.hbmain Successfully deleted: [Registry Key] hkey_local_machine\software\classes\hbr.hbmain.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\hostie.bho Successfully deleted: [Registry Key] hkey_local_machine\software\classes\hostie.bho.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\hostol.mailanim Successfully deleted: [Registry Key] hkey_local_machine\software\classes\hostol.mailanim.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\hostol.webmailsend Successfully deleted: [Registry Key] hkey_local_machine\software\classes\hostol.webmailsend.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\i Successfully deleted: [Registry Key] hkey_local_machine\software\classes\incredibar.dskbnd Successfully deleted: [Registry Key] hkey_local_machine\software\classes\incredibar.dskbnd.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\incredibar.incredibarhlpr Successfully deleted: [Registry Key] hkey_local_machine\software\classes\incredibar.incredibarhlpr.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\incredibarapp.appcore Successfully deleted: [Registry Key] hkey_local_machine\software\classes\incredibarapp.appcore.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\installer\features\a28b4d68debaa244eb686953b7074fef Successfully deleted: [Registry Key] hkey_local_machine\software\classes\installer\products\a28b4d68debaa244eb686953b7074fef Successfully deleted: [Registry Key] hkey_local_machine\software\classes\installer\upgradecodes\f928123a039649549966d4c29d35b1c9 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\mywebsearch.chatsessionplugin Successfully deleted: [Registry Key] hkey_local_machine\software\classes\mywebsearch.chatsessionplugin.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\mywebsearch.htmlpanel Successfully deleted: [Registry Key] hkey_local_machine\software\classes\mywebsearch.htmlpanel.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\mywebsearch.outlookaddin Successfully deleted: [Registry Key] hkey_local_machine\software\classes\mywebsearch.outlookaddin.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\mywebsearch.pseudotransparentplugin Successfully deleted: [Registry Key] hkey_local_machine\software\classes\mywebsearch.pseudotransparentplugin.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\mywebsearchtoolbar.settingsplugin Successfully deleted: [Registry Key] hkey_local_machine\software\classes\mywebsearchtoolbar.settingsplugin.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\mywebsearchtoolbar.toolbarplugin Successfully deleted: [Registry Key] hkey_local_machine\software\classes\mywebsearchtoolbar.toolbarplugin.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\protocols\handler\viprotocol Successfully deleted: [Registry Key] hkey_local_machine\software\classes\s Successfully deleted: [Registry Key] hkey_local_machine\software\classes\screensavercontrol.screensaverinstaller Successfully deleted: [Registry Key] hkey_local_machine\software\classes\screensavercontrol.screensaverinstaller.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\scripthelper.scripthelperapi Successfully deleted: [Registry Key] hkey_local_machine\software\classes\scripthelper.scripthelperapi.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\srv.coreservices Successfully deleted: [Registry Key] hkey_local_machine\software\classes\srv.coreservices.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\tbcommonutils.commonutils Successfully deleted: [Registry Key] hkey_local_machine\software\classes\tbcommonutils.commonutils.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\tbhelper.tbdownloadmanager Successfully deleted: [Registry Key] hkey_local_machine\software\classes\tbhelper.tbdownloadmanager.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\tbhelper.tbpropertymanager Successfully deleted: [Registry Key] hkey_local_machine\software\classes\tbhelper.tbpropertymanager.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\tbhelper.tbrequest Successfully deleted: [Registry Key] hkey_local_machine\software\classes\tbhelper.tbrequest.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\tbhelper.tbtask Successfully deleted: [Registry Key] hkey_local_machine\software\classes\tbhelper.tbtask.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\tbhelper.toolbarhelper Successfully deleted: [Registry Key] hkey_local_machine\software\classes\tbhelper.toolbarhelper.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\toolbar.htmlmenuui Successfully deleted: [Registry Key] hkey_local_machine\software\classes\toolbar.htmlmenuui.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\toolbar.toolbarctl Successfully deleted: [Registry Key] hkey_local_machine\software\classes\toolbar.toolbarctl.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\viprotocol.viprotocolole Successfully deleted: [Registry Key] hkey_local_machine\software\classes\viprotocol.viprotocolole.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\yontooieclient.api Successfully deleted: [Registry Key] hkey_local_machine\software\classes\yontooieclient.api.1 Successfully deleted: [Registry Key] hkey_local_machine\software\classes\yontooieclient.layers Successfully deleted: [Registry Key] hkey_local_machine\software\classes\yontooieclient.layers.1 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\software\classes\Toolbar.CT2418376 Successfully deleted: [Registry Key] hkey_classes_root\clsid\{00a6faf6-072e-44cf-8957-5838f569a31d} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{02478d38-c3f9-4efb-9b51-7695eca05670} Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{02478d38-c3f9-4efb-9b51-7695eca05670} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{07b18ea9-a523-4961-b6bb-170de4475cca} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{07b18eab-a523-4961-b6bb-170de4475cca} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{0f8ecf4f-3646-4c3a-8881-8e138ffcaf70} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{147a976f-eee1-4377-8ea7-4716e4cdd239} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{1bb22d38-a411-4b13-a746-c2a4f4ec7344} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{1e0de227-5ce4-4ea3-ab0c-8b03e1aa76bc} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{25560540-9571-4d7b-9389-0f166788785a} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{2aa2fbf8-9c76-4e97-a226-25c5f4ab6358} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{2eecd738-5844-4a99-b4b6-146bf802613b} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{3e720452-b472-4954-b7aa-33069eb53906} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{53ced2d0-5e9a-4761-9005-648404e6f7e5} Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\internet explorer\searchscopes\{56256a51-b582-467e-b8d4-7786eda79ae0} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{67fa02c4-ab30-4e77-a640-78ee8ec8673b} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{69725738-cd68-4f36-8d02-8c43722ee5da} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{7473d292-b7bb-4f24-ae82-7e2ce94bb6a9} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{7473d296-b7bb-4f24-ae82-7e2ce94bb6a9} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{84da4fdf-a1cf-4195-8688-3e961f505983} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{8e6f1832-9607-4440-8530-13be7c4b1d14} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{938aa51a-996c-4884-98ce-80dd16a5c9da} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233} Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{95b7759c-8c7f-4bf1-b163-73684a933233} Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{95b7759c-8c7f-4bf1-b163-73684a933233} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{98d9753d-d73b-42d5-8c85-4469cda897ab} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{9afb8248-617f-460d-9366-d71cdeda3179} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{9ff05104-b030-46fc-94b8-81276e4e27df} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{a4730ebe-43a6-443e-9776-36915d323ad3} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{a9571378-68a1-443d-b082-284f960c6d17} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{adb01e81-3c79-4272-a0f1-7b2be7a782dc} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{b813095c-81c0-4e40-aa14-67520372b987} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{c9d7be3e-141a-4c85-8cd6-32461f3df2c7} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{cff4ce82-3aa2-451f-9b77-7165605fb835} Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{cff4db9b-135f-47c0-9269-b4c6572fd61a} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{d9fffb27-d62a-4d64-8cec-1ff006528805} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{e46c8196-b634-44a1-af6e-957c64278ab1} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{ef99bd32-c1fb-11d2-892f-0090271d4f88} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{f9639e4a-801b-4843-aee3-03d9da199e77} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{fd72061e-9fde-484d-a58a-0bab4151cad8} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc} Successfully deleted: [Registry Key] "hkey_current_user\software\apn" Successfully deleted: [Registry Key] "hkey_current_user\software\ask.com" Successfully deleted: [Registry Key] "hkey_current_user\software\asktoolbar" Successfully deleted: [Registry Key] "hkey_local_machine\software\apn" Successfully deleted: [Registry Key] "hkey_local_machine\software\asktoolbar" Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\0cfe535c35f99574e8340bfa75bf92c2" Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\120dfadeb50841f408f04d2a278f9509" Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\261f213d1f55267499b1f87d0cc3bcf7" Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\741b4adf27276464790022c965ab6da8" Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\7de196b10195f5647a2b21b761f3de01" Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\9d4f5849367142e4685ed8c25e44c5ed" Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\a5875b04372c19545beb90d4d606c472" Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\a876d9e80b896ec44a8620248cc79296" Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\b66ffab725b92594c986de826a867888" Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\products\a28b4d68debaa244eb686953b7074fef" ~~~ Files Successfully deleted: [File] "C:\WINDOWS\system32\conduitengine.tmp" Successfully deleted: [File] "C:\WINDOWS\system32\f3pssavr.scr" Successfully deleted: [File] "C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job" ~~~ Folders Successfully deleted: [Folder] "C:\Documents and Settings\All Users\application data\tarma installer" Successfully deleted: [Folder] "C:\Documents and Settings\XxCoolNessxX\Application Data\incredibar.com" Successfully deleted: [Folder] "C:\Program Files\fast browser search" Successfully deleted: [Folder] "C:\Program Files\free offers from freeze.com" Successfully deleted: [Folder] "C:\Program Files\funwebproducts" Successfully deleted: [Folder] "C:\Program Files\incredibar.com" Successfully deleted: [Folder] "C:\Program Files\mywebsearch" Successfully deleted: [Folder] "C:\Program Files\search guard plus" Successfully deleted: [Folder] "C:\Program Files\search guard plusu" Successfully deleted: [Folder] "C:\Program Files\sgpsa" Successfully deleted: [Folder] "C:\Program Files\web assistant" Successfully deleted: [Folder] "C:\Program Files\yontoo layers runtime" Successfully deleted: [Folder] "C:\Documents and Settings\All Users\application data\2aca5cc3-0f83-453d-a079-1076fe1a8b65" Successfully deleted: [Folder] "C:\Documents and Settings\All Users\application data\ask" Successfully deleted: [Folder] "C:\Program Files\ask.com" Successfully deleted: [Folder] "C:\Documents and Settings\XxCoolNessxX\local settings\application data\asktoolbar" Successfully deleted: [Folder] "C:\WINDOWS\installer\{86d4b82a-abed-442a-be86-96357b70f4fe}" ~~~ FireFox Successfully deleted: [File] C:\user.js Successfully deleted: [File] "C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml" Successfully deleted: [File] C:\Documents and Settings\XxCoolNessxX\Application Data\mozilla\firefox\profiles\butv8pim.default\user.js Successfully deleted: [File] C:\Documents and Settings\XxCoolNessxX\Application Data\mozilla\firefox\profiles\butv8pim.default\extensions\[removed] Successfully deleted: [File] C:\Documents and Settings\XxCoolNessxX\Application Data\mozilla\firefox\profiles\butv8pim.default\searchplugins\askcom.xml Successfully deleted: [File] C:\Documents and Settings\XxCoolNessxX\Application Data\mozilla\firefox\profiles\butv8pim.default\searchplugins\mystart search.xml Successfully deleted: [Folder] C:\Documents and Settings\XxCoolNessxX\Application Data\mozilla\firefox\profiles\butv8pim.default\jetpack Successfully deleted: [Folder] C:\Documents and Settings\XxCoolNessxX\Application Data\mozilla\firefox\profiles\butv8pim.default\extensions\[removed] Successfully deleted: [Registry Value] hkey_local_machine\software\mozilla\firefox\extensions\\{336d0c35-8a85-403a-b9d2-65c292c39087} Successfully deleted the following from C:\Documents and Settings\XxCoolNessxX\Application Data\mozilla\firefox\profiles\butv8pim.default\prefs.js user_pref("browser.search.defaultengine", "Ask.com"); user_pref("browser.search.defaultenginename", "Ask.com"); user_pref("browser.search.order.1", "Ask.com"); user_pref("browser.startup.homepage", "hxxp://mystart.incredibar.com/mb128?a=6PQydq5qrj&i=26"); user_pref("extensions.asktb.abar-war-regex", "conduit\\.com"); user_pref("extensions.asktb.autofill-competitor-query-enabled", true); user_pref("extensions.asktb.cbid", "TV"); user_pref("extensions.asktb.config-updated", false); user_pref("extensions.asktb.crumb", "2012.07.05+18.10.56-toolbar003iad-US-TGl0dGxlIFJvY2ssQVIsVW5pdGVkIFN0YXRlcw%3D%3D"); user_pref("extensions.asktb.default-channel-url-mask", "hxxp://www.ask.com/web?q={query}&o={o}&l={l}&qsrc={qsrc}&gct=bar"); user_pref("extensions.asktb.displaybehavior", ""); user_pref("extensions.asktb.displaytext", ""); user_pref("extensions.asktb.dtid", "YYYYYYYYUS"); user_pref("extensions.asktb.dyn-weather-do-locid-lookup-weatherWidget", false); user_pref("extensions.asktb.dyn-weather-locid-weatherWidget", "USAR0336"); user_pref("extensions.asktb.dyn-weather-tempunit-weatherWidget", "F"); user_pref("extensions.asktb.ff-original-keyword-url", "hxxp://mystart.incredibar.com/mb128/?loc=IB_DS&a=6PQydq5qrj&&i=26&search="); user_pref("extensions.asktb.first-restart-after-config-update", true); user_pref("extensions.asktb.hxxp-header-whitelist-hosts", "[\"static-dev.en.dev.ask.com\", \"ask.com\", \"www.facebook.com\", \"www.playsushi.com\", \"WWW.google.com\", \"hxxp user_pref("extensions.asktb.l", "dis"); user_pref("extensions.asktb.last-config-req", "1341677779855"); user_pref("extensions.asktb.last-v", "3.15.2.100013"); user_pref("extensions.asktb.locale", "en_US"); user_pref("extensions.asktb.location", "Little Rock,AR,United States"); user_pref("extensions.asktb.lstation", ""); user_pref("extensions.asktb.new-tab-enabled", true); user_pref("extensions.asktb.news-native-on", true); user_pref("extensions.asktb.o", "100000031"); user_pref("extensions.asktb.pstate", ""); user_pref("extensions.asktb.qsrc", "2871"); user_pref("extensions.asktb.search-plugin-suggestions-url", "hxxp://ss.websearch.ask.com/query?qsrc=2922&li=ff&sstype=prefix&q={searchTerms}"); user_pref("extensions.asktb.search-suggestions-enabled", true); user_pref("extensions.asktb.silent-upgrade-from-pre-newtabs-build", false); user_pref("extensions.asktb.socialmini-first", true); user_pref("extensions.asktb.socialmini-interval", "1200000"); user_pref("extensions.asktb.socialmini-max-char-ticker", "33"); user_pref("extensions.asktb.socialmini-max-items", "30"); user_pref("extensions.asktb.socialmini-native-on", true); user_pref("extensions.asktb.socialmini-speed", "10000"); user_pref("extensions.asktb.socialmini-transition-first-open", false); user_pref("extensions.asktb.to", ""); user_pref("extensions.incredibar.actvtyRptTime", "1344591082070"); user_pref("extensions.incredibar.admin", false); user_pref("extensions.incredibar.aflt", "orgnl"); user_pref("extensions.incredibar.afterInstallRpt", "sent"); user_pref("extensions.incredibar.cntry", "US"); user_pref("extensions.incredibar.dfltLng", "EN"); user_pref("extensions.incredibar.dfltSrch", false); user_pref("extensions.incredibar.dfltlng", "EN"); user_pref("extensions.incredibar.dfltsrch", "false"); user_pref("extensions.incredibar.did", "10658"); user_pref("extensions.incredibar.envrmnt", "production"); user_pref("extensions.incredibar.excTlbr", false); user_pref("extensions.incredibar.hdrMd5", "6284784A1982736DE3A39940093A6F14"); user_pref("extensions.incredibar.hmpg", false); user_pref("extensions.incredibar.hrdid", "185455f10000000000000026f2a59766"); user_pref("extensions.incredibar.id", "185455f10000000000000026f2a59766"); user_pref("extensions.incredibar.installerproductid", "26"); user_pref("extensions.incredibar.instlDay", "15483"); user_pref("extensions.incredibar.instlRef", ""); user_pref("extensions.incredibar.instlday", "15483"); user_pref("extensions.incredibar.instlref", ""); user_pref("extensions.incredibar.isDcmntCmplt", true); user_pref("extensions.incredibar.isdcmntcmplt", "false"); user_pref("extensions.incredibar.keywordurl", ""); user_pref("extensions.incredibar.lastVrsnTs", "1.5.11.1422:00:17"); user_pref("extensions.incredibar.mntrvrsn", "1.2.0"); user_pref("extensions.incredibar.newTab", false); user_pref("extensions.incredibar.newtab", "false"); user_pref("extensions.incredibar.newtaburl", ""); user_pref("extensions.incredibar.noFFXTlbr", false); user_pref("extensions.incredibar.ppd", ""); user_pref("extensions.incredibar.prdct", "incredibar"); user_pref("extensions.incredibar.productid", "26"); user_pref("extensions.incredibar.propectorlck", 79906019); user_pref("extensions.incredibar.prtkHmpg", 1); user_pref("extensions.incredibar.prtnrId", "Incredibar"); user_pref("extensions.incredibar.prtnrid", "Incredibar"); user_pref("extensions.incredibar.sg", "none"); user_pref("extensions.incredibar.smplGrp", "none"); user_pref("extensions.incredibar.smplgrp", "none"); user_pref("extensions.incredibar.srch", ""); user_pref("extensions.incredibar.srchprvdr", ""); user_pref("extensions.incredibar.tlbrId", "base"); user_pref("extensions.incredibar.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6PQydq5qrj&loc=IB_TB&i=26&search="); user_pref("extensions.incredibar.tlbrid", "base"); user_pref("extensions.incredibar.tlbrsrchurl", "hxxp://mystart.Incredibar.com/?a=6PQydq5qrj&loc=IB_TB&i=26&search="); user_pref("extensions.incredibar.upn2", "6PQydq5qrj"); user_pref("extensions.incredibar.upn2n", "92542932125148509"); user_pref("extensions.incredibar.vrsn", "[removed]"); user_pref("extensions.incredibar.vrsnTs", "1.5.11.1422:00:17"); user_pref("extensions.incredibar.vrsni", "[removed]"); user_pref("extensions.incredibar.vrsnts", "1.5.11.1422:00:17"); user_pref("extensions.incredibar_i.aflt", "orgnl"); user_pref("extensions.incredibar_i.dfltLng", ""); user_pref("extensions.incredibar_i.did", "10658"); user_pref("extensions.incredibar_i.excTlbr", false); user_pref("extensions.incredibar_i.id", "185455f10000000000000026f2a59766"); user_pref("extensions.incredibar_i.installerproductid", "26"); user_pref("extensions.incredibar_i.instlDay", "15483"); user_pref("extensions.incredibar_i.instlRef", ""); user_pref("extensions.incredibar_i.ms_url_id", ""); user_pref("extensions.incredibar_i.newTab", false); user_pref("extensions.incredibar_i.ppd", ""); user_pref("extensions.incredibar_i.prdct", "incredibar"); user_pref("extensions.incredibar_i.productid", "26"); user_pref("extensions.incredibar_i.prtnrId", "Incredibar"); user_pref("extensions.incredibar_i.smplGrp", "none"); user_pref("extensions.incredibar_i.tlbrId", "base"); user_pref("extensions.incredibar_i.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6PQydq5qrj&loc=IB_TB&i=26&search="); user_pref("extensions.incredibar_i.upn2", "6PQydq5qrj"); user_pref("extensions.incredibar_i.upn2n", "92542932125148509"); user_pref("extensions.incredibar_i.vrsn", "[removed]"); user_pref("extensions.incredibar_i.vrsnTs", "1.5.11.1422:00:17"); user_pref("extensions.incredibar_i.vrsni", "[removed]"); user_pref("extentions.y2layers.defaultEnableAppsList", "ezLooker,pagerage,buzzdock,toprelatedtopics,twittube"); user_pref("extentions.y2layers.installId", "3f1f494c-03c6-4387-ab37-ba9f034c92ba"); user_pref("extentions.y2layers.lastDnsTest", 371993); user_pref("keyword.URL", "hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=ORJ&o=100000031&locale=en_US&apn_uid=F4145D45-008E-4338-9EE3-9817E9148D46&apn_ptnrs=TV&apn_saui ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on Mon 04/15/2013 at 19:40:28.92 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ DDS (Ver_2012-11-20.01) - NTFS_x86 Internet Explorer: 8.0.6001.18702 Run by [removed] at 19:50:13 on 2013-04-15 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.383.25 [GMT -5:00] . AV: AVG Anti-Virus Free Edition 2011 *Enabled/Outdated* {17DDD097-36FF-435F-9E1B-52D74245D6BF} . ============== Running Processes ================ . \??\C:\PROGRA~1\AVG\AVG10\avgchsvx.exe \??\C:\PROGRA~1\AVG\AVG10\avgrsx.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\ANIWConnService.exe C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\explorer.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\svchost.exe -k imgsvc . ============== Pseudo HJT Report =============== . uInternet Connection Wizard,ShellNext = "c:\program files\outlook express\msimn.exe" //mailurl:mailto:?body=http%3A%2F%2Ffc03.deviantart.net%2Ffs46%2Ff%2F2009%2F221%2F6%2Fc%2FPokemon_Ranch__Lapras_by_Pokelova.jpg&subject= dURLSearchHooks: {A3BC75A2-1F87-4686-AA43-5347D756017C} - dURLSearchHooks: {00A6FAF6-072E-44cf-8957-5838F569A31D} - dURLSearchHooks: {CA3EB689-8F09-4026-AA10-B9534C691CE0} - BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - c:\program files\avg\avg10\avgssie.dll BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:\program files\google\googletoolbarnotifier\5.7.8313.1002\swg.dll TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: : {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - LocalServer32 - TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll EB: {2AA2FBF8-9C76-4E97-A226-25C5F4AB6358} - mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSConfig.exe /auto dRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uPolicies-Explorer: NoDriveTypeAutoRun = dword:145 mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1 mPolicies-Explorer: NoDriveTypeAutoRun = dword:145 DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab TCP: Interfaces\{340FF02C-4B34-4423-A28C-B45BC2C6A959} : DHCPNameServer = 192.168.1.254 TCP: Interfaces\{3A30F080-AA65-49BA-A161-C7E926F0640D} : DHCPNameServer = [removed] [removed] Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\xxcoolnessxx\application data\mozilla\firefox\profiles\butv8pim.default\ FF - plugin: c:\documents and settings\all users\application data\nexonus\ngm\npNxGameUS.dll FF - plugin: c:\documents and settings\xxcoolnessxx\local settings\application data\robloxversions\version-037c042a4c1b49fd\NPRobloxProxy.dll FF - plugin: c:\program files\byond\bin\npbyond.dll FF - plugin: c:\program files\common files\avg secure search\sitesafetyinstaller\11.2.0\npsitesafety.dll FF - plugin: c:\program files\google\update\1.3.21.135\npGoogleUpdate3.dll FF - plugin: c:\program files\mozilla firefox\plugins\npbyond.dll FF - plugin: c:\program files\mozilla firefox\plugins\NPMyWebS.dll FF - plugin: c:\program files\oracle\javafx 2.1 runtime\bin\plugin2\npjp2.dll FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_6_602_180.dll FF - plugin: c:\windows\system32\npDeployJava1.dll FF - plugin: c:\windows\system32\npkfx.dll FF - plugin: c:\windows\system32\npkfxcv.dll FF - plugin: c:\windows\system32\npkfxes.dll FF - plugin: c:\windows\system32\npkfxexp.dll FF - plugin: c:\windows\system32\npkfxjv.dll FF - plugin: c:\windows\system32\npkfxmoz.dll FF - plugin: c:\windows\system32\npkfxne.dll FF - plugin: c:\windows\system32\npkfxpa.dll FF - plugin: c:\windows\system32\npkfxxpc.dll FF - plugin: c:\windows\system32\npptools.dll . ============= SERVICES / DRIVERS =============== . R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 22992] R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 32592] R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-12-8 248656] R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 34896] R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2010-11-12 297168] R1 c2scsi;c2scsi;c:\windows\system32\drivers\c2scsi.sys [2009-3-1 241664] R2 ANIWConnService;ANIWConn Service;c:\windows\system32\ANIWConnService.exe [2013-4-11 151552] R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-6-25 35088] R3 JSWSCIMD;jswscimd Service;c:\windows\system32\drivers\jswscimd.sys [2008-10-1 57440] R3 rt2870;D-Link dnetr28u USB Extensible Wireless LAN Card Driver;c:\windows\system32\drivers\Drt2870.sys [2013-4-11 724736] S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2010-8-3 134480] S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2010-8-3 24144] S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2010-8-3 27216] S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.sys [2003-7-24 17149] S3 E3dInst;E3dInst;c:\windows\system32\drivers\e3dinst.sys [2011-2-12 4832] S3 EagleXNt;EagleXNt;\??\c:\windows\system32\drivers\eaglexnt.sys –> c:\windows\system32\drivers\EagleXNt.sys [?] S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2011-6-15 13224] S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2008-11-9 17920] S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2008-11-9 7680] S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys [2008-11-9 22528] S3 npkfxa;npkfxa;c:\windows\system32\npkfxa.sys [2010-10-20 35552] S3 npkfxs;npkfxs;c:\windows\system32\npkfxs.sys [2010-11-30 20320] S3 SWNC8U56;Sierra Wireless MUX NDIS Driver (UMTS56);c:\windows\system32\drivers\swnc8u56.sys [2007-6-27 101248] S3 SWUMX56;Sierra Wireless USB MUX Driver (UMTS56);c:\windows\system32\drivers\swumx56.sys [2007-6-27 73856] S3 WN111v2;NETGEAR WN111v2 USB2.0 Wireless Card Service;c:\windows\system32\drivers\WN111v2.sys [2008-9-30 453120] S4 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2012-1-31 7391072] S4 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2011-2-8 269520] S4 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files\logmein hamachi\hamachi-2.exe [2012-6-27 1385896] S4 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\netgear\wn111v2\jswpsapi.exe [2008-2-27 360547] S4 npkfxsvc;npkfxsvc;c:\windows\system32\npkfxsvc.exe [2010-12-23 222432] S4 SeekeenSrch Service;SeekeenSrch Service;"c:\documents and settings\all users\application data\seekeensrch\seekeen155.exe" "c:\program files\seekeensrch\seekeen.dll" service –> c:\documents and settings\all users\application data\seekeensrch\seekeen155.exe [?] S4 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files\sony ericsson\sony ericsson pc companion\PCCService.exe [2011-6-15 155344] S4 vToolbarUpdater11.2.0;vToolbarUpdater11.2.0;c:\program files\common files\avg secure search\vtoolbarupdater\11.2.0\ToolbarUpdater.exe [2012-7-10 935008] . =============== Created Last 30 ================ . 2013-04-16 00:32:00 ——– d—–w- c:\windows\ERUNT 2013-04-16 00:31:32 ——– d—–w- C:\JRT 2013-04-14 19:58:07 781312 —-a-w- c:\windows\system32\RGSS102J.dll 2013-04-14 19:58:07 778752 —-a-w- c:\windows\system32\RGSS102E.dll 2013-04-14 19:58:07 771584 —-a-w- c:\windows\system32\RGSS100J.dll 2013-04-14 19:58:07 761856 —-a-w- c:\windows\system32\RGSS104J.dll 2013-04-14 19:58:07 758272 —-a-w- c:\windows\system32\RGSS104E.dll 2013-04-14 19:58:07 685056 —-a-w- c:\windows\system32\RGSS103J.dll 2013-04-14 19:57:57 ——– d—–w- c:\program files\common files\Enterbrain 2013-04-14 03:16:03 74136 —-a-w- c:\program files\mozilla firefox\breakpadinjector.dll 2013-04-14 03:15:56 96664 —-a-w- c:\program files\mozilla firefox\webapprt-stub.exe 2013-04-14 03:15:56 26520 —-a-w- c:\program files\mozilla firefox\plugin-hang-ui.exe 2013-04-14 03:15:56 170232 —-a-w- c:\program files\mozilla firefox\webapp-uninstaller.exe 2013-04-12 02:27:57 ——– d—–w- c:\program files\Buzzluck Casino 2013-04-12 02:24:30 237568 —-a-w- c:\windows\system32\ANIWPS.exe 2013-04-12 02:24:29 733184 —-a-w- c:\windows\system32\ANIOWPS.dll 2013-04-12 02:23:34 724736 —-a-w- c:\windows\system32\drivers\Drt2870.sys 2013-04-12 02:23:32 221184 —-a-w- c:\windows\system32\RaCoInst.dll 2013-04-12 02:23:31 ——– d—–w- c:\program files\D-Link 2013-04-12 01:48:25 49265 —-a-w- c:\windows\system32\jpicpl32.cpl 2013-04-12 01:43:30 ——– d—–w- c:\documents and settings\xxcoolnessxx\local settings\application data\{3248F0A6-6813-11D6-A77B-00B0D0150050} . ==================== Find3M ==================== . 2013-04-12 02:36:01 691592 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2013-04-12 02:36:00 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-03-08 08:36:22 293376 —-a-w- c:\windows\system32\winsrv.dll 2013-03-07 01:28:24 2193408 —-a-w- c:\windows\system32\ntoskrnl.exe 2013-03-07 00:50:28 2070016 —-a-w- c:\windows\system32\ntkrnlpa.exe 2013-03-02 02:06:31 916480 —-a-w- c:\windows\system32\wininet.dll 2013-03-02 02:06:30 43520 —-a-w- c:\windows\system32\licmgr10.dll 2013-03-02 02:06:30 1469440 ——w- c:\windows\system32\inetcpl.cpl 2013-03-02 01:25:02 1867264 —-a-w- c:\windows\system32\win32k.sys 2013-03-02 01:08:47 385024 —-a-w- c:\windows\system32\html.iec 2013-02-27 07:56:51 2067456 —-a-w- c:\windows\system32\mstscax.dll 2013-02-12 00:32:23 12928 —-a-w- c:\windows\system32\drivers\usb8023.sys 2013-02-12 00:32:23 12928 ——w- c:\windows\system32\drivers\usb8023x.sys 2013-01-26 03:55:44 552448 —-a-w- c:\windows\system32\oleaut32.dll . ============= FINISH: 19:52:00.12 ===============

Attachments:

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]
  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. 1. Do not mouse-click anywhere on the screen while it is running. That may cause it to stall. In fact, I suggest you do not do anything else on the computer while Combofix is running as it can cause it to stall. It may appear at times that it isn't doing anything but it is. Just let it run. It may also reboot the machine as a part of what it is doing and that is not unusual. (If your computer requires a login then you WILL need to fill in the login/password for it to continue. If your computer does not have a login then it will continue on it's own..) Then, just sit tight until it finishes. Sometimes it takes 10 minutes, sometimes it takes an hour. Just be patient until the log pops up. If it takes more than an hour and doesn't appear to be doing antying, you can stop it and come back and let me know.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now


If you have a problem launching programs after running Combofix, please do not panic! Simply reboot the computer and all should be fine.
as of right not combo fix has been running for about 1 hour 30 minutes the cursor is still blinking does not appear to be stalled I will continue to let it run overnight unless given additional instructions before i go to sleep for the night. Let me know and thanks…
It's fine to let it run overnight. It won't hurt anything. Worst that happens is it's still there in the morning and you know it's stalled at that point (in which case you can shut the computer down and reboot and take a peek for a log at C:\Combofix.txt and see if one is there. If not try rerunning it.

Hopefully, there will be a log awaiting you. On a slow machine, with a lot of data, it can take a long time for the program to run. Patience is the key (that and not touching anything) so going to bed was the best idea!
Yeah it took this morning to finish lol

ComboFix 13-04-15.01 - XxCoolNessxX 04/16/2013 7:51.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.383.127 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Outdated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Application Data\ZangoSA
c:\documents and settings\All Users\Application Data\ZangoSA\ZangoSA.dat
c:\documents and settings\All Users\Application Data\ZangoSA\ZangoSA_kyf.dat
c:\documents and settings\All Users\Application Data\ZangoSA\ZangoSAAbout.mht
c:\documents and settings\All Users\Application Data\ZangoSA\ZangoSAau.dat
c:\documents and settings\All Users\Application Data\ZangoSA\ZangoSAEula.mht
c:\documents and settings\All Users\Start Menu\Programs\Zango
c:\documents and settings\All Users\Start Menu\Programs\Zango\Reset Cursor.lnk
c:\documents and settings\All Users\Start Menu\Programs\Zango\Zango Customer Support Center.lnk
c:\documents and settings\All Users\Start Menu\Programs\Zango\Zango Games!.lnk
c:\documents and settings\All Users\Start Menu\Programs\Zango\Zango Library.lnk
c:\documents and settings\All Users\Start Menu\Programs\Zango\Zango Screensavers!.lnk
c:\documents and settings\All Users\Start Menu\Programs\Zango\Zango Videos!.lnk
c:\windows\system32\Cache
c:\windows\system32\Cache\272512937d9e61a4.fb
c:\windows\system32\Cache\287204568329e189.fb
c:\windows\system32\Cache\28bc8f716fd76a47.fb
c:\windows\system32\Cache\2c53092c95605355.fb
c:\windows\system32\Cache\31a0997e9a5b5eb3.fb
c:\windows\system32\Cache\32c84fe32bb74d60.fb
c:\windows\system32\Cache\3917078cb68ec657.fb
c:\windows\system32\Cache\394b01c9ff92d59a.fb
c:\windows\system32\Cache\590ba23ce359fd0c.fb
c:\windows\system32\Cache\610289e025a3ee9a.fb
c:\windows\system32\Cache\651c5d3cdbfb8bd1.fb
c:\windows\system32\Cache\6c59ac5e7e7a3ad0.fb
c:\windows\system32\Cache\6d03dad1035885d3.fb
c:\windows\system32\Cache\a16d5df2b0952270.fb
c:\windows\system32\Cache\a7b6f23f3fdb1860.fb
c:\windows\system32\Cache\a8556537add6dfc5.fb
c:\windows\system32\Cache\ad10a52aff5e038d.fb
c:\windows\system32\Cache\c1fa887b03019701.fb
c:\windows\system32\Cache\c4d28dca2e7648be.fb
c:\windows\system32\Cache\d201ef9910cd39de.fb
c:\windows\system32\Cache\d2e94710a5708128.fb
c:\windows\system32\Cache\d79b9dfe81484ec4.fb
c:\windows\system32\Cache\e0de16f883bea794.fb
c:\windows\system32\Cache\f4f698d143be4d26.fb
c:\windows\system32\Cache\f998975c9cc711ee.fb
c:\windows\system32\RGSS103J.dll
c:\windows\system32\RGSS104E.dll
c:\windows\system32\RGSS104J.dll
c:\windows\system32\SET43.tmp
c:\windows\system32\SET4F.tmp
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\fusion.dll
c:\windows\system32\URTTemp\mscoree.dll
c:\windows\system32\URTTemp\mscoree.dll.local
c:\windows\system32\URTTemp\mscorsn.dll
c:\windows\system32\URTTemp\mscorwks.dll
c:\windows\system32\URTTemp\msvcr71.dll
c:\windows\system32\URTTemp\regtlib.exe
.
.
((((((((((((((((((((((((( Files Created from 2013-03-16 to 2013-04-16 )))))))))))))))))))))))))))))))
.
.
2013-04-16 00:32 . 2013-04-16 00:32 ——– d—–w- c:\windows\ERUNT
2013-04-16 00:31 . 2013-04-16 00:31 ——– d—–w- C:\JRT
2013-04-14 19:58 . 2005-08-30 05:00 781312 —-a-w- c:\windows\system32\RGSS102J.dll
2013-04-14 19:58 . 2005-08-30 05:00 778752 —-a-w- c:\windows\system32\RGSS102E.dll
2013-04-14 19:58 . 2005-08-30 05:00 771584 —-a-w- c:\windows\system32\RGSS100J.dll
2013-04-14 19:57 . 2013-04-14 19:57 ——– d—–w- c:\program files\Common Files\Enterbrain
2013-04-14 03:16 . 2013-04-14 03:16 74136 —-a-w- c:\program files\Mozilla Firefox\breakpadinjector.dll
2013-04-14 03:15 . 2013-04-14 03:15 96664 —-a-w- c:\program files\Mozilla Firefox\webapprt-stub.exe
2013-04-14 03:15 . 2013-04-14 03:15 26520 —-a-w- c:\program files\Mozilla Firefox\plugin-hang-ui.exe
2013-04-14 03:15 . 2013-04-14 03:15 170232 —-a-w- c:\program files\Mozilla Firefox\webapp-uninstaller.exe
2013-04-12 02:27 . 2013-04-12 02:45 ——– d—–w- c:\program files\Buzzluck Casino
2013-04-12 02:24 . 2009-02-26 16:22 237568 —-a-w- c:\windows\system32\ANIWPS.exe
2013-04-12 02:24 . 2009-09-02 16:00 733184 —-a-w- c:\windows\system32\ANIOWPS.dll
2013-04-12 02:23 . 2009-08-03 15:57 724736 —-a-w- c:\windows\system32\drivers\Drt2870.sys
2013-04-12 02:23 . 2009-08-03 15:54 221184 —-a-w- c:\windows\system32\RaCoInst.dll
2013-04-12 02:23 . 2013-04-12 02:23 ——– d—–w- c:\program files\D-Link
2013-04-12 02:23 . 2013-04-12 02:23 ——– d—–w- c:\documents and settings\XxCoolNessxX\Application Data\InstallShield
2013-04-12 01:48 . 2005-08-26 23:14 49265 —-a-w- c:\windows\system32\jpicpl32.cpl
2013-04-12 01:44 . 2013-04-12 01:44 ——– d—–w- c:\program files\Common Files\Java
2013-04-12 01:43 . 2013-04-12 01:43 ——– d—–w- c:\documents and settings\XxCoolNessxX\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150050}
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-04-12 02:36 . 2012-05-29 13:35 691592 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-04-12 02:36 . 2012-05-29 13:35 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-03-08 08:36 . 2004-08-04 12:00 293376 —-a-w- c:\windows\system32\winsrv.dll
2013-03-07 01:28 . 2004-08-04 12:00 2193408 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-03-07 00:50 . 2004-08-03 22:59 2070016 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-03-02 02:06 . 2004-08-04 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2013-03-02 02:06 . 2004-08-04 12:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2013-03-02 02:06 . 2004-08-04 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2013-03-02 01:25 . 2004-08-04 12:00 1867264 —-a-w- c:\windows\system32\win32k.sys
2013-03-02 01:08 . 2004-08-04 12:00 385024 —-a-w- c:\windows\system32\html.iec
2013-02-27 07:56 . 2008-06-22 20:53 2067456 —-a-w- c:\windows\system32\mstscax.dll
2013-02-12 00:32 . 2008-04-13 18:56 12928 ——w- c:\windows\system32\drivers\usb8023x.sys
2013-02-12 00:32 . 2004-08-04 12:00 12928 —-a-w- c:\windows\system32\drivers\usb8023.sys
2013-01-26 03:55 . 2004-08-04 12:00 552448 —-a-w- c:\windows\system32\oleaut32.dll
2013-04-14 03:16 . 2011-12-17 21:22 263064 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
——- Sigcheck ——-
Note: Unsigned files aren't necessarily malware.
.
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys
[-] 2008-06-20 . 4AFB3B0919649F95C1964AA1FAD27D73 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys
[7] 2008-06-20 . 2A5554FC5B1E04E131230E3CE035C3F9 . 360320 . . [5.1.2600.3394] . . c:\windows\$NtServicePackUninstall$\tcpip.sys
[7] 2008-06-20 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394] . . c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-07 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http://www.avg.com/ww.special-uninstallati...10.0.1424" [?]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NETGEAR WN111v2 Smart Wizard.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\NETGEAR WN111v2 Smart Wizard.lnk
backup=c:\windows\pss\NETGEAR WN111v2 Smart Wizard.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Pavilion A1203W^Start Menu^Programs^Startup^RollerCoaster Tycoon 3 Registration.lnk]
path=c:\documents and settings\Pavilion A1203W\Start Menu\Programs\Startup\RollerCoaster Tycoon 3 Registration.lnk
backup=c:\windows\pss\RollerCoaster Tycoon 3 Registration.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-02-27 22:10 35696 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
2004-09-07 18:47 57344 —-a-w- c:\windows\ALCXMNTR.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ANIWZCS2Service]
2009-08-21 14:27 98304 —-a-w- c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\D-Link D-Link RangeBooster N DWA-140]
2009-09-18 15:24 1708032 —-a-w- c:\program files\D-Link\DWA-140 revB\AirNCFG.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2005-05-12 05:12 49152 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
2004-08-04 12:00 208952 —-a-w- c:\windows\ime\IMJP8_1\imjpmig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
2012-06-27 17:29 1996200 —-a-w- c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
2004-08-04 12:00 455168 -c–a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
2004-08-04 12:00 455168 -c–a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2003-11-01 00:42 32768 -c–a-w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSPower]
2005-04-12 16:31 49152 ——w- c:\windows\system32\SiSPower.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2011-07-22 00:22 17357448 —-a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Companion]
2011-07-25 16:41 433360 —-a-w- c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2003-09-11 18:32 958464 —-a-w- c:\program files\Steam\Steam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-06-07 19:45 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SeekeenSrch Service"=2 (0x2)
"RoxWatch9"=2 (0x2)
"RoxMediaDB9"=3 (0x3)
"RoxLiveShare9"=2 (0x2)
"Roxio Upnp Server 9"=2 (0x2)
"Roxio UPnP Renderer 9"=3 (0x3)
"WMPNetworkSvc"=3 (0x3)
"Web Assistant Updater"=2 (0x2)
"vToolbarUpdater11.2.0"=2 (0x2)
"stllssvr"=3 (0x3)
"Steam Client Service"=3 (0x3)
"Sony Ericsson PCCompanion"=3 (0x3)
"rpcapd"=3 (0x3)
"Pml Driver HPZ12"=2 (0x2)
"npkfxsvc"=2 (0x2)
"MyWebSearchService"=2 (0x2)
"MozillaMaintenance"=3 (0x3)
"jswpsapi"=3 (0x3)
"idsvc"=3 (0x3)
"IDriverT"=3 (0x3)
"Hamachi2Svc"=2 (0x2)
"gusvc"=3 (0x3)
"gupdatem"=3 (0x3)
"gupdate"=2 (0x2)
"avgwd"=2 (0x2)
"AVGIDSAgent"=2 (0x2)
"AdobeFlashPlayerUpdateSvc"=3 (0x3)
"ACS"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\BYOND\\bin\\byond.exe"=
"c:\\Program Files\\BYOND\\bin\\dreamdaemon.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Sony Ericsson\\Update Engine\\Sony Ericsson Update Engine.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"57871:TCP"= 57871:TCP:Pando Media Booster
"57871:UDP"= 57871:UDP:Pando Media Booster
.
R1 c2scsi;c2scsi;c:\windows\system32\drivers\c2scsi.sys [3/1/2009 2:59 PM 241664]
R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [6/25/2010 12:07 PM 35088]
R3 JSWSCIMD;jswscimd Service;c:\windows\system32\drivers\jswscimd.sys [10/1/2008 5:45 PM 57440]
R4 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys –> c:\windows\system32\DRIVERS\AVGIDSEH.Sys [?]
R4 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys –> c:\windows\system32\DRIVERS\avgrkx86.sys [?]
R4 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys –> c:\windows\system32\DRIVERS\avgtdix.sys [?]
S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.sys [7/24/2003 1:10 PM 17149]
S3 E3dInst;E3dInst;c:\windows\system32\drivers\e3dinst.sys [2/12/2011 10:00 AM 4832]
S3 EagleXNt;EagleXNt;\??\c:\windows\system32\drivers\EagleXNt.sys –> c:\windows\system32\drivers\EagleXNt.sys [?]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [6/15/2011 9:33 AM 13224]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [11/9/2008 7:37 PM 17920]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [11/9/2008 7:37 PM 7680]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys [11/9/2008 7:37 PM 22528]
S3 npkfxa;npkfxa;c:\windows\system32\npkfxa.sys [10/20/2010 7:01 PM 35552]
S3 npkfxs;npkfxs;c:\windows\system32\npkfxs.sys [11/30/2010 3:48 AM 20320]
S3 SWNC8U56;Sierra Wireless MUX NDIS Driver (UMTS56);c:\windows\system32\drivers\swnc8u56.sys [6/27/2007 11:41 AM 101248]
S3 SWUMX56;Sierra Wireless USB MUX Driver (UMTS56);c:\windows\system32\drivers\swumx56.sys [6/27/2007 11:42 AM 73856]
S3 WN111v2;NETGEAR WN111v2 USB2.0 Wireless Card Service;c:\windows\system32\drivers\WN111v2.sys [9/30/2008 4:24 AM 453120]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - Avgldx86
.
Contents of the 'Scheduled Tasks' folder
.
2013-04-16 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-29 02:36]
.
2013-04-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-07 22:52]
.
2013-04-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-07 22:52]
.
2013-04-16 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2008-06-22 14:04]
.
2013-04-16 c:\windows\Tasks\User_Feed_Synchronization-{A1E8DAF1-7CF2-451D-A871-EAA58D2493B8}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 09:31]
.
2013-04-16 c:\windows\Tasks\User_Feed_Synchronization-{E4D8CC7E-237B-40F8-92A1-9B054D74B915}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 09:31]
.
.
——- Supplementary Scan ——-
.
uInternet Connection Wizard,ShellNext = "c:\program files\Outlook Express\msimn.exe" //mailurl:mailto:?body=http%3A%2F%2Ffc03.deviantart.net%2Ffs46%2Ff%2F2009%2F221%2F6%2Fc%2FPokemon_Ranch__Lapras_by_Pokelova.jpg&subject;=
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\documents and settings\XxCoolNessxX\Application Data\Mozilla\Firefox\Profiles\butv8pim.default\
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-Wdf01000.sys
MSConfigStartUp-ApnUpdater - c:\program files\Ask.com\Updater\Updater.exe
MSConfigStartUp-AT&T; Communication Manager - c:\program files\AT&T;\Communication Manager\ATTCM.exe
MSConfigStartUp-AVG_TRAY - c:\program files\AVG\AVG10\avgtray.exe
MSConfigStartUp-ccRegVfy - c:\program files\Common Files\Symantec Shared\ccRegVfy.exe
MSConfigStartUp-FBSearch - c:\program files\Search Guard Plus\SearchGuardPlus.exe
MSConfigStartUp-Genius - c:\documents and settings\XxAwesomeNessxX\Application Data\Genius\GeniusInstaller.exe
MSConfigStartUp-HF_G_Jul - c:\program files\AVG Secure Search\HF_G_Jul.exe
MSConfigStartUp-jswtrayutil - c:\program files\NETGEAR\WN111v2\jswtrayutil.exe
MSConfigStartUp-My Web Search Bar Search Scope Monitor - c:\progra~1\MYWEBS~1\bar\2.bin\m3SrchMn.exe
MSConfigStartUp-MyWebSearch Email Plugin - c:\progra~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
MSConfigStartUp-MyWebSearch Plugin - c:\progra~1\MYWEBS~1\bar\2.bin\M3PLUGIN.DLL
MSConfigStartUp-Recordpad - c:\program files\NCH Swift Sound\Recordpad\recordpad.exe
MSConfigStartUp-ROC_roc_dec12 - c:\program files\AVG Secure Search\ROC_roc_dec12.exe
MSConfigStartUp-RoxWatchTray - c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
MSConfigStartUp-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe
MSConfigStartUp-TRx - c:\program files\NCH Swift Sound\TRx\trx.exe
MSConfigStartUp-vProt - c:\program files\AVG Secure Search\vprot.exe
MSConfigStartUp-WeatherDPA - c:\program files\Zango\bin\10.3.75.0\Weather.exe
MSConfigStartUp-WZCSLDR2 - c:\program files\D-Link\DWA-140 revB\WZCSLDR2.exe
MSConfigStartUp-ZangoSA - c:\program files\Zango\bin\10.3.75.0\ZangoSA.exe
AddRemove-incredibar - c:\program files\Incredibar.com\incredibar\1.5.11.14\uninstall.exe
AddRemove-{336D0C35-8A85-403a-B9D2-65C292C39087}_is1 - c:\program files\Web Assistant\unins000.exe
AddRemove-{889DF117-14D1-44EE-9F31-C5FB5D47F68B} - c:\docume~1\ALLUSE~1\APPLIC~1\TARMAI~1\{889DF~1\Setup.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-04-16 08:02
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-606747145-776561741-839522115-1009\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6A228193-BAA3-4BF6-8A53-C6AABFF943C2}*tings]
"AppName"="Roblox.exe"
"Policy"=dword:00000003
"AppPath"="c:\\Documents and Settings\\XxCoolNessxX\\Local Settings\\Application Data\\RobloxVersions\\version-221a4807685c44e7\\"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_169_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_169_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2013-04-16 08:05:13
ComboFix-quarantined-files.txt 2013-04-16 13:05
.
Pre-Run: 15,773,749,248 bytes free
Post-Run: 18,408,128,512 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 86282D1BCDF07F521E509291476A7657
Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.

Also, can you let me know how the machine seems to be running now?
Malwarebytes Anti-Malware (Trial) 1.75.0.1300 www.malwarebytes.org Database version: v2013.04.16.10 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 XxCoolNessxX :: PAVILION-A1203W [administrator] Protection: Enabled 4/16/2013 6:05:09 PM mbam-log-2013-04-16 (18-05-09).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 233465 Time elapsed: 8 minute(s), 13 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 2 HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EDDBB5EE-BB64-4bfc-9DBE-E7C85941335B} (Adware.Zango) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Office\Word\Addins\HostOL.MailAnim (Adware.Hotbar) -> Quarantined and deleted successfully. Registry Values Detected: 1 HKLM\SOFTWARE\Mozilla\Firefox\Extensions|[removed] (Adware.Zango) -> Data: C:\Program Files\Zango\bin\10.3.75.0\firefox\extensions -> Quarantined and deleted successfully. Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) SO FAR THE SPEED ARE A LOT BETTER
This scan make take awhile depending on how many items are on the computer, and since you are working with an older machine. You may want to run it at a time you won't be needing the machine. It should be run from IE and I'd recommend not doing anything else while it's running. You may want to run it overnight.


Go here to run an online scannner from ESET.
  • Note: For browsers other than Internet Explorer, you will need to download and install esetsmartinstaller_enu.exe. Click on it and save the file to a convenient location. Double click on it to install and a new window will open.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.

If it doesn't find anything there will be no log to post.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI