This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Physical Memory Dump Problems, Can Hjt Help?

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm using windows xp, and whenever I am using my cd/dvd drive for anything my computer comes to a near stand still. I can't even listen to a cd because it slows down to the point where the sound breaks up. It takes a ridiculous ammout of time to burn cds and dvds now. If i am reading or writing a disk in the drive and I try to do other stuff at the same time my computer crashes and I get a physical memory dump screen. I don't have any idea what is creating this problem, but I'm hoping that you guys can help. Here is my HJT log.

Logfile of HijackThis v1.99.1
Scan saved at 10:33:26 PM, on 8/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\ehome\RMSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\zHotkey.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
c:\program files\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\PROGRA~1\MYWEBS~1\bar\3.bin\m3SrchMn.exe
C:\PROGRA~1\MYWEBS~1\bar\3.bin\mwsoemon.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\ehome\RMSysTry.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\3.bin\MWSSRCAS.DLL
O1 - Hosts: 66.98.148.65 auto.search.msn.com
O1 - Hosts: 66.98.148.65 auto.search.msn.es
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\3.bin\MWSSRCAS.DLL
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\3.bin\MWSBAR.DLL
O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\Search\YSearchSuggest.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: My &Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\3.bin\MWSBAR.DLL
O4 - HKLM\..\Run: [readericon] "C:\Program Files\Digital Media Reader\readericon45G.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [MSKDetectorExe] "C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" /uninstall
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "C:\Program Files\McAfee.com\VSO\mcvsshld.exe"
O4 - HKLM\..\Run: [OASClnt] "C:\Program Files\McAfee.com\VSO\oasclnt.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [REGSHAVE] "C:\Program Files\REGSHAVE\REGSHAVE.EXE" /AUTORUN
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\3.bin\m3SrchMn.exe" /m=0
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\3.bin\mwsoemon.exe
O4 - HKLM\..\Run: [CanonMyPrinter] "C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" /logon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] C:\WINDOWS\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\3.bin\mwsoemon.exe
O4 - HKCU\..\Run: [Performance Center] C:\Program Files\Ascentive\Performance Center\APCMain.exe -m
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Startup: Delta AutoLoad.lnk = C:\Documents and Settings\Owner\Desktop\PSX\Delta\delta.exe
O4 - Global Startup: Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…html?p=ZNfox000
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab55762.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab55579.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab55668.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab55708.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab55200.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{AB8470E5-C154-4CF3-8C2C-2BFCD6DF6CD6}: NameServer = 68.87.85.98,68.87.69.146
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Howdy BrosephJones,

Welcome to Tom Coyote. Some MyWebSearch infection showing here, and lately when any junk from IAC is around more is interfering as well. To be sure of all possible problem causes how long have you have SpySweeper installed along with this McAfee setup here? Post back on that and do the following as well.


Download ComboFix.exe from here to your desktop, and click the downloaded file to run the repair.

When the command window opens, select 1 (and Enter). Allow the scan to run. When completed a text window will appear - please copy/paste the contents back here. This log can also be found at C:\ComboFix.txt.

A caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop.

Post back the C:\ComboFix as well as a new HijackThis log please.
I've been using McAfee since I got this computer a year ago, and Spy Sweeper for about 2 months now.

Here is my ComboFix log

ComboFix 07-08-25.2 - "Owner" 2007-08-24 22:06:20.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.340 [GMT -6:00]
* Created a new restore point


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\Owner\APPLIC~1\FunWebProducts
C:\Program Files\Common Files\{3CF3E~1
C:\Program Files\Common Files\{DCF3E~1
C:\Program Files\internet explorer\msimg32.dll
C:\Program Files\MyWebSearch
C:\Program Files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL
C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
C:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3BKGERR.JPG
C:\Program Files\MyWebSearch\bar\3.bin\F3BROVLY.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3CJPEG.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3DTACTL.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3HISTSW.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3HTMLMU.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3HTTPCT.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3IMSTUB.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3POPSWT.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3PSSAVR.SCR
C:\Program Files\MyWebSearch\bar\3.bin\F3REPROX.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3RESTUB.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3SCHMON.EXE
C:\Program Files\MyWebSearch\bar\3.bin\F3SCRCTR.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3SHLLVW.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3SPACER.WMV
C:\Program Files\MyWebSearch\bar\3.bin\F3WALLPP.DAT
C:\Program Files\MyWebSearch\bar\3.bin\F3WPHOOK.DLL
C:\Program Files\MyWebSearch\bar\3.bin\M3FFXTBR.JAR
C:\Program Files\MyWebSearch\bar\3.bin\M3FFXTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\3.bin\M3HTML.DLL
C:\Program Files\MyWebSearch\bar\3.bin\M3IDLE.DLL
C:\Program Files\MyWebSearch\bar\3.bin\M3IMPIPE.EXE
C:\Program Files\MyWebSearch\bar\3.bin\M3MSG.DLL
C:\Program Files\MyWebSearch\bar\3.bin\M3NTSTBR.JAR
C:\Program Files\MyWebSearch\bar\3.bin\M3NTSTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\3.bin\M3OUTLCN.DLL
C:\Program Files\MyWebSearch\bar\3.bin\M3PLUGIN.DLL
C:\Program Files\MyWebSearch\bar\3.bin\M3SKIN.DLL
C:\Program Files\MyWebSearch\bar\3.bin\M3SKPLAY.EXE
C:\Program Files\MyWebSearch\bar\3.bin\M3SLSRCH.EXE
C:\Program Files\MyWebSearch\bar\3.bin\M3SRCHMN.EXE
C:\Program Files\MyWebSearch\bar\3.bin\MWSBAR.DLL
C:\Program Files\MyWebSearch\bar\3.bin\MWSOEMON.EXE
C:\Program Files\MyWebSearch\bar\3.bin\MWSOEPLG.DLL
C:\Program Files\MyWebSearch\bar\3.bin\MWSOESTB.DLL
C:\Program Files\MyWebSearch\bar\3.bin\NPMYWEBS.DLL
C:\Program Files\MyWebSearch\bar\Avatar\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\avatar.htm
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\bgfadel.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\bgfader.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\close.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\common-x.css
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\common.css
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\cornerbl.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\cornerbr.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\htmlctrl.js
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\include.js
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\index.htm
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\loading.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\login.htm
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\logo.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\max.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\min.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\noflash.htm
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\spacer.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\spacer.swf
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\unmax.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\wardrobe.htm
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\window.ico
C:\Program Files\MyWebSearch\bar\Cache667CA60
C:\Program Files\MyWebSearch\bar\CacheFAAA075
C:\Program Files\MyWebSearch\bar\Cache\1277F50E
C:\Program Files\MyWebSearch\bar\Cache\1277FBA5
C:\Program Files\MyWebSearch\bar\Cache\127802BA.bin
C:\Program Files\MyWebSearch\bar\Cache\12780431.bin
C:\Program Files\MyWebSearch\bar\Cache\127805C7.bin
C:\Program Files\MyWebSearch\bar\Cache\1278072E.bin
C:\Program Files\MyWebSearch\bar\Cache\127808A5.bin
C:\Program Files\MyWebSearch\bar\Cache\12780A2C.bin
C:\Program Files\MyWebSearch\bar\Cache\12780B93.bin
C:\Program Files\MyWebSearch\bar\Cache\12780D39.bin
C:\Program Files\MyWebSearch\bar\Cache\12780E91
C:\Program Files\MyWebSearch\bar\Cache\12780FCA.bin
C:\Program Files\MyWebSearch\bar\Cache\2928AD09.bin
C:\Program Files\MyWebSearch\bar\Cache\2928AF0D.bin
C:\Program Files\MyWebSearch\bar\Cache\2928B074.bin
C:\Program Files\MyWebSearch\bar\Cache\files.ini
C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S
C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S
C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S
C:\Program Files\MyWebSearch\bar\History\search2
C:\Program Files\MyWebSearch\bar\Message\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Notifier\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Notifier\DOG.F3S
C:\Program Files\MyWebSearch\bar\Notifier\FISH.F3S
C:\Program Files\MyWebSearch\bar\Notifier\KUNGFU.F3S
C:\Program Files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
C:\Program Files\MyWebSearch\bar\Notifier\MAID.F3S
C:\Program Files\MyWebSearch\bar\Notifier\MAILBOX.F3S
C:\Program Files\MyWebSearch\bar\Notifier\OPERA.F3S
C:\Program Files\MyWebSearch\bar\Notifier\ROBOT.F3S
C:\Program Files\MyWebSearch\bar\Notifier\SEDUCT.F3S
C:\Program Files\MyWebSearch\bar\Notifier\SURFER.F3S
C:\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
C:\Program Files\MyWebSearch\SrchAstt\3.bin\MWSSRCAS.DLL
C:\WINDOWS\system32\f3PSSavr.scr
C:\WINDOWS\system32\unsvchosts.lzma
D:\Autorun.inf


((((((((((((((((((((((((( Files Created from 2007-07-25 to 2007-08-25 )))))))))))))))))))))))))))))))


2007-08-24 22:05 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-20 22:15 d——– C:\DOCUME~1\NETWOR~1\APPLIC~1\Webroot
2007-08-06 21:55 d——– C:\Program Files\Recover My Files
2007-08-02 01:43 d——– C:\Program Files\Apple Software Update
2007-08-02 01:42 d——– C:\Program Files\Common Files\Apple
2007-08-02 01:42 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
2007-07-25 19:32 23,694 –a—— C:\WINDOWS\system32\win32k2.sys
2007-07-25 19:31 d——– C:\Program Files\MEDA MP3 Splitter
2007-07-25 19:23 d——– C:\Program Files\mp3split


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-20 21:47 ——— d——– C:\Program Files\Windows Media Connect 2
2007-08-20 21:10 ——— d——– C:\Program Files\CONEXANT
2007-08-20 20:59 ——— d——– C:\DOCUME~1\Owner\APPLIC~1\Azureus
2007-08-20 20:59 ——— d——– C:\DOCUME~1\Owner\APPLIC~1\Azureus
2007-08-20 20:51 ——— d——– C:\Program Files\Azureus
2007-08-17 02:55 ——— d——– C:\DOCUME~1\Owner\APPLIC~1\dvdcss
2007-08-17 02:55 ——— d——– C:\DOCUME~1\Owner\APPLIC~1\dvdcss
2007-08-02 01:51 ——— d——– C:\DOCUME~1\Owner\APPLIC~1\Apple Computer
2007-08-02 01:51 ——— d——– C:\DOCUME~1\Owner\APPLIC~1\Apple Computer
2007-08-02 01:50 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
2007-08-02 01:49 ——— d——– C:\Program Files\QuickTime
2007-08-01 18:17 ——— d——– C:\Program Files\Xvid
2007-08-01 18:17 ——— d——– C:\Program Files\MSN Encarta Plus
2007-08-01 18:17 ——— d——– C:\Program Files\Microsoft Works
2007-08-01 18:17 ——— d——– C:\Program Files\Microsoft Digital Image 2006
2007-08-01 18:17 ——— d——– C:\Program Files\Messenger
2007-08-01 18:17 ——— d——– C:\Program Files\FinePixViewer
2007-08-01 18:17 ——— d——– C:\Program Files\DivX
2007-07-30 19:19 92504 –a—— C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 –a—— C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 –a—— C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 –a—— C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 –a—— C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 203096 –a—— C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 –a—— C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 –a—— C:\WINDOWS\system32\wups.dll
2007-07-19 22:54 1521464 –a—— C:\WINDOWS\WRSetup.dll
2007-07-19 22:42 23864 –a—— C:\WINDOWS\system32\drivers\sskbfd.sys
2007-07-19 22:42 21816 –a—— C:\WINDOWS\system32\drivers\sshrmd.sys
2007-07-19 22:42 20280 –a—— C:\WINDOWS\system32\drivers\SSFS0BB8.sys
2007-07-19 22:42 163128 –a—— C:\WINDOWS\system32\drivers\ssidrv.sys
2007-07-08 17:49 ——— d——– C:\DOCUME~1\LOCALS~1\APPLIC~1\Webroot
2007-07-08 17:48 ——— d——– C:\Program Files\Webroot
2007-07-08 17:48 ——— d——– C:\DOCUME~1\Owner\APPLIC~1\Webroot
2007-07-08 17:48 ——— d——– C:\DOCUME~1\Owner\APPLIC~1\Webroot
2007-07-08 17:48 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Webroot
2007-07-08 16:52 2464 –a—— C:\WINDOWS\system32\tmp.reg
2007-07-07 22:55 ——— d-a—— C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-07-07 19:22 ——— d——– C:\Program Files\Common Files\AOL
2007-07-07 19:22 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
2007-07-07 10:00 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-07-05 22:15 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL Downloads
2007-07-05 00:37 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL OCP
2007-07-02 13:41 524288 –a—— C:\WINDOWS\system32\DivXsm.exe
2007-07-02 13:41 3596288 –a—— C:\WINDOWS\system32\qt-dx331.dll
2007-07-02 13:41 200704 –a—— C:\WINDOWS\system32\ssldivx.dll
2007-07-02 13:41 1044480 –a—— C:\WINDOWS\system32\libdivx.dll
2007-07-02 13:37 823296 –a—— C:\WINDOWS\system32\divx_xx0c.dll
2007-07-02 13:37 823296 –a—— C:\WINDOWS\system32\divx_xx07.dll
2007-07-02 13:37 802816 –a—— C:\WINDOWS\system32\divx_xx11.dll
2007-07-02 13:37 740442 –a—— C:\WINDOWS\system32\DivX.dll
2007-07-02 13:37 73728 –a—— C:\WINDOWS\system32\dpl100.dll
2007-07-02 13:37 593920 –a—— C:\WINDOWS\system32\dpuGUI11.dll
2007-07-02 13:37 57344 –a—— C:\WINDOWS\system32\dpv11.dll
2007-07-02 13:37 53248 –a—— C:\WINDOWS\system32\dpuGUI10.dll
2007-07-02 13:37 344064 –a—— C:\WINDOWS\system32\dpus11.dll
2007-07-02 13:37 294912 –a—— C:\WINDOWS\system32\dpu11.dll
2007-07-02 13:37 294912 –a—— C:\WINDOWS\system32\dpu10.dll
2007-07-02 13:37 196608 –a—— C:\WINDOWS\system32\dtu100.dll
2007-07-02 13:36 124472 –a—— C:\WINDOWS\system32\DivXCodecUpdateChecker.exe
2007-07-02 13:36 12288 –a—— C:\WINDOWS\system32\DivXWMPExtType.dll
2007-06-27 15:08 ——— d——– C:\Program Files\MTV Networks
2007-06-27 14:12 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
2007-06-27 14:10 ——— d——– C:\Program Files\Image-Line
2007-06-27 14:06 ——— d——– C:\Program Files\MySpace
2007-06-26 01:45 ——— d——– C:\Program Files\Common Files\ComponentOne
2007-06-26 00:08 1104896 –a—— C:\WINDOWS\system32\msxml3.dll
2007-06-19 07:31 282112 –a—— C:\WINDOWS\system32\gdi32.dll
2007-06-13 04:23 1033216 –a—— C:\WINDOWS\explorer.exe
2007-01-11 04:53:30 88 –sh–r C:\WINDOWS\system32\EAFF06A1F9.sys
2007-01-11 04:53:49 2,672 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"readericon"="C:\Program Files\Digital Media Reader\readericon45G.exe" [2005-12-09 19:44]
"RTHDCPL"="RTHDCPL.EXE" [2006-04-17 01:34 C:\WINDOWS\RTHDCPL.exe]
"CHotkey"="zHotkey.exe" [2004-12-08 18:57 C:\WINDOWS\zHotkey.exe]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 17:16]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 19:18]
"VirusScan Online"="C:\Program Files\McAfee.com\VSO\mcvsshld.exe" [2005-08-10 13:49]
"OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [2005-08-11 23:02]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 19:29]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 13:05]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 17:40]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2005-03-23 17:26]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-04 23:32]
"My Web Search Bar Search Scope Monitor"="C:\PROGRA~1\MYWEBS~1\bar\3.bin\m3SrchMn.exe" []
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2006-03-21 19:30]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-07-19 22:54]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" []
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-10-09 12:28]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 13:00]
"Performance Center"="C:\Program Files\Ascentive\Performance Center\APCMain.exe" []
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-03-27 15:22]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

R0 SSFS0BB8;Spy Sweeper File System Filer Driver: 0BB8;C:\WINDOWS\system32\Drivers\SSFS0BB8.SYS
R2 RMSvc;Media Center Extender Resource Monitor;C:\WINDOWS\ehome\RMSvc.exe
R3 Point32;Microsoft IntelliPoint Filter Driver;C:\WINDOWS\system32\DRIVERS\point32.sys
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;C:\WINDOWS\system32\DRIVERS\ManyCam.sys
S3 MR97310_USB_DUAL_CAMERA;CIF Dual-Mode Camera;C:\WINDOWS\system32\DRIVERS\mr97310c.sys
S3 QWAVE;QWAVE service;C:\WINDOWS\system32\svchost.exe -k QWAVE
S3 QWAVEDRV;QWAVE driver;C:\WINDOWS\system32\DRIVERS\qwavedrv.sys
S3 xusb21;Xbox 360 Wireless Receiver Driver Service 21;C:\WINDOWS\system32\DRIVERS\xusb21.sys

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
QWAVE QWAVE


Contents of the 'Scheduled Tasks' folder
2007-08-23 04:08:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-24 22:11:07
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-24 22:14:00 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-08-24 22:14

— E O F —
New HJT log

Logfile of HijackThis v1.99.1
Scan saved at 10:19:01 PM, on 8/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\ehome\RMSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\zHotkey.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\QuickTime\QTTask.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\ehome\RMSysTry.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Hijackthis\HijackThis.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\Search\YSearchSuggest.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: My &Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\3.bin\MWSBAR.DLL (file missing)
O4 - HKLM\..\Run: [readericon] "C:\Program Files\Digital Media Reader\readericon45G.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [MSKDetectorExe] "C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" /uninstall
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "C:\Program Files\McAfee.com\VSO\mcvsshld.exe"
O4 - HKLM\..\Run: [OASClnt] "C:\Program Files\McAfee.com\VSO\oasclnt.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [REGSHAVE] "C:\Program Files\REGSHAVE\REGSHAVE.EXE" /AUTORUN
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\3.bin\m3SrchMn.exe" /m=0
O4 - HKLM\..\Run: [CanonMyPrinter] "C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" /logon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Performance Center] C:\Program Files\Ascentive\Performance Center\APCMain.exe -m
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Startup: Delta AutoLoad.lnk = C:\Documents and Settings\Owner\Desktop\PSX\Delta\delta.exe
O4 - Global Startup: Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…html?p=ZNfox000
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab55762.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab55579.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab55668.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab55708.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab55200.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{AB8470E5-C154-4CF3-8C2C-2BFCD6DF6CD6}: NameServer = 68.87.85.98,68.87.69.146
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Still looking like more software conflict than infection if this last removal of much of the MYWebSearch junk didn't help. Let's clean and check to see if perhaps IAC included some of it's Freeze garbage that might be causing issues there. Be sure to disable SpySweeper and McAfee when completing these steps (only for the time steps are being done though).



Close Internet Explorer and all running programs and run a scan in HijackThis. Place a check next to all of the following lines, then select “Fix Checked” and close HijackThis.

O3 - Toolbar: My &Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\3.bin\MWSBAR.DLL (file missing)
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\3.bin\m3SrchMn.exe" /m=0
O4 - HKCU\..\Run: [Power2GoExpress] NA
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…html?p=ZNfox000



Go Here and download ATF cleaner. Click on the downloaded file to run it, and select "Select All", then click Empty Selected (and close ATF).

If you have them, also click on Firefox/Opera at the top and repeat the steps (and close ATF). Firefox/Opera will need to be closed first for the cleaning to be effective.


Then go here for an online AV scan (requires IE to run).

Scan "Local Disks" and when finished save the scan log and then post the log here.


Also Open Hijackthis.
Click Config - Misc Tools - Open Uninstall Manager.
A list of the entries in Add/Remove programs will appear.
Click on Save List…
The list will be saved as 'Uninstall_list.txt'
Copy & Paste the contents back here for review.
I can't get that scan to work for some reason. Every time I try to click on local disks it just says error on page. HJT Uninstall List Adobe Flash Player 9 ActiveX Adobe Reader 7.0 Apple Mobile Device Support Apple Software Update ATI Display Driver Azureus Canon iP1700 Canon iP1700 User Registration Canon My Printer Canon Utilities Easy-PhotoPrint CIF Dual-Mode Camera Comcast High-Speed Internet Install Wizard Cooktop 2.5 Desktop Doctor Digital Media Reader DivX Codec DivX Content Uploader DivX Converter DivX Player DivX Web Player DVD Decrypter (Remove Only) DVD Shrink 3.2 DVD Solution FinePixViewer Ver.4.3 FL Studio 6 FUJIFILM USB Driver Google Toolbar for Firefox High Definition Audio Driver Package - KB888111 Hijackthis 1.99.1 HijackThis 1.99.1 Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 10 (KB903157) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB888795) Hotfix for Windows XP (KB891593) Hotfix for Windows XP (KB895961) Hotfix for Windows XP (KB896256) Hotfix for Windows XP (KB899337) Hotfix for Windows XP (KB899510) Hotfix for Windows XP (KB902841) Hotfix for Windows XP (KB906569) Hotfix for Windows XP (KB909095) Hotfix for Windows XP (KB910728) Hotfix for Windows XP (KB912024) Hotfix for Windows XP (KB914440) Hotfix for Windows XP (KB914906) Hotfix for Windows XP (KB915865) Hotfix for Windows XP (KB926239) Hotfix for Windows XP (KB935448) IrfanView (remove only) J2SE Runtime Environment 5.0 Update 2 Macromedia Extension Manager Macromedia Flash 8 Macromedia Flash 8 Video Encoder Macromedia Flash Player 8 Macromedia Flash Player 8 Plugin McAfee SecurityCenter McAfee VirusScan MEDA MP3 Splitter 2.0.1 Media Center Extender Media Center Extender Microsoft .NET Framework 1.0 Hotfix (KB887998) Microsoft .NET Framework 1.0 Hotfix (KB930494) Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Digital Image Starter Edition 2006 Microsoft Internationalized Domain Names Mitigation APIs Microsoft Kernel-Mode Driver Framework Feature Pack 1.1 Microsoft Money 2006 Microsoft National Language Support Downlevel APIs Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Works mIRC Mozilla Firefox (2.0.0.2) Mozilla Firefox (2.0.0.6) MP3 Splitter MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 6.0 Parser (KB933579) Multimedia Keyboard Driver My Web Search (Smiley Central) Napster Burn Engine Nero 7 Panda ActiveScan Performance Center Power2Go 4.0 PowerDVD Project64 1.6 QuickTime RealPlayer REALTEK GbE & FE Ethernet PCI NIC Driver Realtek High Definition Audio Driver Recover My Files Scientific-Atlanta WebSTAR 2000 series Cable Modem Security Update for Microsoft .NET Framework 2.0 (KB928365) Security Update for Windows Internet Explorer 7 (KB928090) Security Update for Windows Internet Explorer 7 (KB929969) Security Update for Windows Internet Explorer 7 (KB931768) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896688) Security Update for Windows XP (KB899589) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB905915) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB908531) Security Update for Windows XP (KB911280) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912812) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913433) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB916281) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917537) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB922760) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925454) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB938829) Soft Data Fax Modem with SmartCP Sonic Encoders Sonic RecordNow! Spy Sweeper Update for Windows Media Player 10 (KB910393) Update for Windows Media Player 10 (KB913800) Update for Windows Media Player 10 (KB926251) Update for Windows XP (KB900485) Update for Windows XP (KB904942) Update for Windows XP (KB910437) Update for Windows XP (KB912945) Update for Windows XP (KB916595) Update for Windows XP (KB927891) Update for Windows XP (KB929338) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB933360) Update for Windows XP (KB936357) Update for Windows XP (KB938828) Update Rollup 2 for Windows XP Media Center Edition 2005 URGE VideoLAN VLC media player 0.8.6b Viewpoint Media Player Virtual Earth 3D (Beta) Winamp (remove only) Windows Driver Package - Camera Maker (MR97310_USB_DUAL_CAMERA) Image 05/02/2006 2.0.1.0 Windows Imaging Component Windows Internet Explorer 7 Windows Live Messenger Windows Media Encoder 9 Series Windows Media Encoder 9 Series Windows Media Format 11 runtime Windows Media Format 11 runtime Windows Media Player 11 Windows Media Player 11 Windows XP Media Center Edition 2005 KB905589 Windows XP Media Center Edition 2005 KB925766 WinRAR archiver WinZip Xvid 1.1.2 final uninstall Yahoo! Browser Services Yahoo! Browser Services Yahoo! IE Search Suggest Yahoo! Install Manager Yahoo! Internet Mail Yahoo! Messenger Yahoo! Toolbar
Very likely either McAfee or SpySweeper blocking Panda from accessing local drives - you will need to disable those to allow the scan to run, then re-enable after. With SpySweeper disabled do you experience positive changes?


For the installed items, one I do not recognize and a few to change here. Go to Start – Settings – Control Panel. Click on Add/Remove Programs. If any of the following programs are listed there, click on the program to highlight it, and click on Remove. Then close the Control Panel.

Viewpoint Media Player (usually installed without the owner's knowledge and not essential for any use I am aware of)
J2SE Runtime Environment 5.0 Update 2


Then reboot. When you have done that, go here and download and install the latest version of Sun Java (Java Runtime Environment (JRE) 6 Update 2). The current file name for that is jre-6u2-windows-i586-p.exe.

———————————————

Open Hijackthis.
Click Config - Misc Tools - Open Uninstall Manager again.
A list of the entries in Add/Remove programs will appear.

Click to hilight My Web Search (Smiley Central) then click "Delete this entry". The uninstaller and files have already been deleted, so just the entry remains. Also while there click to hilight URGE, then to the right check the Uninstall command entry, and copy/paste that file path information back here please. if you recognize and know this as a trusted software instead just let me know.

Then try the Panda scan again with all security software disabled.
URGE came with Windows Media Player 11. I don't really want it though. Here is the path. MsiExec.exe /I{8BBF6DFD-0AD9-43A7-9FBD-BF065E3866AF} I got Pandascan to work. I had one of the IE Add ons for it disabled for some reason. Here is the log. Incident Status Location Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\z5k50ngd.default\cookies.txt[.trafficmp.com/] Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\z5k50ngd.default\cookies.txt[.doubleclick.net/] Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\z5k50ngd.default\cookies.txt[.trafficmp.com/] Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\z5k50ngd.default\cookies.txt[.realmedia.com/] Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\z5k50ngd.default\cookies.txt[.advertising.com/] Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\z5k50ngd.default\cookies.txt[.2o7.net/] Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\z5k50ngd.default\cookies.txt[.mediaplex.com/] Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\z5k50ngd.default\cookies.txt[.atdmt.com/] Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\z5k50ngd.default\cookies.txt[.atwola.com/] Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\z5k50ngd.default\cookies.txt[.tribalfusion.com/] Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\z5k50ngd.default\cookies.txt[.fastclick.net/] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\z5k50ngd.default\cookies.txt[ad.yieldmanager.com/] Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\z5k50ngd.default\cookies.txt[.serving-sys.com/] Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\z5k50ngd.default\cookies.txt[.bs.serving-sys.com/] Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\z5k50ngd.default\cookies.txt[.adrevolver.com/] Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\z5k50ngd.default\cookies.txt[.casalemedia.com/] Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\Owner\My Documents\ComboFix.exe[nircmd.exe] Virus:Generic Malware Disinfected C:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MSN Messenger\msimg32.dll Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MSN Messenger\riched20.dll Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\Internet Explorer\msimg32.dll.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\F3BROVLY.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\F3CJPEG.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\F3DTACTL.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\F3HISTSW.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\F3HTMLMU.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\F3HTTPCT.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\F3IMSTUB.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\F3POPSWT.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\F3PSSAVR.SCR.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\F3REPROX.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\F3RESTUB.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\F3SCHMON.EXE.vir Potentially unwanted tool:Application/FunWeb Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\F3SCRCTR.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\F3SHLLVW.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\F3WPHOOK.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\M3FFXTBR.JAR.vir[contents.rdf] Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\M3FFXTBR.JAR.vir[menu.xul] Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\M3FFXTBR.JAR.vir[toolbarembed.html] Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\M3FFXTBR.MANIFEST.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\M3HTML.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\M3IDLE.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\M3IMPIPE.EXE.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\M3MSG.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\M3OUTLCN.DLL.vir Virus:Generic Malware Disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\M3PLUGIN.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\M3SKIN.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\M3SKPLAY.EXE.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\M3SLSRCH.EXE.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\M3SRCHMN.EXE.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\MWSBAR.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\MWSOEMON.EXE.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\MWSOEPLG.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\MWSOESTB.DLL.vir Virus:Generic Malware Disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\3.bin\NPMYWEBS.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\Game\CHESS.F3S.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\Game\REVERSI.F3S.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\Program Files\MyWebSearch\SrchAstt\3.bin\MWSSRCAS.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\QooBox\Quarantine\C\WINDOWS\system32\f3PSSavr.scr.vir Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\WINDOWS\nircmd.exe
Looks good - harmless cookies, some tools we sued you can delete now and some MyWebSearch hangers-on to delete. How is the system running at this point?


Locate and delete the tools we used - here is a partial list, though you would know where most are located:

C:\Documents and Settings\Owner\My Documents\ComboFix.exe
C:\WINDOWS\nircmd.exe
ComboFix.exe and the ComboFix logs

C:\QooBox <– folder


Make sure you can View Hidden Files. Also uncheck "Hide Extensions for Known File Types"

Then close any open programs and open HijackThis, and choose None of the above, just start the program. Click Config – Misc Tools - Delete File on Reboot. Navigate to each of the following files, double-click on each, say No to reboot until the last file, say Yes and allow it to reboot.

C:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll
C:\Program Files\MSN Messenger\msimg32.dll
C:\Program Files\MSN Messenger\riched20.dll
Everything seems to be running smoother. And I do notice a change when I'm not using Webroot SS. Cds are playing smoother now. And I just opened a bunch of programs while a cd was playing and I didn't crash. I just noticed that cds play fine when I use winamp, but when I use WMP it's choppy. It is way better than it was before though.
Panda didn't really locate much that would impact WMP use, though one file removed by ComboFix is not normally a solo file like it shows here. Let's take a different look yet.


Go here and download the free version of SUPERAntiSpyware and install it.

After installation accept any prompts to allow SUPERAntiSpyware to install the latest infection definition files. Next follow the prompts to complete the installation. For now, uncheck the option to have SUPERAntiSpyware "Automatically check for program and definition updates". Providing an email address and allowing the software to send diagnostic reports to it's research center are up to you. Do NOT allow SUPERAntiSpyware to Protect your Home Page settings.

Once the installation is complete open SUPERAntiSpyware and press the Preferences button. Under the General and Startup tab, uncheck the following (leaving all other settings as is).

Start-up Options:
*Start SUPERAntiSpyware when Windows starts

Automatic Updates:
*Check for program updates when the application starts.
Start-up Scanning:
*Check for updates before scanning on startup.

Then select Close. Don't scan just yet though.


===============================================


Reboot into Safe Mode (at startup tap the F8 key and select Safe Mode).


Open SUPERAntiSpyware and click the Scan your Computer button. Making sure that Fixed Drive (NTFS) is checked (typically the C Drive), check "Perform Complete Scan", then click Next. SUPERAntiSpyware will now complete a system scan.


SUPERAntiSpyware will now scan your computer and when its finished it will list all the infections it has found. Make sure that they all have a check next to them and click next. If prompted allow the reboot (or manually reboot at this time), and after the reboot open SUPERAntiSpyware again (double click the bug-shaped Taskbar icon).

Click Preferences, then under the Statistics/Logs tab, click to select the most recent Scan Log, then click View Log. Save the log to your desktop, and copy/paste the text from the log back here.
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 09/08/2007 at 08:19 PM

Application Version : 3.9.1008

Core Rules Database Version : 3259
Trace Rules Database Version: 1270

Scan type : Complete Scan
Total Scan Time : 01:22:20

Memory items scanned : 171
Memory threats detected : 0
Registry items scanned : 6262
Registry threats detected : 115
File items scanned : 32646
File threats detected : 3

Adware.MyWebSearch
HKLM\Software\Classes\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D}
HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}
HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}
HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}\InprocServer32
HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}\InprocServer32#ThreadingModel
HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}\Programmable
C:\PROGRAM FILES\MYWEBSEARCH\SRCHASTT\3.BIN\MWSSRCAS.DLL
HKLM\Software\Classes\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\InprocServer32
HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\InprocServer32#ThreadingModel
C:\PROGRAM FILES\MYWEBSEARCH\BAR\3.BIN\MWSBAR.DLL

Adware.Zango Toolbar/Hb
HKLM\Software\Classes\CLSID\{5CBE2611-C31B-401F-89BC-4CBB25E853D7}
HKCR\CLSID\{5CBE2611-C31B-401F-89BC-4CBB25E853D7}
HKCR\CLSID\{5CBE2611-C31B-401F-89BC-4CBB25E853D7}
HKCR\CLSID\{5CBE2611-C31B-401F-89BC-4CBB25E853D7}\InprocServer32
HKCR\CLSID\{5CBE2611-C31B-401F-89BC-4CBB25E853D7}\InprocServer32#ThreadingModel
HKCR\CLSID\{5CBE2611-C31B-401F-89BC-4CBB25E853D7}\ProgID
HKCR\CLSID\{5CBE2611-C31B-401F-89BC-4CBB25E853D7}\Programmable
HKCR\CLSID\{5CBE2611-C31B-401F-89BC-4CBB25E853D7}\TypeLib
HKCR\CLSID\{5CBE2611-C31B-401F-89BC-4CBB25E853D7}\VersionIndependentProgID
C:\PROGRAM FILES\SEEKMOTOOLBAR\BIN\4.8.4.0\SKHOSTIE.DLL
HKCR\CLSID\{37E5D130-E81C-43E5-A2AD-9C155467F334}
HKCR\CLSID\{37E5D130-E81C-43E5-A2AD-9C155467F334}\InprocServer32
HKCR\CLSID\{37E5D130-E81C-43E5-A2AD-9C155467F334}\InprocServer32#ThreadingModel
HKCR\CLSID\{37E5D130-E81C-43E5-A2AD-9C155467F334}\ProgID
HKCR\CLSID\{37E5D130-E81C-43E5-A2AD-9C155467F334}\TypeLib
HKCR\CLSID\{37E5D130-E81C-43E5-A2AD-9C155467F334}\VersionIndependentProgID
HKCR\CLSID\{7585AF6A-6D68-4896-A1A1-F23AA8FCF9F1}
HKCR\CLSID\{7585AF6A-6D68-4896-A1A1-F23AA8FCF9F1}#AppID
HKCR\CLSID\{7585AF6A-6D68-4896-A1A1-F23AA8FCF9F1}\Control
HKCR\CLSID\{7585AF6A-6D68-4896-A1A1-F23AA8FCF9F1}\Implemented Categories
HKCR\CLSID\{7585AF6A-6D68-4896-A1A1-F23AA8FCF9F1}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
HKCR\CLSID\{7585AF6A-6D68-4896-A1A1-F23AA8FCF9F1}\InprocServer32
HKCR\CLSID\{7585AF6A-6D68-4896-A1A1-F23AA8FCF9F1}\InprocServer32#ThreadingModel
HKCR\CLSID\{7585AF6A-6D68-4896-A1A1-F23AA8FCF9F1}\MiscStatus
HKCR\CLSID\{7585AF6A-6D68-4896-A1A1-F23AA8FCF9F1}\MiscStatus\1
HKCR\CLSID\{7585AF6A-6D68-4896-A1A1-F23AA8FCF9F1}\ProgID
HKCR\CLSID\{7585AF6A-6D68-4896-A1A1-F23AA8FCF9F1}\Programmable
HKCR\CLSID\{7585AF6A-6D68-4896-A1A1-F23AA8FCF9F1}\ToolboxBitmap32
HKCR\CLSID\{7585AF6A-6D68-4896-A1A1-F23AA8FCF9F1}\TypeLib
HKCR\CLSID\{7585AF6A-6D68-4896-A1A1-F23AA8FCF9F1}\Version
HKCR\CLSID\{7585AF6A-6D68-4896-A1A1-F23AA8FCF9F1}\VersionIndependentProgID
HKCR\CLSID\{CF1A5756-F372-463E-BC20-1D3D58F4B9AF}
HKCR\CLSID\{CF1A5756-F372-463E-BC20-1D3D58F4B9AF}\LocalServer32
HKCR\CLSID\{CF1A5756-F372-463E-BC20-1D3D58F4B9AF}\ProgID
HKCR\CLSID\{CF1A5756-F372-463E-BC20-1D3D58F4B9AF}\Programmable
HKCR\CLSID\{CF1A5756-F372-463E-BC20-1D3D58F4B9AF}\TypeLib
HKCR\CLSID\{CF1A5756-F372-463E-BC20-1D3D58F4B9AF}\VersionIndependentProgID
HKCR\TypeLib\{049B9813-C417-4A47-A893-604FAD16B251}
HKCR\TypeLib\{049B9813-C417-4A47-A893-604FAD16B251}\1.0
HKCR\TypeLib\{049B9813-C417-4A47-A893-604FAD16B251}\1.0
HKCR\TypeLib\{049B9813-C417-4A47-A893-604FAD16B251}\1.0\win32
HKCR\TypeLib\{049B9813-C417-4A47-A893-604FAD16B251}\1.0\FLAGS
HKCR\TypeLib\{049B9813-C417-4A47-A893-604FAD16B251}\1.0\HELPDIR
HKCR\TypeLib\{DC92EE2E-DF2D-4A80-A48B-17377C81CFC2}
HKCR\TypeLib\{DC92EE2E-DF2D-4A80-A48B-17377C81CFC2}\1.0
HKCR\TypeLib\{DC92EE2E-DF2D-4A80-A48B-17377C81CFC2}\1.0
HKCR\TypeLib\{DC92EE2E-DF2D-4A80-A48B-17377C81CFC2}\1.0\win32
HKCR\TypeLib\{DC92EE2E-DF2D-4A80-A48B-17377C81CFC2}\1.0\FLAGS
HKCR\TypeLib\{DC92EE2E-DF2D-4A80-A48B-17377C81CFC2}\1.0\HELPDIR
HKCR\Interface\{30022029-2C17-4A99-87D2-A382C674A19D}
HKCR\Interface\{30022029-2C17-4A99-87D2-A382C674A19D}\ProxyStubClsid
HKCR\Interface\{30022029-2C17-4A99-87D2-A382C674A19D}\ProxyStubClsid32
HKCR\Interface\{30022029-2C17-4A99-87D2-A382C674A19D}\TypeLib
HKCR\Interface\{30022029-2C17-4A99-87D2-A382C674A19D}\TypeLib#Version
HKCR\Interface\{3A6691EA-C844-46F2-9237-1386A85CE119}
HKCR\Interface\{3A6691EA-C844-46F2-9237-1386A85CE119}\ProxyStubClsid
HKCR\Interface\{3A6691EA-C844-46F2-9237-1386A85CE119}\ProxyStubClsid32
HKCR\Interface\{3A6691EA-C844-46F2-9237-1386A85CE119}\TypeLib
HKCR\Interface\{3A6691EA-C844-46F2-9237-1386A85CE119}\TypeLib#Version
HKCR\Interface\{3D2E7662-85FB-4CC1-875C-A624B1AA5D96}
HKCR\Interface\{3D2E7662-85FB-4CC1-875C-A624B1AA5D96}\ProxyStubClsid
HKCR\Interface\{3D2E7662-85FB-4CC1-875C-A624B1AA5D96}\ProxyStubClsid32
HKCR\Interface\{3D2E7662-85FB-4CC1-875C-A624B1AA5D96}\TypeLib
HKCR\Interface\{3D2E7662-85FB-4CC1-875C-A624B1AA5D96}\TypeLib#Version
HKCR\Interface\{72FEEB09-BB27-46D3-A06D-930D4D544227}
HKCR\Interface\{72FEEB09-BB27-46D3-A06D-930D4D544227}\ProxyStubClsid
HKCR\Interface\{72FEEB09-BB27-46D3-A06D-930D4D544227}\ProxyStubClsid32
HKCR\Interface\{72FEEB09-BB27-46D3-A06D-930D4D544227}\TypeLib
HKCR\Interface\{72FEEB09-BB27-46D3-A06D-930D4D544227}\TypeLib#Version
HKCR\Interface\{736918FE-2349-4230-BA9A-1F23649E32AD}
HKCR\Interface\{736918FE-2349-4230-BA9A-1F23649E32AD}\ProxyStubClsid
HKCR\Interface\{736918FE-2349-4230-BA9A-1F23649E32AD}\ProxyStubClsid32
HKCR\Interface\{736918FE-2349-4230-BA9A-1F23649E32AD}\TypeLib
HKCR\Interface\{736918FE-2349-4230-BA9A-1F23649E32AD}\TypeLib#Version
HKCR\Interface\{89D36231-6BD9-4E20-BBA0-FD28C3A83C40}
HKCR\Interface\{89D36231-6BD9-4E20-BBA0-FD28C3A83C40}\ProxyStubClsid
HKCR\Interface\{89D36231-6BD9-4E20-BBA0-FD28C3A83C40}\ProxyStubClsid32
HKCR\Interface\{89D36231-6BD9-4E20-BBA0-FD28C3A83C40}\TypeLib
HKCR\Interface\{89D36231-6BD9-4E20-BBA0-FD28C3A83C40}\TypeLib#Version
HKCR\Interface\{A53762B6-30F7-469F-BA92-13D63CF09A93}
HKCR\Interface\{A53762B6-30F7-469F-BA92-13D63CF09A93}\ProxyStubClsid
HKCR\Interface\{A53762B6-30F7-469F-BA92-13D63CF09A93}\ProxyStubClsid32
HKCR\Interface\{A53762B6-30F7-469F-BA92-13D63CF09A93}\TypeLib
HKCR\Interface\{A53762B6-30F7-469F-BA92-13D63CF09A93}\TypeLib#Version
HKCR\Interface\{B24FF4F6-D327-4208-8840-68CCEF7D6125}
HKCR\Interface\{B24FF4F6-D327-4208-8840-68CCEF7D6125}\ProxyStubClsid
HKCR\Interface\{B24FF4F6-D327-4208-8840-68CCEF7D6125}\ProxyStubClsid32
HKCR\Interface\{B24FF4F6-D327-4208-8840-68CCEF7D6125}\TypeLib
HKCR\Interface\{B24FF4F6-D327-4208-8840-68CCEF7D6125}\TypeLib#Version
HKCR\Interface\{BD31DF26-7178-41F4-88DD-F16B82D827CA}
HKCR\Interface\{BD31DF26-7178-41F4-88DD-F16B82D827CA}\ProxyStubClsid
HKCR\Interface\{BD31DF26-7178-41F4-88DD-F16B82D827CA}\ProxyStubClsid32
HKCR\Interface\{BD31DF26-7178-41F4-88DD-F16B82D827CA}\TypeLib
HKCR\Interface\{BD31DF26-7178-41F4-88DD-F16B82D827CA}\TypeLib#Version
HKCR\Interface\{E977DE7C-34EA-4876-B333-207C4504589E}
HKCR\Interface\{E977DE7C-34EA-4876-B333-207C4504589E}\ProxyStubClsid
HKCR\Interface\{E977DE7C-34EA-4876-B333-207C4504589E}\ProxyStubClsid32
HKCR\Interface\{E977DE7C-34EA-4876-B333-207C4504589E}\TypeLib
HKCR\Interface\{E977DE7C-34EA-4876-B333-207C4504589E}\TypeLib#Version
HKCR\Interface\{F5FC30C3-68AD-451B-8BC1-8ABD98F2C69A}
HKCR\Interface\{F5FC30C3-68AD-451B-8BC1-8ABD98F2C69A}\ProxyStubClsid
HKCR\Interface\{F5FC30C3-68AD-451B-8BC1-8ABD98F2C69A}\ProxyStubClsid32
HKCR\Interface\{F5FC30C3-68AD-451B-8BC1-8ABD98F2C69A}\TypeLib
HKCR\Interface\{F5FC30C3-68AD-451B-8BC1-8ABD98F2C69A}\TypeLib#Version
HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\{0EBACAF2-E0F9-47A9-98CF-0ECCE30B654C}
Looks to have located and removed more MyWeb, but also some Zango toolbar activity. Hard to determine if these were more remnants than active, though the Zango reg info and files look like it was still functional. Improvements after that?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI