Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
Hi Help.
My daughters computer keeps coming up ith the error message 'error loading C:\PROGRA~1\MYWEBS~1\BAR\4.BIN\WMSBAR.DLL' wot does this mean when i try to add an address it say that it can not load the address.If any one can help me I would be very gratefull. Thank you.
Roberta

double check you don't mean MWSBAR.DLL
If you do, then read through that...
http://www.free-web-browsers.com/su...
...and then download, install and update an anti spyware program. The free SUPERAntispyware will do you.

Thanks for your help yes I did have it wrong sorry tried wot you said thank you I removed the MY WEB programs except 1 MY WEB SEARCH (ZWINKY) when I try it comes up with the same error message as before with 'the system cannot find the file specified'.Then when I try to connect to a web page it comes up 'Internet Explorer Could Not Open the Search Page'. Please help if you can.
Thank You again
Roberta

Ok, no big deal.
I'm assuming you downloaded, installed and updated SUPERAntiSpyware - and then used it? :)
If yes, download, install, update and run Spybot S&D 1.5.1
If it's still there after that, then run both of them in safe mode
Get back after that and if it's still there we'll have to remove it manually using HijackThis (download the executable just in case)

Hi
I can not download the SUPERAntiSpyware as I can not get on the internet do to the error message ' Internet Explorer Could Not Open the Seach Page'
Thank you for all your help as you can tell I know nothing about computers and my daughter is driving me mad??!!Kind Regards
Roberta

Then you need to use a different web browser. (I thought you were already using one)
So from the machine you are using download Firefox and either burn it to a disk or transfer the Firefox file to a usb memory stick or something. Then fire it up from your machine.
You will be struggling to do anything without some tools, unfortunately.
And tell your daughter if she didn't download and install crap on the machine she wouldn't be in this mess. :)

Again thank you for your help will try that when I get home. Keep telling her not to is there any way that I can put I stop on so she can not download except tie her hands together!!!!
Again Thank You
Kind regards
Roberta

Sorry, Forgot to ask also after i have downloaded the firefox can i then get rid of this MY WEB SPACE and try again with my old web browser?
Thanks
Roberta

"Again thank you for your help will try that when I get home. Keep telling her not to is there any way that I can put I stop on so she can not download except tie her hands together!!!!"
Not really, and not really on Windows ME. To be honest education is the best policy with kids which always involves trial and error.This should teach her a lesson and make her think twice about downloading things she doesn't need. Just spell it out to her that if she doesn't need something, then don't download it.
She'll also get the message when you tell her you can't afford to pay someone to come round every time she screws up and downloads junk.
Give her your best stern-faced stare as part of the delivery. :p

"Sorry, Forgot to ask also after i have downloaded the firefox can i then get rid of this MY WEB SPACE and try again with my old web browser?"
You are using Firefox as a backup browser to download the tools above to get yourself clean.After you've cleaned up you will then be able to use Internet Explorer as normal.
But I suggest you both get used to Firefox and use that in future. As it's secure and regularly updated.

Hi
I have downloaded firefox but it is now saying server not found have checked all connections cannot se a problem and my laptop is working ok on wireless???? help againKind Regards
Roberta

Then you more than likely have a larger infection problem unfortunately.
You need to get HijackThis on the infected computer and run it.
You then need to post the log file that HijackThis produces on here so I can look at it.
I can give you directions after that.
All you have to do is get a clean machine or laptop, or go round to a friends who has internet access, and you need to burn to a disk the programs listed on this thread.You then need to install those programs from the CD disk to the infected machine and install them and run them.
But without either a) running the cleaning programs or b) running HijackThis on the infected machine and coming back with a log file, we are really struggling.

Ok will do that now on my laptop I really appreciate all your help How do I get HijacThs on my computer???

As above. You need to get to a machine that has internet access and you need to download HijackThis from the link I gave in post #3.
You then need to get the HijackThis file from the 'clean machine' to the 'infected machine'.
Normally the easiest way would be to use a burning program (like Nero) to burn the file to a blank CD.
Then pop the CD into the infected machine's CD drive and open the file up by double clicking on it (through Windows Explorer).
But if you are able to do this then download all the programs I have listed above.
Report back if you don't understand any of that.

We are talking about the HijackThis log file that looks like a big long list of numbers and gobbledygook - right??
It's a text file (.txt) right??
If so, either burn the text file or copy and paste the information into wordpad / notepad save it and burn it (or transfer it the same method you did before).
Then post the gobbledygook here.

well here goes hope this works??///
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:20:56, on 23/01/2008
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: NormalRunning processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.exe
C:\WINDOWS\SYSTEM\SPOOL32.exe
C:\WINDOWS\SYSTEM\MPREXE.exe
C:\WINDOWS\SYSTEM\MSTASK.exe
C:\WINDOWS\SYSTEM\STIMON.exe
C:\WINDOWS\SYSTEM\LEXBCES.exe
C:\WINDOWS\SYSTEM\RPCSS.exe
C:\WINDOWS\SYSTEM\LEXPPS.exe
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\RESTORE\STMGR.exe
C:\WINDOWS\EXPLORER.exe
C:\PROGRAM FILES\THOMSON\SPEEDTOUCH USB\DRAGDIAG.exe
C:\WINDOWS\LOADQM.exe
C:\PROGRAM FILES\MSN APPS\UPDATER\01.03.0000.1005\EN-US\MSNAPPAU.exe
C:\WINDOWS\SYSTEM\E_S5I0B1.exe
C:\WINDOWS\SYSTEM\SYSTRAY.exe
C:\PROGRAM FILES\EPSON\EPSON CARDMONITOR\EPSON CARDMONITOR1.2.exe
C:\WINDOWS\SYSTEM\WMIEXE.exe
C:\PROGRAM FILES\TREND MICRO\HIJACKTHIS\HIJACKTHIS.exe
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.exe
C:\PROGRAM FILES\SUPERANTISPYWARE\SUPERANTISPYWARE.exe
C:\PROGRAM FILES\TREND MICRO\HIJACKTHIS\HIJACKTHIS.exe
C:\PROGRAM FILES\TREND MICRO\HIJACKTHIS\HIJACKTHIS.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.wanadoo.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Wanadoo
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\PROGRAM FILES\MYWEBSEARCH\SRCHASTT\4.BIN\MWSSRCAS.DLL (file missing)
R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\PROGRAM FILES\ASKTBAR\SRCHASTT\1.BIN\A5SRCHAS.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: CSObj Class - {CD209A08-98B5-4669-AF9F-447AC5253356} - C:\WINDOWS\SYSTEM\CSAPP.DLL
O2 - BHO: CATLEvents Object - {60112085-E1CE-4e0e-823A-EBB1AD98804C} - C:\WINDOWS\TEMP\XAFBK.DAT
O2 - BHO: CATLEvents Object - {3EC8E271-FAB9-418a-8A8E-65AEB4029E64} - C:\WINDOWS\TEMP\XAFBK.DAT
O2 - BHO: CATLEvents Object - {8109AF33-6949-4833-8881-43DCC232B7B2} - C:\WINDOWS\TEMP\XAFBK.DAT
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.5000.1021\EN-US\MSNTB.DLL (file missing)
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\PROGRAM FILES\MSN APPS\ST\01.03.0000.1005\EN-XU\STMAIN.DLL
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\PROGRAM FILES\EPSON\EPSON WEB-TO-PAGE\EPSON WEB-TO-PAGE.DLL
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\PROGRAM FILES\EBAY\EBAY TOOLBAR2\EBAYTB.DLL (file missing)
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\PROGRAM FILES\MYWEBSEARCH\BAR\4.BIN\MWSBAR.DLL (file missing)
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\PROGRAM FILES\MYWEBSEARCH\SRCHASTT\4.BIN\MWSSRCAS.DLL (file missing)
O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\PROGRAM FILES\ASKTBAR\BAR\1.BIN\ASKTBAR.DLL
O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\PROGRAM FILES\ASKTBAR\SRCHASTT\1.BIN\A5SRCHAS.DLL
O3 - Toolbar: Wanadoo - {8B68564D-53FD-4293-B80C-993A9F3988EE} - C:\PROGRA~1\WANADOO\WSBAR\WSBAR.DLL
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.5000.1021\EN-US\MSNTB.DLL (file missing)
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\PROGRAM FILES\EPSON\EPSON WEB-TO-PAGE\EPSON WEB-TO-PAGE.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN0\YT.DLL
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\PROGRAM FILES\EBAY\EBAY TOOLBAR2\EBAYTB.DLL (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\PROGRAM FILES\ASKTBAR\BAR\1.BIN\ASKTBAR.DLL
O4 - HKLM\..\Run: [ImInstaller] C:\WINDOWS\TEMP\ImInstaller\IncrediMail\IMLOADER.exe -product IncrediMail
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.03.0000.1005\en-us\msnappau.exe"
O4 - HKLM\..\Run: [LexStart] Lexstart.exe
O4 - HKLM\..\Run: [LexmarkPrinTray] PrinTray.exe
O4 - HKLM\..\Run: [EPSON Stylus CX3600 Series] C:\WINDOWS\SYSTEM\E_S5I0B1.exe /P26 "EPSON Stylus CX3600 Series" /O5 "LPT1:" /M "Stylus CX3600"
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.exe
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\BAR\4.BIN\MWSBAR.DLL,S
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\BAR\4.BIN\MWSOEMON.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\BAR\4.BIN\MWSOEMON.exe
O4 - HKUS\.DEFAULT\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\BAR\4.BIN\MWSOEMON.exe (User 'Default user')
O4 - .DEFAULT Startup: EPSON CARDMONITOR.LNK = C:\Program Files\epson\EPSON CardMonitor\EPSON CardMonitor1.2.exe (User 'Default user')
O4 - Startup: EPSON CARDMONITOR.LNK = C:\Program Files\epson\EPSON CardMonitor\EPSON CardMonitor1.2.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE10\EXCEL.EXE/3000
O8 - Extra context menu item: Search with Wanadoo - res://C:\PROGRA~1\WANADOO\WSBAR\WSBAR.DLL/VSearch.htm
O8 - Extra context menu item: &eBay Search - res://C:\PROGRAM FILES\EBAY\EBAY TOOLBAR2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolba...
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\MSN Messenger\MSMSGS.exe
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O12 - Plugin for .mp3: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/no...
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game02.zylom.com/activex/zyl...
O20 - Winlogon Notify: !SASWinLogon - C:\PROGRAM FILES\SUPERANTISPYWARE\SASWINLO.DLL--
End of file - 7324 bytesthanks again
Roberta

It's a mess because it's stuffed full of tool bar crap. But fortunately you can salvage it with a good old clean up.
First thing you do is go into Add and Remove programs and uninstall every toolbar - that includes Yahoo, Google, MSN, Ask etc etc etc toolbars.
I want you to also uninstall everything that is none essential. Leave only programs that are legitimate and useful (put back after if need be)
After that I want you run HijackThis again and if you can - post another log file.

Roberta,
Make a note and let me know what you uninstall and what programs you have left before you post the log. Ta.

evening Viking
I have got rid of everything I know I could not get rid of the ebay toolbarScan saved at 17:43:46, on 24/01/2008
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: NormalRunning processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.exe
C:\WINDOWS\SYSTEM\SPOOL32.exe
C:\WINDOWS\SYSTEM\MPREXE.exe
C:\WINDOWS\SYSTEM\MSTASK.exe
C:\WINDOWS\SYSTEM\STIMON.exe
C:\WINDOWS\SYSTEM\LEXBCES.exe
C:\WINDOWS\SYSTEM\RPCSS.exe
C:\WINDOWS\SYSTEM\LEXPPS.exe
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\RESTORE\STMGR.exe
C:\WINDOWS\EXPLORER.exe
C:\PROGRAM FILES\THOMSON\SPEEDTOUCH USB\DRAGDIAG.exe
C:\WINDOWS\LOADQM.exe
C:\PROGRAM FILES\MSN APPS\UPDATER\01.03.0000.1005\EN-US\MSNAPPAU.exe
C:\WINDOWS\SYSTEM\E_S5I0B1.exe
C:\WINDOWS\SYSTEM\SYSTRAY.exe
C:\PROGRAM FILES\SUPERANTISPYWARE\SUPERANTISPYWARE.exe
C:\WINDOWS\SYSTEM\WMIEXE.exe
C:\PROGRAM FILES\EPSON\EPSON CARDMONITOR\EPSON CARDMONITOR1.2.exe
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.exe
C:\PROGRAM FILES\TREND MICRO\HIJACKTHIS\HIJACKTHIS.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.wanadoo.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Wanadoo
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\PROGRAM FILES\MYWEBSEARCH\SRCHASTT\4.BIN\MWSSRCAS.DLL (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.5000.1021\EN-US\MSNTB.DLL (file missing)
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\PROGRAM FILES\MSN APPS\ST\01.03.0000.1005\EN-XU\STMAIN.DLL
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\PROGRAM FILES\EPSON\EPSON WEB-TO-PAGE\EPSON WEB-TO-PAGE.DLL
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\PROGRAM FILES\EBAY\EBAY TOOLBAR2\EBAYTB.DLL (file missing)
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\PROGRAM FILES\MYWEBSEARCH\BAR\4.BIN\MWSBAR.DLL (file missing)
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\PROGRAM FILES\MYWEBSEARCH\SRCHASTT\4.BIN\MWSSRCAS.DLL (file missing)
O3 - Toolbar: Wanadoo - {8B68564D-53FD-4293-B80C-993A9F3988EE} - C:\PROGRA~1\WANADOO\WSBAR\WSBAR.DLL (file missing)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.5000.1021\EN-US\MSNTB.DLL (file missing)
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\PROGRAM FILES\EPSON\EPSON WEB-TO-PAGE\EPSON WEB-TO-PAGE.DLL
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\PROGRAM FILES\EBAY\EBAY TOOLBAR2\EBAYTB.DLL (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ImInstaller] C:\WINDOWS\TEMP\ImInstaller\IncrediMail\IMLOADER.exe -product IncrediMail
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.03.0000.1005\en-us\msnappau.exe"
O4 - HKLM\..\Run: [LexStart] Lexstart.exe
O4 - HKLM\..\Run: [LexmarkPrinTray] PrinTray.exe
O4 - HKLM\..\Run: [EPSON Stylus CX3600 Series] C:\WINDOWS\SYSTEM\E_S5I0B1.exe /P26 "EPSON Stylus CX3600 Series" /O5 "LPT1:" /M "Stylus CX3600"
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.exe
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\BAR\4.BIN\MWSBAR.DLL,S
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\BAR\4.BIN\MWSOEMON.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\BAR\4.BIN\MWSOEMON.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\PROGRAM FILES\SUPERANTISPYWARE\SUPERANTISPYWARE.exe
O4 - HKUS\.DEFAULT\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\BAR\4.BIN\MWSOEMON.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [SUPERAntiSpyware] C:\PROGRAM FILES\SUPERANTISPYWARE\SUPERANTISPYWARE.exe (User 'Default user')
O4 - .DEFAULT Startup: EPSON CARDMONITOR.LNK = C:\Program Files\epson\EPSON CardMonitor\EPSON CardMonitor1.2.exe (User 'Default user')
O4 - Startup: EPSON CARDMONITOR.LNK = C:\Program Files\epson\EPSON CardMonitor\EPSON CardMonitor1.2.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE10\EXCEL.EXE/3000
O8 - Extra context menu item: Search with Wanadoo - res://C:\PROGRA~1\WANADOO\WSBAR\WSBAR.DLL/VSearch.htm
O8 - Extra context menu item: &eBay Search - res://C:\PROGRAM FILES\EBAY\EBAY TOOLBAR2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolba...
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O12 - Plugin for .mp3: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/no...
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game02.zylom.com/activex/zyl...
O20 - Winlogon Notify: !SASWinLogon - C:\PROGRAM FILES\SUPERANTISPYWARE\SASWINLO.DLL--
End of file - 6320 bytes
hope this is betaroberta

Open up HijackThis and put a tick next to all these entries, take your time, no rush.
When you've got them all ticked off, go down to the bottom of HijackThis and press the Fix Checked button and have HJT remove the entries.
Reboot (shut down - start back up) the machine afterwards and I want you try Internet Explorer web browser and see if you can connect to Google.co.uk.
Then make it your homepage.
Then run HijackThis another time and post the log file.
=========================================
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.wanadoo.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Wanadoo
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\PROGRAM FILES\MYWEBSEARCH\SRCHASTT\4.BIN\MWSSRCAS.DLL (file missing)
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.5000.1021\EN-US\MSNTB.DLL (file missing)
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\PROGRAM FILES\MSN APPS\ST\01.03.0000.1005\EN-XU\STMAIN.DLL
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\PROGRAM FILES\EPSON\EPSON WEB-TO-PAGE\EPSON WEB-TO-PAGE.DLL
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\PROGRAM FILES\MYWEBSEARCH\BAR\4.BIN\MWSBAR.DLL (file missing)
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\PROGRAM FILES\MYWEBSEARCH\SRCHASTT\4.BIN\MWSSRCAS.DLL (file missing)
O3 - Toolbar: Wanadoo - {8B68564D-53FD-4293-B80C-993A9F3988EE} - C:\PROGRA~1\WANADOO\WSBAR\WSBAR.DLL (file missing)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.5000.1021\EN-US\MSNTB.DLL (file missing)
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\PROGRAM FILES\EPSON\EPSON WEB-TO-PAGE\EPSON WEB-TO-PAGE.DLL
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\BAR\4.BIN\MWSBAR.DLL,S
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\BAR\4.BIN\MWSOEMON.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\BAR\4.BIN\MWSOEMON.exe
O4 - HKUS\.DEFAULT\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\BAR\4.BIN\MWSOEMON.exe (User 'Default user')
O8 - Extra context menu item: Search with Wanadoo - res://C:\PROGRA~1\WANADOO\WSBAR\WSBAR.DLL/VSearch.htm
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolba...
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/no...O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game02.zylom.com/activex/zyl...

internet explorer can not open the page can not find server
here is the highjack log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:59:38, on 24/01/2008
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: NormalRunning processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.exe
C:\WINDOWS\SYSTEM\SPOOL32.exe
C:\WINDOWS\SYSTEM\MPREXE.exe
C:\WINDOWS\SYSTEM\MSTASK.exe
C:\WINDOWS\SYSTEM\STIMON.exe
C:\WINDOWS\SYSTEM\LEXBCES.exe
C:\WINDOWS\SYSTEM\RPCSS.exe
C:\WINDOWS\SYSTEM\LEXPPS.exe
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.exe
C:\WINDOWS\SYSTEM\RESTORE\STMGR.exe
C:\WINDOWS\LOADQM.exe
C:\PROGRAM FILES\MSN APPS\UPDATER\01.03.0000.1005\EN-US\MSNAPPAU.exe
C:\WINDOWS\SYSTEM\E_S5I0B1.exe
C:\WINDOWS\SYSTEM\SYSTRAY.exe
C:\PROGRAM FILES\SUPERANTISPYWARE\SUPERANTISPYWARE.exe
C:\WINDOWS\SYSTEM\WMIEXE.exe
C:\PROGRAM FILES\TREND MICRO\HIJACKTHIS\HIJACKTHIS.exe
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.wanadoo.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Wanadoo
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\PROGRAM FILES\MYWEBSEARCH\SRCHASTT\4.BIN\MWSSRCAS.DLL (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.5000.1021\EN-US\MSNTB.DLL (file missing)
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\PROGRAM FILES\MSN APPS\ST\01.03.0000.1005\EN-XU\STMAIN.DLL
O4 - HKLM\..\Run: [ImInstaller] C:\WINDOWS\TEMP\ImInstaller\IncrediMail\IMLOADER.exe -product IncrediMail
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.03.0000.1005\en-us\msnappau.exe"
O4 - HKLM\..\Run: [LexStart] Lexstart.exe
O4 - HKLM\..\Run: [LexmarkPrinTray] PrinTray.exe
O4 - HKLM\..\Run: [EPSON Stylus CX3600 Series] C:\WINDOWS\SYSTEM\E_S5I0B1.exe /P26 "EPSON Stylus CX3600 Series" /O5 "LPT1:" /M "Stylus CX3600"
O4 - HKLM\..\Run: [SystemTray] SysTray.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\BAR\4.BIN\MWSOEMON.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\PROGRAM FILES\SUPERANTISPYWARE\SUPERANTISPYWARE.exe
O4 - HKUS\.DEFAULT\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\BAR\4.BIN\MWSOEMON.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [SUPERAntiSpyware] C:\PROGRAM FILES\SUPERANTISPYWARE\SUPERANTISPYWARE.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE10\EXCEL.EXE/3000
O8 - Extra context menu item: Search with Wanadoo - res://C:\PROGRA~1\WANADOO\WSBAR\WSBAR.DLL/VSearch.htm
O8 - Extra context menu item: &eBay Search - res://C:\PROGRAM FILES\EBAY\EBAY TOOLBAR2\eBayTb.dll/RCSearch.html
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O12 - Plugin for .mp3: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/no...
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game02.zylom.com/activex/zyl...
O20 - Winlogon Notify: !SASWinLogon - C:\PROGRAM FILES\SUPERANTISPYWARE\SASWINLO.DLL--
End of file - 4269 bytes

No, that's the same log. :)
You need to use HijackThis to remove all the entries I listed.
...by using the Fix Checked button

Roberta :)
What exactly are you doing when you run HijackThis?
Are you...
1) Running HijackThis on the infected machine?
2) Putting a tick (check mark in American) next to all the entries I listed?
3) then pressing the Fix Checked button
...humm?

It's just occurred to me. When you downloaded HijackThis which one did you download??
HijackThis executable
HijackThis installable
HijackThis zipAre you running HJT directly from the zip maybe?

yeah, that's the right version. but when you downloaded it off the web page, there are 3 versions (confusingly) which one did you get??
HijackThis executable
HijackThis installable
HijackThis zip

I need to know what you are doing with it to determine if it's you or if there is another problem.
So answer the questions in posts #25 #26 #28 please. :)

Describe to me what you do when you 'do' HijackThis for me.
It's on your daughter's infected machine cus I can see the log and see the crap. What happens after that.
When you open HijackThis do you open it from a folder with a zip down the middle??
Or do you just double click the icon and it comes up??
please and thank you :-D

I double click on the icon and then it comes up asking if i want to 'Do a system scan and save a logfile' which is wot i click on then it runs a file and gives me a break down in notepad. I closed that and ticked all the boxes you asked then restarted my computer and ran anoher log I hope I am not wasting your time. As i really am grateful for your help
Roberta

Cool.
You know when it says 'Do a system scan and save a logfile'?
Pick the next one down 'Do a System Scan Only'
Then tick all the boxes again and press Fix Checked immediately after.
It should then ask if you really want to permanently delete the items. Click Yes and exit the program.
Reboot the machine.

Viking hi this is the latest log hope ive done it right.
Kind Regards
Roberta
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:30:09, on 24/01/2008
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: NormalRunning processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.exe
C:\WINDOWS\SYSTEM\SPOOL32.exe
C:\WINDOWS\SYSTEM\MPREXE.exe
C:\WINDOWS\SYSTEM\MSTASK.exe
C:\WINDOWS\SYSTEM\STIMON.exe
C:\WINDOWS\SYSTEM\LEXBCES.exe
C:\WINDOWS\SYSTEM\RPCSS.exe
C:\WINDOWS\SYSTEM\LEXPPS.exe
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.exe
C:\WINDOWS\SYSTEM\RESTORE\STMGR.exe
C:\WINDOWS\LOADQM.exe
C:\PROGRAM FILES\MSN APPS\UPDATER\01.03.0000.1005\EN-US\MSNAPPAU.exe
C:\WINDOWS\SYSTEM\E_S5I0B1.exe
C:\WINDOWS\SYSTEM\SYSTRAY.exe
C:\PROGRAM FILES\SUPERANTISPYWARE\SUPERANTISPYWARE.exe
C:\WINDOWS\SYSTEM\WMIEXE.exe
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.exe
C:\PROGRAM FILES\TREND MICRO\HIJACKTHIS\HIJACKTHIS.exeO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O4 - HKLM\..\Run: [ImInstaller] C:\WINDOWS\TEMP\ImInstaller\IncrediMail\IMLOADER.exe -product IncrediMail
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.03.0000.1005\en-us\msnappau.exe"
O4 - HKLM\..\Run: [LexStart] Lexstart.exe
O4 - HKLM\..\Run: [LexmarkPrinTray] PrinTray.exe
O4 - HKLM\..\Run: [EPSON Stylus CX3600 Series] C:\WINDOWS\SYSTEM\E_S5I0B1.exe /P26 "EPSON Stylus CX3600 Series" /O5 "LPT1:" /M "Stylus CX3600"
O4 - HKLM\..\Run: [SystemTray] SysTray.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\PROGRAM FILES\SUPERANTISPYWARE\SUPERANTISPYWARE.exe
O4 - HKUS\.DEFAULT\..\Run: [SUPERAntiSpyware] C:\PROGRAM FILES\SUPERANTISPYWARE\SUPERANTISPYWARE.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE10\EXCEL.EXE/3000
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O12 - Plugin for .mp3: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll
O20 - Winlogon Notify: !SASWinLogon - C:\PROGRAM FILES\SUPERANTISPYWARE\SASWINLO.DLL--
End of file - 2466 bytes

Provided you just stuck to the ones i listed it should be good.
Ok, and can you connect to the internet? Go to google.co.uk and see if it plays ball, try setting it as a homepage if you can.

Don't want the search page, want google.co.uk.
Install Firefox on it (if you haven't already) and try that.

Roberta, if you go to Add and Remove Programs and highlight Internet Explorer 6 and hit the Remove button. There should be further options that come up, one of those is Repair Internet Explorer. Select it, and follow the repair through.

Evening Roberta.
Ok. Question time. :)
Do you have broadband or dial up ?
Do you still have Orange as your ISP?
Is your daughters machine the one that is hooked up to the internet?
Are you connecting to the internet through a laptop via a WiFi connection?
Describe your set up to me. Ta.

Hi
We have broadband, through Orange,and my daughters desktop is hooked up to the internet and the laptop is wireless.Thanks

http://www.computerhope.com/issues/...
See the above, follow the instructions to get to a command prompt. When you are there, type..
ping www.computing.net
and report back with the packets recieved and packets lost information. Or if it doesn't do anything, just say so.

Go to Start >> Programs >> Accessories >> and look for DOS command prompt. Access it from there and type the stuff again.

ME networking is pooched. I could fix it, but you couldn't, you'd end up getting bogged down. The easiest thing to do is reinstall ME and then reinstall the orange software.
The question is, do you have the ME disk and serial number to reinstall ME.
Now you could try uninstalling the orange broadband software from the machine and then reinstalling it, as an outside bet.
But that will leave you without an internet connection unless you set the laptop up.

oh well thanks for all your help anyway. is it best to take it to pc world for them to fix it and will i lose the wireless if the desk top is not pugged in to the interent?

PC World won't do anything unless you have an original Windows ME disk or the original Tiny disks. All they will do is wipe the machine and reinstall.
You can do that yourself.
Do you have the original disks that came with the machine?

That would be just spiffy :)
Yes. That's exactly what you need.
Now if you reinstall your daughters machine you are going to be without an internet connection until you set it back up (reinstall orange software) which is straight forward provided you have the orange software disk handy.
Do you have the Orange software disk?

do you mean the tiny disc?? when i last installed orange i had to do it via the internet by putting in 198.162.1.1 as the disc did not work does that mean anything to you??

You need the Tiny reinstall disk(s) and you need the Orange software disk.
If you reinstall the machine with windows ME on it using the Tiny reinstall disk - you will lose everything on the machine, including your internet connection.
Ok so far?
You know the free ISP disks that land on your door mat every few months? (like AOL disks)
You want an Orange one of those to get your internet connection back up and running.
Ok so far?
Or, would it be easier for you if I gave you my email address and you can contact me over the phone before you attempt any of this?

your number would be great i could get a disc tomorrow after work
Looking at the tiny disc i dont thnk it the right one i think i got excited for nothing it actully says tiny easy install cd and underneath it reads in small letters Entertainment Disc??? i have also found a floppy disc saying System Restore Pack Millennium Edition R1 does that mean any thing????

Tiny went bust some time ago I've forgotten what the deal is with their reinstall disk procedure, I'll have to look it up (if there's any information left).
Don't do anything for now and I'll Private Message you my email address and take it from there.
If you scroll back up and look at the left hand side you will see My Computing.Net. Go in there and you will see the Private Messages bit.
And if you can pick an Orange broadband disk up tomorrow that would be a start.

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |