Rid Me of MyWebsearch and other!!!
Original Message
Name: JustineB
Date: January 28, 2004 at 14:22:18 Pacific
Subject: Rid Me of MyWebsearch and other!!!OS: XPCPU/Ram: ?
Comment: Hello! Before I begin my question, please note that I do have AdAware and Spybot Search & Destroy, and have ran both numerous times and cannot remove "MyWebSearch"
Anyway...my main annoyance is that I am trying to help my 14 year old get this crap off her computer and it won't remove. I have gone to Add/Remove programs, and when I find "MyWebSearch" and try to remove, I get a script error. I am assuming this is intentional since it does not want to be removed for obvious reasons. I have taken a copy of my log file for Hijackthis. Please tell me which are safe to remove. There may be more than just MyWebsearch. Seems that my kid has gotten all kinds of weird toolbars and hijacked search engines things going on. I have already removed LOP.com but I don't know if the registry removed it. Also....I am assuming that mwsoemon.exe is part of MyWebSearch, so that will not let me delete it either. Please help. thank you!!
Logfile of HijackThis v1.97.7 Scan saved at 3:11:11 PM, on 1/28/2004 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe c:\Program Files\Norton AntiVirus\navapsvc.exe C:\windows\system\hpsysdrv.exe C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\PROGRA~1\NORTON~1\navapw32.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe C:\Program Files\QUICKENW\QAGENT.EXE C:\Program Files\AIM95\aim.exe C:\WINDOWS\System32\mrtMngr.EXE C:\Program Files\hp center\137903\Program\BackWeb-137903.exe C:\WINDOWS\System32\wuauclt.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Justine\Local Settings\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://server224.smartbotpro.net/7search/?hkcu R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://server224.smartbotpro.net/7search/?002 R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://server224.smartbotpro.net/7search/?003 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://default-homepage-network.com/start.cgi?hklm R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://server224.smartbotpro.net/7search/?hklm R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost R3 - Default URLSearchHook is missing O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: Popup Manager - {08E74C67-99A6-45C7-94DA-A397A8FD8082} - (no file) O2 - BHO: (no name) - {4DF1DB24-A57C-11d3-A180-00A0C90AE44B} - C:\Documents and Settings\Justine\Desktop\BPS Popup and Cookie Shield\PopupShield.dll (file missing) O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Updated.Toolbar - {9F6A22E6-1682-4F82-9B72-6314794CB253} - C:\Program Files\Pop Blocker\Updated.dll (file missing) O3 - Toolbar: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - (no file) O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe O4 - HKLM\..\Run: [NAV Agent] c:\PROGRA~1\NORTON~1\navapw32.exe O4 - HKLM\..\Run: [checktime] c:\program files\HPSelect\Frontend\ct.exe O4 - HKLM\..\Run: [WT GameChannel] C:\Program Files\WildTangent\Apps\GameChannel.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe O4 - HKLM\..\Run: [QAGENT] C:\Program Files\QUICKENW\QAGENT.EXE O4 - HKLM\..\Run: [Antivirus] C:\WINDOWS\b.exe O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl O4 - HKCU\..\Run: [Ultimate Popup Killer] C:\Program Files\Ultimate Popup Killer\Popupkiller.exe O4 - Global Startup: Date Manager.lnk = C:\Program Files\Date Manager\DateManager.exe O4 - Global Startup: hp center UI.lnk = C:\Program Files\hp center\137903\Shadow\ShadowBar.exe O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe O4 - Global Startup: KeenValue.lnk = C:\Program Files\Common Files\KeenValue\keenvalue.exe O4 - Global Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\PrecisionTime.exe O9 - Extra button: AIM (HKLM) O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: ConferenceRoom Java Client - http://glass.webmaster.com:8000/java/cr.cab O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt1_x.cab O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/potc_x.cab O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32 Class) - http://rimmel.ai-media.com/save/makeover.cab O16 - DPF: {1954A4B1-9627-4CF2-A041-58AA2045CB35} (Brix6ie Control) - http://a19.g.akamai.net/7/19/7125/1269/ftp.coupons.com/v6/brix6ie.cab O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebproducts/PopSwatterInitialSetup1.0.0.5.cab O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0309.cab O16 - DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} (Pool Control) - http://mirror.worldwinner.com/games/v44/pool/pool.cab O16 - DPF: {412F2472-59BC-4CCB-A3D4-C16A7D57CDCF} (CouponsIncIECtl Class) - http://a19.g.akamai.net/7/19/7125/1290/ftp.coupons.com/v7/brix7ie.cab O16 - DPF: {4C226336-4032-489F-9674-67E74225979B} (OTXMovie Class) - http://otx.ifilm.com/OTXMedia/OTXMedia.dll O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/178d29384ea22b5d0704/netzip/RdxIE601.cab O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab O16 - DPF: {8699D723-6DC6-47D3-B55C-489BA006B917} - http://tdmy.com/180/webinstaller.exe O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297C} - http://download.weatherbug.com/minibug/tricklers/AWS/minibuginstaller.cab?rand=200322518 O16 - DPF: {A48D0309-8DA3-41AA-98E4-89194D471890} (Pulse V5 ActiveX Control) - http://www.pulse3d.com/players/english/5.0/win/PulsePlayer5AxWin.cab O16 - DPF: {B991DA79-51F7-4011-98D2-1F2592E82A56} (ACNPlayer2 Class) - http://204.118.132.145/2_0/test/ACNePlayer.cab O16 - DPF: {C6B086D2-146B-47A4-A218-B82DCAF2D872} (cpbrxpie Control) - http://a19.g.akamai.net/7/19/7125/4007/ftp.coupons.com/r3120/cpbrxpie.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab O16 - DPF: {E6D5237D-A6C7-4C83-A67F-F9F15586FA62} (SBFullInst Control) - http://www.spyblast.com/download/SBFull.cab
Report Offensive Message For Removal
Response Number 1
Name: josh (by jpag3074 )
Date: January 28, 2004 at 14:39:18 Pacific
Subject: Rid Me of MyWebsearch and other!!!
Reply: (edit )well the reason that it keep coming up is because it is in your startup, it reinstalls on every startup, so go to your start menu, go to run, type msconfig, then go to start up and look for something around the lines of "mywebsearch" then remove the app from add/remove programs and restart
Report Offensive Follow Up For Removal
Response Number 2
Name: rick
Date: January 28, 2004 at 14:48:40 Pacific
Subject: Rid Me of MyWebsearch and other!!!
Reply: (edit )also check www.symantec.com
and
www.pchell.com
for removeale tools and instructions on many other browser hijackers.
Report Offensive Follow Up For Removal
Response Number 3
Name: JustineB
Date: January 28, 2004 at 14:56:47 Pacific
Subject: Rid Me of MyWebsearch and other!!!
Reply: (edit )Thanks guys, but isn't there someone here who can look at a logfile and tell me what to remove. Josh, I was able to remove the program from start-up, however....that program (MyWebSearch) is still under ADD/REMOVE programs and it will not uninstall it. When you go to uninstall, it asks if you want to unistall it, then you click YES and it gives a script error. To me, that means that there is no way to get this out of add/remove. I have to manually delete it somehow. Rick, that is the reason I came here and not Symantec or the other. I see people posting logfiles and they are getting help. I don't want to be told to go elsewhere. No offense. I have already checked Norton, and they don't tell you how to remove it.Thank you!!
Report Offensive Follow Up For Removal
Response Number 4
Name: josh (by jpag3074 )
Date: January 28, 2004 at 15:04:42 Pacific
Subject: Rid Me of MyWebsearch and other!!!
Reply: (edit )now that it is not in startup anymore, when you open IE is the search bar still there? if it is go to veiw, toolbars, and uncheck it, it shouldn't be startin up anymore so you should be ok in that aspect as long as it doesn't load, if i was you i would search on yahoo.com for a uninstall of that program, sometimes you can find them on sites that people had the same problem, and i know you came here to have your hijack file read, but i don't like the program, there is no need for it, i can see everything i want without it...
Report Offensive Follow Up For Removal
Response Number 5
Name: Kevin The Tech Dude
Date: January 28, 2004 at 15:29:18 Pacific
Subject: Rid Me of MyWebsearch and other!!!
Reply: (edit )The reason nobody is responding is because us folks that know how to read the log files hang out in the Security/Virus forum.
You are infected with a virus though.
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
Those are both viruses and are you sure you ran Spybot? It would have killed this line.
O4 - Global Startup: KeenValue.lnk = C:\Program Files\Common Files\KeenValue\keenvalue.exe
Did you update both Ad-Aware and Spybot before you ran them?
Even though I spent the day removing viruses off of 4 computers I will help you out.
These lines can go also...
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://server224.smartbotpro.net/7search/?hkcu R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://server224.smartbotpro.net/7search/?002 R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://server224.smartbotpro.net/7search/?003 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://default-homepage-network.com/start.cgi?hklm R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://server224.smartbotpro.net/7search/?hklm O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - Global Startup: KeenValue.lnk = C:\Program Files\Common Files\KeenValue\keenvalue.exe
I will look over it some more to see if I missed something. Visit these web sites as well.
HouseCalls Online Virus Scan and go get TDS-3 and the latest Radius File and update TDS-3 and run it.
KTTD
Report Offensive Follow Up For Removal
Response Number 6
Name: JustineB
Date: January 28, 2004 at 15:39:16 Pacific
Subject: Rid Me of MyWebsearch and other!!!
Reply: (edit )Thanks KTTD!!! I ran a full system scan with Norton anti-virus last night. I had "0" infected files as a result. How did Norton's not find this???
thanks for your help!!! I am so frustrated right now.
Justine
Report Offensive Follow Up For Removal
Response Number 7
Name: Kevin The Tech Dude
Date: January 28, 2004 at 15:48:08 Pacific
Subject: Rid Me of MyWebsearch and other!!!
Reply: (edit )Once the scans are done, repost a fresh log file and I'll take another look. Make sure you killed the junk though I told ya was bad.
NAV should have picked up the files though if you have the latest DAT files.
KTTD
Report Offensive Follow Up For Removal
Response Number 8
Name: JustineB
Date: January 28, 2004 at 16:21:24 Pacific
Subject: Rid Me of MyWebsearch and other!!!
Reply: (edit )Hi again, here is a fresh log after I did what you asked. Don't forget I want to get rid of MyWebSearch stuff too. But I didn't remove any of that, I only did what you told me to. Is the virus still there too?
I hope I don't sound like a complete idiot. I am pretty savvy when it comes to most computer stuff, but this spyware stuff is getting to be worse, and I didn't really keep up with prevention and all that till now.
Logfile of HijackThis v1.97.7 Scan saved at 5:18:35 PM, on 1/28/2004 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\windows\system\hpsysdrv.exe C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\PROGRA~1\NORTON~1\navapw32.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\QUICKENW\QAGENT.EXE C:\Program Files\AIM95\aim.exe C:\WINDOWS\System32\mrtMngr.EXE c:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\hp center\137903\Program\BackWeb-137903.exe C:\WINDOWS\System32\wuauclt.exe C:\Program Files\Outlook Express\msimn.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Justine\Local Settings\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost R3 - Default URLSearchHook is missing O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: Popup Manager - {08E74C67-99A6-45C7-94DA-A397A8FD8082} - (no file) O2 - BHO: (no name) - {4DF1DB24-A57C-11d3-A180-00A0C90AE44B} - C:\Documents and Settings\Justine\Desktop\BPS Popup and Cookie Shield\PopupShield.dll (file missing) O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Updated.Toolbar - {9F6A22E6-1682-4F82-9B72-6314794CB253} - C:\Program Files\Pop Blocker\Updated.dll (file missing) O3 - Toolbar: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - (no file) O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe O4 - HKLM\..\Run: [NAV Agent] c:\PROGRA~1\NORTON~1\navapw32.exe O4 - HKLM\..\Run: [checktime] c:\program files\HPSelect\Frontend\ct.exe O4 - HKLM\..\Run: [WT GameChannel] C:\Program Files\WildTangent\Apps\GameChannel.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [QAGENT] C:\Program Files\QUICKENW\QAGENT.EXE O4 - HKLM\..\Run: [Antivirus] C:\WINDOWS\b.exe O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl O4 - HKCU\..\Run: [Ultimate Popup Killer] C:\Program Files\Ultimate Popup Killer\Popupkiller.exe O4 - Global Startup: Date Manager.lnk = C:\Program Files\Date Manager\DateManager.exe O4 - Global Startup: hp center UI.lnk = C:\Program Files\hp center\137903\Shadow\ShadowBar.exe O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe O4 - Global Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\PrecisionTime.exe O9 - Extra button: AIM (HKLM) O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: ConferenceRoom Java Client - http://glass.webmaster.com:8000/java/cr.cab O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt1_x.cab O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/potc_x.cab O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32 Class) - http://rimmel.ai-media.com/save/makeover.cab O16 - DPF: {1954A4B1-9627-4CF2-A041-58AA2045CB35} (Brix6ie Control) - http://a19.g.akamai.net/7/19/7125/1269/ftp.coupons.com/v6/brix6ie.cab O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebproducts/PopSwatterInitialSetup1.0.0.5.cab O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0309.cab O16 - DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} (Pool Control) - http://mirror.worldwinner.com/games/v44/pool/pool.cab O16 - DPF: {412F2472-59BC-4CCB-A3D4-C16A7D57CDCF} (CouponsIncIECtl Class) - http://a19.g.akamai.net/7/19/7125/1290/ftp.coupons.com/v7/brix7ie.cab O16 - DPF: {4C226336-4032-489F-9674-67E74225979B} (OTXMovie Class) - http://otx.ifilm.com/OTXMedia/OTXMedia.dll O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/178d29384ea22b5d0704/netzip/RdxIE601.cab O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab O16 - DPF: {8699D723-6DC6-47D3-B55C-489BA006B917} - http://tdmy.com/180/webinstaller.exe O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297C} - http://download.weatherbug.com/minibug/tricklers/AWS/minibuginstaller.cab?rand=200322518 O16 - DPF: {A48D0309-8DA3-41AA-98E4-89194D471890} (Pulse V5 ActiveX Control) - http://www.pulse3d.com/players/english/5.0/win/PulsePlayer5AxWin.cab O16 - DPF: {B991DA79-51F7-4011-98D2-1F2592E82A56} (ACNPlayer2 Class) - http://204.118.132.145/2_0/test/ACNePlayer.cab O16 - DPF: {C6B086D2-146B-47A4-A218-B82DCAF2D872} (cpbrxpie Control) - http://a19.g.akamai.net/7/19/7125/4007/ftp.coupons.com/r3120/cpbrxpie.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab O16 - DPF: {E6D5237D-A6C7-4C83-A67F-F9F15586FA62} (SBFullInst Control) - http://www.spyblast.com/download/SBFull.cab
Report Offensive Follow Up For Removal
Response Number 9
Name: Kevin The Tech Dude
Date: January 28, 2004 at 16:38:11 Pacific
Subject: Rid Me of MyWebsearch and other!!!
Reply: (edit )Well this one I am still torn over..
C:\WINDOWS\System32\wuauclt.exe
While it can be a legit file I do not trust it myself and would remove it but then again I am not infront of the computer. This one as too stands out like a sore thumb.
C:\WINDOWS\system32\dla\tfswctrl.exe
You might have to restart the computer in safe mode to get rid of the "dla" folder and problems as well.
Keep me posted
KTTD
P.S. Just remember you are 2hrs behind me :)
Report Offensive Follow Up For Removal
Response Number 10
Name: capt
Date: January 28, 2004 at 17:06:51 Pacific
Subject: Rid Me of MyWebsearch and other!!!
Reply: (edit )KTTD has caught the major problems. I would get rid of some thing listed in 016, especially "weatherbug" in 016 and some of the others, but you must decide on them. Go to http://wilders.org/ and get Spybot/Adaware/Spywareblaster Be sure to update all of these programs right after you install them. With Spybot when you see that a download is available click the mirror to the right of download button at the top of the page and select Australia as the mirror to get the download. Make sure you use Spybots immuninize feature and select the silent feature and lock homepage too. I did not see "my websearch" in your log. Have you emptied your temp internet files and off line content recently?
Report Offensive Follow Up For Removal
Response Number 11
Name: Abnormal
Date: January 28, 2004 at 17:19:08 Pacific
Subject: Rid Me of MyWebsearch and other!!!
Reply: (edit )Need a hand Kevin? This takes me forever, but I can help on this one. And hi capt, every 016 I listed is blocked by spywareblaster.
Put a check mark nex to these, click "fix checked" then reboot.
R3 - Default URLSearchHook is missing O2 - BHO: Popup Manager - {08E74C67-99A6-45C7-94DA-A397A8FD8082} - (no file) O3 - Toolbar: Updated.Toolbar - {9F6A22E6-1682-4F82-9B72-6314794CB253} - C:\Program Files\Pop Blocker\Updated.dll (file missing) O3 - Toolbar: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - (no file) O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe O4 - HKLM\..\Run: [Antivirus] C:\WINDOWS\b.exe O4 - Global Startup: Date Manager.lnk = C:\Program Files\Date Manager\DateManager.exe O4 - Global Startup: hp center UI.lnk = C:\Program Files\hp center\137903\Shadow\ShadowBar.exe O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe O4 - Global Startup: KeenValue.lnk = C:\Program Files\Common Files\KeenValue\keenvalue.exe O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebproducts/PopSwatterInitialSetup1.0.0.5.cab O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/178d29384ea22b5d0704/netzip/RdxIE601.cab O16 - DPF: {8699D723-6DC6-47D3-B55C-489BA006B917} - http://tdmy.com/180/webinstaller.exe O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297C} - http://download.weatherbug.com/minibug/tricklers/AWS/minibuginstaller.cab?rand=200322518 O16 - DPF: {E6D5237D-A6C7-4C83-A67F-F9F15586FA62} (SBFullInst Control) - http://www.spyblast.com/download/SBFull.cab
after reboot delete: C:\WINDOWS\b.exe
Post a new log after your done, and get IE 6sp1 and all critical windows updates.
Will be back later to check on you.
a b n o r m a l
Report Offensive Follow Up For Removal
Response Number 12
Name: Abnormal
Date: January 29, 2004 at 19:13:14 Pacific
Subject: Rid Me of MyWebsearch and other!!!
Reply: (edit )O4 - HKLM\..\Run: [Antivirus] C:\WINDOWS\b.exe is a virus, not an anti-virus.
Are you having problems? Do you need more help?
TV is looking better every day.
Can't stay on this page forever...
Report Offensive Follow Up For Removal
Use following form to reply to current message: