:-D OK LadyLuv,
Crisis management engaged.
I am going to need you to do a few things for me starting with downloading the some programs.
I would like you to download
CCleaner,
Spy Sweeper,
Adaware SE,
Spybot S&D,
ewido, and
RegSupremePro from my signature. Please install them, and update Spy Sweeper, Adaware, ewido, and Spybot.
Next please make sure all files and folders are showing, in Windows Explorer, click on Tools, Folder Options, View, Show all Hidden Files and Folders.
Then disable your
System Restore, right click on My Computer, click on Properties. Click on the System Restore tab and put a check in disable System Restore. Answer Yes to any warnings.
Then, please run the Housecall link in my signature, it is an online virus scanner, let it fix everything that it finds.
Now I would like you to install and run
Housecall from my signature, it is an online virus scanner, let it fix whatever it finds.
OK, now that that is done, please boot into Safe Mode, tap the F8 key while booting and choose Safe Mode from the menu. Open CCleaner, make sure that all options are checked, including Advanced, answer Yes to any warnings. Click on Analyze and let it run, when it has finished, click on Run Cleaner. Once that has finished, close CCleaner.
Now run a full scan with both Adaware SE, Spybot S&D, and ewido in that order. Quarantine everything that Adaware finds. Fix everything in
red, that Spybot finds. Have ewido fix each of the things it finds in turn, but make sure to read them, ewido occassionally comes up with false positives. If you are unsure, answer? none? for action to be taken, it will show up in the log. When ewido has finished, click save log, I will need you to post it back here when you are done.
Next run HijackThis!, choosing the top option of saving a log. Put a check next to the following items and click on Fix. Then delete the items in bold if they are still in your computer.
C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =?
http://www.joyiex.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL? =
http://www.joyiex.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =?
http://www.joyiex.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =?
http://www.joyiex.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =?
http://www.joyiex.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL =?
http://www.joyiex.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =?
http://www.joyiex.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title =? Microsoft Internet Explorer provided by Compaq
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D}? - C:\Program Files\MyWebSearch\SrchAstt\
2.bin\
MWSSRCAS.DLL
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\
MyWebSearch\SrchAstt\
2.bin\
MWSSRCAS.DLL
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} -? C:\Program Files\
MyWebSearch\bar\
2.bin\
MWSBAR.DLL
O4 - HKLM\..\Run: [MyWebSearch Email Plugin]C:\PROGRA~1\
MYWEBS~1\bar\2.bin\mwsoemon.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\
MYWEBS~1\bar\2.bin\mwsoemon.exe
O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\
MyWebSearch\bar\2.bin\MWSOEMON.EXEO4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\
MyWebSearch\bar\2.bin\MWSOEMON.EXE
O8 - Extra context menu item: &Search -
http://bar.mywebsearch.com/menusearc...S_ZUxdm082YYUS
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
http://ak.imgfarm.com/images/nocache...FunBuddyIconsF WBInitialSetup1.0.0.8-2.cab
I would then ask that you run CCleaner again, letting it clean everything that it finds.
Boot into Normal Mode, run RegSupremePro, it will want to create a back up of your registry, let it. When it is finished, click on Registry Cleaner and select Agressive, let it run. When it is finished, click on Select, choose All, click on Fix. Close RegSupremePro.
Run
HJT one more time, posting the new log back here.
We will be looking for your reply,
TTFN
T