Member Panel


Sponsors and Ads

Join the Team

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [FIXED] Joyiex.com!!!!!!!!!!!

[Fixed] Hijackthis! Logs - [FIXED] Joyiex.com!!!!!!!!!!! posted in the Security & Safety forums; Could somebody please help me get rid of this virus. I have attached a hjt doc for your perusal and please treat this as urgent. Thanks...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 09-25-2005
ladyluv's Avatar
Bronze Member
 
Join Date: Sep 2005
Posts: 5
ladyluv - See this Members User comments on their Profile page
Default [FIXED] Joyiex.com!!!!!!!!!!!

Could somebody please help me get rid of this virus. I have attached a hjt doc for your perusal and please treat this as urgent. Thanks


  #2  
Old 09-25-2005
ladygreenwitch's Avatar
Elite Member
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 4,642
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default Re: Joyiex.com!!!!!!!!!!!

:-) Hi Ladyluv,

I'll take a look, need to move this topic to the HijackThis log forum.

TTFN

T


  #3  
Old 09-25-2005
ladygreenwitch's Avatar
Elite Member
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 4,642
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default Re: Joyiex.com!!!!!!!!!!!

:-D OK LadyLuv,

Crisis management engaged.

I am going to need you to do a few things for me starting with downloading the some programs.

I would like you to download CCleaner, Spy Sweeper, Adaware SE, Spybot S&D, ewido, and RegSupremePro from my signature. Please install them, and update Spy Sweeper, Adaware, ewido, and Spybot.

Next please make sure all files and folders are showing, in Windows Explorer, click on Tools, Folder Options, View, Show all Hidden Files and Folders.

Then disable your System Restore, right click on My Computer, click on Properties. Click on the System Restore tab and put a check in disable System Restore. Answer Yes to any warnings.
Then, please run the Housecall link in my signature, it is an online virus scanner, let it fix everything that it finds.

Now I would like you to install and run Housecall from my signature, it is an online virus scanner, let it fix whatever it finds.

OK, now that that is done, please boot into Safe Mode, tap the F8 key while booting and choose Safe Mode from the menu. Open CCleaner, make sure that all options are checked, including Advanced, answer Yes to any warnings. Click on Analyze and let it run, when it has finished, click on Run Cleaner. Once that has finished, close CCleaner.

Now run a full scan with both Adaware SE, Spybot S&D, and ewido in that order. Quarantine everything that Adaware finds. Fix everything in red, that Spybot finds. Have ewido fix each of the things it finds in turn, but make sure to read them, ewido occassionally comes up with false positives. If you are unsure, answer? none? for action to be taken, it will show up in the log. When ewido has finished, click save log, I will need you to post it back here when you are done.

Next run HijackThis!, choosing the top option of saving a log. Put a check next to the following items and click on Fix. Then delete the items in bold if they are still in your computer.

C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =? http://www.joyiex.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL? = http://www.joyiex.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =? http://www.joyiex.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =? http://www.joyiex.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =? http://www.joyiex.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL =? http://www.joyiex.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =? http://www.joyiex.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title =? Microsoft Internet Explorer provided by Compaq
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D}? - C:\Program Files\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} -? C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL
O4 - HKLM\..\Run: [MyWebSearch Email Plugin]C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXEO4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearc...S_ZUxdm082YYUS
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache...FunBuddyIconsF WBInitialSetup1.0.0.8-2.cab

I would then ask that you run CCleaner again, letting it clean everything that it finds.

Boot into Normal Mode, run RegSupremePro, it will want to create a back up of your registry, let it. When it is finished, click on Registry Cleaner and select Agressive, let it run. When it is finished, click on Select, choose All, click on Fix. Close RegSupremePro.

Run HJT one more time, posting the new log back here.

We will be looking for your reply,

TTFN

T


  #4  
Old 09-25-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default Re: Joyiex.com!!!!!!!!!!!



Also add this entry to the fix list:

O4 - HKCU\..\Run: [ctfnom.exe] C:\WINDOWS\OSRSS.exe

and after fixing , delete the file in bold.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #5  
Old 09-25-2005
ladyluv's Avatar
Bronze Member
 
Join Date: Sep 2005
Posts: 5
ladyluv - See this Members User comments on their Profile page
Default Re: Joyiex.com!!!!!!!!!!!

Thanks
I am working on it currently and will give you a feed back and soon as I am done. I really appreciate the help.


  #6  
Old 09-25-2005
ladygreenwitch's Avatar
Elite Member
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 4,642
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default Re: Joyiex.com!!!!!!!!!!!

:-D No problem, that's what we're here for.

Looking forward to your reply,

TTFN

T



Reply
New! Norton Internet Security 2008 – Download Now Click Here

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


All times are GMT +1. The time now is 12:54 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top