Good to speak with you again! :-)) Thanks for this. Going to try the hijackthis stuff now, and kick off the scans. It's almost midnight here in London, so will continue in the morning (gotta sleep sometime!). I brought the client's PC home, as I usually do, else it's like watching paint dry and looking at their walls. At least this way I can do other things and watch TV!
Also with prospect of another client visit in the afteroon who reports spyware-related problems and their AOL (yuk) won't work! With your help I am becoming better at all this. Thanks. I'll report on progress tomorrow.
Main Topics
Browse All Topics





by: SheharyaarSaahilPosted on 2004-07-07 at 15:44:25ID: 11497290
Hello gerlis =)
ternet Explorer\Main,Search Bar = file://C:\WINDOWS\System32 \SearchBar .htm 00C04FD644 97} - (no file) 29649C8011 1D} - (no file) 32\wsaupda ter.exe, 0000000022 1} - C:\Program Files\ClearSearch\CSIE.DLL (file missing) A4827C2E4C 8} - C:\WINDOWS\nem219.dll (file missing) D56626C6C4 2} - C:\WINDOWS\twaintec.dll 838F569A31 D} - C:\Program Files\MyWebSearch\SrchAstt \2.bin\MWS SRCAS.DLL 86FA05C83A B} - C:\Program Files\SysAI\plg0\AproposPl ugin.dll 84B7D6BE0B 3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEH elper.ocx 70DE4475CC A} - C:\Program Files\MyWebSearch\bar\2.bi n\MWSBAR.D LL 9649C80111 D} - C:\PROGRA~1\INCRED~1\BHO\I NCFIN~2.DL L 28AE5AB496 6} - C:\WINDOWS\System32\SWin32 .dll 0E04C60FAF 2} - C:\WINDOWS\2_0_1browserhel per2.dll 176083F35C F} - C:\WINDOWS\System32\bridge .dll 00A16B6CF9 4} - C:\Program Files\SEP\sep.dll 20FAF53D84 1} - C:\Program Files\Common Files\midaddle\midaddle.dl l 70DE4475CC A} - C:\Program Files\MyWebSearch\bar\2.bi n\MWSBAR.D LL 00A16B6CF9 4} - C:\Program Files\SEP\sep.dll .bin\mwsoe mon.exe .exe k.exe e.exe" svc.exe ve.exe e.dll",Loa d .exe e n\MWSOEMON .EXE n\MWSOEMON .EXE /menusearc h.html?p=Z Szeb029 0104B242EA 3} - http://install.wildtangent .com/bgn/p artners/sh ockwave/ po larbowler/ install.ca b ========== ========== ========== ========== ========== =========
========== ========== ========== ownload/dl adaware.sh tml ownload/dl spybot.htm l program/co olwebshred der.html h2k/toolba rcop.htm nger ========== ========== ==========
R1 - HKCU\Software\Microsoft\In
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-
R3 - URLSearchHook: (no name) - _{4FC95EDD-4796-4966-9049-
F2 - REG:system.ini: UserInit=C:\Windows\System
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: (no name) - {00000000-0000-0000-0000-0
O2 - BHO: (no name) - {00000010-6F7D-442C-93E3-4
O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-D
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5
O2 - BHO: (no name) - {01C5BF6C-E699-4CD7-BEA1-7
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-1
O2 - BHO: NavErrRedir Class - {4FC95EDD-4796-4966-9049-2
O2 - BHO: (no name) - {5FA6752A-C4A0-4222-88C2-9
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-0
O2 - BHO: (no name) - {9C691A33-7DDA-4C2F-BE4C-C
O2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-5
O2 - BHO: WinPage Affiliate - {E8EAEB34-F7B5-4C55-87FF-7
O3 - Toolbar: My &Web Search - {07B18EA9-A523-4961-B6BB-1
O3 - Toolbar: Band Class - {C5183ABC-EB6E-4E05-B8C9-5
O4 - HKLM\..\Run: [updater] C:\Program Files\Common files\updater\wupdater.exe
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2
O4 - HKLM\..\Run: [yN2] C:\documents and settings\steve\local settings\temp\yN2.exe
O4 - HKLM\..\Run: [2LRX2W83X2T3MQ] C:\WINDOWS\System32\Jhng4O
O4 - HKLM\..\Run: [qrqwfx] C:\WINDOWS\System32\ycllau
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdat
O4 - HKLM\..\Run: [Pcsv] C:\WINDOWS\system32\pcs\pc
O4 - HKLM\..\Run: [Dpi] C:\Program Files\Common Files\Dpi\dpi.exe
O4 - HKLM\..\Run: [updmgr] C:\Program Files\Common files\updmgr\updmgr.exe
O4 - HKLM\..\Run: [Adstartup] C:\WINDOWS\System32\automo
O4 - HKLM\..\Run: [rFni3qW] fasrov.exe
O4 - HKLM\..\Run: [wmplayer] C:\Program Files\Windows Media Player\wmplayer.exe -invisible
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\System32\bridg
O4 - HKLM\..\Run: [Windows SA] C:\Program Files\WindowsSA\omniscient
O4 - HKLM\..\Run: [DCT] C:\WINDOWS\System32\DCT.ex
O4 - HKCU\..\Run: [ao4sRka6S] fdemlr.exe
O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\2.bi
O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\2.bi
O4 - Global Startup: updater.lnk = ?
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com
O16 - DPF: {FA13A9FA-CA9B-11D2-9780-0
==========================
Turn off ur system restore, and Fix the above entries,,,,,, then Download these tools and install them:
==========================
AdAware ==> http://www.webattack.com/d
SpyBot ==> http://www.snapfiles.com/d
CoolWebShredder ==> http://www.spychecker.com/
ToolBar Cop >> http://www.mvps.org/srames
Stinger >> http://vil.nai.com/vil/sti
==========================
After that Follow these Instructions:
1. First turn Off ur System Restore
2. Boot into safemode and Login as Administrator
3. Run the AntiVirus tool and delete all viruses it found
4. Run the Spyware Removal tools(atleast three of them) and delete everything they detect
5. Then goto C:\Documents and Settings\ur usernmae\Local Settings\Temp and delete all files present here
6. Goto C:\Documents and Settings\ur usernmae\Local Settings\Temporary Internet Files, and delete the folder of ContentIE
7. Goto C:\Documents and Settings\ur usernmae\Cookies, and delete all cookies present here.
8. Reboot back in Normal Mode and check if problems are gone
9. If YES then Great, otherwise run the Hijakcthis scan, and post the LOG file here
10. After making sure that every junk stuff is deleted, and System is Clean, Turn On the System Restore again !!!
!! GOOD LUCK !!