I unchecked all bars(toolbar and statusbar), just visit a site from favorite link, the problem is still there, unfortunately. what can I do? :-(
Thank you anyway!
Main Topics
Browse All Topicsmy OS: WindowsXP professional(SP2). When I start IE6, and visit a website(any website, even http://127.0.0.1/), a dir named 8848 will be created under c:\program files,the whole path is:C:\Program Files\8848\MySearch\0.9.6.
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Open ‘Add/Remove Programs’ in the Control Panel. Select the ‘My Search Bar’ (MySearch variant), ‘MyWay Speed Bar’ (MyWay) or ‘My Web Search Bar’ (MyWeb) entry and click ‘Remove’. For the MyWeb variant, be sure to also remove ‘Fun Web Products Easy Installer’.
For more information - http://www.doxdesk.com/par
You could start by downloading Hijackthis from http://hijackthis.de/downl
Look at the results and do whatever is suggested to deal with dangerous entries
>>MySearch is a search bar<<
MySearch is spyware. Kill it with Microsoft AntiSpyware...it's free.
Microsoft AntiSpyware
http://www.microsoft.com/d
I've had pretty good luck removing Adware/Spyware/etc with a combination of Ad-Aware and Spybot-Search & Destroy. What one doesn't get, the other usually does...
http://www.lavasoftusa.com
http://www.safer-networkin
Of course, MySearch is a spyware. Remove it immediately.
See the instructions to remove it manually here :
http://www.scanspyware.net
http://www.spywareremove.c
You have to manually kill the dropper of that spyware.
The droppers hide in the _restore folder and even though shutting off xp system restore is suppose to delete
the restore points...the spyware alters Windows so the restore points remain.
The _restore folder in Windows XP is behind a double protected hidden area of Windows XP.
Open a Windows Explorer and in the menu
Tools
Folder Options
View(tab)
uncheck "Hide protected operating system files (Recommended)"
put a check on "Show hidden files and folders"
click OK
Now to access the C:\System Volume Information folder you two-click it if your Windows XP was installed
selecting FAT32 as the file system format. If your Windows XP was installed selecting NTFS file system
format then there are more steps to be able to two-click, and access, the C:\System Volume Information
folder...these steps for NTFS are...
Start
Run...
type cmd hit enter
type cd\ hit enter
type
cacls "c:\system volume information" /E /G username:F
(username= your actual username you log on to XP with)
hit enter
...you can now two-click and access that folder via Windows Explorer and inside there is a folder named _restore*****.
***** = a bunch of numbers and letters, two-click that folder and you'll see a bunch of folders named RP*, delete
them all...and all files in there as well. When your done deleting all the files and folders in there (the actual restore points)
you MUST re-enable the permissions you shut off. You type the command...
cacls "c:\system volume information" /E /R username
...to turn it back on.
In Windows Explorer delete contents of
C:\Documents and Settings\{username}\Local Settings\Temporary Internet Files
C:\Documents and Settings\{username}\Local Settings\Temp
C:\Windows\Temp (if exists)
Once this is done you reboot back into "Safe Mode with Networking" and then run Microsoft AntiSpyware
hi, spiderfix,
I tried what you said, there are 2 files in <System Volume Information> folder:MountPointManagerRe
I deleted them, and reboot into "Safe Mode with Networking", run MS AntiSpyware, found no spyware, and then run IE6, visit a website, the folder 8848\MySearch appears again.
Go to Panda online scanner, it doesn't kill spyware but it will show the path to the files.
http://www.pandasoftware.c
("Scan your PC" button)
I should have added...Shut off XP System Restore...
right-click My Computer
click Properties
click the System Restore(tab)
select "Turn off System Restore" or "Turn off System Restore on all drives"
click Apply
you'll get a popup warning about restore points being deleted and system restore being turned off
click Yes
...to kill this stuff the basic idea is you sit in "Safe Mode with Networking" throwing everything but the Sun
at it until AntiSpyware, Panda, and HJT tell you it's gone as well as a triple check the "system volume information"
folder and the cache are clear.
Don't forget every username on the computer has it's own cache folders.
MySearch must still be residing in your Registry, you'll need to remove it from there do the following;
first backup your registry and then remove the following Registry entries
Open the registry (click ‘Start’, choose ‘Run’, enter ‘regedit’) and open the key HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ {014DA6C1-189F-421a-88CD-0
HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ {014DA6C9-189F-421a-88CD-0
HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID\ {0494D0D1-F8E0-41ad-92A3-1
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Browser Helper Objects \ {014DA6C1-189F-421a-88CD-0
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Browser Helper Objects \ {014DA6C9-189F-421a-88CD-0
'HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Browser Helper Objects \ {0494D0D1-F8E0-41ad-92A3-1
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Uninstall \ My Search Uninstall \ DisplayName'
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Uninstall \ My Way Speedbar Uninstall \ DisplayName
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Uninstall \ MyWaySearchAssistant \ DisplayName
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Internet Explorer \ Toolbar\{014DA6C9-189F-421
HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Internet Explorer \ Toolbar \ WebBrowser\{014DA6C9-189F-
Hmmmmm... dump IE ;)
If spyware removal tools/tips don't work, neither do other things like BHO (http://www.definitivesolu
Boot in to safe mode without networking and run Adaware and Spybot with latest defs and then run hijack this. Save the log and post it. I have run into some spyware where you have to deny rights to a folder(to stop processes from running at startup) and reboot then take ownership of the folder and delete it and the programs registry entires.
I boot into safe mode without network, run MS AntiSpyware, no spyware found. run Hijackthis and get log below:
hijackthis.log
--------------------------
Logfile of HijackThis v1.99.1
Scan saved at 11:15, on 2005-3-22
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\system32\svchos
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\conime
C:\tools\HijackThis.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
O6 - HKCU\Software\Policies\Mic
O6 - HKCU\Software\Policies\Mic
O6 - HKLM\Software\Policies\Mic
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\ws2_6
O18 - Protocol: cdl - {3DD53D40-7B8B-11D0-B013-0
O18 - Protocol: cdo - {CD00020A-8B95-11D1-82DB-0
O18 - Protocol: dvd - {12D51199-0DB5-46FE-A120-4
O18 - Protocol: file - {79EAC9E7-BAF9-11CE-8C82-0
O18 - Protocol: ftp - {79EAC9E3-BAF9-11CE-8C82-0
O18 - Protocol: gopher - {79EAC9E4-BAF9-11CE-8C82-0
O18 - Protocol: http - {79EAC9E2-BAF9-11CE-8C82-0
O18 - Protocol: https - {79EAC9E5-BAF9-11CE-8C82-0
O18 - Protocol: ic32pp - {BBCA9F81-8F4F-11D2-90FF-0
O18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0
O18 - Protocol: local - {79EAC9E7-BAF9-11CE-8C82-0
O18 - Protocol: mk - {79EAC9E6-BAF9-11CE-8C82-0
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-0
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: tv - {CBD30858-AF45-11D2-B6D6-0
O18 - Protocol: wia - {13F3EA8B-91D7-4F0A-AD76-D
O18 - Filter: text/html - {65CBAF77-19CA-4B81-86D5-7
O20 - Winlogon Notify: PCANotify - C:\WINDOWS\SYSTEM32\PCANot
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2ev
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpms
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\SYSTEM32\SPOOL\
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrv
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvM
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpS
--------------------------
does any item suspect?
BTW, under safemode without network, start IE6, open a html file on my harddrive, the folder(8848\mysearch\0.9.6
conime.exe is a back door trojan
http://www.liutilities.com
you may have to boot in to command line to remove this file.
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\ws2_6
This is a bad file also.
http://computercops.biz/ls
Try running this to fix the 010 problem
http://download.softpedia.
Open Task Manager and end process on conime.exe
Go to C:\WINDOWS\system32\ and delete conime.exe
Start
Run...
msconfig
Startup(tab)
uncheck conime.exe (or C:\WINDOWS\system32\conime
Remove these with HijackThis:
O6 - HKCU\Software\Policies\Mic
O6 - HKCU\Software\Policies\Mic
O6 - HKLM\Software\Policies\Mic
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\ws2_6
O18 - Protocol: cdl - {3DD53D40-7B8B-11D0-B013-0
O18 - Protocol: cdo - {CD00020A-8B95-11D1-82DB-0
O18 - Protocol: dvd - {12D51199-0DB5-46FE-A120-4
O18 - Protocol: file - {79EAC9E7-BAF9-11CE-8C82-0
O18 - Protocol: ftp - {79EAC9E3-BAF9-11CE-8C82-0
O18 - Protocol: gopher - {79EAC9E4-BAF9-11CE-8C82-0
O18 - Protocol: http - {79EAC9E2-BAF9-11CE-8C82-0
O18 - Protocol: https - {79EAC9E5-BAF9-11CE-8C82-0
O18 - Protocol: ic32pp - {BBCA9F81-8F4F-11D2-90FF-0
O18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0
O18 - Protocol: local - {79EAC9E7-BAF9-11CE-8C82-0
O18 - Protocol: mk - {79EAC9E6-BAF9-11CE-8C82-0
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-0
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: tv - {CBD30858-AF45-11D2-B6D6-0
O18 - Protocol: wia - {13F3EA8B-91D7-4F0A-AD76-D
O18 - Filter: text/html - {65CBAF77-19CA-4B81-86D5-7
Windows Update does not work in Firefox.
Firefox can be used as a vehicle to attack IE since it is part of the OS. This will not affect Firefox, but will hit IE.
This just means you need to keep your system up to date.
I surprised nobody mentioned using msconfig and seeing if anything was listed in startup.
Sometimes I've not been able to remove a piece of spyware because it's always running, but I have been able to rename the exectuable so that on the next restart the program is not loaded. That may help you get rid of the apyware.
Business Accounts
Answer for Membership
by: concretesailorsPosted on 2005-03-19 at 07:49:42ID: 13582260
You're using a toolbar
Under View - uncheck any toolbar and see if this still happens
I bet it stops
MySearch is a search bar