Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

loads all slow, norton installed

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

loads all slow, norton installed

Unread postby stevemel2003 » July 19th, 2007, 9:58 pm

Scan Status:

Scan: 1

Start Scan: 07/19/07 19:06:30

Scan Targets: Running Processes;Entry Points;C:\

Virus Definitions: 07/19/07

Scan Count: 201638

Risks Found: 20

Risks resolved: 7

Risks unresolved: 13

Scan Time: 8036 sec

Complete Scan: 07/19/07 21:20:26



Resolved Threats:

SecurityRisk.Downldr

Virus ID: 4294909773

Risk: High

Categories: Security Risk

State: Deleted

-----------

Infection:

c:\program files\common files\fjbdpael\dlppetnn\aanlntjt.exe

Browser Cache





SecurityRisk.Downldr

Virus ID: 4294909773

Risk: High

Categories: Security Risk

State: Deleted

-----------

Infection:

c:\program files\common files\fjbdpael\fphpclajpl\rcnanhlcb.exe

Browser Cache





W95.CIH.remnants

Virus ID: 34681

Risk: High

Categories: Virus

State: Repaired

-----------

Infection:

c:\program files\totally hip products\giffyview\GiffyVw.exe

Browser Cache





SecurityRisk.Downldr

Virus ID: 4294909773

Risk: High

Categories: Security Risk

State: Deleted

-----------

Infection:

c:\WINDOWS\SYSTEM32\SysUpd.exe

Browser Cache





Downloader

Virus ID: 26637

Risk: High

Categories: Virus

State: Deleted

-----------

Infection:

c:\WINDOWS\SYSTEM32\getupd.exe

Browser Cache





Dialer.Generic

Virus ID: 4294906232

Risk: High

Categories: Dialer

State: Deleted

-----------

Infection:

c:\WINDOWS\SYSTEM32\ieaccess2.dll

Browser Cache





Trojan.StartPage

Virus ID: 24374

Risk: High

Categories: Virus

State: Deleted

-----------

Process:

C:\Program Files\Internet Explorer\iexplore.exe

Infection:

c:\WINDOWS\SYSTEM32\sethomepage.exe

Registry:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search->SearchAssistant:http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main->Start Page:http://securityresponse.symantec.com/avcenter/fix_homepage/

HKEY_USERS\S-1-5-21-1392284910-1316817595-1404449762-1003\SOFTWARE\Microsoft\Internet Explorer\Main->Use Custom Search URL

HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main->Use Custom Search URL

HKEY_USERS\S-1-5-21-1392284910-1316817595-1404449762-1003\SOFTWARE\Microsoft\Internet Explorer\Search->SearchAssistant

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main->Search Bar:http://search.msn.com/spbasic.htm

HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\->Start Page:http://securityresponse.symantec.com/avcenter/fix_homepage/

HKEY_USERS\S-1-5-21-1392284910-1316817595-1404449762-1003\Software\Microsoft\Internet Explorer\Main\->Start Page:http://securityresponse.symantec.com/avcenter/fix_homepage/

HKEY_USERS\S-1-5-21-1392284910-1316817595-1404449762-1006\Software\Microsoft\Internet Explorer\Main\->Start Page:http://securityresponse.symantec.com/avcenter/fix_homepage/

HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\->Start Page:http://securityresponse.symantec.com/avcenter/fix_homepage/

HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\->Start Page:http://securityresponse.symantec.com/avcenter/fix_homepage/

HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main->Search Page:http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

HKEY_USERS\S-1-5-21-1392284910-1316817595-1404449762-1003\Software\Microsoft\Internet Explorer\Main->Search Page:http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main->Search Page:http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main->Search Page:http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main->Search Bar:http://search.msn.com/spbasic.htm

HKEY_USERS\S-1-5-21-1392284910-1316817595-1404449762-1003\Software\Microsoft\Internet Explorer\Main->Search Bar:http://search.msn.com/spbasic.htm

HKEY_USERS\S-1-5-21-1392284910-1316817595-1404449762-1006\Software\Microsoft\Internet Explorer\Main->Search Bar:http://search.msn.com/spbasic.htm

HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main->Search Bar:http://search.msn.com/spbasic.htm

HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main->Search Bar:http://search.msn.com/spbasic.htm

HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main->Use Search Asst:no

HKEY_USERS\S-1-5-21-1392284910-1316817595-1404449762-1006\Software\Microsoft\Internet Explorer\Main->Use Search Asst:no

HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main->Use Search Asst:no

HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main->Use Search Asst:no

Browser Cache







Unresolved Threats:

Adware.GAIN

Virus ID: 4294905904

Risk: Low

Categories: AdWare

State: Unhandled

-----------

File:

C:\WINDOWS\GatorPdpSetup.log

C:\WINDOWS\GatorHDPlugin.log

Registry:

HKEY_LOCAL_MACHINE\Software\Gator.com

HKEY_USERS\S-1-5-21-1392284910-1316817595-1404449762-1006\Software\Gator.com

HKEY_CLASSES_ROOT\CLSID\{21FFB6C0-0DA1-11D5-A9D5-00500413153C}

HKEY_USERS\S-1-5-21-1392284910-1316817595-1404449762-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\GAIN Publishing

File:

c:\documents and settings\Owner\local settings\Temp\fsg_tmp\files\pdpsetup5102.ex_

Directory:

c:\documents and settings\Owner\local settings\Temp\fsg_tmp\files

File:

c:\documents and settings\Owner\local settings\Temp\fsg_tmp\GTD15F.tmp

c:\documents and settings\Owner\local settings\Temp\fsg_tmp\GTD161.tmp

c:\documents and settings\Owner\local settings\Temp\fsg_tmp\GTD24D.tmp

c:\documents and settings\Owner\local settings\Temp\fsg_tmp\GTD250.tmp

c:\documents and settings\Owner\local settings\Temp\fsg_tmp\GTD252.tmp

c:\documents and settings\Owner\local settings\Temp\fsg_tmp\GTD4C.tmp

c:\documents and settings\Owner\local settings\Temp\fsg_tmp\GTD4F.tmp

c:\documents and settings\Owner\local settings\Temp\fsg_tmp\GTD51.tmp

c:\documents and settings\Owner\local settings\Temp\fsg_tmp\GTI15D.tmp

c:\documents and settings\Owner\local settings\Temp\fsg_tmp\GTI24E.tmp

c:\documents and settings\Owner\local settings\Temp\fsg_tmp\GTI4D.tmp

c:\documents and settings\Owner\local settings\Temp\fsg_tmp\GTR15E.tmp

c:\documents and settings\Owner\local settings\Temp\fsg_tmp\GTR24C.tmp

c:\documents and settings\Owner\local settings\Temp\fsg_tmp\GTR24F.tmp

c:\documents and settings\Owner\local settings\Temp\fsg_tmp\GTR4B.tmp

c:\documents and settings\Owner\local settings\Temp\fsg_tmp\GTR4E.tmp

Directory:

C:\Documents and Settings\Owner\Local Settings\Temp\fsg_tmp

Browser Cache





Tracking Cookie

Virus ID: 4294909925

Risk: Low

Categories: Unknown

State: Unhandled

-----------

Cookie:

Cookie:owner@dm.travelocity.com/

Cookie:owner@adopt.specificclick.net/

Cookie:owner@ad.yieldmanager.com/





Adware.PrecisionTime

Virus ID: 4294906713

Risk: Low

Categories: AdWare

State: Unhandled

-----------

Infection:

c:\program files\precisiontime\precisiontime.exe

Registry:

HKEY_LOCAL_MACHINE\SOFTWARE\Gator.com\AppInfo\PrecisionTime

HKEY_LOCAL_MACHINE\SOFTWARE\Gator.com\PrecisionTime

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PrecisionTime

File:

c:\program files\precisiontime\INSTALL.LOG

c:\program files\precisiontime\precisiontime.exe

c:\program files\precisiontime\precisiontime.exe.manifest

c:\program files\precisiontime\precisiontime.ini

c:\program files\precisiontime\precisiontime.lcl

c:\program files\precisiontime\precisiontimewebsite.url

c:\program files\precisiontime\UNWISE.EXE

Directory:

C:\Program Files\PrecisionTime

Browser Cache





Spyware.Netrat

Virus ID: 4294909828

Risk: Med

Categories: SpyWare

State: Unhandled

-----------

Service:

nmconpid

Process:

c:\program files\netratingsnetmeter\NetMeter\nielsenonline.exe

Infection:

c:\program files\netratingsnetmeter\NetMeter\nielsenonline.exe

Registry:

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{80D5D403-C430-4E44-877E-7627124DC23F}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2CFD6C20-5CA7-41F6-8464-173B04D90F1E}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6C7F7FAC-F1B3-4D42-985F-F776F91FA945}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D01CBDEC-6B8A-4A9B-A3AD-AE73D5510359}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NMIEObserver.NMIEWebObj

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NMIEObserver.NMIEWebObj.1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\->PrInstall

Browser Cache

Registry:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run->NetMeter

Infection:

c:\documents and settings\Owner\local settings\Temp\Net1.tmp\nielsenonline.exe

c:\documents and settings\Owner\local settings\Temp\Net2.tmp\nielsenonline.exe





Adware.WinAd

Virus ID: 4294905987

Risk: High

Categories: AdWare

State: Unhandled

-----------

Infection:

c:\WINDOWS\SYSTEM32\Winad2.dll

Browser Cache

Registry:

HKEY_CLASSES_ROOT\CLSID\{53D3C442-8FEE-4784-9A21-6297D39613F0}

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53D3C442-8FEE-4784-9A21-6297D39613F0}





Spyware.Netrat

Virus ID: 4294909828

Risk: Med

Categories: SpyWare

State: Unhandled

-----------

File:

c:\Documents and Settings\Owner\Local Settings\Temp\NetMeter_setup_en_4.70.24.0_MEGAPANEL_USA.exe





Adware.GAIN

Virus ID: 4294905904

Risk: Low

Categories: AdWare

State: Unhandled

-----------

File:

c:\Documents and Settings\Owner\Local Settings\Temp\fsg_tmp\files\PdpSetup5102.ex_





Adware.GAIN

Virus ID: 4294905904

Risk: Low

Categories: AdWare

State: Unhandled

-----------

File:

c:\Documents and Settings\Owner\Local Settings\Temp\fsg_tmp\GTR24F.tmp





Spyware.Netrat

Virus ID: 4294909828

Risk: Med

Categories: SpyWare

State: Unhandled

-----------

File:

c:\Program Files\NetRatingsNetmeter\NetMeter\NetMeter_maj2_en_4.70.25.0_MEGAPANEL_USA.exe





Spyware.Netrat

Virus ID: 4294909828

Risk: Med

Categories: SpyWare

State: Unhandled

-----------

File:

c:\Program Files\NetRatingsNetmeter\NetMeter\NetMeter_maj3_en_4.70.25.0_MEGAPANEL_USA.exe





Download.Adware

Virus ID: 4294909728

Risk: High

Categories: AdWare

State: Unhandled

-----------

Infection:

c:\WINDOWS\SYSTEM32\webinstall.dll

Browser Cache





Trojan.Startpage

Virus ID: 24374

Risk: High

Categories: Virus

State: Repair Failed

-----------

File:

c:\WINDOWS\Temp\hp_upd.cab





Adware.InstantAccess

Virus ID: 4294905920

Risk: Med

Categories: AdWare

State: Unhandled

-----------

Infection:

c:\WINDOWS\iedisco.exe

Browser Cache








--------------------------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 9:44:19 PM, on 7/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\NetRatingsNetmeter\NetMeter\NielsenOnline.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us4.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us4.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/av ... _homepage/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/av ... _homepage/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: Advertiser Class - {53D3C442-8FEE-4784-9A21-6297D39613F0} - C:\WINDOWS\System32\Winad2.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [NetMeter] C:\Program Files\NetRatingsNetmeter\NetMeter\NielsenOnline.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden /tgcmdwrapper
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NielsenOnline] C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredi ... xmk572MFUS
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocach ... 0.15-3.cab
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: MSSQL$MICROSOFTSMLBIZ - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe" -sMICROSOFTSMLBIZ (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\System32\PackethSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: SQLAgent$MICROSOFTSMLBIZ - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlagent.EXE" -i MICROSOFTSMLBIZ (file missing)

Adobe Acrobat 4.0
Adobe Download Manager 2.0 (Remove Only)
Adobe Photoshop 6.0
Adobe Reader 7.0.8
America Online
Arthur's Computer Adventure
Atomic Pop
Battle Snake 1.4
BellSouth FastAccess DSL Help Center
BellSouth Internet Security - Alert Manager 1.3.20
Bowl-Ed Over
Bryce(R) 5
CardRd81
CCScore
CR2
Detto IntelliMover
Digital Blue(tm) QX3(tm) Computer Microscope
Easy Internet Sign-up
EPSON Printer Software
ESSBrwr
ESSCDBK
ESScore
ESSCT
ESSgui
ESShelp
ESSini
ESSPCD
ESSPDock
ESSSONIC
ESSTOOLS
ESSTUTOR
ESSvpaht
ESSvpot
Excavation from Hewlett-Packard Desktops (remove only)
Eye Candy 4000
Fantasy Tetrix
GemMaster 2
Google Earth
Google Toolbar for Internet Explorer
Google Updater
Guitar Pro 5.1
Happyland Adventures - Xmas Edition
HijackThis 1.99.1
HLPIndex
HLPPDOCK
HLPRFO
hp center
HP Image Zone 3.5
HP Instant Support
HP PSC & OfficeJet 3.5
HP RecordNow
HP Software Update
Inactive HP Printer Drivers (Remove only)
iTunes
J2SE Runtime Environment 5.0 Update 1
KBD
Kodak EasyShare software
KSU
LEGO Island 2
LEGO Racers
LEGO Racers 2
Lernout & Hauspie TruVoice American English TTS Engine
Logitech Desktop Messenger
Logitech iTouch Software
Logitech MouseWare 9.79.3
Macromedia Flash Player 8
McAfee.com Agent
Microsoft .NET Framework 1.1
Microsoft Money 2002
Microsoft Money 2002 System Pack
Microsoft Office Small Business Accounting 2006
Microsoft SQL Server Desktop Engine (MICROSOFTSMLBIZ)
Microsoft Works 6.0
Microsoft Works and Money 2002 Setup Launcher
Mozilla Firefox (2.0.0.3)
Mozilla Firefox (2.0.0.5)
MSXML 4.0 SP2 (KB927978)
My Photo Center
My Web Search (Smiley Central)
Nielsen Online
Nielsen//NetRatings
Norton Security Scan
Notifier
NVIDIA Windows 2000/XP Display Drivers
Orbital from Hewlett-Packard Desktops (remove only)
OTtBP
OTtBPSDK
Overball from Hewlett-Packard Desktops (remove only)
Packad Bell Interactive
PC-Doctor for Windows
PigPen
Power Retouche Demo
PrecisionTime
Presto! PageManager
Presto! PageType
PS2
Python 1.5 combined Win32 extensions
Python 1.5.2 (final)
QuickTime
Reader Rabbit(R) Reading Ages 6-9
Reader Rabbit's(R) Math Ages 6 - 9
RealPlayer
RingMaster from Hewlett-Packard Desktops (remove only)
S3 Gamma
S3 Savage4 Family Display Switch2 Utility
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Sega Smash Pack II
SEGA Swirl
SFR
SHASTA
Shockwave
SierraHome Print Artist 8.0
SKIN0001
SKINXSDK
SONIC HEROES TRIAL
Sony Preset Manager 2.0d
Space Rocks
Speedway
Spyware Doctor 5.0
Super Worms
Tcl 8.0.5 for Windows
Tradewinds 2
TuneLand
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB936357)
VPRINTOL
Webinstall
WebPainter for Win32 version 3.0
WildTangent GameChannel (remove only)
WildTangent Web Driver
Windows Blaster Worm Removal Tool (KB833330)
Windows Installer 3.1 (KB893803)
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Service Pack 2
WIRELESS
Wrecked Trial

:?:
stevemel2003
Active Member
 
Posts: 5
Joined: July 18th, 2007, 6:43 pm
Advertisement
Register to Remove

Unread postby Blade81 » July 20th, 2007, 6:52 am

Hi

Remove thru add/remove programs following entries:
My Web Search (Smiley Central)
Nielsen Online
Nielsen//NetRatings


Start hjt, click do a system scan only, check (if found):
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: Advertiser Class - {53D3C442-8FEE-4784-9A21-6297D39613F0} - C:\WINDOWS\System32\Winad2.dll
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [NielsenOnline] C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredi ... xmk572MFUS
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocach ... 0.15-3.cab

Close all browsers and other windows. Click fix checked.


Show hidden files
-----------------
* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK.


Delete following file if found:
C:\WINDOWS\system32\Winad2.dll

and following folders if found:
C:\Program Files\MyWebSearch
C:\Program Files\NetRatingsNetSight

Post a fresh hjt log.
User avatar
Blade81
Admin/Teacher
Admin/Teacher
 
Posts: 5245
Joined: July 17th, 2006, 3:36 am
Location: Finland

Unread postby NonSuch » July 29th, 2007, 12:30 am

As it appears that this topic is related to the same machine for which help is currently being received in another topic, this thread will now be closed...

http://www.malwareremoval.com/forum/viewtopic.php?p=199961

In order to avoid confusion and duplication of effort by multiple helpers, please confine your posts to one topic.
User avatar
NonSuch
Administrator
Administrator
 
Posts: 28747
Joined: February 23rd, 2005, 7:08 am
Location: California


  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 439 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware