AllExperts > Computer Security & Viruses 
Search      
Computer Security & Viruses
Volunteer
Answers to thousands of questions
 Home · More Computer Security & Viruses Questions · Answer Library  · Encyclopedia ·
More Computer Security & Viruses Answers
Question Library

Ask a question about Computer Security & Viruses
Volunteer
Experts of the Month
Expert Login

Awards

About Us
Tell friends
Link to Us
Disclaimer

 
 
 
 
About Brian Benosky
Expertise
I will help you in eradicating malware and all forms of virus/trojans/adware. I can answer all PC-related hardware issues. I can also troubleshoot Windows OS errors (including Vista) and other software problems. HijackThis logs are a MUST for virus related help. If you do not know how to do this, I have posted easy-to-follow instructions on the Ask a Question page. Every computer infection is different, so I will give you personal instructions on how to remove the malware, not a 'pat' answer. You can be assured of a prompt, polite, and knowledgeable response in all regards.

Experience
I have over 25 years experience in using, building, and repairing computers. I have helped over a thousand people here on AllExperts, with consistent Top Feedback Scores. Please look at my answers here: http://en.allexperts.com/q/Computer-Security-Viruses-1737/indexExp_84308.htm I am also a Top Contributer of General Computing answers in Yahoo! Questions.

Education/Credentials
College Educated Self-taught Computer Skills

 
   

You are here:  Experts > Computing/Technology > Internet/Network Security > Computer Security & Viruses > trojan zlob

Computer Security & Viruses - trojan zlob


Expert: Brian Benosky - 9/6/2008

Question
QUESTION: Aloha brian, my son has helped me to get another email that I can open. He has been helped by you before. Here is the log file.Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:41:24 PM, on 9/5/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18241)
Boot mode: Normal

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesCommon FilesAppleMobile Device SupportinAppleMobileDeviceService.exe
C:Program FilesSymantecLiveUpdateAluSchedulerSvc.exe
C:WINDOWSsystem32CTsvcCDA.EXE
C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
C:Program FilesCommon FilesSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}PifSvc.exe
C:WINDOWSsystem32svchost.exe
C:Program FilesViewpointCommonViewpointService.exe
C:WINDOWSExplorer.EXE
C:WINDOWSMXOALDR.EXE
C:WINDOWSstsystra.exe
C:Program FilesMaxtorOneTouchutilsOnetouch.exe
C:Program FilesCommon FilesInstallShieldUpdateServiceissch.exe
C:Program FilesGoogleGoogle Desktop SearchGoogleDesktop.exe
C:Program FilesCyberLinkPowerDVDDVDLauncher.exe
C:Program FilesDell Photo AIO Printer 942memcard.exe
C:Program FilesDell Photo AIO Printer 942dlbubmgr.exe
C:Program FilesCreativeSBAudigy2ZSSurround MixerCTSysVol.exe
C:Program FilesDell Photo AIO Printer 942dlbubmon.exe
C:WINDOWSsystem32CTHELPER.EXE
C:Program FilesCreativeSBAudigy2ZSDVDAudioCTDVDDET.EXE
C:Program FilesMicrosoft IntelliPointipoint.exe
C:Program FilesQuickTimeQTTask.exe
C:Program FilesJavajre1.6.0_07injusched.exe
C:Program FilesCommon FilesSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}PifSvc.exe
C:WINDOWSsystem32ctfmon.exe
C:Program FilesAIM6aim6.exe
C:Program FilesCommon FilesAheadLibNMBgMonitor.exe
C:Program FilesMessengermsmsgs.exe
C:Program FilesWindows LiveMessengermsnmsgr.exe
C:Program FilesCommon FilesAheadLibNMIndexingService.exe
C:Program FilesGoogleGoogle Desktop SearchGoogleDesktop.exe
C:Program FilesCommon FilesAheadLibNMIndexStoreSvr.exe
C:Program FilesGoogleGoogle UpdaterGoogleUpdater.exe
C:Program FilesAIM6aolsoftware.exe
C:PROGRA~1AVGAVG8avgwdsvc.exe
C:PROGRA~1AVGAVG8avgrsx.exe
C:PROGRA~1AVGAVG8avgemc.exe
C:Program FilesAVGAVG8avgtray.exe
C:Program FilesWindows LiveMessengerusnsvc.exe
C:Program FilesWindows Media Playerwmplayer.exe
C:Program FilesTrend MicrocrackerHijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://home.sweetim.com
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://home.sweetim.com
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R1 - HKCUSoftwareMicrosoftInternet Connection Wizard,ShellNext = http://www.dellconect.com/
R3 - URLSearchHook: {EA551C00-2AE5-11d3-8592-00A0C98E9EA4} -  - (no file)
F2 - REG:system.ini: Shell=
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:PROGRA~1Yahoo!CompanionInstallscpnyt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:Program FilesAVGAVG8avgssie.dll
O2 - BHO: ALOT Toolbar - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:Program Filesalotinalot.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:Program FilesYahoo!Commonyiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.6.0_07inssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:Program FilesAOLAIM Toolbar 5.0aoltb.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:PROGRA~1AVGAVG8AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:Program FilesGoogleGoogleToolbarNotifier.1.509.5470swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:Program FilesWindows Live Toolbarmsntb.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:Program FilesMSNToolbar.0.0426.0msneshellx.dll
O3 - Toolbar: ALOT Toolbar - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:Program Filesalotinalot.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:Program FilesWindows Live Toolbarmsntb.dll
O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:PROGRA~1Yahoo!CompanionInstallscpnyt.dll
O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:Program FilesAOLAIM Toolbar 5.0aoltb.dll
O3 - Toolbar: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - (no file)
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:Program FilesMSNToolbar.0.0426.0msneshellx.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:PROGRA~1AVGAVG8AVGTOO~1.DLL
O4 - HKLM..Run: [MXOBG] C:WINDOWSMXOALDR.EXE
O4 - HKLM..Run: [UpdReg] C:WINDOWSUpdReg.EXE
O4 - HKLM..Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM..Run: [MaxtorOneTouch] C:Program FilesMaxtorOneTouchutilsOnetouch.exe
O4 - HKLM..Run: [ISUSScheduler] "C:Program FilesCommon FilesInstallShieldUpdateServiceissch.exe" -start
O4 - HKLM..Run: [ISUSPM Startup] C:PROGRA~1COMMON~1INSTAL~1UPDATE~1ISUSPM.exe -startup
O4 - HKLM..Run: [Google Desktop Search] "C:Program FilesGoogleGoogle Desktop SearchGoogleDesktop.exe" /startup
O4 - HKLM..Run: [DVDLauncher] "C:Program FilesCyberLinkPowerDVDDVDLauncher.exe"
O4 - HKLM..Run: [DellMCM] C:Program FilesDell Photo AIO Printer 942memcard.exe
O4 - HKLM..Run: [Dell Photo AIO Printer 942] "C:Program FilesDell Photo AIO Printer 942dlbubmgr.exe"
O4 - HKLM..Run: [CTSysVol] C:Program FilesCreativeSBAudigy2ZSSurround MixerCTSysVol.exe /r
O4 - HKLM..Run: [CTHelper] CTHELPER.EXE
O4 - HKLM..Run: [CTDVDDET] "C:Program FilesCreativeSBAudigy2ZSDVDAudioCTDVDDET.EXE"
O4 - HKLM..Run: [ATIPTA] C:Program FilesATI TechnologiesATI Control Panelatiptaxx.exe
O4 - HKLM..Run: [HotbarOE] C:Program FilesHotbarin.0.368.0OEAddOn.exe
O4 - HKLM..Run: [IntelliPoint] "C:Program FilesMicrosoft IntelliPointipoint.exe"
O4 - HKLM..Run: [Adobe Reader Speed Launcher] "C:Program FilesAdobeReader 8.0ReaderReader_sl.exe"
O4 - HKLM..Run: [NeroFilterCheck] C:Program FilesCommon FilesAheadLibNeroCheck.exe
O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeQTTask.exe" -atboottime
O4 - HKLM..Run: [SunJavaUpdateSched] "C:Program FilesJavajre1.6.0_07injusched.exe"
O4 - HKLM..Run: [My Web Search Bar Search Scope Monitor] "C:PROGRA~1MYWEBS~1ar.binm3SrchMn.exe" /m=2 /w
O4 - HKLM..Run: [RegistryMechanic] C:Program FilesRegistry MechanicRegMech.exe /QS
O4 - HKLM..Run: [Symantec PIF AlertEng] "C:Program FilesCommon FilesSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}PifSvc.exe" /a /m "C:Program FilesCommon FilesSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}AlertEng.dll"
O4 - HKLM..Run: [AVG8_TRAY] C:PROGRA~1AVGAVG8avgtray.exe
O4 - HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [Aim6] "C:Program FilesAIM6aim6.exe" /d locale=en-US ee://aol/imApp /HIDEBL
O4 - HKCU..Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:Program FilesCommon FilesAheadLibNMBgMonitor.exe"
O4 - HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
O4 - HKCU..Run: [msnmsgr] "C:Program FilesWindows LiveMessengermsnmsgr.exe" /background
O4 - Global Startup: Google Updater.lnk = C:Program FilesGoogleGoogle UpdaterGoogleUpdater.exe
O8 - Extra context menu item: &AIM Search - c:program filesaolaim toolbar 5.0
esourcesen-USlocalsearch.html
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZRfox000
O8 - Extra context menu item: &Windows Live Search - res://C:Program FilesWindows Live Toolbarmsntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_07inssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_07inssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:Program FilesWindows LiveWriterWriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:Program FilesWindows LiveWriterWriterBrowserExtension.dll
O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:Program FilesAOLAIM Toolbar 5.0aoltb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:Program FilesYahoo!Commonyiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O16 - DPF: CabBuilder - http://ak.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:Program FilesYahoo!CommonYinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muwe...
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-c225878a79e6e412.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:Program FilesAVGAVG8avgpp.dll
O20 - AppInit_DLLs: C:PROGRA~1GoogleGOOGLE~3GOEC62~1.DLL,avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:Program FilesCommon FilesAppleMobile Device SupportinAppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:WINDOWSsystem32Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:WINDOWSsystem32ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:Program FilesSymantecLiveUpdateAluSchedulerSvc.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:PROGRA~1AVGAVG8avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:PROGRA~1AVGAVG8avgwdsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:WINDOWSsystem32CTsvcCDA.EXE
O23 - Service: dlbu_device - Dell - C:WINDOWSsystem32dlbucoms.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:Program FilesGoogleGoogle Desktop SearchGoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:Program FilesCommon FilesInstallShieldDriverE0Intel 32IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:Program FilesSymantecLiveUpdateLuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}PifSvc.exe
O23 - Service: NBService - Nero AG - C:Program FilesNeroNero 7Nero BackItUpNBService.exe
O23 - Service: NMIndexingService - Nero AG - C:Program FilesCommon FilesAheadLibNMIndexingService.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:Program FilesViewpointCommonViewpointService.exe

--
End of file - 14139 bytes


ANSWER: Hi Chelle

Please download Malwarebytes' Anti-Malware to your desktop from here:
http://www.besttechie.net/tools/mbam-setup.exe
Double-click mbam-setup.exe and follow the prompts to install the program.
 * At the end, be sure a checkmark is placed next to
       o Update Malwarebytes' Anti-Malware
       o and Launch Malwarebytes' Anti-Malware
 * then click Finish.
 * If an update is found, it will download and install the latest version.
 * Once the program has loaded, select Perform full scan, then click Scan.
 * When the scan is complete, click OK, then Show Results to view the results.
 * Be sure that everything is checked, and click Remove Selected.
 * When completed, a log will open in Notepad.  Copy that log into a reply here and also include a new HJT log.

Brian

---------- FOLLOW-UP ----------

QUESTION: Malwarebytes' Anti-Malware 1.26
Database version: 1119
Windows 5.1.2600 Service Pack 3

9/6/2008 4:06:48 AM
mbam-log-2008-09-06 (04-06-48).txt

Scan type: Full Scan (C:|)
Objects scanned: 146359
Time elapsed: 2 hour(s), 44 minute(s), 4 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 108
Registry Values Infected: 4
Registry Data Items Infected: 0
Folders Infected: 37
Files Infected: 128

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT unwebproducts.browseroverlaybarbutton (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT unwebproducts.browseroverlaybarbutton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT unwebproducts.browseroverlayembed (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT unwebproducts.browseroverlayembed.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT unwebproducts.datacontrol (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT unwebproducts.datacontrol.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT unwebproducts.historykillerscheduler (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT unwebproducts.historykillerscheduler.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT unwebproducts.historyswattercontrolbar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT unwebproducts.historyswattercontrolbar.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT unwebproducts.htmlmenu (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT unwebproducts.htmlmenu.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT unwebproducts.htmlmenu.2 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT unwebproducts.iecookiesmanager (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT unwebproducts.iecookiesmanager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT unwebproducts.killerobjmanager (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT unwebproducts.killerobjmanager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT unwebproducts.popswatterbarbutton (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT unwebproducts.popswatterbarbutton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT unwebproducts.popswattersettingscontrol (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT unwebproducts.popswattersettingscontrol.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT unwebproducts.shellviewcontrol (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT unwebproducts.shellviewcontrol.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTmywebsearch.chatsessionplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTmywebsearch.chatsessionplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTmywebsearch.htmlpanel (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTmywebsearch.htmlpanel.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTmywebsearch.outlookaddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTmywebsearch.outlookaddin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTmywebsearch.pseudotransparentplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTmywebsearch.pseudotransparentplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTmywebsearchtoolbar.settingsplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTmywebsearchtoolbar.settingsplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTmywebsearchtoolbar.toolbarplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTmywebsearchtoolbar.toolbarplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTscreensavercontrol.screensaverinstaller (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTscreensavercontrol.screensaverinstaller.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{07b18eaa-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{07b18eac-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{1093995a-ba37-41d2-836e-091067c4ad17} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{120927bf-1700-43bc-810f-fab92549b390} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{17de5e5e-bfe3-4e83-8e1f-8755795359ec} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{1f52a5fa-a705-4415-b975-88503b291728} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{247a115f-06c2-4fb3-967d-2d62d3cf4f0a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{2763e333-b168-41a0-a112-d35f96f410c0} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{2e3537fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{38a7c9da-8db7-4d0f-a7b1-c4b1a305bddb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{3e1656ed-f60e-4597-b6aa-b6a58e171495} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{3e53e2cb-86db-4a4a-8bd9-ffeb7a64df82} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{3e720451-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{3e720453-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{63d0ed2b-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{63d0ed2d-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{6e74766c-4d93-4cc0-96d1-47b8e07ff9ca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{72ee7f04-15bd-4845-a005-d6711144d86a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{7473d291-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{7473d293-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{7473d295-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{7473d297-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{8d292ec0-6792-4a38-82ed-73a087e41ba6} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{90449521-d834-4703-bb4e-d3aa44042ff8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{991aac62-b100-47ce-8b75-253965244f69} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{a626cdbd-3d13-4f78-b819-440a28d7e8fc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{bbabdc90-f3d5-4801-863a-ee6ae529862d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{d6ff3684-ad3b-48eb-bbb4-b9e6c5a355c1} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{de38c398-b328-4f4c-a3ad-1b5e4ed93477} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{e342af55-b78a-4cd0-a2bb-da7f52d9d25e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{e342af55-b78a-4cd0-a2bb-da7f52d9d25f} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{e79dfbc9-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{e79dfbcb-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{eb9e5c1c-b1f9-4c2b-be8a-27d6446fdaf8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTInterface{f87d7fb5-9dc5-4c8c-b998-d8dfe02e2978} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTCLSID{5aa2ba46-9913-4dc7-9620-69ab0fa17ae7} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTCLSID{202836d7-782e-468a-9958-4d529e7d69f5} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USERSOFTWAREMicrosoftInternet ExplorerSearchScopes{5aa2ba46-9913-4dc7-9620-69ab0fa17ae7} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{5aa2ba46-9913-4dc7-9620-69ab0fa17ae7} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTCLSID{ec5bb7d4-9860-46d1-931c-c1a98e0e0e34} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTCLSID{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTCLSID{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTCLSID{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTTypelib{07b18ea0-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTTypelib{0d26bc71-a633-4e71-ad31-eadc3a1b6a3a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTTypelib{29d67d3c-509a-4544-903f-c8c1b8236554} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTTypelib{3e720450-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTTypelib{621feacd-8857-43a6-ae26-451d670d5370} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTTypelib{7473d290-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTTypelib{8ca01f0e-987c-49c3-b852-2f1ac4a7094c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTTypelib{8e6f1830-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTTypelib{98635087-3f5d-418f-990c-b1efe0797a3b} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTTypelib{c8cecde3-1ae1-4c4a-ad82-6d5b00212144} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTTypelib{e47caee0-deea-464a-9326-3f2801535a4d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTTypelib{e79dfbc0-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTTypelib{f42228fb-e84e-479e-b922-fbbd096e792c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USERSOFTWAREMicrosoftInternet ExplorerSearchScopes{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USERSOFTWAREMicrosoftInstallerProducts.8267acfc5644dab06f058006ddbae3 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CURRENT_USERSOFTWAREalot (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallalotToolbar (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTMIMEDatabaseContent Typeapplication/x-f3embed (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftMultimediaWMPlayerSchemes 3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallMyWebSearch bar Uninstall (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftOfficeOutlookAddinsMyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftOfficeWordAddinsMyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREFun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREFocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USERSOFTWAREFun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar{5aa2ba46-9913-4dc7-9620-69ab0fa17ae7} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USERSOFTWAREMicrosoftInternet ExplorerMenuExt&Search (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows MediaWMSDKSources 3PopularScreensavers (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionInternet SettingsUser AgentPost PlatformFunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:Program FilesMyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearchar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearchar.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharAvatar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharCache (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharGame (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharHistory (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharicons (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharMessage (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharNotifier (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharSettings (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesFunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesFunWebProductsScreenSaver (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesFunWebProductsScreenSaverImages (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesFunWebProductsShared (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesFunWebProductsSharedCache (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program Filesalot (Adware.BHO) -> Quarantined and deleted successfully.
C:Program Filesalotin (Adware.BHO) -> Quarantined and deleted successfully.
C:Documents and Settings
ochelleApplication Dataalot (Adware.BHO) -> Quarantined and deleted successfully.
C:Documents and Settings
ochelleApplication DataalotBrowserSearch (Adware.BHO) -> Quarantined and deleted successfully.
C:Documents and Settings
ochelleApplication Dataalotconfigurator (Adware.BHO) -> Quarantined and deleted successfully.
C:Documents and Settings
ochelleApplication DataalotErrorSearch (Adware.BHO) -> Quarantined and deleted successfully.
C:Documents and Settings
ochelleApplication DataalotpostInstallLayout (Adware.BHO) -> Quarantined and deleted successfully.
C:Documents and Settings
ochelleApplication Dataalotproducts (Adware.BHO) -> Quarantined and deleted successfully.
C:Documents and Settings
ochelleApplication DataalotProduct_0 (Adware.BHO) -> Quarantined and deleted successfully.
C:Documents and Settings
ochelleApplication DataalotProduct_1 (Adware.BHO) -> Quarantined and deleted successfully.
C:Documents and Settings
ochelleApplication DataalotProduct_2 (Adware.BHO) -> Quarantined and deleted successfully.
C:Documents and Settings
ochelleApplication DataalotProduct_3 (Adware.BHO) -> Quarantined and deleted successfully.
C:Documents and Settings
ochelleApplication DataalotProduct_4 (Adware.BHO) -> Quarantined and deleted successfully.
C:Documents and Settings
ochelleApplication DataalotProduct_5 (Adware.BHO) -> Quarantined and deleted successfully.
C:Documents and Settings
ochelleApplication DataalotProduct_6 (Adware.BHO) -> Quarantined and deleted successfully.
C:Documents and Settings
ochelleApplication DataalotResources (Adware.BHO) -> Quarantined and deleted successfully.
C:Documents and Settings
ochelleApplication DataalotResourcesImages (Adware.BHO) -> Quarantined and deleted successfully.
C:Documents and Settings
ochelleApplication DataalotTimerManager (Adware.BHO) -> Quarantined and deleted successfully.
C:Documents and Settings
ochelleApplication DataalotToolbarSearch (Adware.BHO) -> Quarantined and deleted successfully.
C:Documents and Settings
ochelleApplication DataalotUpdater (Adware.BHO) -> Quarantined and deleted successfully.
C:Documents and SettingsmarkApplication Dataalot (Adware.BHO) -> Quarantined and deleted successfully.

Files Infected:
C:Program Filesalotinalot.dll (Adware.BHO) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearchar.binMWSOEPLG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMSN Messenger
iched20.dll (Adware.MyWeb.FunWeb) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearchar.binF3WPHOOK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearchar.binF3IMSTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearchar.binF3PSSAVR.SCR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearchar.binF3REPROX.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearchar.binF3RESTUB.DLL (Adware.MyWeb.FunWeb) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearchar.binF3SCHMON.EXE (Adware.MyWeb.FunWeb) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearchar.binM3IDLE.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearchar.binM3IMPIPE.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearchar.binM3PLUGIN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearchar.binM3SKPLAY.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearchar.binM3SLSRCH.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearchar.binNPMYWEBS.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesInternet Explorermsimg32.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMozilla FirefoxpluginsNPMyWebS.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:System Volume Information_restore{97A1C656-A449-41F1-A783-48C181351814}RP3A0002057.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:System Volume Information_restore{97A1C656-A449-41F1-A783-48C181351814}RP3A0002058.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:System Volume Information_restore{97A1C656-A449-41F1-A783-48C181351814}RP3A0002059.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:System Volume Information_restore{97A1C656-A449-41F1-A783-48C181351814}RP3A0002060.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:System Volume Information_restore{97A1C656-A449-41F1-A783-48C181351814}RP3A0002061.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:System Volume Information_restore{97A1C656-A449-41F1-A783-48C181351814}RP3A0002062.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:System Volume Information_restore{97A1C656-A449-41F1-A783-48C181351814}RP3A0002063.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:System Volume Information_restore{97A1C656-A449-41F1-A783-48C181351814}RP3A0002064.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:System Volume Information_restore{97A1C656-A449-41F1-A783-48C181351814}RP3A0002066.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:System Volume Information_restore{97A1C656-A449-41F1-A783-48C181351814}RP3A0002067.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:System Volume Information_restore{97A1C656-A449-41F1-A783-48C181351814}RP3A0002068.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:System Volume Information_restore{97A1C656-A449-41F1-A783-48C181351814}RP3A0002069.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:System Volume Information_restore{97A1C656-A449-41F1-A783-48C181351814}RP3A0002070.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:System Volume Information_restore{97A1C656-A449-41F1-A783-48C181351814}RP3A0002071.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:System Volume Information_restore{97A1C656-A449-41F1-A783-48C181351814}RP3A0002072.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:System Volume Information_restore{97A1C656-A449-41F1-A783-48C181351814}RP3A0002065.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:WINDOWSsystem32 3PSSavr.scr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearchar.binF3BKGERR.JPG (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearchar.binF3SPACER.WMV (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearchar.binF3WALLPP.DAT (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearchar.binM3FFXTBR.JAR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearchar.binM3FFXTBR.MANIFEST (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearchar.binM3NTSTBR.JAR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearchar.binM3NTSTBR.MANIFEST (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharAvatarCOMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharCache5E086.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharCache5E26A.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharCache5F026.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharCache5F1BC.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharCache5F3B0.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharCache3F902 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharCache
F4227 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharCache
F4489.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharCache
F466D.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharCache
36AA0.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharCache
37703.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharCache iles.ini (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharGameCHECKERS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharGameCHESS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharGameREVERSI.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharHistorysearch2 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearchariconsCM.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearchariconsMFC.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearchariconsPSS.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearchariconsSMILEY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearchariconsWB.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearchariconsZWINKY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharMessageCOMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharNotifierCOMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharNotifierDOG.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharNotifierFISH.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharNotifierKUNGFU.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharNotifierLIFEGARD.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharNotifierMAID.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharNotifierMAILBOX.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharNotifierOPERA.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharNotifierROBOT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharNotifierSEDUCT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharNotifierSURFER.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharSettingsprevcfg2.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesMyWebSearcharSettingss_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesFunWebProductsScreenSaverImages

Answer
Hi Chelle

It seems you log was cut short, but I see that Malwarebytes has deleted a great deal of malware from your computer.  Give me an update on how the computer is running.  Also post me a new HijackThis log.  When the scan opens in notepad, please make sure that Word Wrap checked.  Click Format in the menu bar and see that Word Wrap has a check next to it.  Otherwise, your log files will be unreadable.  Thanks.

Brian

Add to this Answer    Ask a Question



  Rate this Answer
   Was this answer helpful?
Not at allDefinitely              
   12345  

     
About Us | Advertise on This Site | User Agreement | Privacy Policy | Help
Copyright  © 2008 About, Inc. About and About.com are registered trademarks of About, Inc. The About logo is a trademark of About, Inc. All rights reserved.