View Single Post
Old 08-17-2005, 07:42 AM   #5 (permalink)
sUBs
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
 
sUBs's Avatar
 
Join Date: May 2005
Posts: 24,353
OS: N/A


Go to Control Panel > Add/Remove programs. If you have this entry, uninstal the program:

My WebSearch



CLOSE ALL OTHER PROGRAMS & ALL OPENED WINDOWS

Run a scan with HiJackThis & select/tick the following & click "Fix checked" :

O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZN


If you have not done so already, please enable the viewing of Hidden files
  1. From Windows Explorer, go to Tools>Folder Options> View tab.
  2. Enable the option for Show hidden files and folder
  3. Disable the option for Hide file extensions for known types
  4. Disable the option for Hide protected operating system files
  5. Click Yes to confirm & then click OK
Locate and delete the following file(s), if present:
  • C:\WINDOWS\smdat32m.sys
    C:\WINDOWS\usta33.ini

  1. Go to Start> Run - type cleanmgr (this starts Windows DiskCleanup)
  2. Select Drive C: & click the 'OK' button
  3. Select the following options:
    • Temporary Internet Files
    • Recycle Bin
    • Temporary Files
  4. Click the 'OK' button

Reboot & Perform an online scan with Internet Explorer with Kaspersky WebScanner

Next Click on Launch Kaspersky Anti-Virus Web Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    • Standard
    • Scan Options:
    • Scan Archives
      Scan Mail Bases
  • Click OK
  • Now under select a target to scan:
    • Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
Take note the names and locations of any file it detects but fails to clean.
* Turn off the real time scanner of any existing antivirus program while performing the online scan


After that, post the following logs:

Online scan
HijackThis log


Tell me how the machine is behaving now
__________________

Question - what have you done for the community today?
sUBs is offline