PC very slow....

Solved/Closed
baby jane Posts 72 Registration date Sunday March 28, 2010 Status Member Last seen January 3, 2012 - Oct 24, 2010 at 01:56 PM
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 - Oct 31, 2010 at 04:25 AM
Hello,

I don't know what happened to my laptop, last time the problem was it cannot connect to the internet, then it was fixed by my roommate who happens to be an IT. unfortunately after that, my PC becomes very slow... i can't even attached a single attachment on the email that im working with. I tried cleaning my pc thru comodo cleaner, i tried open disk clean-up also scanning for viruses and even defragmenting my hard drive. What can I do then??? I can't even load my family feud game in Facebook because of that??? It will just show a blank page unlike before that i used to play it. Also it takes 1-2 minutes just to load a new tab or browser that i am opening... PLS HELP!!!

PLSSSSSSSSSSSSSSSSSSS!!!
Related:

14 responses

Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,172
Oct 25, 2010 at 05:14 AM
Hello Baby,

Well, I am afraid that your system is infected and in my opinion there is an malicious process running that should not be running at boot time

Please follow the following procedure carefully and to the letter.

You must kill the evil processes which the virus is presently running and preventing you from running Hyjackthis. If you don't, it will keep reproducing the files for ever.

To kill the processes:

1. Download to your desktop and run Rogue Kill:

https://download.bleepingcomputer.com/grinler/rkill.com

2. You should now see a window that shows all of your desktop icons, including the rkill.com program.

3. Double-click on the rkill.com in order to automatically attempt to stop any processes associated with the virus. Please be patient while the program looks for various malware programs and ends them. When it has finished, the black window will automatically close and you can continue with the next step.

If you get a message that rkill is an infection, do not be concerned. This message is just a fake warning given by the s when it terminates programs that may potentially remove it. If you run into these infections warnings that close Rkill, a trick is to leave the warning on the screen and then run Rkill again. By not closing the warning, this typically will allow you to bypass the malware trying to protect itself so that rkill can terminate the processes . So, please try running Rkill until malware is no longer running.

As a matter of a fact, if you get messages, it is a sign that the virus is agonizing with excrutiating pain, so you can just grin while it is suffering!:)))

Please, DO NOT REBOOT your computer or the processes will come back to haunt you!

Download to your desktop Malwarebyte.

https://ccm.net/downloads/security-and-maintenance/4621-malwarebytes-anti-malware/

Once on your desktop, we must still outwit the virus.

Right click on the MBAM icon and click on rename. Rename it kioskea.exe.

Install Malwarebyte and launch it. From the second tab, update it.

Pretty please, request a FULL system scan which should take more than hour. Once the scan is finish, delete all of item that were found.

Let me know the result because after this problem is solve, I have another tip to make your system run faster.

Regards
3
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,172
Oct 24, 2010 at 04:17 PM
Hello

To fix the problem, I must have a Hyjacthis log. You may have nasty processes running.

http://free.antivirus.com/hijackthis/

Please download, install and request a scan and save a log. Copy the log and post it here.

Regards
2
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,172
Oct 28, 2010 at 04:48 PM
Baby,

Your system is still infected

Please run another Hyjackthis scan but do not request a log because we do not need it.

Once the scan is over, you must check the items listed. Once all checked, click on fix checked and close Hyjackthis.

You must then run another FULL Malwarebyte scan. Here are the items you must check:

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/

R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL

O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL

O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL

O2 - BHO: (no name) - {5b0a01d2-b8a0-4e56-9e6b-cba0ef4b4eb5} - (no file)

O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)

O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)

O3 - Toolbar: (no name) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)

O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL

O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=2 /w /h

O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe

O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe

O9 - Extra button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - (no file)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe (file missing)

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe (file missing)

O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe

Please, never go back to "My Web Search" again who you will be returning to the Virus/Security forum for help.

I would also install a better antivirus programme then the one you have. You will find them in Kioskea's download section.

Let me know
1
baby jane Posts 72 Registration date Sunday March 28, 2010 Status Member Last seen January 3, 2012
Oct 28, 2010 at 06:01 PM
can u tell me what anti-virus are u referring to? I am currently scanning the PC thru malwarebytes..
once it's finish i'll let u know...
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,172
Oct 30, 2010 at 05:35 AM
I'm back!

Please run another Hyjackthis log no scan and check the following items. After you have checked them, click on fix checked.

Close Hyjackthis, reboot your machine and tell me if it is faster.

Here are the items:

O1 - Hosts: ::1 localhost

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll

O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll

O2 - BHO: SimpleAdblock Class - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files\Common Files\Simple Adblock\SimpleAdblock.dll

O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll

O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll

O4 - Global Startup: Bluetooth.lnk = ?

O23 - Service: My Web Search Service (MyWebSearchService) - Unknown owner - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe (file missing)

P.S. You know that application you add smileys with? Well they are often infected. Also, as I suggested before, stay away from "My Web Search"
1
baby jane Posts 72 Registration date Sunday March 28, 2010 Status Member Last seen January 3, 2012
Oct 30, 2010 at 05:45 AM
hi i alredy fixed it but i tried ti do a scan again why O23 is always there???
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,172
Oct 30, 2010 at 05:54 AM
It was a good idea to have run another scan.
That what I noticed too that it was still there and that 023 in particular is very nasty and it is the one which is slowing down everything.
Let me look into my bag of tricks for a moment and as General McArthur once said: 'I shall return!"
...soon
0
Well what about trying ComboFix to see if it removes it bug in her computer maybe an hope for it to work?
0
baby jane Posts 72 Registration date Sunday March 28, 2010 Status Member Last seen January 3, 2012
Oct 30, 2010 at 05:59 AM
am will i find that combofix in kioskea also??? by the way i still remember u will tell me a better antivirus that the one im using, what is it???
0
baby jane Posts 72 Registration date Sunday March 28, 2010 Status Member Last seen January 3, 2012
Oct 30, 2010 at 06:02 AM
i think my english right now is not good hahahha... what i mean is, where will i find that combofix? and what anti-virus u can recommend that is better than the one im using...
0

Didn't find the answer you are looking for?

Ask a question
baby jane Posts 72 Registration date Sunday March 28, 2010 Status Member Last seen January 3, 2012
Oct 25, 2010 at 04:04 AM
Hi,

I was trying run the hijack this but it says my system is denying this to run, i tried to do the recommended action run it as administrator but i cant find a way to run it like that because whenever im trying to right-click theres no option to run it as administrator...
0
baby jane Posts 72 Registration date Sunday March 28, 2010 Status Member Last seen January 3, 2012
Oct 25, 2010 at 06:10 AM
can u send me another link for rogue kill??? because currently i'm in UAE and the website u gave me is currently blocked in this country...
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,172
Oct 25, 2010 at 06:25 AM
Dear Jane,

Why on earth would they block a direct link like this one? There is nothing there that would compromise UAE's stability and it does not contain porc! The link I have given you get you directly to the download panel. RKill is exclusive to Bleeping Computer so I have no other links to it.

See if you can at least run Malwarebyte.
0
baby jane Posts 72 Registration date Sunday March 28, 2010 Status Member Last seen January 3, 2012
Oct 25, 2010 at 08:37 AM
it said that it is infected by 3 objects one is riskware tool, malware trace and trojan fake.... the it gave this log after i deleted it:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4941

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18943

10/25/2010 5:35:58 PM
mbam-log-2010-10-25 (17-35-58).txt

Scan type: Full scan (C:\|D:\|I:\|)
Objects scanned: 271661
Time elapsed: 1 hour(s), 38 minute(s), 5 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\QZAIB7KITK (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
I:\program installer\Microsoft office 2007\Keygen\msoe2007kg.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
0
baby jane Posts 72 Registration date Sunday March 28, 2010 Status Member Last seen January 3, 2012
Oct 25, 2010 at 08:49 AM
Hi,
I've just sent u the copy of the log and found out that there is 3 infections 1) malware trace 2) trojan fake 3) i forgot ... but then after i deleted the said infections it says that i need to restart the computer i dont know why it isnt send to u now i dont know where to find the said log again so i can show it to u....
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,172
Oct 25, 2010 at 04:12 PM
Hello Jane,

Okay I got the log

The culprit is here:

I:\program installer\Microsoft office 2007\Keygen\msoe2007kg.exe (RiskWare.Tool.CK) ->

A key generator

How is your system now?
0
baby jane Posts 72 Registration date Sunday March 28, 2010 Status Member Last seen January 3, 2012
Oct 26, 2010 at 07:08 AM
Hi,

Sorry im really not good in this... but what am i going to do with this??? I:\program installer\Microsoft office 2007\Keygen\msoe2007kg.exe (RiskWare.Tool.CK) ->
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,172
Oct 26, 2010 at 04:51 PM
There is nothing to do, it was deleted.

How is your system behaving now.
0
baby jane Posts 72 Registration date Sunday March 28, 2010 Status Member Last seen January 3, 2012
Oct 26, 2010 at 11:34 PM
but i still need help, its speed is now improved however still takes time doing like uploading pics in facebook, can't even play family feud, internet cannot open the webpage... and i need to reset some applications 3x before it will work.... any tips for this matter????
0
baby jane Posts 72 Registration date Sunday March 28, 2010 Status Member Last seen January 3, 2012
Oct 27, 2010 at 12:38 AM
by the way whenever im playing a game aapplication for example in facebook this error always occur... Error: Error #2134: Cannot create SharedObject.
at flash.net::SharedObject$/getLocal()
at XdComm/get cache()
at XdComm/get contextCache()
at XdComm/getCache()
at Function/http://adobe.com/AS3/2006/builtin::apply(
at flash.external::ExternalInterface$/_callIn()
at Function/<anonymous>()
what's this supposed to mean???
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,172
Oct 27, 2010 at 04:19 AM
Sorry Baby Jane
But video games are out of my sphere of influence. I would start a new thread about the subject.

As for speed, you may need more ram so some useless applications may be running in the background at boot time.

I suggest you run the following applications, if of course UAE will not consider them as threat to their security

https://ccm.net/downloads/security-and-maintenance/4555-ccleaner/

https://www.eusing.com/free_registry_cleaner/registry_cleaner.htm

https://www.malwarebytes.com/mwb-download/

Last but not least defragment your hard disk.

Best regards
0
Gervarod Posts 306 Registration date Saturday March 27, 2010 Status Member Last seen June 8, 2014 21
Oct 26, 2010 at 08:27 PM
Hello, Ambucias hope you don't mind me butting in and giving the person a little tip on the Key Generators thanks.


Hell Baby Jane, as for Key Generators do not download them as they may contain Malware, Worms and viruses in them. People out there say they are safe to use but when you think about it that a key gen is made by a person and wants people out there to download it so he can get control over your computer and still information like passwords accounts and any Credit card numbers you use to buy stuff over the net, so the best way to keep safe too is not to down load the Key Gens just to get the full version of the program. But what Anti-Virus are you using if so it should pick up the key gen as an trojan a worm or an virus then.

So the key Gen you got on it that malwarebytes found on it that Microsoft office 2007 RiskWare was an Scareware to get you to pay for a product that tells you that you need better protection to remove this virus or trojan but that's what i mean they steal your credit card information on you.

Hope that i told you a little on about the Key Gens that you should never download them at all.


Cheers, Gervarod
0
baby jane Posts 72 Registration date Sunday March 28, 2010 Status Member Last seen January 3, 2012
Oct 26, 2010 at 11:34 PM
thanks.. but i still need help, its speed is now improved however still takes time doing like uploading pics in facebook, can't even play family feud, internet cannot open the webpage... and i need to reset some applications 3x before it will work.... any tips for this matter????
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,172
Oct 27, 2010 at 04:23 AM
Hello Gervarod,

Your butt in is most appropriate, wise and well put!
0
Gervarod Posts 306 Registration date Saturday March 27, 2010 Status Member Last seen June 8, 2014 21
Oct 27, 2010 at 11:06 AM
Ok then Baby Jane can you do an online virus scan for me from Trend Micro but this is free to use here's the link which you are able to get to and download the program which is called Trend Micro house call online scan. OK but please download the 32 bit as your OS is VISTA...

https://www.trendmicro.com/en_us/forHome/products/housecall.html

and let us know how it went on finding any bugs on it.
0
baby jane Posts 72 Registration date Sunday March 28, 2010 Status Member Last seen January 3, 2012
Oct 27, 2010 at 12:52 PM
there's no threat bu tthe system is still slow... compared before..
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,172
Oct 27, 2010 at 04:19 PM
- Baby did you do as I suggested?

- Gervarod, Malwarebyte cleaned the system but because Baby cannot run Hyjackthis, we cannot help her to remove some of the molasses, they only do is try to speed the system by increasing ram but we will not be able to speed her Internet connection.
0
baby jane Posts 72 Registration date Sunday March 28, 2010 Status Member Last seen January 3, 2012
Oct 28, 2010 at 05:59 PM
can someone pls tell me what is the meaning of this??? Whenever I am opening a certain application this error message is continuously popping...
Message was from Adobe Flash Player 10 message was:

Error: Error #2134: Cannot create SharedObject.
at flash.net::SharedObject$/getLocal()
at XdComm/get cache()
at XdComm/get contextCache()
at XdComm/getCache()
at Function/http://adobe.com/AS3/2006/builtin::apply(
at flash.external::ExternalInterface$/_callIn()
at Function/<anonymous>()
0
Gervarod Posts 306 Registration date Saturday March 27, 2010 Status Member Last seen June 8, 2014 21
Oct 28, 2010 at 08:18 PM
Hello Baby hers to info for you.

Error #2134: Cannot create SharedObject when trying to edit (Ctrl+E) in InContext Editing

* Comments (0)
*
Ratings:0

Issue
You receive the error "Error #2134: Cannot create SharedObject" when you press Ctrl+E to edit a page in InContext Editing, and cannot enter the editing environment.
Reason
The "Allow third-party Flash content to store data on your computer" checkbox is unchecked and the slider is set to 0 in the Global Storage Settings panel of your Adobe Flash Player Settings Manager. You are using the debug version of the Flash Player.
Solution

1. Go to the Adobe Flash Player Settings Manager Global Storage Settings panel.
2. Move the slider to a setting other than 0.
3. Check the Allow third-party Flash content to store data on your computer checkbox.

Additional Information
When the "Allow third-party Flash content to store data on your computer" checkbox is unchecked, and the slider is set to 0 in the Global Storage Settings for your installation of the Flash Player, InContext Editing is unable to store content required to enter the editing environment.

let us know how you went ok.
0
Gervarod Posts 306 Registration date Saturday March 27, 2010 Status Member Last seen June 8, 2014 21
Oct 29, 2010 at 09:12 AM
your OS is Vista right but what have you got in your computer that makes it run like how much RAM and what is your processor in it and what is inside it too. to find out what you got just go and type in system information in the search bar where you close it down and copy that and paste it here ok then.
0
baby jane Posts 72 Registration date Sunday March 28, 2010 Status Member Last seen January 3, 2012
Oct 29, 2010 at 10:26 AM
Hi,

Can u simplify your instructions??? actually im not very familiar in system info, like where to find that one...plssss... ang just an hour ago my laptop cannot connect to the internet.. there's no problem with the router all in my laptop... just after i've done scanning thru malwarebytes... and still slow...
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,172
Oct 29, 2010 at 04:43 AM
Greetings to all,

There much too many people intervening on this thread and more than one problem being discussed at the same time.

I did my part with the virus.

It's all yours Gervarod.

Regards
0
baby jane Posts 72 Registration date Sunday March 28, 2010 Status Member Last seen January 3, 2012
Oct 29, 2010 at 05:37 AM
After everything I've done, hijackthis, malwarebytes, still my PC is much slower now... what will do then??? PLSSSSSSSSSSSSSS
0
baby jane Posts 72 Registration date Sunday March 28, 2010 Status Member Last seen January 3, 2012
Oct 29, 2010 at 10:26 AM
hi, I appreciate your help.... hope u will still extend your hand in still helping me...
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,172
Oct 29, 2010 at 03:48 PM
Slow? Please be specific as to when you find it slow doing what?
0
baby jane Posts 72 Registration date Sunday March 28, 2010 Status Member Last seen January 3, 2012
Oct 29, 2010 at 03:55 PM
everything is slow, in terms of opening a new browser, opening something, as in the wholw performance of the PC...
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,172
Oct 29, 2010 at 04:00 PM
How much ram do you have?
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,172
Oct 30, 2010 at 06:28 AM
Rarely is Malwarebyte not capable of deleting a My Websearch virus.

I think that I found the source, it is in the processes,

Please run another scan with Hyjackthis and check the following:

C:\Program Files\SweetIM\Messenger\SweetIM.exe

C:\Program Files\uTorrent\uTorrent.exe

C:\Windows\system32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

O1 - Hosts: ::1 localhost

O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL

O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll

O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe

O23 - Service: My Web Search Service (MyWebSearchService) - Unknown owner - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe (file missing)

Once you have finished, we should have killed the vicious process which should permit Malwarebyte to send the rest of the virus to the glue factory. So run another full Malwarebyte scan.

If you do not see an improvement, I will eat my brand new shirt and I will send you a very potent medicinal compound.
-1
baby jane Posts 72 Registration date Sunday March 28, 2010 Status Member Last seen January 3, 2012
Oct 30, 2010 at 07:49 AM
don't be silly hahahaha, hot sauce maybe the right sauce hehehe just kidding... dont worry about it, u've done a great and big help on all my PC problems so dont u worry.... besides everything seems to return on its original state... still waiting for the malwarebytes result.... have a nice day!!!
0
baby jane Posts 72 Registration date Sunday March 28, 2010 Status Member Last seen January 3, 2012
Oct 30, 2010 at 08:14 AM
Finally this is the result:


Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4941

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18975

10/30/2010 5:12:32 PM
mbam-log-2010-10-30 (17-12-32).txt

Scan type: Full scan (C:\|D:\|)
Objects scanned: 277031
Time elapsed: 1 hour(s), 39 minute(s), 38 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 14
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 15
Files Infected: 33

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\mywebsearch.multiplebutton (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.multiplebutton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.urlalertbutton (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.urlalertbutton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MyWebSearchService (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\WMSDK\Sources\f3popularscreensavers (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\funwebproducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts\ScreenSaver (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts\ScreenSaver\Images (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\chrome (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Avatar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Game (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Message (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Overlay (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files\MyWebSearch\bar\1.bin\CHROME.MANIFEST (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3BKGERR.JPG (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3IMSTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3SPACER.WMV (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3WALLPP.DAT (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\FWPBUDDY.PNG (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\INSTALL.RDF (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\chrome\M3FFXTBR.JAR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Avatar\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons\CM.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons\MFC.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons\PSS.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons\SMILEY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons\WB.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons\ZWINKY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Message\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\DOG.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\FISH.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\KUNGFU.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\LIFEGARD.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\MAID.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\MAILBOX.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\OPERA.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\ROBOT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\SEDUCT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\SURFER.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Overlay\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,172
Oct 30, 2010 at 03:39 PM
Jane,
Now that all of these malicious items have been removed, do you see an improvement in your speed, like there were a lot of them?
0
baby jane Posts 72 Registration date Sunday March 28, 2010 Status Member Last seen January 3, 2012
Oct 30, 2010 at 10:18 PM
yeas it is a lot better now... so u dont need to eat ur shirt no more.... hahahaha... by the way any software that will give an extra boost for my PC??? juz curious.... THANKS A LOT FOR EVERYTHING!!!
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,172
Oct 31, 2010 at 04:25 AM
Great,
Sorry, no such thing as speeding software but if you find it, let me know, I will use it myself,

Please remember to purchase an antivirus and to longer to put smileys and stay away from my web search.

Farewell
0