mikejamm
2010-09-01, 01:44
I was watching a baseball game on a site called ATDHE.net when my computer started automatically downloading some type of program called "antivirlock.com", something also downloaded saying "Sun microsystems or Java", I could not stop it and I immediately got all kinds of pop ups stating my computer was "infected" and I needed to purchase software from this company to repair it. It will not allow me to run Spybot search and destroy, saying it's infected too. I tried to open my windows programs to see if could uninstall whatever this is, but nothing comes up! I was using Firefox, but at one point only IE would come up and again the same message that my computer was infected. I was finally able to get Firefox to come back up so I could get to the forum to post. I've always used spybot, and my anti virus program is Avira Antivirus Personal, and Zone Alarm for a firewall. My system is a Dell, running Windows XP sevvice pack 3. Can someone please help me? Thanks, mike
Update, I read the "before you post" thread, I went and downloaded the ERUNT program, saved it to my desktop, but when I attempt to open it and run it, I'm getting the same fake window message from this virus or malware, that the ERUNT file is infected and do I want to activate my antivirus or security propgram now.
Also I've download and saved to my desktop the program to provide a DDS log, and again when I attempt to open or run the program, I'm getting a message stating "Application cannot be executed, rundll32 is infected" and another message states "dds.com is not a valid win32 application".
Please help, I don't know what to do! Thanks, mike
Also I keep getting pop ups in IE for porn sites! I've attempted to bring up IE so I can go to windows update to see if I have missed any, even though I've always had my computer set to receive automatic updates. I don't visit porn or gambling sites and have always kept my computer up to date with any software I'm using.
I've rebooted my computer several times, and I was able to run spybot before the fake pop ups started again. It found 1 Malware and I removed it and saved a log of it. I'm still not able to get into add or remove programs, it comes up for a second and then disappears! Also I can't bring up windows task manger to try and shut this rouge program down. Will somebody please respond, I need my computer because I use it to work from home. Thanks, mike
Another update to my problem. When I restarted my computer this morning, I clicked on the ERUNT program before anything else had a chance to load and was able to back up my system. It's weird, because if I click on something before the rouge virus or malware pop ups start to come up, I'm able to run that program. The virus or malware has installed an icon in my task bar and continues to pop up saying my computer is infected. I haven't clicked on it, because when I did the first time, the rouge program started a scan of my system and I was unable to stop it! I'm using Firefox to post and it seems to be the only thing not affected by this. Every few minutes or so though, IE will pop up with a page to porn site. I rebooted and quickly clicked on Spybot and ran the Immunize feature, it protected everything in Firefox but left 58320 things unprotected in IE. Again, I'm just trying to provide as much information as possible and any help would be greatly appreciated.
Update 9/01/10, 3:26AM. I was doing some reading in the forums, so maybe I can get a handle on what's wrong with my computer. I didn't download or run ComboFix because it was stated not to do so unless advised. I did download and was able to run Malwarebytes' Anti-Malware, only after doing what I stated earlier, rebooting my computer and clicking on the program before the malware and / or fake virus warning pop ups began. I had attempted to run the program after windows had loaded once, just to see if it would, and again after clicking on the desktop icon, a pop up stated that Malwarebytes' was "infected" and would not run. I rebooted, click the icon right as it came on the screen and was able to start the scan. I made three separate scans and have posted the logs from each one here. The first and second scans appear to have found several bad trojans, with the third one I think comming up clean.
At last some success! The rouge virus or malware icon is gone from my task bar and the IE pop ups for porn sites have stopped. I'm still not able to get IE to load, so I'm not able to go to windows update to check if my system is missing any critical updates. When I click the IE icon, it acts like it wants to load, but I get the standard "IE cannot display the web page' message. I've tried clicking on the "Diagnose connection problems", but nothing happens.
Also, neither dds.com nor dds.scr programs will launch, the icons are on my desktop but a click on either one results in the same message, "dds.com is not a valid windows32 application".
I rebooted my system again and this time was able to run a full scan of SpybotS&D "after" windows completely loaded and it came up clean. The Immunize feature again protected everything in Firefox, but still left 58320 items unprotected in IE.
I really could use some help in finding out why IE won't load and whether I still have viruses, rootkits, and malware on my system. I'm in fear of visiting any site where I have to divulge any passwords or personal information, because I'm sure there is still a problem. Something really nasty go into my system and I'm very concerned. I've always practiced safe computing and was kinda shocked that this happened to me!
Here a the results of the Malwarebytes' three scans:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org (http://www.malwarebytes.org)
Database version: 4052
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
8/31/2010 6:33:32 AM
mbam-log-2010-08-31 (06-33-32).txt
Scan type: Full scan (C:\|D:\|E:\|)
Objects scanned: 217609
Time elapsed: 1 hour(s), 4 minute(s), 12 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 24
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{98279c38-de4b-4bcf-93c9-8ec26069d6f4} (Adware.SelectRebates) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4d25f926-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{98279c38-de4b-4bcf-93c9-8ec26069d6f4} (Adware.SelectRebates) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2eff3cf7-99c1-4c29-bc2b-68e057e22340} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{a6573479-9075-4a65-98a6-19fd29cf7374} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{98279c38-de4b-4bcf-93c9-8ec26069d6f4} (Adware.SelectRebates) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Scan #2
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org (http://www.malwarebytes.org)
Database version: 4513
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
8/31/2010 9:51:55 PM
mbam-log-2010-08-31 (21-51-55).txt
Scan type: Full scan (C:\|E:\|)
Objects scanned: 237741
Time elapsed: 1 hour(s), 3 minute(s), 9 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
C:\Documents and Settings\mike\Local Settings\Application Data\mhhyhptwk\panwodishdw.exe (Trojan.FakeAlert) -> Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\knaluxfm (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Documents and Settings\mike\Local Settings\Application Data\mhhyhptwk\panwodishdw.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\mike\Local Settings\Temp\7144621.109706226.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Scan #3
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org (http://www.malwarebytes.org)
Database version: 4518
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
9/1/2010 2:15:02 AM
mbam-log-2010-09-01 (02-15-02).txt
Scan type: Full scan (C:\|D:\|E:\|)
Objects scanned: 235079
Time elapsed: 1 hour(s), 6 minute(s), 6 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
--------------------------
Edit
Posting additional comments or logs before a volunteer responds, can push you back instead of forward, because your thread ends up with a newer date. In addition helpers would think you are already being assisted because of the post count, they look for topics with a 0 response. For that reason we may merge such posts but please do not count on it. "BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)
Update, I read the "before you post" thread, I went and downloaded the ERUNT program, saved it to my desktop, but when I attempt to open it and run it, I'm getting the same fake window message from this virus or malware, that the ERUNT file is infected and do I want to activate my antivirus or security propgram now.
Also I've download and saved to my desktop the program to provide a DDS log, and again when I attempt to open or run the program, I'm getting a message stating "Application cannot be executed, rundll32 is infected" and another message states "dds.com is not a valid win32 application".
Please help, I don't know what to do! Thanks, mike
Also I keep getting pop ups in IE for porn sites! I've attempted to bring up IE so I can go to windows update to see if I have missed any, even though I've always had my computer set to receive automatic updates. I don't visit porn or gambling sites and have always kept my computer up to date with any software I'm using.
I've rebooted my computer several times, and I was able to run spybot before the fake pop ups started again. It found 1 Malware and I removed it and saved a log of it. I'm still not able to get into add or remove programs, it comes up for a second and then disappears! Also I can't bring up windows task manger to try and shut this rouge program down. Will somebody please respond, I need my computer because I use it to work from home. Thanks, mike
Another update to my problem. When I restarted my computer this morning, I clicked on the ERUNT program before anything else had a chance to load and was able to back up my system. It's weird, because if I click on something before the rouge virus or malware pop ups start to come up, I'm able to run that program. The virus or malware has installed an icon in my task bar and continues to pop up saying my computer is infected. I haven't clicked on it, because when I did the first time, the rouge program started a scan of my system and I was unable to stop it! I'm using Firefox to post and it seems to be the only thing not affected by this. Every few minutes or so though, IE will pop up with a page to porn site. I rebooted and quickly clicked on Spybot and ran the Immunize feature, it protected everything in Firefox but left 58320 things unprotected in IE. Again, I'm just trying to provide as much information as possible and any help would be greatly appreciated.
Update 9/01/10, 3:26AM. I was doing some reading in the forums, so maybe I can get a handle on what's wrong with my computer. I didn't download or run ComboFix because it was stated not to do so unless advised. I did download and was able to run Malwarebytes' Anti-Malware, only after doing what I stated earlier, rebooting my computer and clicking on the program before the malware and / or fake virus warning pop ups began. I had attempted to run the program after windows had loaded once, just to see if it would, and again after clicking on the desktop icon, a pop up stated that Malwarebytes' was "infected" and would not run. I rebooted, click the icon right as it came on the screen and was able to start the scan. I made three separate scans and have posted the logs from each one here. The first and second scans appear to have found several bad trojans, with the third one I think comming up clean.
At last some success! The rouge virus or malware icon is gone from my task bar and the IE pop ups for porn sites have stopped. I'm still not able to get IE to load, so I'm not able to go to windows update to check if my system is missing any critical updates. When I click the IE icon, it acts like it wants to load, but I get the standard "IE cannot display the web page' message. I've tried clicking on the "Diagnose connection problems", but nothing happens.
Also, neither dds.com nor dds.scr programs will launch, the icons are on my desktop but a click on either one results in the same message, "dds.com is not a valid windows32 application".
I rebooted my system again and this time was able to run a full scan of SpybotS&D "after" windows completely loaded and it came up clean. The Immunize feature again protected everything in Firefox, but still left 58320 items unprotected in IE.
I really could use some help in finding out why IE won't load and whether I still have viruses, rootkits, and malware on my system. I'm in fear of visiting any site where I have to divulge any passwords or personal information, because I'm sure there is still a problem. Something really nasty go into my system and I'm very concerned. I've always practiced safe computing and was kinda shocked that this happened to me!
Here a the results of the Malwarebytes' three scans:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org (http://www.malwarebytes.org)
Database version: 4052
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
8/31/2010 6:33:32 AM
mbam-log-2010-08-31 (06-33-32).txt
Scan type: Full scan (C:\|D:\|E:\|)
Objects scanned: 217609
Time elapsed: 1 hour(s), 4 minute(s), 12 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 24
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{98279c38-de4b-4bcf-93c9-8ec26069d6f4} (Adware.SelectRebates) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4d25f926-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{98279c38-de4b-4bcf-93c9-8ec26069d6f4} (Adware.SelectRebates) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2eff3cf7-99c1-4c29-bc2b-68e057e22340} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{a6573479-9075-4a65-98a6-19fd29cf7374} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{98279c38-de4b-4bcf-93c9-8ec26069d6f4} (Adware.SelectRebates) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Scan #2
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org (http://www.malwarebytes.org)
Database version: 4513
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
8/31/2010 9:51:55 PM
mbam-log-2010-08-31 (21-51-55).txt
Scan type: Full scan (C:\|E:\|)
Objects scanned: 237741
Time elapsed: 1 hour(s), 3 minute(s), 9 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
C:\Documents and Settings\mike\Local Settings\Application Data\mhhyhptwk\panwodishdw.exe (Trojan.FakeAlert) -> Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\knaluxfm (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Documents and Settings\mike\Local Settings\Application Data\mhhyhptwk\panwodishdw.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\mike\Local Settings\Temp\7144621.109706226.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Scan #3
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org (http://www.malwarebytes.org)
Database version: 4518
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
9/1/2010 2:15:02 AM
mbam-log-2010-09-01 (02-15-02).txt
Scan type: Full scan (C:\|D:\|E:\|)
Objects scanned: 235079
Time elapsed: 1 hour(s), 6 minute(s), 6 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
--------------------------
Edit
Posting additional comments or logs before a volunteer responds, can push you back instead of forward, because your thread ends up with a newer date. In addition helpers would think you are already being assisted because of the post count, they look for topics with a 0 response. For that reason we may merge such posts but please do not count on it. "BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)