C:\Documents and Settings\Sylvie Langlais\Application Data\rhcc9kj0ev8v\Quarantine (Rogue.Multiple) -> No action taken. What do I do? C:\Documents and Settings\All Users\Bureau\Antivirus XP 2008.lnk (Rogue.Antivirus) -> No action taken. HKEY_CURRENT_USER\Control Panel\Desktop\convertedwallpaper (Hijack.Wallpaper) -> No action taken. https://www.bleepingcomputer.com/forums/t/154540/antivirus-xp-08/

C:\Documents and Settings\Chastity Burton\Local Settings\Temp\.ttE.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\Chastity Burton\Application Data\alot\Product_5\Product_5.xml (Adware.BHO) -> Quarantined and deleted successfully. C:\Program Files\MyWebSearch\SrchAstt (Adware.MyWebSearch) -> Delete on reboot.

This seems to be one of the bits of malware making the rounds lately. C:\Documents and Settings\Chastity Burton\Application Data\alot\configurator\configurator.xml.backup (Adware.BHO) -> Quarantined and deleted successfully. C:\Documents and Settings\Sylvie Langlais\Application Data\rhcc9kj0ev8v\Quarantine\Autorun\HKCU\RunOnce (Rogue.Multiple) -> No action taken. To do this, restart your computer and after hearing your computer beep once during startup [but before the Windows icon appears] press the F8 key repeatedly.

Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe O9 - Extra 'Tools' menuitem: Yahoo! Choose from the menu File => Standard scripts and mark the 3. It may take a while to get a response because the HJT Team members are very busy working logs posted before yours. https://forums.techguy.org/threads/i-too-have-been-duped-into-loading-this-antivirusxp08.737965/ C:\Documents and Settings\Chastity Burton\Application Data\alot\BrowserSearch\BrowserSearch.xml (Adware.BHO) -> Quarantined and deleted successfully.

I've done everything that the ''you must read this...' thread mentioned. I too have been duped into loading this AntivirusXP08 Discussion in 'Virus & Other Malware Removal' started by Tamer, Aug 7, 2008. HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Do I turn off the computer by forcing it or wait? I already gave the link to you at my previous instruction.. 0 #51 mbrikha Posted 01 August 2008 - 06:25 PM mbrikha Member Topic Starter Member 47 posts AhnLab-V3 2008.7.26.0 2008.07.28 HKEY_CLASSES_ROOT\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3} (Adware.MyWebSearch) -> Quarantined and deleted successfully. Download SDFix and save it to your desktop.

so just let them run.====STEP 1====Jotti File Submission:Please go to Jotti's malware scanCopy and paste the following file path into the "File to upload & scan"box on the top of the HKEY_CLASSES_ROOT\Interface\{07b18eaa-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-f3embed (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{3e53e2cb-86db-4a4a-8bd9-ffeb7a64df82} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

C:\Documents and Settings\Chastity Burton\Application Data\alot\Resources\Images\default_215_alot_music_freeradio.bmp (Adware.BHO) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{8e6f1830-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{e79dfbc9-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Program Files\MyWebSearch\bar\Notifier\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.

C:\Program Files\FunWebProducts\ScreenSaver (Adware.MyWebSearch) -> Quarantined and deleted successfully. It is. HKEY_CLASSES_ROOT\CLSID\{2eff3cf7-99c1-4c29-bc2b-68e057e22340} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{7473d292-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\funwebproducts.browseroverlaybarbutton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. If it encounters a file that is difficult to remove, you need to restart the computer so the malware can be fully removed. HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

scanning hidden autostart entries ...scanning hidden files ...