Turn off System Restore.
Go to Add/Remove Programs in your Control Panel and remove (if present):
Oemji
WeatherBug
For every User listed under C:\Documents and Settings, delete the entire contents of these folders (not the folders themselves):
Local Settings\Temp
Cookies
History
Local Settings\Temporary Internet Files\Content.IE5
Delete the entire contents of your C:\Windows\Temp folder.
Delete the entire contents of your C:\Temp folder (if you have one).
Do a search for
*.tmp and delete all entries found.
Go to
Start,
Run, and type in
cleanmgr, and then click
OK. Select the drive XP is on, and check the boxes for
Downloaded Program Files (move any files you wish to keep out of this folder first),
Temporary Internet Files,
Recycle Bin,
Temporary Files,
Temporary Offline Files,
Offline Files, (and
Compress old files &
Catalog files for the Content Indexer if you wish), and then click
OK. Click
Yes to confirm you want these files deleted. It may take awhile for this to run, please be patient.
Note: if any of these temporary files cannot be deleted while in normal mode, try Safe Mode.
Download, install, update, and run PurityScan uninstaller --
http://www.purityscan.com/uninstall.html
Scan with hijackthis and have it fix the following entries:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.oemji.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.oemji.com/side_search.html
O2 - BHO: OemjiSearchPlus - {D240DC29-C093-4388-B71F-A7103C796B0C} - C:\Program Files\Oemji\OemjiSearchPlus\OemjiPls.dll
O3 - Toolbar: Oemji - {804DB5C7-31E6-4885-850A-F1941B58A4C7} - C:\Program Files\Oemji\Toolbar\OemjiSrc.dll
O15 - Trusted Zone: *.media-motor.net (if you did not put this in your Trusted Zone yourself)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?lin...467&clcid=0x409
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://appldnld.m7z.net/content.inf...iTunesSetup.exe
O16 - DPF: {7149E79C-DC19-4C5E-A53C-A54DDF75EEE9} -
http://cabs.media-motor.net/cabs/alien.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/...all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) -
http://www3.ca.com/securityadvisor/...nfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} (AIM UPF Control) -
http://pictures04.aim.com/ygp/aol/p...AIM.9.5.1.8.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/M...pDownloader.cab
O16 - DPF: {B8E71371-F7F7-11D2-A2CE-0060B0FB9D0D} (CDToolCtrl Class) -
http://free.aol.com/tryaolfree/cdt175/aolcdt175.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) -
http://ax.phobos.apple.com.edgesuit.../ITDetector.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://download.games.yahoo.com/gam...aploader_v6.cab
Remember to close any open windows, other then hijackthis, before hitting
Fix checked.
Reboot into Safe Mode.
Go to the following locations and delete the highlighted files and folders (if present):
C:\WINDOWS\
imgthin.exe
C:\WINDOWS\Downloaded Program Files\
clientax.dll
C:\WINDOWS\Downloaded Program Files\
m67m.ocx
C:\WINDOWS\SYSTEM32\
f3PSSavr.scr
C:\WINDOWS\
tmpcpyis.bat
C:\Program Files\
Oemji
C:\Program Files\
AWS
Scan with Ewido.
Reboot normally and empty your Recycle Bin.
Close any open browser windows, scan with hijackthis, and post a new log along with the new Ewido log.