Ok, first of all,
Do the following, With all browsers CLOSED. Go to Add/Remove
Look for and Uninstall ALL of the following that you may find there:
FunWebProducts.
* My Web Search (Smiley Central or FWP product as applicable)
* My Way Speedbar (Smiley Central or other FWP as applicable)
* My Way Speedbar (AOL and Yahoo Messengers
) (beta users only)
* My Way Speedbar (Outlook, Outlook Express, and IncrediMail)
* Search Assistant - My Way
You also need to STOP from running at start up and therefore running in the background, Windows Defender, SuperANTISPYWARE and AdAware. If possible do this from within the programs themselves. Having these running in the background can interfere with fixes attempted. Plus...SAS and AdAware background services only work IF you have purchased the programs. While the services run on the FREE versions they do nothing but consume valuable resources.
Reboot the computer, in NORMAL mode. You DO NOT have to be online to do this.
Run HJT again and put check marks next to the following entries if they remain:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://safesearch.cyberdefender.com/smallsearch.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
O1 - Hosts: 89.149.210.26 www.google.com
O1 - Hosts: 89.149.210.26 www.google.de
O1 - Hosts: 89.149.210.26 www.google.fr
O1 - Hosts: 89.149.210.26 www.google.co.uk
O1 - Hosts: 89.149.210.26 www.google.com.br
O1 - Hosts: 89.149.210.26 www.google.it
O1 - Hosts: 89.149.210.26 www.google.es
O1 - Hosts: 89.149.210.26 www.google.co.jp
O1 - Hosts: 89.149.210.26 www.google.com.mx
O1 - Hosts: 89.149.210.26 www.google.ca
O1 - Hosts: 89.149.210.26 www.google.com.au
O1 - Hosts: 89.149.210.26 www.google.nl
O1 - Hosts: 89.149.210.26 www.google.co.za
O1 - Hosts: 89.149.210.26 www.google.be
O1 - Hosts: 89.149.210.26 www.google.gr
O1 - Hosts: 89.149.210.26 www.google.at
O1 - Hosts: 89.149.210.26 www.google.se
O1 - Hosts: 89.149.210.26 www.google.ch
O1 - Hosts: 89.149.210.26 www.google.pt
O1 - Hosts: 89.149.210.26 www.google.dk
O1 - Hosts: 89.149.210.26 www.google.fi
O1 - Hosts: 89.149.210.26 www.google.ie
O1 - Hosts: 89.149.210.26 www.google.no
O1 - Hosts: 89.149.210.26 search.yahoo.com
O1 - Hosts: 89.149.210.26 us.search.yahoo.com
O1 - Hosts: 89.149.210.26 uk.search.yahoo.com
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=0
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: My Web Search Service (MyWebSearchService) - Unknown owner - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe (file missing)
Once you have placed the check marks click the Fix Checked button. Exit HJT and Reboot the computer.
Malwarebytes' Anti-Malware is really not meant to be run in safe mode UNLESS it is 100% impossible to run in in normal mode. Here is that info from the MBA-M developers:
Safe mode doesn't let MBAM load all it's drivers which are often necessary for the best detection and removal results. MBAM works in safe mode but is crippled, so if at all possible it should be used in normal mode in an admin account.
MBAM is designed to work in normal mode. It's simply most effective when run this way. Other tools like Spybot Search & Destroy work pretty much the same in normal mode vs safe mode, but MBAM does not and that's the most important thing to remember. Nothing bars you from using it in safe mode, but the results just probably won't be as good as they would if run from normal mode. Of course, doing both as you are shouldn't cause any harm, just perhaps a bit more time consuming.
MBAM is stronger from regular mode . This is by design as a lot of new malware runs from safemode also so you gain nothing anyway . There are also multiple infections that as part of their first step blow away the entire safeboot keyset
So I DO recommend that youNEXT update MBA-M if possible and then run a full scan with it in NORMAL mode. Have it Remove everything found and reboot the computer.
Reboot the computer.
Run a new HJT scan and save the log. Post back here with the MBA-M log and the HJT log.