OK- you've definitely got "unwanted guests". Please do the following:
You will need to close/quit all web browser programs and disconnect from the Internet for the following, so you should print out these instructions or save them into a text file with Notepad.
Before beginning the procedures below, uninstall these programs using your Add/Remove Programs control panel:
ViewPoint/ViewPoint manager
Wild Tangent
MyWebSearch
1. Download and install these utilities (but do not run scans with them yet):
ewido Security Suite - http://www.ewido.net/en/download/
Microsoft Anti-Spyware beta - http://www.microsoft.com/downloads/...&displaylang=en
Ad Aware SE Personal - http://www.lavasoftusa.com/
SpyBot Search & Destroy - http://www.safer-networking.org/
- Open ewido. In the main screen, click "Update" and click "Start Update". After the update process completes, exit from Ewido.
- Open MS Antispyware beta. Make sure the "AntiSpyware Autoupdater" feature is enabled, and that it has downloaded the most current antispyware updates. Close the program after you've verified this.
- Open SpyBot and use its update feature to download and install the most current spyware definitions file. Close the program once the update is complete.
- Open AdAware, click the "Check for updates now" button, and follow the prompts to install the most current spyware definition database. Close the program once the update is complete.
- Open your anti-virus program and use its update feature to make sure that you have the most current virus definitions installed. As with the above programs, don't run a scan yet; just close it once it is updated.
3. Download and install the CleanUp! utility, but don't run it yet.
4. Run HijackTHis again, put a check mark next to the following entries, and then click the "Fix checked" button. Close HJT once it has finished performing its fixes:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
O2 - BHO: (no name) - {8B6DA27E-7F64-4694-8F8F-DC87AB8C6B22} - (no file)
O3 - Toolbar: (no name) - {71ED4FBA-4024-4bbe-91DC-9704C93F453E} - (no file)
O4 - HKLM\..\Run: [RecoverFromReboot.SS] C:\WINDOWS\Temp\RECOVE~1.EXE
O4 - HKLM\..\Run: [Antivirus] C:\WINDOWS\av.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [timessquare] C:\windows\timessquare.exe
O4 - HKLM\..\Run: [adtech2006] C:\windows\adtech2006.exe
O4 - HKLM\..\Run: [lspins] "C:\WINDOWS\System32\igps.exe"
O4 - HKLM\..\Run: [04cg0ryk.dll] RUNDLL32.EXE 04cg0ryk.dll,b 187510390
O4 - HKLM\..\Run: [uXoEiN9] C:\WINDOWS\jwurfc.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
O18 - Filter: text/html - (no CLSID) - (no file)
O20 - Winlogon Notify: Setup - C:\WINDOWS\system32\ir66l5js1.dll
5. Reboot into Safe Mode (you get to the safe mode boot option by hitting the F8 key as your computer is starting up).
6. Run CleanUP! It may take a while for the program to perform its cleaning, so be patient. Close the program when it has finished.
7. Run full system scans with SpyBot, ewido, AdAware, MS Antispyware, and your avnti-virus utility; have the programs fix all malicious items they find.
When ewido finds the first malicious object on your system, it will ask you if it should clean it. When it asks this, put a checkmark in the lower left corner of the box that says "Perform action on all infections", then choose clean and click OK.
Save the log file that ewido will create after it finishes scanning; you'll be including that log in your next post here.
8. Open Windows Explorer, and in the Folder Options->View settings under the Tools menu, select "show hidden files and folders", and uncheck "Hide protected operating system files" and "Hide extentions for known file types".
- Locate and delete the following files (some of these should already have been deleted by the removal utilities):
C:\WINDOWS\av.exe
C:\windows\timessquare.exe
C:\windows\adtech2006.exe
C:\WINDOWS\System32\igps.exe
04cg0ryk.dll
C:\WINDOWS\jwurfc.exe
C:\WINDOWS\system32\ir66l5js1.dll
C:\WINDOWS\csvas.exe
C:\WINDOWS\System32\pgws.exe
C:\Program Files\ISTsvc\istsvc.exe
- Delete the following folders entirely:
C:\Program Files\Viewpoint
C:\Program Files\WildTangent
C:\Program Files\ISTsvc
C:\Program Files\MYWEBSEARCH
9. Empty your Recycle Bin, reboot normally, run HijackThis again, and post the new log. Also post the log that ewido generated.