I got nailed with xmedx emails going out to my Yahoo.mail contact list. I deactivated the yahoo account and asked it be on the list for permanent deletion. Then the FaceBook account started sending out xmedx mail and some kind of online chocolates store. So I
deactivated the Facebook account and reinvented myself on FaceBook. I use Spybot and RegEdit, AVG Free Anti Virus. I wish I knew where the virus is. Last time I ran RegEdit and Spybot there was nothing noted. It's embarrassing.
I use win2000P and Opera.
Here is a Malwarebyte Log. Five infections. Pressed "Fix"
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4796
Windows 5.0.2195 Service Pack 4
Internet Explorer 6.0.2800.1106
10/11/2010 6:26:51 PM
mbam-log-2010-10-11 (18-26-51).txt
Scan type: Quick scan
Objects scanned: 108959
Time elapsed: 8 minute(s), 36 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 7
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> No action taken.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page (Hijack.StartPage) -> Bad: (http://bing.zugo.com/?cfg=2-76-0-11xf7) Good: (http://www.google.com) -> No action taken.
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)