1
   

searchweb2

 
 
Reply Fri 1 Apr, 2005 09:02 pm
Hi: I need help getting rid of searchweb2 toolbar. Here is my hijackthis log. Please help. Thanks
Logfile of HijackThis v1.98.2
Scan saved at 8:03:31 PM, on 01/04/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\Blubster\Blubster.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Java\jre1.5.0_01\bin\jucheck.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\ScsiAccess.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
C:\Program Files\Network Associates\VirusScan\Webscanx.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\Program Files\Ares\Ares.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\Denise\LOCALS~1\Temp\Temporary Directory 2 for hijackthis[1].zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://pocuqcbiwfdkcjfejx.com/MEVtqNVeCg/0tIHU3AIwgbcI7LrTB6vh9WzjHcRwDM0nUXetjW7H7pAHtKHfc_5S.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.avrocomputers.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: NavExcel Toolbar - {5AA06644-BC46-4220-A460-47A6EB47C96D} - C:\Program Files\NavExcel Search Toolbar\NavExcelBar.dll
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Blubster] C:\Program Files\Blubster\Blubster.exe SILENT
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O4 - Global Startup: Microsoft Office.hta
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.avrocomputers.com
O16 - DPF: Yahoo! Canasta - http://download.games.yahoo.com/games/clients/y/yt1_x.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1094757163830
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {CAFECAFE-0013-0001-0017-ABCDEFABCDEF} (JInitiator 1.3.1.17) -
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_game
  • Topic Stats
  • Top Replies
  • Link to this Topic
Type: Discussion • Score: 1 • Views: 621 • Replies: 2
No top replies

 
timberlandko
 
  1  
Reply Fri 1 Apr, 2005 09:59 pm
You have a number of problems there - which is not uncommon with yuckware - them critters run in packs. Removin' 'em is gonna also remove Messenger Plus and assorted p2p software from your machine, just so's ya know up front. I'd like to know what video card or adapter your machine has - an entry in your log could be legitimate, or it might be yuckware-related, dependin' on your video hardware/software setup. If you wish to pursue this, read on.

Please see THIS TOPIC.

Before doin' anything else, you should fully update your Windows, place the latest available version of HJT into a folder of its own on your root drive, and perform all of the preliminary downloads, application updates, and scans as listed in that topic. The removal advice to come will be offered with the assumption that all that has been done accordin' to instructions, and will not be effective if that is not the case.

Once that's been done, here's what I'd suggest to start with.

1) Print out these instructions and get all the suggested downloads before starting with this, as you will have to disconnect from the internet durin' the cleanup. These steps should be taken in order listed. This first procedure is "Broad Spectrum". It will solve many if not most problems, and provide you with tools to aid in the prevention of future infection. Once this runthrough has been completed, things get easier - sorta. There will be less to do per runthrough, but the critters we'll be goin' after once this procedure has been done will be the sneakier, trickier, nastier buggers. We'll likely get 'em, but its gonna take time, effort, and attention to detail. There's quite a bit more to gettin' rid of yuckware than there is to gettin' it.

First, a few basic set-up things. Be sure you understand what to do and how to do it before tryin' it. If you have any questions, ask first. These all are safe if used correctly, but improper use of some can cripple your system. Again, if you're unsure, please ASK!

2) Make sure your Windows is operatin' properly apart from your browser issues. Turn off System Restore. Right-click the "My Computer" icon on your desktop and click "Properties". Click the "System Restore" tab, select "Turn off System Restore", click Apply > Yes > OK. Doing this will remove your saved restore points, so be sure Windows itself is operatin' satisfactorily. When the cleanup has been completed, re-enable System Restore by followin' the same procedure. Then, set a fresh restore point and reboot.
DO NOT RE-ENABLE SYSTEM RESTORE UNTILL THE ENTIRE CLEANUP PROCESS HAS BEEN COMPLETED!.
There may - most likely will - be steps required beyond those listed in this post.

3) Some of the procedures to follow need to be carried out in Safe Mode. To enter safe mode, restart your computure, then when the machine begins to boot up, start tapping the "F8" key. The machine may complain with a few beeps, but ignore that. You should eventually be presented with a black-abnd-white boot option screen. Using your keyboard's up/down arrows, select the option named simply "Safe Mode", then hit "Enter". If this method does not work for you, consult your computer's documentation or vendor's website support pages for instructions specific to your machine.

4) Many of the required dowloaded applications should be placed in folders of their own on your root drive, the one on which Windows resides. Open "My Computer, then locate your root drive folder, usually "Local Drive ( C: )", click-to-open that folder, select "File" from that folder's toolbar, select "New", then select "Folder", and name the new folder as would be appropriate for the download to go into it. The recommended applications should not be downloaded to or run from Desktop or Temporary folders.

5)It probably will be necessary to hunt around deep within Windows. Enable Explorer to view all files. Open "My Computer", click "Tools", select "Folder Options", and click the "View" tab. Place a check mark in the following boxes:

"Display the contents of system folders"
"Display full path in address bar"

Under "Hidden Files and folders" select the "Show hidden files and folders" button

Uncheck the following boxes:

"Hide extensions for known file types"
"Hide protected operating system files" (Recommended)"
Click "Yes" to confirm, Click "Apply", then click "OK" . Close the folder.

6) Enable "Search to search all files and folders. Click Start>Search, under "What do you want to search for?" select "All files and folders", then select "More advanced options, and make sure the 1st 3 boxes, "Search ssystem folders", "Search hidden files and folders", and "Search subfolders" are checked, then close the application; it should "remember" those settin's.



**** IMPORTANT: When running the scans and fixes, do so with no other windows, browsers, mail, or chat/messaging clients open, and with no other applications running. Also, before running any of the scans, disable any antivirus, popup/ad blocking, and antispyware applications you may have on your machine. Such applications can interfere with the some of the tools we're using. Re-enable these when the scan or fix has been completed. ****



7) Now, with the basic setup stuff out of the way, download LSP-Fix. Just download it to a folder you will be able to find easily later, either on your root drive or in your Programs folder, as you prefer. It may or may not be needed, but if it is necessary, you'll have it. Removal of some yuckware can prevent you from accessing the internet. In the event this happens, you will need to run LSP-Fix to repair things. If after performin' a repair operation you find yourself unable to connect, run LSP Fix, followin' the onscreen prompts, and you should be able to get on line again.

8) Download to a folder of its own either on your root drive or in your Programs folder, as you prefer, Gibun Software's Move On Boot. This will not be used yet, just downloadload it. If and when it is needed, exact instructions for its use WITH SPECIFIC FILES OR FOLDERS will be provided as applicable.


9) Download Cleanup. Again, just save it to an easilly findable folder either on your root drive or in your Programs folder. We will use this, probably frequently, but not just yet.

10) Run the Microsoft Malicious Software Removal Tool, then download and install, into a folder of its own, preferably in your Programs folder,

11) Microsoft Windows Antispyware. Before runnin' it, click its "Advanced Options" icon, then click the "Browser Hijack Restore" icon. At the bottom of the page that will open, click "Select All", then click "Restore". Go back up to the top of the page, click "File", and click "Check for updates". When that's been done, disconnect from the internet, then click "Spyware Scan". Click "Scan options", and see to it that "Full system scan" is selected, and that all 3 boxes underneath it are checked; "Scan Memory", "Scan drives/folders", and "Deep scan folders". Also check to be sure that "Scan drives/folders" is configured to scan your entire root drive (click the little folder icon; your root drive - "(C)" - should be selected). Finally, click "Run Scan Now" and let it run to completion, followin' whatever prompts or instructions - if any - it might pop up.

12 Download JavaCool Software's SpywareBlaster into a folde of its own, either in your Programs folder or directly on your root drive as you prefer. Install it, then click "Updates", and click the "Check for Updates" bar on the next page. When the update has been completed, click "Back", then click "Enable All Protection", and close the application.

13) Open AdAware and have it check for updates by clicking the blue-ish globe icon at the upper right of the page and following the onscreen prompts. When the update process has been completed, click the grey-ish "Gear" icon to open AdAware's Configuration and Settings utility.

On the first tab, "General", be sure all 3 buttons in the top panel, "Safety", are green and checkmarked. Next, from the lefthand colum, select "Scanning". Be sure the 1st 2 buttons in the top panel, "Drives, folders, & files", are green and checkmarked. The 3rd button, "Skip files larger than ... ", should be red and display an "x". If any button is not as it should be, click to change its setting.

Under "Select drives and folders to scan", be certain AdAware is configured to scan your entire root drive (the drive on which Windows resides, usually "C".

In the bottom panel, "Memory & Registry", all buttons should be green and checked.

From the lefthand column, select "Advanced". In the first 2 panels, all buttons should be green and checked. In the bottom panel, "Alternate Data Streams", both buttons should be red and display an "x"

From the lefthand panel, select the last option, "Tweak". In the righthand panel, select the 1st option, "Scanning Engine" to open its tree. The 3rd button, "Run scan as background ... etc", should be red and display an "x", all other buttons should be green and checked.

Click "Cleaning Engine" to open its tree. The first 5 buttons should be green and checked, the last 3 should be red and display an "x".

Click "Proceed" to save the settings, but do not run an AdAware scan yet, just close the application.

14) Next, go to LavaSoft and download AdAware VX2Cleaner Plugin[/i][/u]. Read, understand, and follow the directions on that page to install the plugin. Don't run it yet, but be sure you know how to. Close AdAware if it is open.

15) Open Spybot Search & Destroy, select "Mode" from its toolbar, and select "Advanced". Have it check for and install updates. When the update procedure has completed, select "Immunize", then click the green "+" icon to install Spybot's immunization. In the lower pane, select "Enable permanent blocking of bad addresses in Internet Explorer", then from the dropdown, select "Block all bad pages silently"

Next, select "Tools", and place checkmarks in "Resident", "ActiveX", "BHOs", "Browser Pages", and "Hosts File". Double-click "Hosts File" then click the green "+" icon to install Spybot's Hosts file.

Select "Settings", then select the "Settings' icon. Under Main Settings", place check marks next to:
"I do know all that legal stuff" (check that even if you don't :wink:)
"Save All Settings"
"Create backups of fixed spyware problems ... "
"Create backups of fixed system ... "
"Create system restore point when fixing spyware/usage tracks (Win XP only)"
"Create System restore point when fixing system internals (Win XP only)"
Then close Spybot S&D.


16) Create a folder on your root drive named "Sysclean". Download Trend Micro's Sysclean Package to that folder. Into the same folder, download the Latest Pattern File. This will be a compressed folder; extract the contents. When you have done so, the Sysclean folder should contain 3 items: a folder named "lpt528", a compressed folder named "lpt.528.zip", and the application "sysclean.com". Move sysclean.com into the lpt528 folder.


17) Reboot into safe mode, find and open the lpt528 folder, then click sysclean.com to run the application. When it has completed, note the full path and name of all files it says it could not clean or delete, if any. Save that list, if there is one, for later use.

18) Still in safe mode, open AdAware, and run the VX2 Cleanup plugin, followed by an AdAware system scan, being sure the "Use custom scanning options" button is checked, and have AdAware fix whatever, if anything, it finds. Reboot normally, but do not connect to the internet, and run another full AdAware scan, again fixing whatever, if anything, it finds. If AdAware asks to run again on boot, let it do so. Boot normally; AdAware should be the first thing that runs. Fix whatever, if anything, it finds. If it did not ask to run again on boot, reboot normally, do not connect to the internet, and run another Adware scan, and again fix whatever, if anything, is found. When it has completed, reboot into safe mode once again.

19) While in safemode, open Spybot S&D, run a scan, and fix anything it finds and lists in red. Again, if it asks to run again on boot, let it do so, booting normally. Spybot should be the first thing that runs. Again, fix anything found and listed in red. If it did not ask to run at boot, reboot normally, do not connect to the internet, and run another full scan, again fixin anything found and listed in red. When finished, reboot into safe mode once more.


20) Now, run Cleanup, and reboot, normally, when it prompts you to. Run a new HJT scan immediately followin' bootup, connect to the internet, and post the fresh log to this thread, along with any lists of stuff any of the applications said they could not clean or delete.
0 Replies
 
glennkress
 
  1  
Reply Fri 1 Apr, 2005 11:24 pm
Thanks...I'll give this a try and let you know the outcome. Your reply is appreciated. thanks
0 Replies
 
 

Related Topics

Clone of Micosoft Office - Question by Advocate
Do You Turn Off Your Computer at Night? - Discussion by Phoenix32890
The "Death" of the Computer Mouse - Discussion by Phoenix32890
Windows 10... - Discussion by Region Philbis
Surface Pro 3: What do you think? - Question by neologist
Windows 8 tips thread - Discussion by Wilso
GOOGLE CHROME - Question by Setanta
.Net and Firefox... - Discussion by gungasnake
Hacking a computer and remote access - Discussion by trying2learn
 
  1. Forums
  2. » searchweb2
Copyright © 2025 MadLab, LLC :: Terms of Service :: Privacy Policy :: Page generated in 0.03 seconds on 12/27/2025 at 09:11:01