Azesearch won't go away

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by samhr, Apr 26, 2005.

  1. samhr

    samhr Private E-2

    Re: Azesearch won't go away plus pop-ups

    Am having the same problem with AZESearch toolbar. It has replaced my default web settings with porn sites and icons in my desktop. I tried all the scans listed in this site. None of them could get rid of it.

    I want to remove it before anything critical happens to my system.
    I have done the HijackThis scan and have attached the HJT log in this
    message. Pls check it and help me to solve this problem.

    I would greatly appreciate any help in this.
    Thanks in Advance

    Sam
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Azesearch won't go away plus pop-ups

    You posted in a thread that does not belong to you. We prefer that all user problems be worked in separate threads. Your original post was here: http://forums.majorgeeks.com/showthread.php?t=60241

    Why didn't you just do the same steps that were provided in the thread you have many of the same symptoms (the O1 lines, the AZsearch lines). They would probably have fixed this problem for you.

    At any rate I'm moving you to your own thread where we can continue to work your problem.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Azesearch won't go away plus pop-ups

    - Make sure viewing of hidden files is enabled (per the tutorial).

    - Run HijackThis and select the below lines but do not click fix until you exit all browsers including this one:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    O1 - Hosts: 69.50.166.11 www.google.com
    O1 - Hosts: 69.50.166.11 google.com
    O1 - Hosts: 69.50.166.11 www.google.co.uk
    O1 - Hosts: 69.50.166.11 google.co.uk
    O1 - Hosts: 69.50.166.11 www.google.ca
    O1 - Hosts: 69.50.166.11 google.ca
    O1 - Hosts: 69.50.166.11 www.google.es
    O1 - Hosts: 69.50.166.11 google.es
    O1 - Hosts: 69.50.166.11 www.google.de
    O1 - Hosts: 69.50.166.11 google.de
    O1 - Hosts: 69.50.166.11 www.google.fr
    O1 - Hosts: 69.50.166.11 google.fr
    O1 - Hosts: 69.50.166.11 www.google.com.au
    O1 - Hosts: 69.50.166.11 google.com.au
    O1 - Hosts: 69.50.166.14 www.yahoo.com
    O1 - Hosts: 69.50.166.14 yahoo.com
    O1 - Hosts: 66.218.75.184 mail.yahoo.com
    O1 - Hosts: 69.50.166.12 www.msn.com
    O1 - Hosts: 69.50.166.12 msn.com
    O1 - Hosts: 69.50.166.12 search.msn.com
    O1 - Hosts: 69.50.166.12 www.go.com
    O1 - Hosts: 69.50.166.12 go.com
    O1 - Hosts: 69.50.166.13 astalavista.com
    O1 - Hosts: 69.50.166.13 www.astalavista.com
    O1 - Hosts: 69.50.166.13 astalavista.box.sk
    O2 - BHO: (no name) - {031B6D43-CBC4-46A5-8E46-CF8B407C1A33} - (no file)
    O2 - BHO: ZToolbar Activator Class - {da7ff3f8-08be-4cac-bc00-94d91c6ae7f4} - C:\WINNT\system32\azesearch3.ocx

    Did you install this Lightning Download program? If not or if you do not use it, fix the next line too.
    O2 - BHO: bho2gr Class - {F1FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\Lightning Download\LD_Catch.dll

    O2 - BHO: AddressBar Class - {f65b197f-8260-4d52-909a-f70118e646eb} - C:\WINNT\system32\iasadm.dll
    O3 - Toolbar: AZE Search - {a19ef336-01d4-48e6-926a-fe7e1c747aed} - C:\WINNT\system32\azesearch3.ocx
    O4 - HKLM\..\Run: [loader32] C:\Program Files\Internet Explorer\IEXPLORE.EXE
    O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZSXXXXXX41US
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O16 - DPF: {D7BF3304-138B-4DD5-86EE-491BB6A2286C} - http://www.azebar.com/install/azesearch3.cab



    - After clicking fix exit HijackThis

    - Now reboot into safe mode and run Windows Explorer and delete the below:
    C:\WINNT\system32\iasadm.dll
    C:\WINNT\system32\azesearch3.ocx

    - Now reboot in normal mode and create a new HJT log

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  4. samhr

    samhr Private E-2

    i managed to delete of the following files, but i couldnot find the azesearch3.ocx
    but i deleted off the azesearch.xml file
    is that alrite? and finally the azesearch toolbar is gone.

    but after booting to normal mode,the monitor display settings has been changed.. when i checked the properties its in 16 BIT color VGA setting

    wat should i do to bring to normal settings? :(

    pls view the new attached log, thanks
     

    Attached Files:

  5. samhr

    samhr Private E-2

    regarding the display settings, it doesnt have any other color resolutions to choose from the drop down menu . Only 16 BIT is listed. :(
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't understand what is causing this. None of the items we fixed should have had anything to do with this. Are you sure it is selecting your Video Graphics card properly at boot up? Are your drivers loading? are any errors shown in Device Manager?

    Please exit all browsers and have HJT fix the below line.
    O2 - BHO: AzEntretien Class - {0d2def3a-f4f1-42ec-ac4f-132e7ba6e292} - %SystemRoot%\azentretien.dll (file missing)
     
  7. samhr

    samhr Private E-2

    Now i reinstalled my Video Graphics Adapter. Now it works fine. But i hear beep sound at times.

    Btw,how should i find out whether it is selecting the Video Graphics card properly at boot up?

    OK,i shall fix the line. Do i have to post the log after that?

    Anyway thanks for the gr8 help :)
    Learnt quite a number of things thru this problem.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    Right click on your Desktop and select Properties. Then click the Settings tab. Does it indicate your Display Adapter correctly?

    No I do not need a new log. Is everything working OK now.
     
  9. samhr

    samhr Private E-2

    yep, the adapter is displayed correctly.Everything is fine now. :)
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds