findthewebsiteyouneed

Discussion in 'Malware Help (A Specialist Will Reply)' started by dadpad, Feb 20, 2006.

  1. dadpad

    dadpad Private E-2

    Following a major infection and subsequent removal
    (I followed directions at A2K forums and used on line scans, ewido adaware and spybot as well as ccleaner) the following files appeared in my hjt log

    ......findthewebsiteyouneed

    Having Googled the file name and followed links to Symantics website I found these listed as a spywear registry change.
    I downloaded and ran the recomended tool "FxDtcmtb"

    This tool reported no malware and did not remove the entries from HJT.

    I removed the files using HJT.

    Is it cause for concern that symntecs tool did not find any spy wear?

    I enclose 2 HJT logs
     
    Last edited: Apr 20, 2007
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That tool from Symantec is for removing the Dotcom Toolbar only.

    See: http://www.symantec.com/avcenter/venc/data/spyware.dotcomtoolbar.html

    Please do no post any HijackThis logs here without having run our cleaning procedures covered in the READ & RUN ME sticky thread.

    Are you having malware problems at the present time? If so, run the READ & RUN ME.

    Note: its spyware not spy wear or spywear ;)
     
  3. dadpad

    dadpad Private E-2

    Thanks for the speling lesson chaslang I'll be sure to return next time I need a spell check. ;)

    With repect, the proceedures i have followed are almost exactly the same as yours. i included the logs in case there was something unusual about the enteries.

    I am not having a problem with malware at this time I was more curiouse about why the entries were still there and the symantec tool had not removed them.

    from the symantec web site..................

    When Spyware.Dotcomtoolbar runs, it does following:

    6. Adds the values:

    "Search Bar" = "[Web site on the searchbar.findthewebsiteyouneed.com domain]"
    "Default_Search_URL" = "[Web site on the searchbar.findthewebsiteyouneed.com domain]"

    to the registry subkey:

    HKEY_ALL_USERS\Software\Microsoft\Internet Explorer\Main

    ---------------------------------------------------------------------

    Was it necessary to remove the files in question?

    If you feel i am wasting your time please say so and i will get out of your Hair. :)
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is just typical of many of Symantec's tools. They are supposedly designed to remove particular problems but in many cases they don't even find the problems. They have released many tools like this. Their Virtumonde (at least 3 or 4 versions) tools were useless too. The same was true for their Apropos fix.

    What files are you referring to? You did not mention any files. You only mentioned a few registry keys.
     
    Last edited: Feb 20, 2006
  5. dadpad

    dadpad Private E-2

    Re: findthewebsiteyouneed (Resolved)

    My apologies for using the wrong terminology I meant registry keys, (which i think you knew). :( As a matter of interest, in this thread, i have never refered to registry keys.

    chaslang Thanks for taking the time to correct my spelling and improve my knowledge of technical terminology. Its been an absolute pleasure to do business with you.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: findthewebsiteyouneed (Resolved)

    Yes you did! The logs you posted referred to them:

    R1-HKCU\Software\Microsoft\InternetExplorer\Main,Search Page=http://searchbar.findthewebsiteyouneed.com
    09......Main,Search bar=http://searchbar.findthewebsiteyouneed.com
    RO......Main,Start page=http://gomicrosoft.comfwdlink/?Id=56626&homepage=


    These are registry keys that HijackThis is showing to you.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds