help exactsearch wont leave

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by shaycla, Oct 15, 2004.

  1. shaycla

    shaycla Private E-2

    Hi I need help. I have run adaware/spybot S&D (both updated programs) and I still have Exactsearch in the address bar. It is not located in the add remove program. Issue is I have upgraded from WIn98 to XP. As part of this upgrade I need to reinstall my ethernet broadband connection. Problem is all I get is the exactsearch in the address bar and I can't type the 10.1.1.1 thingy. it puts www.exactsearch first. Next issue it is my son's pc .. Please save me from a sarcastic 14 yr old teenager. I have run hijack this on his pc and have his weblog ( I am logging in from mine as I have killed his pc!! :rolleyes:

    this is the hijack this log
    [Log removed]
     
    Last edited by a moderator: Oct 15, 2004
  2. Kodo

    Kodo SNATCHSQUATCH

  3. jarcher

    jarcher I can't handle a title

    if you do need to run HJT


    you are runnung HJT from the desktop
    you need to put it in its own folder(not on the desktop)
    like
    c:\program files\Hjt

    then if you are asked for a log
    we will ask you for it as an attachment in a .txt
     
    Last edited: Oct 15, 2004
  4. shaycla

    shaycla Private E-2

    Hi and apologises to Kodo
    I thought I had read all the info before posting and it is obvious I did not.

    Followed the links in your post and completed the clsid info, however the issue is still there.
    tried the

    example address page is sent to www.exactsearch.net/search.php?keywords=http://goggle.com.au

    tried this
    http://forums.majorgeeks.com/showthread.php?t=35407
    He has adaware 6 (all clear) have used CW shredder (all clear) unable to access the net to download others

    jarcher I thought by having it (HJT) in my documents meant it was not on the desktop(though it was originally) I have now relocated it to C:\Documents and settings
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you followed the 35407 link correctly, you would not have Ad-Aware 6.
    It is better not to have HijackThis in any sub-directory of c:\Documents and Settings
    It is a program. Not a document and not a setting. Too many trojans also deposit themselves there and clean up attempts will remove your HJT backups. Use something like recommended:
    C:\Program Files\HJT or C:\HJT
     
  6. shaycla

    shaycla Private E-2

    thank you for your assistance.

    However as explained it is on my son's PC which does not have the internet enabled as EXACTSEARCH appears in the toolbar so I can't load the programs noted unless they fit on a floppy!

    No did not know that about docs settings will fix
     
  7. Kodo

    Kodo SNATCHSQUATCH

    double click on MyComputer icon.. when the window pops up.. in the location bar at the top, type in WWW.MAJORGEEKS.COM and see if you can get to our site that way.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If what Kodo suggested does not work, make sure you have HijackThis version 1.98.2 and place it in its own, non-temporary, non-desktop folder like C:\Program Files\HJT and shut down all browser sessions on the PC in question and run a HJT scan. Post your log back here as a .txt file attachment.
     
  9. shaycla

    shaycla Private E-2

    Thanks Kodo.......Sadly going through My computer brought up the same error exactseach

    chaslang hijack this log attached

    I have gone through this log about 100 times and I can't seem to find it :(
     

    Attached Files:

  10. jarcher

    jarcher I can't handle a title

    end this in the task manager, remove it manually and check the box in HJT
    C:\Program Files\NaviSearch\bin\nls.exe

    also check the box for these

    O2 - BHO: (no name) - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - (no file)

    O2 - BHO: Zedd4Proj.clsUnoOne - {08227B4B-54FE-4C4D-809F-BCA46292FC5B} -
    C:\WINDOWS\SYSTEM32\AANTX.dll

    O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} -
    C:\WINDOWS\SYSTEM32\nvms.dll

    O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} -
    C:\WINDOWS\SYSTEM32\mscb.dll

    O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} -
    C:\WINDOWS\SYSTEM32\msbe.dll

    O9 - Extra button: Your PC is infected with Spyware - click here to fix
    your PC - {FB74C951-ACA1-4e33-A94C-A9261EB2CCB7} -
    https://www.spydeleter.com/order2.php?KBID=1004 (file missing)

    O9 - Extra 'Tools' menuitem: Your PC is infected with Spyware - click here
    to fix your PC - {FB74C951-ACA1-4e33-A94C-A9261EB2CCB7} -
    https://www.spydeleter.com/order2.php?KBID=1004 (file missing)

    close all browsers ( including this one) and click fix in HJT
     
  11. jarcher

    jarcher I can't handle a title

    chaslang,
    what is
    C:\WINDOWS\System32\ZoneLabs\vsmon.exe
    a firewall?

    oh. . nevermind
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! ZoneAlarm. By the way SpyDeleter will probalbly not get fixed by simply fix the HJT lines. And those other O2 lines have been real problems fixing in another thread (http://forums.majorgeeks.com/showthread.php?t=44512).

    Here is how I have been fixing SpyDeleter:

    Click Start, Run, and enter into the box the following without the quotes "Notepad"
    Now copy and paste the contents the next 3 lines (including the blank line) into the notepad window.
    REGEDIT4

    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB74C951-ACA1-4e33-A94C-A9261EB2CCB7}]


    Now save it as file name: "delspy.reg" (without the quotes).
    Use Save as file type: All files (*.*)
    Save it on your Desktop where it is easy to locate.

    Now on your Desktop double-click on delspy.reg.

    At the prompt "Do you wish to merge the information into the registry?"
    Answer 'Yes' and wait for a message to appear similar to "Merged Successfully".
     
  13. jarcher

    jarcher I can't handle a title

    , sorry. .
    thats really good to know
    thanks
     
  14. shaycla

    shaycla Private E-2

    thank you all very much

    exact search has left the building !


    After discussion with my ISP it appears that my XP is corrupt ?

    so I was unable to connect no ping ? even with everearch gone

    I have gone back to win 98
    which now is griding so slowly and when i tried to download the adaware se version it unzipped fine but asks for what to open the program with and it is not opening anything ?


    thankyou all again for your help with exactsearch
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Many people who have done an "upgrade" to WinXp from Win98 or WinMe have run into problems. It is a better idea to do a clean install of WinXP.

    Ad-Aware's install file is a self extracting executable (EXE) file. Nothing should be required to open it. It should just run and install.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds