Homepage Stuck on Iwantsearch.com

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by flyingbb, Oct 12, 2004.

  1. flyingbb

    flyingbb Private E-2

    My homepage is hopelessly stuck on ‘iwantsearch.com’ as is my toolbar. I am running WinXP SP1a and IE6 for my browser. Further I have Ad-ware SE PRO and have Adwatch Monitor active, both with current definitions.

    I have performed all the tests listed in your READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal article; the only thing found were in temp folders that CCCleaner removed.

    Attached is the log from Hijack This (I hope I was correct in sending it now). I might note that I had the Hijack This website analyze a couple of previous logs, told the program to fix everything that the website said it could, but the same ‘Nasty’ entries seem to reappear.

    Thanks so much if someone can help here, I’m pulling what few hair I have left out over this!

    Chris
     
  2. flyingbb

    flyingbb Private E-2

    Somehow my log didnt attach, here it is:
     
    Last edited by a moderator: Oct 12, 2004
  3. jarcher

    jarcher I can't handle a title

    lets see something shall we?

    http://www.iwantsearch.com/uninstall/remove.exe
    that should take care of that toolbar(let me know if it works)
    do a windows update
    boot it safe mode and run hjt again
    and save your log as a .txt file
    reboot in normal mode
    attach it
    (manage attachments)
    dont forget to click upload
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do not post HijackThis logs unless we ask you to post them and then only post them as .txt file attachments. No inline text. (as jarcher already stated) And be careful of your text formatting. You log is a little messed up.

    HijackThis is the last step and we have rules about how and when to post a log.

    You should read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Do not post a HijackThis log until we ask you to and when we do it must be text document attachment to your message. To do this save the log file and select manage attachments in a new thread to upload it. All running programs should be closed, including your web browser, e-mail, items in the tray, anything you can close... Close before running Hijack This!


    So please repost your log properly as a .txt file attachment that does not have the formatting of the text all messed up. The one you posted is too difficult to read and was deleted.
     
    Last edited: Oct 12, 2004
  5. flyingbb

    flyingbb Private E-2

    Thanks Jacher, I tried iwantsearch's remove tool, and it didnt do anything.

    Chris
     
  6. Kodo

    Kodo SNATCHSQUATCH

    Please follow Chaslangs post above yours at this time.
     
  7. flyingbb

    flyingbb Private E-2

    Sorry Charslang. I tried earlier to it post as an attachment, but here goes again. Thanks for your help and understanding, I often think some of the '* For Dummies' series was written for me!

    Chris
     

    Attached Files:

  8. PhilliePhan

    PhilliePhan Guest

    Hi Chris,

    You could also try looking in Add or Remove Programs or running a search of your computer for SBSoft and/or Apropos Media as they are related to Iwantsearch. (I think)

    Best luck,
    PP
     
    Last edited by a moderator: Oct 12, 2004
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Look to see if you have any of those items in Add/Remove programs that PP gave you. If so, uninstall them. Then follow the below (assuming these lines are still present).

    Make sure you have system restore disabled and viewing of hidden files enabled.
    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Find the below processes and End them:
    bmupdate.exe


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.iwantsearch.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://twc-sa.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://tdak.com/searchbar.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = =%3D
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
    O4 - HKCU\..\Run: [BMUpdate] C:\WINDOWS\System32\BMUpdate.exe
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) -
    O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) -


    Boot into safe mode and use Windows Explorer to delete:

    C:\WINDOWS\System32\BMUpdate.exe

    No reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please stop posting these in threads. It is already recommended several places in our sticky threads. This kind of post is not solving the current problem the user has. And it does not provide "maximum protection". It is just less problematic right now because it does not have some of the security holes IE has and not too many of these malware creators are attacking it yet since so few people use it compared to IE.
     
  11. flyingbb

    flyingbb Private E-2

    A snag or two... I could not find the process ‘bmupdate.exe’ running, and I did check all users. I hope its okay I have attached two jpg’s showing the Task Manager I was viewing. BTW still the same problem with the homepage.

    Also, I found a file ‘BUUPDATE.EXE-2563E73A.pf’ by doing a files and folders search, but in the c:\Windows\Prefetch folder, not ...System32.

    What to do now, shoot this @*&* thing? Thanks for your continuing help.

    Chris
     

    Attached Files:

  12. flyingbb

    flyingbb Private E-2

    CORRECTION - In the below reply I meant I found the file BMUPDATE.EXE-2563E73A

    Sorry for the typo

    Chris
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to post a new HJT log.

    When you ran the previous steps:
    1) Did you find and delete C:\WINDOWS\System32\BMUpdate.exe ?
    2) Are you sure it deleted?
     
  14. PhilliePhan

    PhilliePhan Guest

    Did you run a search of your machine for SBSoft and/or Apropos Media as I suggested? I am fairly certain that SBSoft is responsible for Iwantsearch.

    The uninstall tool Jarcher linked is indeed effective for removing earlier versions of Iwantsearch. Did you try running it in Safe Mode w/ System Restore Off?

    Just tossing out some ideas – Take ‘em or leave ‘em :)

    Best luck,
    PP
     
  15. flyingbb

    flyingbb Private E-2

    Thanks for everyones help. FYI I tried the uninstaller in both normal and safe modes, no luck. I also tried performing the HJT fixes suggested, but they returned on the next scan. This is related to SBSoft I did notice, but something prevents these keys from being changed.

    I finally gave up, installed Firefox and removed IE. Not what I wanted, but gave up. Thanks again for everyones time and help.

    Chris
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds