need some mysearchnow removal help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by shimonkefa, Jun 27, 2005.

  1. shimonkefa

    shimonkefa Private E-2

    I'm had a very difficult time trying removing mysearchnow toolbar and pop-ups. I've tried the major steps outlined in the other topics here and have failed to so far get the bug mysearchnow removed. For the moment it has not tried to redirect any URLs. This bugger is a little frustrating (understatement). And I really need some more advise and help and would appreciate your helpful knowledge. ;)
     
  2. shimonkefa

    shimonkefa Private E-2

    I have tried all these
    Ad-Aware SE
    Ad-Aware VX2
    CCleaner
    Spybot
    SpywareBlaster
    McAfee AVERT Stinger
    CWShredder
    Kill2me
    about:Buster
    HSRemove
    and my Symantec "Norton AV"

    One of these programs is cleaing my history and cookies everytime I reboot - anyone know which one that is, in the furture I'll want to turn that off.
     
  3. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Try the below thread.Its a good place to start. When finished post your results here. Chas or BJ will assist you from there.

    [thread=35407]PLEASE READ THIS BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal ![/thread]

    -Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? Etc
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It looks like you have run all of the steps in the READ ME FIRST. If so, please follow the steps below exactly:


    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  5. shimonkefa

    shimonkefa Private E-2

    Is it possible can you guys can take a look at this tool? Removal Tool it has seemed to clear the problem
    I tool the risk based on a couple recommends and looking at the guys website. It seems to have worked. I'll keep diligently monitoring things to see if it was the real deal. But if anyone has a test pc or somewhay to see what the program does - could be a nice solution.

    Not sure if my case is closed yet but I've booked marked the site there is a wealth of info here to be studied up on. ;)
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We do not have the problem so we cannot verify the effectiveness any offsite tools, however, this problem is not a difficult one to fix. Just post the HJT log I requested.
     
  7. shimonkefa

    shimonkefa Private E-2

    Log is here
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Logs must be from normal boot mode.
     
  9. shimonkefa

    shimonkefa Private E-2

    revised
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    mysearchnow does not show in you HJT log. Did you check each of the below it:
    - Add/Remove programs
    - Manage Browser Add-Ons in Internet Explorer -> Tools
     
  11. shimonkefa

    shimonkefa Private E-2

    yes - it never did show up in either place

    most frustrating thing I've had to deal with in awhile
    I usually pretty careful
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you have Messenger Plus 3 installed at anytime? It has been known to install this.

    How are you finding it? How is it that you know it is on your PC?
     
  13. shimonkefa

    shimonkefa Private E-2

    Pretty sure I got tricked with the Messenger Plus 3 (bs) - the toolbar on the bottom of the browser was a dead give-away. A couple of the AV programs could find it but not delete it, the MS anti-spyware kept warning about the URL change and block option but was also unable to delete it.

    In the beginning I really didn't keep a written track of which ones could or couldn't find it, but this is some pretty cool stuff to keep in the tools chest.
    Ad-Aware SE
    Ad-Aware VX2
    CCleaner
    Spybot
    SpywareBlaster
    McAfee AVERT Stinger
    CWShredder
    Kill2me
    about:Buster
    HSRemove
    and my Symantec "Norton AV"
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Show me a log from the programs that find it because nothing is visible. It could just be a left over registry key. Or possibly you may need to disable you protection programs so we can let it manifest itself inorder to fix it.

    Normally you would see something like the below in a log:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearchnow.com/searchbar.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://mysearchnow.com/searchbar.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearchnow.com/searchbar.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://mysearchnow.com/searchbar.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://mysearchnow.com/searchbar.html
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you use Add/Remove programs to uninstall Messenger Plus 3?
     
  16. shimonkefa

    shimonkefa Private E-2

    I may have not been clear - it seems like I have it removed, and I'm sorry to say I either did not keep the logs or have forgotten where I placed them, I was sifting through the drives and directories where I thought I put them and I just cannot remember what I did, pdf, doc, or txt. I guess that's another learning point on organization. I will keep looking around.
     
  17. shimonkefa

    shimonkefa Private E-2

    I removed all messenger programs and reinstalled AOL and Y, didn't go for MSN yet. deleted from add/remove and search and delete.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you referring to Messenger Plus or mysearchnow?
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Oh and by the way, about your history and cookies being cleared on reboot. You told Ccleaner to do it. You should not have chosen that option. The below line in your HJT log shows that setting:

    O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO

    Just disable the option in CCleaner.
     
  20. shimonkefa

    shimonkefa Private E-2

    Messenger Plus - I don't remember - I've been pretty single minded about just plugging away at this darm mess since Friday. On Saturday night I just started removing things - via deinstall first then - deleting anything left over, and if any spyware or clearner saw anything I said delete.
     
  21. shimonkefa

    shimonkefa Private E-2

    Sort of getting used to logging in and remembering passwords now - LOL - I might let it continue.

    I have 40+ websites worth of html and other data to be keeping safe.
     
  22. shimonkefa

    shimonkefa Private E-2

    The PC with Linux-SuSE is looking more attractive all the time (or that's what I keep telling myself).
    I almost have the Mrs and kids moved into open office, thunderbird, and firefox now - so we're not to far off.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So I'm a little confused by the message exchange. Do you still have problems with mysearchnow or not? If so, what program is finding it and where is it?
     
  24. shimonkefa

    shimonkefa Private E-2

    My problems seem all solved now - thank you! :D
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds