New search asistant "Seekmo"

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Sandwarrior, Mar 10, 2006.

  1. Sandwarrior

    Sandwarrior Private E-2

    I did a search of the site and didn't find any threads on this particular program. The reason I posted to malware, is that this program cannot be removed from my Daughters computer and seems to be generating random porn pop ups on her system. I am in the process of cleaning her computer per the "malware" instructions, just wanted to know if anyone had heard anything about this Program?

    Bill
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! Seekmo Search is a 180Solutions adware variant.

    Look in Add/Remove Programs for things you do not recognize. If fact, attach the below log along with the three requested in the READ & RUN ME.

    Let's get an installed programs list from HijackThis too!

    Run HijackThis, click Open the Misc Tools section
    Click Open Uninstall Manager
    Click Save List (generates uninstall_list.txt)
    Click Save, to save it to a file where you can find it.
    Upload this file as an attachment too.
     
    Last edited: Mar 11, 2006
  3. Sandwarrior

    Sandwarrior Private E-2

    I went through the programs (add/delete programs folder), but the 180 solutions was not listed. Seekmo was listed, but everytime I tried to remove it, the computer would lockup and need to be rebooted. I rebooted into safe mode when starting the cleaning process, and removed it that way. I am still having problems with porn pop ups.

    I have enclosed the bit defender, hijackthis, activescan, and counterspy reports.

    This system is a intel 4, 1.60 ghz system with 767 mgb of ram. It is running windows 2000. I could not get the Microsoft Windows Defnder 1051 (beta2) to load or run. That is why I loaded Counterspy.

    Thank you for your help.

    Bill
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please attach the uninstall list from HijackThis too.

    Why didn't you uninstall Viewpoint Manager, WeatherBug, and WildTangent in step 0 of the Read Me? Notice how CounterSpy is complaining about them. If you uninstalled them in step 0, CounterSpy would not have found them.

    Also uninstall MediaPipe P2P Loader if found in Add/Remove programs! Tell me if you find it and if it uninstalled.
     
    Last edited: Mar 11, 2006
  5. Sandwarrior

    Sandwarrior Private E-2

    I didn't see any on the programs you listed when I started the cleaning process. When I went back, after reading your reply, Viewpoint manager was listed and the P2P loader. Both uninstalled without having to boot to safe mode.

    Attatched is the Hijack this "uninstall list"

    Bill
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that's good. You have a ton on crap left over from a WildTangent install. It may be easier for us to try a couple other scanning tools to remove more garbage than it would be to do manual editing of the registry. Please run the below two procedures and attach the two requested logs:

    Running Spy Sweeper

    Running Ewido Anti-Malware

    After running them I would suggest getting a new CounterSpy log to see if some of the issues it was finding have been fixed. Attach this log too.

    Also please attach a new HJT log so we can see what is left to fix.
     
  7. Sandwarrior

    Sandwarrior Private E-2

    I ran the Ewido program and it cleaned up 21 problems, howv\ever, in the process of saving the report the computer locked up and had to be rebooted. I don't have that report. I have attatched the other 3 though.

    Bill
     
  8. Sandwarrior

    Sandwarrior Private E-2

    They didn't attatch with the last message. Here they are.

    Bill
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixme.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixadt.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    Then use Windows Explorer to delete the below:
    c:\documents and settings\heathers1\application data\weatherbug <--- the whole folder
    C:\Program Files\Common Files\Real\WeatherBug <--- the whole folder
    c:\winnt\system32\camplugin.exe

    Now tell me how things are working!
     
  10. Sandwarrior

    Sandwarrior Private E-2

    There is no file on this computer called "fixadt.reg". Did I miss creating/loading it at some point in the cleaning instructions? I have done all the rest though. Deleted the files and saved the quote box for later use. How/ or where can I find this file?

    Bill
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it is a typo! Sorry about that. Both of those bold print items should say fixme.reg.
     
  12. Sandwarrior

    Sandwarrior Private E-2

    No Problem with the typo.

    So far the system seems to be running fine. I left it plugged into the internet all night and not a single pop up.

    Are there any of the programs I downloaded to clean the system that should be removed now to improve the performance of the system? My daughter plays World of Warcraft on this computer and I was wondering if any of them would slow the performance down that can be removed without loosing protection?

    Bill
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes having too many scanner programs that provide active protection will be a resource drain.

    Did you purchase any of the below or do you plan to?
    CounterSpy
    Ewido
    SpySweeper

    You need to have only one such program like this (that is a full active blocking/scanning/removal tool).


    You can free up more resource by not loading the below at startup. They are not necessary and the programs will work with out them loading at startup.
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
     
  14. Sandwarrior

    Sandwarrior Private E-2

    No,I didn't purchase any of these, mainly because its my Daughters computer.

    I will uninstall two of them.

    As for the "O4" lines,how do I turn those off?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You may as well uninstall all three of them! They are only trials that expire in 15 days from the date of installation. If you are not going to buy anything, then use Microsoft Windows Defender which is free.

    Run HijackThis and do a scan. Select those lines and then click Fixed checked

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  16. Sandwarrior

    Sandwarrior Private E-2

    Okay, done all of that. Once again...thank you to all of you for your help.

    Bill
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome and surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds