Search Extender and Shopping Assistant

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by futisaba, Dec 28, 2004.

  1. futisaba

    futisaba Private E-2

    I've followed all the instructions to get rid of about:blank, installed and run all the various spyware options that folks have listed here, including Major Attitude, and Chaslang. However, I still have two programs that have embedded themselves into my system and I can't figure out how to rid my computer of them

    Search Extender and Shopping Assistant are still with me, and if I try to remove them in Add/Remove programs I get routed to http://looking-for.cc/uninstall/SearchExtender.html OR http://looking-for.cc/uninstall/ShoppingWizard.html
    There, I am begged to give a reason for wanting to remove the programs. I chose not to, and there is an uninstall program there for me to download if I want. I used them both the other day, to no result. The I ran all the spyware stuff...

    FYI - I'm running XP, SP1 and I use Mozillla. However, frequently my IE pops up and brings me to unwanted pages. That's why I ran the cleanup options listed in the "How To" from Major Attitude, and "Generic Solution" by Chaslang.

    Any ideas would be helpful!

    :rolleyes:
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you run ALL of the steps of the Generic Solution exactly as listed, in the order listed, and were you physically disconnected from the internet when you did them?


    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. futisaba

    futisaba Private E-2

    Yep, I'm pretty sure I did. You want me to attach the log? I followed the instructions when installing it and put it in its own folder.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not just its own folder. Make sure it is not in any of the ones I specified and all browsers are shutdown. Then run a scan and attach it.
     
  5. futisaba

    futisaba Private E-2

    Here it is. Thanks.

    Edit by chaslang: HJT run incorrectly, log removed
     
    Last edited by a moderator: Dec 28, 2004
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Follow directions and try again. You have HJT running from exactly one of the places we said not to run it from. You are running it from the ZIP file.

    C:\Documents and Settings\Brian\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
     
  7. futisaba

    futisaba Private E-2

    I beg forgiveness. Will run again
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I won't be here much longer tonight though! It's now 4:32 AM my time.
     
  9. futisaba

    futisaba Private E-2

    Voila!
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must only run one antivirus program. You are running both AVG and Norton. You must uninstall one of them.

    And please remember ALL browsers must be shut down before using HJT. You had this running.
    C:\Program Files\mozilla.org\Mozilla\Mozilla.exe


    EDIT: Okay That appears to be a quick lauch program. Not a browser itself

    Is this your home page: http://www.salon.com/
     
  11. futisaba

    futisaba Private E-2

    AVG removed successfully, restart later.
     
  12. futisaba

    futisaba Private E-2

    It was in the task bar I guess.
     
  13. futisaba

    futisaba Private E-2

    Yes, Salon.com
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay one more question, is the below proxy setting something you require.
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = dynhost.inetcam.com;register.inetcam.com;;localhost
     
  15. futisaba

    futisaba Private E-2

    I'm not aware of what it does, so I'd have a hard time saying yes to that. What is it?
     
  16. futisaba

    futisaba Private E-2

    No I don't think it is.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is typcically used (more in companies) as a server that you go thru to get in and out of your internal network. Do you recognize those addresses? Is this a work PC?
     
  18. futisaba

    futisaba Private E-2

    It is a home PC and I don't recognize it at all.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay for now let's skip the proxy line and see where we get. We'll have to finish later. I have to get some sleep. So do the below and get back to me with the results.

    Make sure you have system restore disabled and viewing of hidden files enabled (per the tutorial).

    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Look for the below process(es) and if found, End them:
    C:\WINNT\netoa32.exe

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\dnfwd.dll/sp.html#93256
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\dnfwd.dll/sp.html#93256
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {6CA0D7D0-70AB-C9B7-FD57-3BC938F6A456} - C:\WINNT\system32\netxl32.dll
    O4 - HKLM\..\Run: [javads32.exe] C:\WINNT\system32\javads32.exe
    O4 - HKLM\..\Run: [B.tmp] C:\DOCUME~1\Brian\LOCALS~1\Temp\B.tmp.exe 0 10001
    O4 - HKLM\..\Run: [B.tmp.exe] C:\DOCUME~1\Brian\LOCALS~1\Temp\B.tmp.exe 0 10001
    O4 - HKLM\..\Run: [winpj.exe] C:\WINNT\winpj.exe
    O4 - HKLM\..\RunOnce: [netoa32.exe] C:\WINNT\netoa32.exe
    O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
    O15 - Trusted Zone: *.awmdabest.com
    O15 - Trusted Zone: *.awmdabest.com (HKLM)
    O23 - Service: PictureTaker - Unknown - c:\fixit\pt\PCTKRNT.SYS (file missing)
    O23 - Service: Remote Procedure Call (RPC) Helper - Unknown - C:\WINNT\system32\crrm32.exe (file missing)
    After clicking FIX, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINNT\netoa32.exe
    C:\WINNT\winpj.exe
    C:\WINNT\dnfwd.dll
    C:\WINNT\system32\netxl32.dll
    C:\WINNT\system32\javads32.exe
    C:\Documents and Settings\Brian\Local Settings\Temp\B.tmp.exe <--- it may be a good idea to remove all files in this directory.

    Reset Web Settings
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to http://www.salon.com/
    Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  20. futisaba

    futisaba Private E-2

    I'll respond probably in the morning, after some sleep, too.

    Thanks!
     
  21. futisaba

    futisaba Private E-2

    Here's my HJT log. I reboted in normal mode and the two programs are still running in my add/remove programs. I must be missing something.
    :rolleyes:
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That log does not appear to be from normal boot mode. HJT logs should always be from normal boot mode unless otherwise specified. If it is from normal boot mode, jus tell me. But then I would wonder why none of your virus application items are running.
     
  23. futisaba

    futisaba Private E-2

    Bizarre...I'm at work right now and will have to check when I get home. I didn't disable any AV stuff and the Norton icon is in the lower right system try. Looks like I'll go home for lunch!
     
  24. futisaba

    futisaba Private E-2

    OK, Chaslang, here's my latest HJT bootlog. Lunch is over and I'm heading back to work. Normal mode. ;)
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's more like it! Log is clean!

    Try this:

    Save the lines from the quote box below to a file called hsafix.reg, then using windows explorer double click on the hsafix.reg file a merge the fix into the registry.

    Tell me what you see in Add/Remove programs now.
     
  26. futisaba

    futisaba Private E-2

    I'm not sure which gives you greater satisfaction - beating the dirtbags who make and install this stuff, or helping people like me who suffer from their wares?

    I followed your instructions and those two problems are fixed! You're a star!

    Now I need to trek through the messages in other posts to see some of the best ways to keep from getting infected.

    Thanks for all your help and patience.

    Futisaba
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  28. futisaba

    futisaba Private E-2

    Thanks again, and is there a way to disable IE in XP? Believe it or not, IE discovered IE open, having been prompted to do so by SpySubtract! I was being asked to buy a full version or something.

    UGH.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't understand what you mean about SpySubtract.

    No you cannot and probably should not disable IE. You will find that sometimes you may need it. Some sites will not work correctly unless you use IE. Even downloading form Microsoft update can be a problem without it. Just use FireFox and make it your default browser.
     
  30. futisaba

    futisaba Private E-2

    Yeah, I went to do a Windows Update and it is much easier than w/o IE.

    I was checking email froo home, and I minimized me Mozilla, and behind it was IE at a page for the SpySubtract web page. It is one of the apps. reccomended to beign the uninstall of spyware, etc. Somehow IE opened on without my instruction or clicking or anything.
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So what are you asking me?

    Did you make FireFox you default browser? If not, you should do that.

    If you clicked on anything that would cause a popup and IE is still your default browser, it will come up.
     
  32. futisaba

    futisaba Private E-2

    IE hasn't been my default for a year. Mozilla is. I didn't click on IE.
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well then I would blame SpySubtract which you have installed for popping up some kind of notification. They probably have defaulted to using IE (poor programming). What was the page showing? Was it a prompt to update or a prompt to buy it. If you did not buy it, uninstall it. The free programs available are better anyway.
     
  34. futisaba

    futisaba Private E-2

    Yep, it took me to a webpage where there was a notice about a better version of it than the free one I had downloaded. That, to me, stunk of the very thing I was trying to rid myself of - someone else controlling what happens in my computer - so I uninstalled it. I will download one of the others mentioned in your posts and give that a whirl.

    Again, thanks.
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Happy, safe, surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds