searchenhancement continually reappearing

Discussion in 'Malware Help (A Specialist Will Reply)' started by jabaka, May 26, 2005.

  1. jabaka

    jabaka Private E-2

    Whenever I restart my computer, MS Antispyware pops up with a window informing me that "SearchEnhancement" is trying to install itself. I click on Deny, and a few seconds later am informed that Searchenhancement has been removed ----- until the next time I restart the computer.
    Any suggestions?
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    http://www.majorgeeks.com/images/grenade.gif Download HijackThis 1.99.1

    http://www.majorgeeks.com/images/grenade.gif Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    http://www.majorgeeks.com/images/grenade.gif Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the ZIP file as your backups will not be safely stored.

    http://www.majorgeeks.com/images/grenade.gifBefore running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    http://www.majorgeeks.com/images/grenade.gifRun HijackThis and save your log file.

    http://www.majorgeeks.com/images/grenade.gif Post your log as an ATTACHMENT to your next post. (Do NOT copy/paste the log into your post as it will be removed).

    http://www.majorgeeks.com/images/grenade.gifNeed help with HJT? See this thread: NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting
     
  3. jabaka

    jabaka Private E-2

    Here's the HijackThis log. I have deleted (fixed) all of the 'nofile' BHOs many time but they are back the next time I boot the computer.
    Thanks for the help.
     

    Attached Files:

  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, tempoararily disable Spybot S&D's TeaTimer because it will block some of this fix!


    Please boot into Safe Mode with the Viewing of Hidden Files & Folders Enabled


    Now scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.

    O2 - BHO: (no name) - SOFTWARE - (no file)
    O2 - BHO: (no name) - {00041A26-7033-432C-94C7-6371DE343822} - (no file)
    O2 - BHO: (no name) - {0411069B-207E-4E65-9C65-DD57B74A97EB} - (no file)
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
    O2 - BHO: (no name) - {0BE61716-7C5F-428F-9A80-F80DD3340276} - (no file)
    O2 - BHO: (no name) - {2073A9F2-7CE3-440A-80F3-7007A71BD595} - (no file)
    O2 - BHO: (no name) - {2141AA06-F673-4033-AE83-A0D4C8D6D92B} - (no file)
    O2 - BHO: (no name) - {22BDBD99-6329-4B4C-A660-8B9063BF5758} - (no file)
    O2 - BHO: (no name) - {243B8EB3-FE8F-4C53-81D8-27365DFD8045} - (no file)
    O2 - BHO: (no name) - {2E56209F-E289-4C0A-BC0D-EADA11F9EBD8} - (no file)
    O2 - BHO: (no name) - {3238E543-373D-46DC-AC05-A63587E84CE2} - (no file)
    O2 - BHO: (no name) - {34DD0AC3-CFFE-4FA9-AA88-46DF186F1C90} - (no file)
    O2 - BHO: (no name) - {3514FBB5-2E6B-4B24-AB59-B5C5B78C292A} - (no file)
    O2 - BHO: (no name) - {36B8C667-D37F-44C7-A13B-0084507027F3} - (no file)
    O2 - BHO: (no name) - {3B17875B-6AF2-472D-9E3F-49970B8795EE} - (no file)
    O2 - BHO: (no name) - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - (no file)
    O2 - BHO: (no name) - {4F999C25-C3DB-4979-AD32-027332BFB8EA} - (no file)
    O2 - BHO: (no name) - {55269E2E-AABB-4878-8249-D6D647A298EF} - (no file)
    O2 - BHO: (no name) - {5763558D-9FF3-44D8-A9E3-A16A40CA9860} - (no file)
    O2 - BHO: (no name) - {69135BDE-5FDC-4B61-98AA-82AD2091BCCC} - (no file)
    O2 - BHO: (no name) - {720AD4EA-D9A6-4E58-9147-F1F1CBE4DF37} - (no file)
    O2 - BHO: (no name) - {7213EA96-4667-48CB-BE1F-E750D4D560C5} - (no file)
    O2 - BHO: (no name) - {773C6A5B-9187-40EC-AF11-0598A00DD617} - (no file)
    O2 - BHO: (no name) - {7A5ECB85-647C-4073-A0A2-4D7886254CE6} - (no file)
    O2 - BHO: (no name) - {8171A724-3941-4F6C-B316-48AE88911E8A} - (no file)
    O2 - BHO: (no name) - {85A702BA-EA8F-4B83-AA07-07A5186ACD7E} - (no file)
    O2 - BHO: (no name) - {8EC49DEA-F9AC-4AF3-8042-C2E2821CA687} - (no file)
    O2 - BHO: (no name) - {8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} - (no file)
    O2 - BHO: (no name) - {A3FDD654-A057-4971-9844-4ED8E67DBBB8} - (no file)
    O2 - BHO: (no name) - {AC7B7E9B-0EEA-45AF-ABF8-3B7BFDD16B58} - (no file)
    O2 - BHO: (no name) - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - (no file)
    O2 - BHO: (no name) - {B8292284-10F2-4FAE-95DF-233CBB1139D2} - (no file)
    O2 - BHO: (no name) - {BC6357DC-CE59-483E-AAEE-58246CCEBDD2} - (no file)
    O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
    O2 - BHO: (no name) - {CE31A1F7-3D90-4874-8FBE-A5D97F8BC8F1} - (no file)
    O2 - BHO: (no name) - {D3579C81-A2D4-4BED-9CA0-676F50113AB4} - (no file)
    O2 - BHO: (no name) - {D428ECAB-FBA5-4C56-A55A-EE6C9DD6E9B8} - (no file)
    O2 - BHO: (no name) - {D8604F6B-077A-4E00-BFC5-C0FEF977662D} - (no file)
    O2 - BHO: (no name) - {DD29436C-44A8-4E6E-960B-3F2215222EE1} - (no file)
    O2 - BHO: (no name) - {E0DF4503-FF6B-4849-A37F-A2BE59609704} - (no file)
    O2 - BHO: (no name) - {E5D5A7A9-1B81-4EA3-92A6-538611494B1D} - (no file)
    O2 - BHO: (no name) - {EBF6900A-7BF5-4355-9265-86E36D673AD2} - (no file)
    O2 - BHO: (no name) - {EE46DD00-DDAC-4531-B1CD-AC68825B18C9} - (no file)
    O2 - BHO: (no name) - {EE500300-E228-4A26-85C1-92CD1A6B433C} - (no file)
    O2 - BHO: (no name) - {F0539050-38EA-4D67-8EF1-241A07E79BF2} - (no file)
    O2 - BHO: (no name) - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} -
    O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} -
    O16 - DPF: {666DDE35-E955-11D0-A707-000000521958} -

    Again, make sure All Browser Windows are Closed when you Click FIX.

    NEXT:
    Run CCleaner and Spybot S&D and have Spybot fix what it finds.
    Note: Dont forget to update Spybot S&D by selecting "Search For Updates"

    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.


    Reboot to Normal Windows , Scan with HijackThis and attach the new log.
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now.

    Good Luck!:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds