searchweb2 problem

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by PiP32, Oct 22, 2004.

  1. PiP32

    PiP32 Private E-2

    ok i have the searchweb2 toolbar, searchbar and other thing that pops up down the bottom and wont close whenever i open internet explorer. i have done all the stuff it says to do on the http://forums.majorgeeks.com/showthread.php?t=35407 page and it didnt help.
    can someone please tell me how to get rid of it?
    thanks, PiP
     
  2. PhilliePhan

    PhilliePhan Guest

    Hi PiP32,

    Try this tool - OmegaKillerSM v1.2

    Please post back and let me know if it does the job. I'll try to check back when I can.

    Best luck,
    PP
     
  3. PiP32

    PiP32 Private E-2

    wow i think it did the job.
    thank you so much.
    PiP
     
  4. PhilliePhan

    PhilliePhan Guest

    Glad to hear it! Happy to help :)

    Let us know if you have any further problems.

    Best,
    PP
     
  5. PiP32

    PiP32 Private E-2

    ok turns out it didnt work coz the bars are back and this time that program doesnt find anything wrong with my pc.
    wat else could i do to get rid of it?
    PiP.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder or choose run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  7. PiP32

    PiP32 Private E-2

    ok here it is
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay first a couple of notes:
    1) You are using an old version of HijackThis. Please get the current version (link was in the READ ME FIRST). And post a new log. The old version does not reveal or fix certain items.

    2) Our directions specifically request that you shutdown browsers before using HijackThis. You had IE running:
    C:\Program Files\Internet Explorer\iexplore.exe

    3) You OS and Internet Explorer are seriously out of date. You must get updated after we fix the current problems. You have:
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)


    Question:
    1) Do you know what the below application is? It looks very suspicious to me.
    O4 - HKCU\..\Run: [Defaultsoap] C:\DOCUME~1\pip\APPLIC~1\COMPRE~1\htmlocks.exe
     
  9. PiP32

    PiP32 Private E-2

    no i dont know what that is
    i got the new version of HJT and closed the invisible iexplorer and run hjt again.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have system restore disabled and viewing of hidden files enabled (per the tutorial).

    Print these instructions or save them locally. Because I want you to be physically disconnecteded from the Internet (disconnect you cables) and to reboot in safe mode after doing this. Do not open a browser (IE) or reconnect to the Internet until I tell you to do so.

    Okay disconnect cables and boot into safe mode now!

    After booting in safe mode, bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Find the below processes and End them (note these file names may change at each boot of your PC):
    C:\DOCUMENTS and SETTINGS\pip\LOCAL SETTINGS\Temp\mertrhvn.exe
    C:\DOCUMENTS and SETTINGS\pip\LOCAL SETTINGS\Temp\knmkrdpr.exe


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bnvqbevdnyottxeoqntlx.us/tL5QnWheOIuU3CZQcJ2lmXBCbVFiBSnJMzRgh4cFBC/ACqWYiHal1/xwJoABaZpe.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    O4 - HKCU\..\Run: [Defaultsoap] C:\DOCUME~1\pip\APPLIC~1\COMPRE~1\htmlocks.exe


    Use Windows Explorer to delete (if found):
    C:\DOCUMENTS and SETTINGS\pip\APPLICATION DATA\COMPRE~1\htmlocks.exe
    C:\DOCUMENTS and SETTINGS\pip\LOCAL SETTINGS\Temp <--- delete all files in this folder

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel, Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reconnect your cables and reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  11. PiP32

    PiP32 Private E-2

    ok i did all that and i think its working now, the bars hav gone so theyre not annoying me.
    thanks for the help.
    here is my new hjt file like u asked too
    thanks again
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds