Page 1 of 1

exploit searchterror.com

PostPosted: Tue Jul 19, 2005 12:16 am
by action
Can you help me get rid of this danged thing! exploit searchterror.com. Bazooka found it but I can't seem to get rid of it.
Thanks............ ACTION

PostPosted: Tue Jul 19, 2005 2:25 pm
by Gecko
Please download , unzip it to it's own folder.
Start HijackThis and select 'Do a system scan and save a logfile'
Now post the contents of the logfile back into this thread

PostPosted: Wed Jul 20, 2005 5:33 pm
by action
Logfile of HijackThis v1.99.1
Scan saved at 6:47:36 PM, on 7/18/05
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\ISAFE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\INTERMUTE\SPYSUBTRACT\SPYSUB.EXE
C:\PROGRAM FILES\DYNAWARES' DYNASPELLER\DYNASPELLER.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\WINZIP\WINZIP32.EXE
C:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) = ,
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\RunServices: [CAISafe] C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O4 - Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SPYSUB.EXE
O4 - Startup: DynaSpeller.LNK = C:\Program Files\DynaWares' DynaSpeller\DynaSpeller.exe
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - http://www.xblock.com/download/xclean_micro.exe
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/Media ... e-c139.cab
O18 - Protocol: start - (no CLSID) - (no file)

PostPosted: Wed Jul 20, 2005 5:58 pm
by Gecko
Please copy this to Notepad and print it. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes.
You should not have any open windows when you are following the procedures below.

Please download and run the fix it button
Make sure you update it before you use the Fix it


Once CWShreader has finished close all other open Windows and have HiJackThis Fix:
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/Media ... e-c139.cab
O18 - Protocol: start - (no CLSID) - (no file)


Now, empty all your TEMP Folders, Temporary Internet Files Folder and then empty your Recycle Bin, reboot and post a new HiJackThis log.

PostPosted: Wed Jul 20, 2005 7:41 pm
by action
Followed directions to a tee but did not find;
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/Media ... e-c139.cab
O18 - Protocol: start - (no CLSID) - (no file) in registry.




Bazooka still detects exploit searchterror.com..........?

PostPosted: Wed Jul 20, 2005 7:46 pm
by action
Now hijackthis save log is being saved in windows media player?

PostPosted: Wed Jul 20, 2005 8:11 pm
by action
Logfile of HijackThis v1.99.1
Scan saved at 2:49:06 PM, on 7/20/05
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\ISAFE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\INTERMUTE\SPYSUBTRACT\SPYSUB.EXE
C:\PROGRAM FILES\DYNAWARES' DYNASPELLER\DYNASPELLER.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\WINZIP\WINZIP32.EXE
C:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) = ,
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\RunServices: [CAISafe] C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O4 - Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SPYSUB.EXE
O4 - Startup: DynaSpeller.LNK = C:\Program Files\DynaWares' DynaSpeller\DynaSpeller.exe
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O18 - Protocol: start - (no CLSID) - (no file)

exploit

PostPosted: Wed Jul 20, 2005 8:23 pm
by action
Unable to delete these registry 2 files
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O18 - Protocol: start - (no CLSID) - (no file)

PostPosted: Thu Jul 21, 2005 2:56 pm
by action
Logfile of HijackThis v1.99.1
Scan saved at 9:35:02 AM, on 7/21/05
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\ISAFE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\INTERMUTE\SPYSUBTRACT\SPYSUB.EXE
C:\PROGRAM FILES\DYNAWARES' DYNASPELLER\DYNASPELLER.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\WINZIP\WINZIP32.EXE
C:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) = ,
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
Can't seem to delete 015 and 018 form registry, can you help?


O4 - HKLM\..\RunServices: [CAISafe] C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O4 - HKLM\..\RunOnce: [washindex] C:\Program Files\Washer\washidx.exe "JACKSON"
O4 - HKLM\..\RunServicesOnce: [washindex] C:\Program Files\Washer\washidx.exe "JACKSON"
O4 - HKCU\..\RunOnce: [washindex] C:\Program Files\Washer\washidx.exe "JACKSON"
O4 - HKCU\..\RunServicesOnce: [washindex] C:\Program Files\Washer\washidx.exe "JACKSON"
O4 - Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SPYSUB.EXE
O4 - Startup: DynaSpeller.LNK = C:\Program Files\DynaWares' DynaSpeller\DynaSpeller.exe
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O18 - Protocol: start - (no CLSID) - (no file)