It is currently Tue Sep 01, 2026 4:18 pm


exploit searchterror.com

All versions of Window XP and 2003 including 32 bit and 64 bit

Moderator: icecube

exploit searchterror.com

Postby action » Tue Jul 19, 2005 12:16 am

Can you help me get rid of this danged thing! exploit searchterror.com. Bazooka found it but I can't seem to get rid of it.
Thanks............ ACTION
User avatar
action
Newbie
Newbie
 
Posts: 12
Joined: Tue Jul 19, 2005 1:00 am

Thanks given:0
Thanks received:0
Top

Postby Gecko » Tue Jul 19, 2005 2:25 pm

Please download , unzip it to it's own folder.
Start HijackThis and select 'Do a system scan and save a logfile'
Now post the contents of the logfile back into this thread
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Postby action » Wed Jul 20, 2005 5:33 pm

Logfile of HijackThis v1.99.1
Scan saved at 6:47:36 PM, on 7/18/05
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\ISAFE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\INTERMUTE\SPYSUBTRACT\SPYSUB.EXE
C:\PROGRAM FILES\DYNAWARES' DYNASPELLER\DYNASPELLER.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\WINZIP\WINZIP32.EXE
C:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) = ,
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\RunServices: [CAISafe] C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O4 - Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SPYSUB.EXE
O4 - Startup: DynaSpeller.LNK = C:\Program Files\DynaWares' DynaSpeller\DynaSpeller.exe
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - http://www.xblock.com/download/xclean_micro.exe
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/Media ... e-c139.cab
O18 - Protocol: start - (no CLSID) - (no file)
User avatar
action
Newbie
Newbie
 
Posts: 12
Joined: Tue Jul 19, 2005 1:00 am

Thanks given:0
Thanks received:0
Top

Postby Gecko » Wed Jul 20, 2005 5:58 pm

Please copy this to Notepad and print it. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes.
You should not have any open windows when you are following the procedures below.

Please download and run the fix it button
Make sure you update it before you use the Fix it


Once CWShreader has finished close all other open Windows and have HiJackThis Fix:
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/Media ... e-c139.cab
O18 - Protocol: start - (no CLSID) - (no file)


Now, empty all your TEMP Folders, Temporary Internet Files Folder and then empty your Recycle Bin, reboot and post a new HiJackThis log.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Postby action » Wed Jul 20, 2005 7:41 pm

Followed directions to a tee but did not find;
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/Media ... e-c139.cab
O18 - Protocol: start - (no CLSID) - (no file) in registry.




Bazooka still detects exploit searchterror.com..........?
User avatar
action
Newbie
Newbie
 
Posts: 12
Joined: Tue Jul 19, 2005 1:00 am

Thanks given:0
Thanks received:0
Top

Postby action » Wed Jul 20, 2005 7:46 pm

Now hijackthis save log is being saved in windows media player?
User avatar
action
Newbie
Newbie
 
Posts: 12
Joined: Tue Jul 19, 2005 1:00 am

Thanks given:0
Thanks received:0
Top

Postby action » Wed Jul 20, 2005 8:11 pm

Logfile of HijackThis v1.99.1
Scan saved at 2:49:06 PM, on 7/20/05
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\ISAFE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\INTERMUTE\SPYSUBTRACT\SPYSUB.EXE
C:\PROGRAM FILES\DYNAWARES' DYNASPELLER\DYNASPELLER.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\WINZIP\WINZIP32.EXE
C:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) = ,
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\RunServices: [CAISafe] C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O4 - Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SPYSUB.EXE
O4 - Startup: DynaSpeller.LNK = C:\Program Files\DynaWares' DynaSpeller\DynaSpeller.exe
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O18 - Protocol: start - (no CLSID) - (no file)
User avatar
action
Newbie
Newbie
 
Posts: 12
Joined: Tue Jul 19, 2005 1:00 am

Thanks given:0
Thanks received:0
Top

exploit

Postby action » Wed Jul 20, 2005 8:23 pm

Unable to delete these registry 2 files
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O18 - Protocol: start - (no CLSID) - (no file)
User avatar
action
Newbie
Newbie
 
Posts: 12
Joined: Tue Jul 19, 2005 1:00 am

Thanks given:0
Thanks received:0
Top

Postby action » Thu Jul 21, 2005 2:56 pm

Logfile of HijackThis v1.99.1
Scan saved at 9:35:02 AM, on 7/21/05
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\ISAFE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\INTERMUTE\SPYSUBTRACT\SPYSUB.EXE
C:\PROGRAM FILES\DYNAWARES' DYNASPELLER\DYNASPELLER.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\WINZIP\WINZIP32.EXE
C:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) = ,
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
Can't seem to delete 015 and 018 form registry, can you help?


O4 - HKLM\..\RunServices: [CAISafe] C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O4 - HKLM\..\RunOnce: [washindex] C:\Program Files\Washer\washidx.exe "JACKSON"
O4 - HKLM\..\RunServicesOnce: [washindex] C:\Program Files\Washer\washidx.exe "JACKSON"
O4 - HKCU\..\RunOnce: [washindex] C:\Program Files\Washer\washidx.exe "JACKSON"
O4 - HKCU\..\RunServicesOnce: [washindex] C:\Program Files\Washer\washidx.exe "JACKSON"
O4 - Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SPYSUB.EXE
O4 - Startup: DynaSpeller.LNK = C:\Program Files\DynaWares' DynaSpeller\DynaSpeller.exe
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O18 - Protocol: start - (no CLSID) - (no file)
User avatar
action
Newbie
Newbie
 
Posts: 12
Joined: Tue Jul 19, 2005 1:00 am

Thanks given:0
Thanks received:0
Top


Return to Windows XP and 2003

Who is online

Users browsing this forum: No registered users and 1 guest

cron