Jump to content


Photo

Websearch prob


  • Please log in to reply
13 replies to this topic

#1 sok

sok

    Member

  • Full Member
  • Pip
  • 10 posts

Posted 02 June 2004 - 08:28 PM

ive already read the faq

ive run spy sweeper, ad aware, and spybot. all show up the same websearch thing in the registry, heres the hijack this log

not sure if this is related or not, but my interenet screen keeps going inactive while im using it (as if a popup showed up but w/o the actual popup) So i have to re-click the screen again

Logfile of HijackThis v1.97.7
Scan saved at 9:21:21 PM, on 6/2/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\COMMON FILES\WINTOOLS\WTOOLSA.EXE
C:\PROGRAM FILES\COMMON FILES\WINTOOLS\WSUP.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\PCTVOICE.EXE
C:\PROGRAM FILES\B'S CLIP\BSCLIP.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\AIM\AIM.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\PROGRAM FILES\PCI AUDIO APPLICATIONS\BIN\WDM\FULL\MIXER.EXE
C:\PROGRAM FILES\AMERICA ONLINE 8.0A\AOLTRAY.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\SAJ0KPR.EXE
C:\WINDOWS\SYSTEM\BCN4.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\SPYWARE\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch...spx?tb_id=50093
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://boards.ign.co...ar_Online/b5187
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.websearch...spx?tb_id=50093
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch...spx?tb_id=50093
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSB.DLL
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSB.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [C-Media Mixer] C:\Program Files\PCI Audio Applications\Bin\AudioRack.exe /MixerStartup
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [PCTVOICE] pctvoice.exe
O4 - HKLM\..\Run: [B'sCLiP] C:\PROGRA~1\B'SCLI~1\BSCLIP.exe
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [2F#L6#D2Z#4SW@] C:\WINDOWS\SYSTEM\NuzK63G.exe
O4 - HKLM\..\Run: [WinTools] C:\Program Files\Common files\WinTools\WToolsA.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [WinTools] C:\Program Files\Common files\WinTools\WToolsA.exe
O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [NIWOTOGP.EXE] C:\WINDOWS\NIWOTOGP.EXE /dk
O4 - HKCU\..\Run: [WINT] C:\WINDOWS\SYSTEM\wcpcc.exe
O4 - Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0a\aoltray.exe
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsearch.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsimilar.html
O8 - Extra context menu item: Backward &Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmtrans.html
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: AIM (HKLM)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macr...director/sw.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.micr...922/wmv9VCM.CAB
O16 - DPF: {0000000A-0000-0010-8000-00AA00389B71} - http://download.micr...0367/wmavax.CAB
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupd...8126.4865162037
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab


a person showed me this link
http://www.securemos...rch_toolbar.htm

but i have a few questions

about the uninstall manually process (from that site)

1 Kill these running processes with Task Manager:
programfilesdir+\websearch\websearch1.exe

wheres task manager?

3 Unregister these DLLs with Regsvr32, then reboot:
systemroot+\system32\spotonbh.dll
systemroot+\system\spotonbh.dll, toolbar.dll

err, i searched this and found the application
and it gave me all this [/i] and [/u] stuff, i dont get how you do this

4 Remove these files (if present) with Windows Explorer:
programfilesdir+\websearch\websearch1.exe
systemroot+\system32\spotonbh.dll
systemroot+\system\spotonbh.dlltoolbar.dll
xzxsv.wzg

5 Remove these directories (if present) with Windows Explorer:
programfilesdir+\websearch

how do i find these files/directories using windows explorer?

thanks

Edited by sok, 02 June 2004 - 08:31 PM.


#2 sok

sok

    Member

  • Full Member
  • Pip
  • 10 posts

Posted 03 June 2004 - 11:00 AM

bump

#3 sok

sok

    Member

  • Full Member
  • Pip
  • 10 posts

Posted 03 June 2004 - 08:19 PM

need help please

#4 sok

sok

    Member

  • Full Member
  • Pip
  • 10 posts

Posted 04 June 2004 - 11:36 AM

anyone?

#5 Daemon

Daemon

    Security Expert

  • Emeritus
  • PipPipPipPipPip
  • 3,350 posts

Posted 04 June 2004 - 02:16 PM

Click here to download the PeperFix tool, save it to your desktop, doubleclick on it, click 'Find and Fix' and reboot if prompted.

Rescan with HJT and post a new log here so that any remnants can be removed manually.
Posted Image

#6 sok

sok

    Member

  • Full Member
  • Pip
  • 10 posts

Posted 04 June 2004 - 02:41 PM

ok, i ran the peper thing, it found like 5 files, restarted my comp. Then i go to run hijack, when i click scan, it gives the scan results but the top part of the window shows a blue bar, and the program freezes up. So i have to end it.

Should i re-download hijack or what?

#7 Daemon

Daemon

    Security Expert

  • Emeritus
  • PipPipPipPipPip
  • 3,350 posts

Posted 04 June 2004 - 02:45 PM

Reboot again - see if you can get a new scan.
Posted Image

#8 sok

sok

    Member

  • Full Member
  • Pip
  • 10 posts

Posted 04 June 2004 - 10:05 PM

i rebooted when it first failed the first time. THen the computer was off for a few hours and it still doesnt work now

#9 sok

sok

    Member

  • Full Member
  • Pip
  • 10 posts

Posted 04 June 2004 - 10:19 PM

i re-downloaded hijack and it still doesnt work

#10 sok

sok

    Member

  • Full Member
  • Pip
  • 10 posts

Posted 05 June 2004 - 08:37 PM

bump, any more advice here?

hijack still not working properly :/

i just re-installed it and it still freezes up

Edited by sok, 05 June 2004 - 08:46 PM.


#11 sok

sok

    Member

  • Full Member
  • Pip
  • 10 posts

Posted 05 June 2004 - 08:59 PM

ok, spyware guard keeps saying my IE search bar has been changed to

http://www.websearch...spx?tb_id=50093

and is kinda annoying since it pops up every few minutes. Anyway i can make SG do this automatically or something?


...how does websearch keep coming back up....especailly since system restore has been off for days

Edited by sok, 05 June 2004 - 09:06 PM.


#12 Daemon

Daemon

    Security Expert

  • Emeritus
  • PipPipPipPipPip
  • 3,350 posts

Posted 06 June 2004 - 03:40 AM

Could you click here to download CWShredder by Merijn Bellekom and run it, hit 'fix' as opposed to 'scan only'. Make sure you are on v1.59. Reboot when done.

Try and get a new HJT log - I need to see that to help you further.
Posted Image

#13 sok

sok

    Member

  • Full Member
  • Pip
  • 10 posts

Posted 06 June 2004 - 10:48 PM

ok, i redownloaded cws from that link, ran it and it found nothing. I rebooted still and tried hijack, still freezes up when i scan. I can still configure hijack's settings if that helps any.

Its odd, since hijack started freezing right after i ran peperfix and rebooted/restared

#14 Daemon

Daemon

    Security Expert

  • Emeritus
  • PipPipPipPipPip
  • 3,350 posts

Posted 07 June 2004 - 02:01 AM

I think it's coincidental that it happened after peperfix, the two programs are unrelated. It does pause for a while with that blue bar - how long are you waiting before you end it? You haven't got the calculate MD5 box checked have you - that'll slow it down. Also try running it in safe mode - you should be able to get a log that way.
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of ASAP and UNITE
Support SpywareInfo Forum - click the button