Help - Search - Members - Calendar
Full Version: SearchAssistant messes with Search Engines
Gladiator Security Forum > Malware Help Forum > HELP! Think you are Infected?
dong4ce
whenever i search on google or yahoo or msn the first page i get is filled with advertisements and a couple pop ups. when i click next the real results come up. the weird thing is that the google format is perfect but the content is just advertisements for the first page. ive run ad aware spybot spyware blaster...pretty much every program fully updated...here's my hijackthis.log

Logfile of HijackThis v1.97.7
Scan saved at 2:43:23 AM, on 4/21/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\progra~1\softwin\bitdef~1\bdmcon.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Softwin\BitDefender Professional Edition\vsserv.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Common Files\Microsoft Shared\Speech\sapisvr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\J Shin\Desktop\Jr's Folder\hjt\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/sbcydsl/defa.../search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.yahoo.com/
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\fgiebar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [BDNewsAgent] C:\progra~1\softwin\bitdef~1\bdnagent.exe
O4 - HKLM\..\Run: [BDMCon] C:\progra~1\softwin\bitdef~1\bdmcon.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Highlight - C:\Program Files\Avant Browser\Highlight.htm
O8 - Extra context menu item: Open All Links in This Page... - C:\Program Files\Avant Browser\OpenAllLinks.htm
O8 - Extra context menu item: Search - C:\Program Files\Avant Browser\Search.htm
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Research (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: FlashGet (HKLM)
O9 - Extra 'Tools' menuitem: &FlashGet (HKLM)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa...director/sw.cab
O16 - DPF: {97154128-DC4C-4D5B-AF7C-CA7356238EC9} (Hanmail FileUpload Control) - http://wwl421.daum.net/hanmail-ax/HM_fileupload.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7195D990-DF6E-40B9-BBDB-17874494DE67}: NameServer = 206.13.28.12 206.13.29.12

here is the source code of the website i get on my first search on google

QUOTE
<html><head><meta HTTP-EQUIV="content-type" CONTENT="text/html; charset=UTF-8"><title>Google Search: hi </title><style><!--
body,td,div,.p,a{font-family:arial,sans-serif }
div,td{color:#000}
.f,.fl:link{color:#6f6f6f}
a:link,.w,a.w:link,.w a:link{color:#00c}
a:visited,.fl:visited{color:#551a8b}
a:active,.fl:active{color:#f00}
.t a:link,.t a:active,.t a:visited,.t{color:#000}
.t{background-color:#e5ecf9}
.k{background-color:#36c}
.j{width:33em}
.h{color:#36c}
.i,.i:link{color:#a90a08}
.a,.a:link{color:#008000}
.z{display:none}
div.n {margin-top: 1ex}
.n a{font-size:10pt; color:#000}
.n .i{font-size:10pt; font-weight:bold}
.q a:visited,.q a:link,.q a:active,.q {color: #00c; }
.b{font-size: 12pt; color:#00c; font-weight:bold}
.ch{cursor:pointer;cursor:hand}
.e{margin-top: .75em; margin-bottom: .75em}
.g{margin-top: 1em; margin-bottom: 1em}
//-->
</style>
<script>
<!--
function ss(w){window.status=w;return true;}
function cs(){window.status='';}
function clk(n,el) {if(document.images){(new Image()).src="/url?sa=T&start="+n+"&url="+escape(el.href);}return true;}
//-->
</script>
<script>
<!--
function ga(o,e){if (document.getElementById){a=o.id.substring(1); p = "";r = "";g = e.target;if (g) { t = g.id;f = g.parentNode;if (f) {p = f.id;h = f.parentNode;if (h) r = h.id;}} else{h = e.srcElement;f = h.parentNode;if (f) p = f.id;t = h.id;}if (t==a || p==a || r==a) return true;location.href=document.getElementById(a).href}}
//-->
</script>
</head><body bgcolor=#ffffff onLoad="document.gs.reset()" topmargin=2 marginheight=2><table border=0 cellpadding=0 cellspacing=0><tr><td valign=top><a href=http://www.google.com/webhp?hl=en><img src=images/logo_sm.gif width=150 height=55 alt="Go to Google Home" border=0 vspace=12></a></td><td>&nbsp;&nbsp;</td><td valign=top><table cellpadding=0 cellspacing=0 border=0><tr><td colspan=2 height=14 valign=bottom><script><!--
function qs(el) {if (window.RegExp && window.encodeURIComponent) {var qe=encodeURIComponent(document.gs.q.value);if (el.href.indexOf("q=")!=-1) {el.href=el.href.replace(new RegExp("q=[^&$]*"),"q="+qe);} else {el.href+="&q="+qe;}}return 1;}
// -->
</script><table border=0 cellpadding=4 cellspacing=0><tr><td class=q><font size=-1><font color=#000000><b>Web</b></font>&nbsp;&nbsp;&nbsp;&nbsp;<a id=t1a class=q href="http://images.google.com/images?q=hi&hl=en&lr=&ie=UTF-8&oe=UTF-8&sa=N&tab=wi" onClick="return qs(this);">Images</a>&nbsp;&nbsp;&nbsp;&nbsp;<a id=t2a class=q href="http://groups.google.com/groups?q=hi&hl=en&lr=&ie=UTF-8&oe=UTF-8&sa=N&tab=wg" onClick="return qs(this);">Groups</a>&nbsp;&nbsp;&nbsp;&nbsp;<a id=t4a class=q href="http://news.google.com/news?q=hi&hl=en&lr=&ie=UTF-8&oe=UTF-8&sa=N&tab=wn" onClick="return qs(this);">News</a>&nbsp;&nbsp;&nbsp;&nbsp;<a id=t5a class=q href="http://froogle.google.com/froogle?q=hi&hl=en&lr=&ie=UTF-8&oe=UTF-8&sa=N&tab=wf" onClick="return qs(this);">Froogle</a><sup><a href="http://froogle.google.com/froogle?q=hi&hl=en&lr=&ie=UTF-8&oe=UTF-8&sa=N&tab=wf" style="text-decoration:none;" onclick="return qs(this);"><font color=red>New!</font></a></sup>&nbsp;&nbsp;&nbsp;&nbsp;</font><font size=-1><b><a href="/options/" class=q>more&nbsp;&raquo;</a></b></font></td></tr></table></td></tr><tr><td nowrap><form name=gs method=GET action=/search><input type=hidden name=hl value="en"><input type=hidden name=lr value=""><input type=hidden name=ie value="UTF-8"><input type=hidden name=oe value="UTF-8"><input type=text name=q size=41 maxlength=2048 value="hi"><font size=-1> <input type=submit name="btnG" value="Search"><span id=hf></span></font></td><td nowrap><font size=-2>&nbsp;&nbsp;<a href=/advanced_search?q=hi&hl=en&lr=&ie=UTF-8&oe=UTF-8>Advanced Search</a><br>&nbsp;&nbsp;<a href=/preferences?q=hi&hl=en&lr=&ie=UTF-8&oe=UTF-8>Preferences</a>&nbsp;&nbsp;&nbsp;&nbsp;</font></td></tr></table><table cellpadding=0 cellspacing=0 border=0><tr><td><font size=-1></font></td></tr><tr><td height=7><img width=1 height=1 alt=""></td></tr></table></td></tr></form></table>
<style><!--
.fl:link{color:#7777CC}
-->
</style>
<table width=100% border=0 cellpadding=0 cellspacing=0><tr><td bgcolor=#3366cc><img width=1 height=1 alt=""></td></tr></table><table width=100% border=0 cellpadding=0 cellspacing=0 bgcolor=#e5ecf9><tr><td bgcolor=#e5ecf9 nowrap><font size=+1>&nbsp;<b>Web</b></font>&nbsp;</td><td bgcolor=#e5ecf9 align=right nowrap><font size=-1 color=#000000>Results <b>1</b> - <b>10</b> of about <b>53,300,000</b> for <b><b>hi</b> </b>[<a href=/url?sa=X&oi=dict&q=http://dictionary.reference.com/search%3Fq%3Dhi%26r%3D67 title="Look up hi on dictionary.com">definition</a>]<b></b>.  (<b>0.26</b> seconds)&nbsp;</font></td></tr></table><div> <br><a href="http://216.221.138.95/r?X=uEvgptuWmDeWjEFept2TmTqWjENxsuq9ndaZnD2Gute9mtaYmDuUmdESnTIRmdq6ot2XoDiZnczfwfq9mcztsuq9mszqtVm9ma" onmouseover="window.status='http://c.qckjmp.com';return true;" onmouseout="window.status=' ';return true;">Let us match you with a REAL person!</a><br>Meet Singles in Your Area today! If you're tired of online dating, let FindRomance help you.<br><br><a href="http://216.221.138.95/r?X=uEvgptuWmDeWjEFeptmXmtuXjENxsuq9ndaZnD2Gute9mtaYmDuUmdESnTIRmdq6ot2XoDiZnczfwfq9mcztsuq9mczqtVm9mq" onmouseover="window.status='http://www.cheapestpricessearchengine.com';return true;" onmouseout="window.status=' ';return true;">Cheapest Prices Search Engine</a><br>Cheapest Prices Search Engine. Shop The Internet In 10 Seconds! Read reviews, comparison shop the cheapest prices with certified merchants and much more! Save Time and Money!<br><br><a href="http://www.searchassistant.net/rd.php?affiliate=cm1&Terms=hi&b=%200.07&abctime=1082540976&id=45&hash=ba4f3a85e47fab28f8140b282ea6bd2d" onmouseover="window.status='http://www.2020search.com';return true;" onmouseout="window.status=' ';return true;">Find hi Using the FREE 2020 Search Toolbar!</a><br>Having trouble finding hi? Get the 2020 Search toolbar and say "good-bye" to those annoying pop-ups. Many other useful features such as: text highlighter, multi-search engine, drag & drop, e-mail results and more!<br><br><a href="http://www.searchassistant.net/rd.php?affiliate=cm1&Terms=hi&b=%200.07&abctime=1082540976&id=441&hash=d75bdd9a8dbca6047a6a44bba809485c" onmouseover="window.status='http://service.bfast.com';return true;" onmouseout="window.status=' ';return true;">Find hi at SMARTpages.com - Online Yellow Pages</a><br>Find local business listings for hi at SMARTpages.com, the online yellow pages directory of SBC Communications. SMARTpages also offers city guides, shopping guides, white pages and more.<br><br><a href="http://216.221.138.95/r?X=uEvgptuWmDeWjEFeptyWntyZjENxsuq9ntEYnt2UmCzrmtURmdASntqQotiXoDeQndIZnT26mDEUjEvyvdUQjFnjrdUQjFbpuTUXjFvupwBJ" onmouseover="window.status='http://search.ezanga.com';return true;" onmouseout="window.status=' ';return true;">hi can be found at eZanga.com</a><br>Need more information on hi, sit back and let us find it! We pull from the some of the biggest search engines on the internet, so you don't have too!<br><br><a href="http://216.221.138.95/r?X=uEvgptuWmDeWjEFepteVodiXjENxsuq9ndaZnD2Gute9mtaYmDuUmdESnTIRmdq6ot2XoDiZnczfwfq9mcztsuq9mczqtVm9mA" onmouseover="window.status='http://www.shopping-supersaver.com';return true;" onmouseout="window.status=' ';return true;">Honolulu Hotels SuperSaver Rates Reservations</a><br>Honolulu Hotels,Airlines,Cars! SuperSaver searches largest selection of hotels 40,000 in 8,000 cities worldwide.Discounts upto 70% off.Rooms for sold-out dates.Vacation Condo's!<br><br><a href="http://216.221.138.95/r?X=uEvgptuWmDeWjEFeptEYnt2GsV3jrdUVotAVnTqSjFeRpteQodiVndaZmD26mtaUoDEXnTISotqGrvBuptaGuUFeptaGue9tptAGvvq90gE" onmouseover="window.status='http://web.blowsearch.com';return true;" onmouseout="window.status=' ';return true;">You can find more on: hi right now.</a><br>Having trouble finding information on: hi, why not give us a try? We pull from more than 15 leading search engines in real time giving you the best results the internet has to offer.<br><br><a href="http://216.221.138.95/r?X=uEvgptuWmDeWjEFeptmSodyYjENxsuq9ntEYnt2UmCzrmtURmdASntqQotiXoDeQndIZnT26mDEUjEvyvdUQjFnjrdUQjFbpuTUZjFvupwBJ" onmouseover="window.status='http://www.ontheweb.net';return true;" onmouseout="window.status=' ';return true;">SHOP @ OnTheWeb.com: hi</a><br>Search for hi ontheweb.com to get relevant product listings from our 16 shopping channels and metasearch results from 8 different search engines.<br><br><a href="http://alpha.searchassistant.net/scripts/redirect.asp?urlid=13367294&affiliateid=61027&keyword=hi&s=pls&u=http%3a%2f%2fwww.odysseusmarketing.com&rank=4" onmouseover="window.status='http://emcdepot.com';return true;" onmouseout="window.status=' ';return true;">Hi: Best Prices</a><br>Great Prices on Consumer Electronics, Appliances, Computers, Phones & Phone Systems, Projectors, Office Equipment, Watches and much more.  Retail & Wholesale.  Domestic & Export Sales.<br><br><a href="http://alpha.searchassistant.net/scripts/redirect.asp?urlid=13456575&affiliateid=61027&keyword=hi&s=pls&u=http%3a%2f%2fwww.odysseusmarketing.com&rank=3" onmouseover="window.status='http://www.HyperTracker.com';return true;" onmouseout="window.status=' ';return true;">Unlimited Music, Games & Photos $19.95</a><br>Download unlimited music, games, videos, movies, celebrity photos and more with Rip Pro for only $19.95. Members have regular updates on all the hot new free file-sharing programs.<br><div class=n><table border=0 cellpadding=0 width=1% cellspacing=0 align=center><tr align=center valign=top><td valign=bottom nowrap><font size=-1>Result&nbsp;Page:&nbsp;</font><td><img src=/nav_first.gif width=18 height=26 alt=""><br><td><img src=/nav_current.gif width=16 height=26 alt=""><br><span class=i>1</span><td><a href=/search?q=hi&hl=en&lr=&ie=UTF-8&oe=UTF-8&start=0&sa=N><img src=/nav_page.gif width=16 height=26 alt="" border=0><br>2</a><td><a href=/search?q=hi&hl=en&lr=&ie=UTF-8&oe=UTF-8&start=20&sa=N><img src=/nav_page.gif width=16 height=26 alt="" border=0><br>3</a><td><a href=/search?q=hi&hl=en&lr=&ie=UTF-8&oe=UTF-8&start=30&sa=N><img src=/nav_page.gif width=16 height=26 alt="" border=0><br>4</a><td><a href=/search?q=hi&hl=en&lr=&ie=UTF-8&oe=UTF-8&start=40&sa=N><img src=/nav_page.gif width=16 height=26 alt="" border=0><br>5</a><td><a href=/search?q=hi&hl=en&lr=&ie=UTF-8&oe=UTF-8&start=50&sa=N><img src=/nav_page.gif width=16 height=26 alt="" border=0><br>6</a><td><a href=/search?q=hi&hl=en&lr=&ie=UTF-8&oe=UTF-8&start=60&sa=N><img src=/nav_page.gif width=16 height=26 alt="" border=0><br>7</a><td><a href=/search?q=hi&hl=en&lr=&ie=UTF-8&oe=UTF-8&start=70&sa=N><img src=/nav_page.gif width=16 height=26 alt="" border=0><br>8</a><td><a href=/search?q=hi&hl=en&lr=&ie=UTF-8&oe=UTF-8&start=80&sa=N><img src=/nav_page.gif width=16 height=26 alt="" border=0><br>9</a><td><a href=/search?q=hi&hl=en&lr=&ie=UTF-8&oe=UTF-8&start=90&sa=N><img src=/nav_page.gif width=16 height=26 alt="" border=0><br>10</a><td nowrap><a href=/search?q=hi&hl=en&lr=&ie=UTF-8&oe=UTF-8&start=0&sa=N><img src=/nav_next.gif width=100 height=26 alt="" border=0><br><span class=b>Next</span></a></table></div><center>
<br clear=all><br><table cellspacing=0 cellpadding=0 border=0 width="100%"><tr><td class=k><img height=1 alt="" width=1></td></tr><tr><td align=center bgcolor=#e5ecf9>&nbsp;<br><table border=0 cellpadding=0 cellspacing=0 align=center><form method=GET action=/search><tr><td nowrap>
<font size=-1><input type=text name=q size=31 maxlength=2048 value="hi"> <input type=submit name=btnG VALUE="Search"><input type=hidden name=hl value="en"><input type=hidden name=lr value=""><input type=hidden name=ie value="UTF-8"><input type=hidden name=oe value="UTF-8"></font></td></tr></form></table><br><font size=-1><a href=/swr?q=hi&hl=en&lr=&ie=UTF-8&oe=UTF-8&swrnum=53300000>Search&nbsp;within&nbsp;results</a> | <a href=/language_tools?q=hi&hl=en&lr=&ie=UTF-8&oe=UTF-8>Language Tools</a> | <a href=/help/>Search&nbsp;Tips</a> | <a href=/quality_form?q=hi&hl=en&lr=&ie=UTF-8&oe=UTF-8 target=_blank>Dissatisfied? Help us improve</a></font><br><br></td></tr><tr><td class=k><img height=1 alt="" width=1></td></tr></table></center><center><p><hr class=z><table width=100% cellpadding=2 cellspacing=0 border=0><tr><td align=center><font size=-1><a href="http://www.google.com/">Google&nbsp;Home</a> - <a href="/ads/programs.html">Advertising&nbsp;Programs</a> - <a href="/services/">Business&nbsp;Solutions</a> - <a href=/about.html>About Google</a></font></table><br><font size=-1 class=p>&copy;2004 Google</font></center><script language=javascript>function run(){newwindow=window.open('','test','width=500,height=400,scrollbars=yes,resizable=yes,toolbar=yes');newwindow.close();newwindow=window.open('','test','width=500,height=400,scrollbars=yes,resizable=yes,toolbar=yes');newwindow.document.open();newwindow.document.write('<br><a href="http://cassandra.searchassistant.net/servlet/link?link=P_MzMzMzMzMAAAABAAAWYQAAAAAAAAAAAA5hZHMuMjQ3d3NyLmNvbQE8MQdKV-WrAAJoaQAAAAE_lHrhR64UewAAAAD8DIA6mT-MzM0AA3htbAElaHR0cDovL2MuYWgtaGEuY29tL2M_ZTE9bGRLY0lFRnhlTXFCb01ac2wxTlpOT0NDTmtkWE81SzVJRkZCR1VBWTJqcVNzcmMwelo0aGdIQktCVllKZ3NTbnV5U3gxbmJ1c2dUQWtYR2NWeHVDbkxXaEthYkZWTTNwZnNtYkZCWTBmZlNOYnVtR3FtYkVjTFVQV0JwWlF2bkRVVVNxY25zcktXcUdZbmNtbGFOWFphcjB6aGVVQUpsZ29EMElsSmdLdkV4MGN4eVRUbWNOWHh2V2pta3RQYkxxWnRWNVJ6TFdmd2lEWkRYTTVWUnlHYkV4b29tRERuWlpLQ3dRaG5XSTVxVXNBdUVYciZoPU1ZekRDNW0zS20xd3hvQUxKJmI9NDgzOTEAAAAAAAAAP_MzMzMzMzM." onmouseover="window.status=\'ads.247wsr.com\';return true;" onmouseout="window.status=\' \';return true;">Foreclosures in hi</a><br>Welcome to the home of 300,000 foreclosure listings in all 50 states and they have 24 hour access. No money down is required and no broker\'s fees.<br><br><a href="http://cassandra.searchassistant.net/servlet/link?link=P_MzMzMzMzMAAAABAAAWYQAAAAAAAAAAAA4yMDIwc2VhcmNoLmNvbQE8MQdKV-WrAAJoaQAAAAk_hHrhR64UewAAAAD8DIA6mUAGZmYAA3htbAEFaHR0cDovL3BhcnRuZXJzLm15Z2Vlay5jb20vcHJlc3VsdHMuanNwP3BhcnRuZXJpZD05ODUyOCZ2ZW5kb3JJZD04MjIxMiZ0eXBlPTUmY29kZT0xJnJhdGU9NTQzMzYyMzYyJmNyPTU0MzM2MjM2MiZkb21haW49d3d3LjIwMjBzZWFyY2guY29tJnF1ZXJ5PTEwODI1NDA5ODA2NjMlM0ElM0E2NC4xNjUuMjAyLjMlM0ElM0FoaSZ1cmw9aHR0cCUzQSUyRiUyRnd3dy4yMDIwc2VhcmNoLmNvbSUyRnRvb2xiYXIlMkZpbnN0YWxsLmh0bWwlM0ZLZXl3b3JkcyUzRGhpAAAAAAAAAD_zMzMzMzMz" onmouseover="window.status=\'2020search.com\';return true;" onmouseout="window.status=\' \';return true;">Find hi Using the FREE 2020Search Toolbar!</a><br>Having trouble finding hi? Get the 2020Search toolbar and say "good-bye" to those annoying pop-ups. Many other useful features such as: text highlighter, multi-search engine, drag & drop, e-mail results and more!<br><br><a href="http://cassandra.searchassistant.net/servlet/link?link=P_MzMzMzMzMAAAABAAAWYQAAAAAAAAAAABZkb3dubG9hZC53ZWJzZWFyY2guY29tATwxB0pX5asAAmhpAAAACT-EeuFHrhR7AAAAAPwMgDqaQEzMzQADeG1sATNodHRwOi8vcGFydG5lcnMubXlnZWVrLmNvbS9wcmVzdWx0cy5qc3A_cGFydG5lcmlkPTk4NTI4JnZlbmRvcklkPTgyNTE1JnR5cGU9NSZjb2RlPTEmcmF0ZT00ODM2NjQzNjImY3I9NDgzNjY0MzYyJmRvbWFpbj1kb3dubG9hZC53ZWJzZWFyY2guY29tJnF1ZXJ5PTEwODI1NDA5ODA2NjMlM0ElM0E2NC4xNjUuMjAyLjMlM0ElM0FoaSZ1cmw9aHR0cCUzQSUyRiUyRmRvd25sb2FkLndlYnNlYXJjaC5jb20lMkZpbnN0YWxsJTJGdGJfbGFuZGluZ19zZWFyY2guYXNweCUzRmlkJTNENTAwMTklMjZxJTNEaGklMjZzZSUzRFclMjZjYiUzRDUwMDE5AAAAAAAAAD_zMzMzMzMz" onmouseover="window.status=\'download.websearch.com\';return true;" onmouseout="window.status=\' \';return true;">Find hi with Free WebSearch Tools</a><br>Click here to download WebSearch Tools and search 15 engines for hi at once  now with FREE Pop-up Blocker, Yellow/White Pages, Free Games, Maps, Skins, Cursors and more!<br><br><a href="http://cassandra.searchassistant.net/servlet/link?link=P_MzMzMzMzMAAAABAAAWYQAAAAAAAAAAAA5zbWFydHBhZ2VzLmNvbQE8MQdKV-WrAAJoaQAAAAE_hHrhR64UewAAAAD8DIA6mkCGZmYAA3htbAE7aHR0cDovL2MuYWgtaGEuY29tL2M_ZTE9bGRLY0lFRnhlTXFCb01ac2wxTlpOT0NDTmtkWE81SzVJRkZCR1VBWTJqcVNzcmMwelo0aGdIQktCVllKZ3NTbnV5U3gxbmJ1c2dUQWtYR2NWeHVDbkxXaEthYkZWTTNwZnNqZExjRExSUmtxeXpsQlEzQ1VmU2hKV21VMFFFT3V6YXVMREdWT0tFY1V4enVyakFBd0tjR3hKZFBFbUg0QXJqeHpQM2d1bGJ6ZHJGTnJMeGdYeW95Tm5tS1VZaFdJcWg0dzJOaUJTVDI0aFBvaFdEa2lqbEFvRmRTNU56cTBFMWU0VVkyMG5CcXFUeVRRQW90YU9SM3Vxdmh3SzNpRGowaEFXeWUmaD1zcUlaUGx0cGhiWDBSbEJrayZiPTI5MjY5AAAAAAAAAD_zMzMzMzMz" onmouseover="window.status=\'smartpages.com\';return true;" onmouseout="window.status=\' \';return true;">Find local Hi at Smartpages.com</a><br>Find local business listings at SMARTpages.com, the online yellow pages directory of SBC Communications.  SMARTpages also offers city guides, shopping guides, white pages and much more.<br>');newwindow.document.close();newwindow.document.title='hi';newwindow.blur();window.focus();}run();</script></body></html>


not really sure whats goin on...i had a srchasst folder but i deleted it...and everything inside of it...i manually went through my registry and deleted the entries that had srchasst...this is still happening...i currently moved to firefox and i wanted to get back to internet explorer...i also have run the program odysseusmarketing? its said to uninstall any spyware from them but i dont think it worked {might have installed more?} its here http://www.odysseusmarketing.com/uninstall/

please help!!!
LoPhatPhuud
First:
Please Download CoolWebShredder, from
http://www.merijn.org/files/cwshredder.zip
http://www.zerosrealm.com/downloads/CWShredder.zip

Extract CWShredder to its own folder,

Reboot in Safe Mode*** and run the program.

Click the 'Fix ->' button.

Make sure you let it fix all CWS Remnants.

Afterwards, Please Post a fresh Hijack This log in this thread.


Next:
Download the latest version of Ad-Aware at
http://www.lavasoft.de/software/adaware/

After installing AAW, and before running the program, you NEED to FIRST update the reference file following the instructions here: http://www.lavahelp.com/howto/updref/index.html

Now do the following:
- Under Ad-aware 6 > Settings (Gear at the top) > Tweaks > Scanning Engine:
check: "Unload recognized processes during scanning."

- Under Ad-aware 6 > Settings (Gear at the top) > Tweaks > Cleaning Engine:
Check: "Let Windows remove files in use after reboot."


Press "Scan Now"
- Check option "Use Custom scanning options"
- Check option "Activate In-Depth Scan"
- Press "Select drives\folders to scan"
- Select the active partition which is usually C:

Now press "Next" to let Ad-aware scan your drives...
It will find a number of "bad" files and registry keys.
Right-click in that pane and choose "select all"


Now press "Next" again.
It will ask you whether you'd like to remove all checked items. Click OK.

Finally, close Ad-Aware, and reboot.

That ought to get rid of most of your spyware.
When you've done all that, restart your computer, re-run Hijack This, and post a fresh log in this thread..
There will be more to do!
dong4ce
wow! the coolwebshredder did the job thnx very much

it was really stressin me out too... :mad:

but WAHAHHAA
LoPhatPhuud
Please follow ALL the directions given and run AdAware as well.

Then post another HiJackThis log in this thread for review.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.