goehring Posted December 2, 2003 Report Share Posted December 2, 2003 Hi guys!I become crazy with this idgsearch! Please help me to remove this rubbish!thx a lotLogfile of HijackThis v1.97.7Scan saved at 18:45:52, on 02.12.2003Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeC:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXED:\Program Files\Winamp3\winampa.exeC:\Program Files\Common Files\Symantec Shared\ccApp.exeD:\documents and settings\administrator\desktop\qttask.exeC:\WINDOWS\System32\ctfmon.exeC:\Program Files\Messenger\msmsgs.exeC:\WINDOWS\System32\RUNDLL32.EXEC:\program files\GlobalDialer\wordi00055\svchost.exeC:\Program Files\Common Files\Symantec Shared\ccProxy.exeC:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exeD:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exeC:\WINDOWS\System32\nvsvc32.exeC:\WINDOWS\System32\rundll32.exeD:\Program Files\WinZip\WZQKPICK.EXEC:\Program Files\Common Files\Symantec Shared\SNDSrvc.exeC:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exeC:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.exeC:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exeC:\WINDOWS\System32\wuauclt.exeC:\Program Files\Internet Explorer\IEXPLORE.EXED:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exeD:\Program Files\Spybot - Search & Destroy\SpybotSD.exeD:\PROGRA~1\WINZIP\winzip32.exeC:\Documents and Settings\Administrator\Local Settings\Temp\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.ewebsearch.net/sp.htmR1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.idgsearch.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.idgsearch.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.idgsearch.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.idgsearch.com/iecR1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.idgsearch.com/R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.idgsearch.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.idgsearch.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.idgsearch.com/R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.idgsearch.com/iecR0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.htmlR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.idgsearch.com/R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.idgsearch.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.idgsearch.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.idgsearch.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://www.ewebsearch.net/O1 - Hosts: 69.56.223.196 t.rack.ccO1 - Hosts: 69.56.223.196 www.alfa-search.comO1 - Hosts: 69.56.223.196 webcoolsearch.comO1 - Hosts: 69.56.223.196 in.webcounter.ccO1 - Hosts: 69.56.223.196 i-lookup.comO1 - Hosts: 69.56.223.196 www.hand-book.comO1 - Hosts: 69.56.223.196 www.maxxxhosters.comO1 - Hosts: 69.56.223.196 allneedsearch.comO1 - Hosts: 69.56.223.196 nativehardcore.comO1 - Hosts: 69.56.223.196 teen-biz.comO1 - Hosts: 69.56.223.196 tits.hardcore4ever.netO1 - Hosts: 69.56.223.196 best.royalsearch.netO1 - Hosts: 69.56.223.196 default-homepage-network.comO1 - Hosts: 69.56.223.196 xwebsearch.bizO1 - Hosts: 69.56.223.196 www.rightfinder.netO1 - Hosts: 69.56.223.196 www.search-1.netO1 - Hosts: 69.56.223.196 www.searchv.comO1 - Hosts: 69.56.223.196 www.websearch.comO1 - Hosts: 69.56.223.196 mysearchnow.comO1 - Hosts: 69.56.223.196 www.therealsearch.comO1 - Hosts: 69.56.223.196 www.find-itnow.comO1 - Hosts: 69.56.223.196 find.microgirls.comO1 - Hosts: 69.56.223.196 super-spider.comO1 - Hosts: 69.56.223.196 www.searching-the-net.comO1 - Hosts: 69.56.223.196 www.firstbookmark.comO2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocxO2 - BHO: Microsoft Excel - {17DA0C9E-4A27-4ac5-BB75-5D24B8CDB972} - C:\DOCUME~1\ADMINI~1\APPLIC~1\MICROS~1\Office\Excel10.dllO2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dllO2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dllO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocxO3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dllO3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dllO4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exeO4 - HKLM\..\Run: [WinampAgent] "D:\Program Files\Winamp3\winampa.exe"O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"O4 - HKLM\..\Run: [urlLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exeO4 - HKLM\..\Run: [QuickTime Task] "D:\documents and settings\administrator\desktop\qttask.exe" -atboottimeO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exeO4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO4 - HKCU\..\Run: [Password Depot] D:\Program Files\AceBIT\Password Depot\PasswordDepot.exeO4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInitO4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHookO4 - HKCU\..\Run: [sws.exe] c:\program files\GlobalDialer\wordi00055\svchost.exe -removeO4 - Global Startup: Acrobat Assistant.lnk = D:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exeO4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXEO4 - Global Startup: WinZip Quick Pick.lnk = D:\Program Files\WinZip\WZQKPICK.EXEO8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO15 - Trusted Zone: *.teensguru.comO15 - Trusted Zone: *.xxxtoolbar.comO16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedCon...bin/AvSniff.cabO16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200305...meInstaller.exeO16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab Quote Link to comment Share on other sites More sharing options...
mark2 Posted December 2, 2003 Report Share Posted December 2, 2003 Hi goehring, I've split this so you have your own thread.1st of all unzip Hijack this to a folder on your drive, if we fix it whilst running from a temp folder you will have no back up if anything goes wrong :wacko: then run Hijackthis and have it fix the following.R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.ewebsearch.net/sp.htmR1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.idgsearch.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.idgsearch.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.idgsearch.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.idgsearch.com/iecR1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.idgsearch.com/R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.idgsearch.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.idgsearch.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.idgsearch.com/R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.idgsearch.com/iecR0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.htmlR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.idgsearch.com/R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.idgsearch.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.idgsearch.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.idgsearch.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://www.ewebsearch.net/O1 - Hosts: 69.56.223.196 t.rack.ccO1 - Hosts: 69.56.223.196 www.alfa-search.comO1 - Hosts: 69.56.223.196 webcoolsearch.comO1 - Hosts: 69.56.223.196 in.webcounter.ccO1 - Hosts: 69.56.223.196 i-lookup.comO1 - Hosts: 69.56.223.196 www.hand-book.comO1 - Hosts: 69.56.223.196 www.maxxxhosters.comO1 - Hosts: 69.56.223.196 allneedsearch.comO1 - Hosts: 69.56.223.196 nativehardcore.comO1 - Hosts: 69.56.223.196 teen-biz.comO1 - Hosts: 69.56.223.196 tits.hardcore4ever.netO1 - Hosts: 69.56.223.196 best.royalsearch.netO1 - Hosts: 69.56.223.196 default-homepage-network.comO1 - Hosts: 69.56.223.196 xwebsearch.bizO1 - Hosts: 69.56.223.196 www.rightfinder.netO1 - Hosts: 69.56.223.196 www.search-1.netO1 - Hosts: 69.56.223.196 www.searchv.comO1 - Hosts: 69.56.223.196 www.websearch.comO1 - Hosts: 69.56.223.196 mysearchnow.comO1 - Hosts: 69.56.223.196 www.therealsearch.comO1 - Hosts: 69.56.223.196 www.find-itnow.comO1 - Hosts: 69.56.223.196 find.microgirls.comO1 - Hosts: 69.56.223.196 super-spider.comO1 - Hosts: 69.56.223.196 www.searching-the-net.comO1 - Hosts: 69.56.223.196 www.firstbookmark.comO15 - Trusted Zone: *.teensguru.comO15 - Trusted Zone: *.xxxtoolbar.comThis is a dialer type virusO4 - HKCU\..\Run: [sws.exe] c:\program files\GlobalDialer\wordi00055\svchost.exe -remove sws.exeHaldex type adult content diallerremoval instructions hereMake sure you have the right svchost.exeC:\program files\GlobalDialer\wordi00055\svchost.exeClose all browser windows before letting HJT fix the above.Once done run HJT once more and post the updated log Quote Link to comment Share on other sites More sharing options...
Redhat Posted December 2, 2003 Report Share Posted December 2, 2003 Then stop going to them nawty sites :drool: :innocent: :thumbup: :shutup: Quote Link to comment Share on other sites More sharing options...
mark2 Posted December 2, 2003 Report Share Posted December 2, 2003 On the subject of the dialler this http://forums.spywareinfo.com/index.php?showtopic=3079&st=0 might be an interesting read, don't use the uninstaller !! Quote Link to comment Share on other sites More sharing options...
Emmadw Posted December 2, 2003 Report Share Posted December 2, 2003 As he seems to have a Cool Web infection as well as other nasties, would it be worth him running Cool Web Shredder as well?It's a nasty one to get rid of :( Quote Link to comment Share on other sites More sharing options...
mark2 Posted December 3, 2003 Report Share Posted December 3, 2003 You're right, Emmadw, it was staring me in the face too :blush: Download it HERE Once you have scanned press 'next' Quote Link to comment Share on other sites More sharing options...
christmascracker Posted December 3, 2003 Report Share Posted December 3, 2003 What is cool web shredder? Quote Link to comment Share on other sites More sharing options...
Boris Posted December 3, 2003 Report Share Posted December 3, 2003 CoolWebShredderA small utility for removing CoolWebSearch (aka CoolWwwSearch, YouFindAll, White-Pages.ws and a dozen other names). Spybot S&D tends to forget essential parts of the hijack, so until it is updated to reflect this, you can use CWS to completely remove the hijack. Its updated to remove the new variants once they come out.http://www.spywareinfo.com/~merijn/ Quote Link to comment Share on other sites More sharing options...
christmascracker Posted December 3, 2003 Report Share Posted December 3, 2003 Ah, thanks for that Quote Link to comment Share on other sites More sharing options...
Emmadw Posted December 3, 2003 Report Share Posted December 3, 2003 As it happens, it was updated (CWS that is!) today.Emma Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.