View Full Version : searchweb2
jwh532
28 Aug 2004, 7:44am
I cannot find this pest in regedit or file search.
It has taken over my search assistant spot.
I also keep getting a web bar across the bottom of the screen.
can any one help?
Dexter
28 Aug 2004, 10:07am
OmegakillerSM will fix you up:
http://www.short-media.com/forum/showthread.php?t=17163
Dexter...
jwh532
28 Aug 2004, 4:12pm
Cannot use it on ME platform
Dexter
29 Aug 2004, 9:38am
Well, since you did not post a Hijack This log, I had no way of knowing you were running Windows ME. Maybe that's why we have the BIG BOLD RED LETTERS at the top of every page in this forum... ;)
So, find the the big red letters that say "Steps To Take Before Posting a Hijack This Log", perform the steps in Posts 1 and 2, post an HJT log, and we will be happy to help you get rid of your problem manually. :)
Dexter...
jwh532
29 Aug 2004, 10:37pm
First let me appologize for forgetting the log.
I had earlier posted a problem with spyware guard not working properly.
In which I found that I needed something downloaded from windows update
to let it do its job. I just ran a hijack and got rid of some of the same things
you had me get rid of while trying to fix the spyware guard problem. At this time I will reboot. then run another hijack then post it in next reply.
I hope this will help. Again appologize.
John Hicks
jwh532
29 Aug 2004, 10:44pm
Here is the new hijack log
The problem is searchweb2
Dexter
31 Aug 2004, 9:00am
Oh, don't mind me, you just happened to be the 4th or 5th person who did that on that day so my patience was wearing out ;) Let's get you fixed up:
Please make sure that HijackThis.exe is in its own folder, as explained here. (http://www.short-media.com/forum/showpost.php?p=172584&postcount=2)
Set your system to Show Hidden Files and folders. (http://www.short-media.com/forum/showpost.php?p=172588&postcount=3)
Reboot into Safe Mode. (http://www.short-media.com/forum/showpost.php?p=175908&postcount=6)
Run Hijack This. FIX THE FOLLOWING:
**************
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.lwgzplfpeodkis.com/RSe8grJ8XujOtaSVO_KPcELhwnLhxQ9QW_89GvchAFFtk_m4rvv512_21NqIlJsK.html
O4 - HKLM\..\Run: [InsideMix] C:\PROGRA~1\EQCAKE~1\Four Sign.exe
**************
Stay in Safe mode, manually locate the exe and dll files in the entries above, and quarantine them. (http://www.short-media.com/forum/showpost.php?p=173532&postcount=5)
In this case, you can delete the whole folder C:\Program Files\EQCAKE???? as well.
Reboot normally, check things out, and come back to let us know how it turned out. Post a fresh HJT log for review.
Please read our article on Defeating Spyware (http://www.short-media.com/review.php?r=132) for tips on how to improve your Internet Explorer security, or to learn how to switch to a different browser. For more general information about spyware read this page. (http://www.short-media.com/review.php?r=252&p=4)
Finally, if you have not already done so, please take the time to find out more about Folding For a Cure (http://www.short-media.com/folding.php?v=projectinfo), a good cause by which your computer uses it's spare power to help search for cures to diseases. We would love to have you on our Team.
Dexter...
jwh532
4 Sep 2004, 12:01am
I deleted the EQCAKE folder.
I could not determine the dll files.
I saved a log in safe mode and one after reboot.As far a quarantine of files
I am not sure of how it is done or if the ME platform can do so.
Dexter
4 Sep 2004, 10:37am
Log looks good.
Note that you likely got this through Messenger Plus 3. That program contains the C2 Media Spyware, and you probably happily clicked I ACCEPT and installed it yourself.
See the attached image for what you should have read, and where you should have clicked.
In the future, when you install the next wonderful piece of FREE! software you find, please do yourself a favour: slow down, read the End User License Agreement (EULA), and pay attention to what buttons you are clicking. Don't just press NEXT NEXT NEXT YES YES YES OK OK OK. Hopefully you can save yourself some future grief.
Dexter...
vBulletin® v3.8.1, Copyright ©2000-2009, Jelsoft Enterprises Ltd.