Options

Hello everyone! the searchbar ...

Hello everyone, I am surpise when I see the mysearchnow appears on my computer. Anyways, I manage to remove the blue search bar ony my IE, but the other ie that pop ups thats from mysearchnow.com. I want to get rid of it for good. I done the Ad aware and Search and distroy to remove all those stuff. Now how do i boot into safe mode? do i have to boot into safe mode to use the hijackthis? Thanks in advance.

Comments

  • primesuspectprimesuspect Beepin n' Boopin Detroit, MI Icrontian
    edited June 2004
    Welcome to short-media :)

    You can boot into safe mode by pressing F8 key before windows starts loading. After the BIOS screens, keep pressing F8 until a menu comes up that allows you to select safe mode.

    While you are in safe mode, get a HijackThis log, and post it here for review.
  • edited June 2004
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    E:\HJT\HijackThis.exe

    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
    O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [WinampAgent] d:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [Mirabilis ICQ] D:\PROGRA~1\ICQ\ICQNet.exe
    O4 - HKLM\..\Run: [MessengerPlus3] "D:\Program Files\Messenger Plus! 3\MsgPlus.exe"
    O4 - HKLM\..\Run: [Atom Inside] C:\PROGRA~1\SPAMSE~1\Idle User.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [MessengerPlus3] "D:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
    O9 - Extra button: ICQ Pro (HKLM)
    O9 - Extra 'Tools' menuitem: ICQ (HKLM)
    O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 (HKLM)
    O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 (HKLM)
  • DexterDexter Vancouver, BC Canada
    edited June 2004
    This guy:

    O4 - HKLM\..\Run: [Atom Inside] C:\PROGRA~1\SPAMSE~1\Idle User.exe

    Is your problem.

    Reboot in SAFE MODE and run HJT. Fix that entry.

    Then, manually locate that file:

    C:\PROGRAM FILES\SPAMSE~1\Idle User.exe

    (the actual folder will have a longer name that starts with "SPAMSE." Move that file to a new folder called C:\Quarantine. Rename the .exe part to .XXX. you may have to enable extension viewing in the folder: Tools -> Folder Options -> View -> "uncheck" the Hide Extensions for Known file types option.

    Then reboot normally, and you should be safe. Check it out and let us know.

    Dexter...
  • edited June 2004
    Yep It work after I also reset the homepage to my default. Thanks, hope It doesnt appear again. I use Opera now lol.
  • primesuspectprimesuspect Beepin n' Boopin Detroit, MI Icrontian
    edited June 2004
    Make sure to check out our Folding Team :)

    Stick around! We love new members!
Sign In or Register to comment.