searchweb2

jwh532jwh532 Sweet Home, OR
edited September 2004 in Spyware & Virus Removal
I cannot find this pest in regedit or file search.
It has taken over my search assistant spot.
I also keep getting a web bar across the bottom of the screen.
can any one help?

Comments

  • DexterDexter Vancouver, BC Canada
    edited August 2004
    OmegakillerSM will fix you up:

    http://www.short-media.com/forum/showthread.php?t=17163

    Dexter...
  • jwh532jwh532 Sweet Home, OR
    edited August 2004
    Cannot use it on ME platform
  • DexterDexter Vancouver, BC Canada
    edited August 2004
    Well, since you did not post a Hijack This log, I had no way of knowing you were running Windows ME. Maybe that's why we have the BIG BOLD RED LETTERS at the top of every page in this forum... ;)

    So, find the the big red letters that say "Steps To Take Before Posting a Hijack This Log", perform the steps in Posts 1 and 2, post an HJT log, and we will be happy to help you get rid of your problem manually. :)

    Dexter...
  • jwh532jwh532 Sweet Home, OR
    edited August 2004
    First let me appologize for forgetting the log.
    I had earlier posted a problem with spyware guard not working properly.
    In which I found that I needed something downloaded from windows update
    to let it do its job. I just ran a hijack and got rid of some of the same things
    you had me get rid of while trying to fix the spyware guard problem. At this time I will reboot. then run another hijack then post it in next reply.
    I hope this will help. Again appologize.

    John Hicks
  • jwh532jwh532 Sweet Home, OR
    edited August 2004
    Here is the new hijack log

    The problem is searchweb2
  • DexterDexter Vancouver, BC Canada
    edited August 2004
    Oh, don't mind me, you just happened to be the 4th or 5th person who did that on that day so my patience was wearing out ;) Let's get you fixed up:


    Please make sure that HijackThis.exe is in its own folder, as explained here.

    Set your system to Show Hidden Files and folders.

    Reboot into Safe Mode.


    Run Hijack This. FIX THE FOLLOWING:

    **************





    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.lwgzplfpeodkis.com/RSe8grJ8XujOtaSVO_KPcELhwnLhxQ9QW_89GvchAFFtk_m4rvv512_21NqIlJsK.html

    O4 - HKLM\..\Run: [InsideMix] C:\PROGRA~1\EQCAKE~1\Four Sign.exe


    **************

    Stay in Safe mode, manually locate the exe and dll files in the entries above, and quarantine them.

    In this case, you can delete the whole folder C:\Program Files\EQCAKE???? as well.

    Reboot normally, check things out, and come back to let us know how it turned out. Post a fresh HJT log for review.

    Please read our article on Defeating Spyware for tips on how to improve your Internet Explorer security, or to learn how to switch to a different browser. For more general information about spyware read this page.


    Finally, if you have not already done so, please take the time to find out more about Folding For a Cure, a good cause by which your computer uses it's spare power to help search for cures to diseases. We would love to have you on our Team.

    Dexter...
  • jwh532jwh532 Sweet Home, OR
    edited September 2004
    I deleted the EQCAKE folder.
    I could not determine the dll files.
    I saved a log in safe mode and one after reboot.As far a quarantine of files
    I am not sure of how it is done or if the ME platform can do so.
  • DexterDexter Vancouver, BC Canada
    edited September 2004
    Log looks good.

    Note that you likely got this through Messenger Plus 3. That program contains the C2 Media Spyware, and you probably happily clicked I ACCEPT and installed it yourself.

    See the attached image for what you should have read, and where you should have clicked.

    In the future, when you install the next wonderful piece of FREE! software you find, please do yourself a favour: slow down, read the End User License Agreement (EULA), and pay attention to what buttons you are clicking. Don't just press NEXT NEXT NEXT YES YES YES OK OK OK. Hopefully you can save yourself some future grief.

    Dexter...
This discussion has been closed.