Options

can't get rid of home search

Hello staf and members,

Like many of the posters in this forum I'm having trouble getting rid of Home Search. I tried the removal guide a few times but it keeps coming back. I'm probably missing something and I hope you can help me by finding it.

Here is my HJT log

Logfile of HijackThis v1.98.2
Scan saved at 10:39:58, on 5/09/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Telemeter 3.0\telemeter3.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\ntmw.exe
C:\PROGRA~1\Ashampoo\ASHAMP~1\PopUpKiller.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Kurt\Application Data\apor.exe
C:\WINDOWS\ODBCINST.INI:bbzsq
C:\PROGRA~1\ICQ\ICQ.exe
C:\internet downloads\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\gloxk.dll/sp.html#37794
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\gloxk.dll/sp.html#37794
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\gloxk.dll/sp.html#37794
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\gloxk.dll/sp.html#37794
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\gloxk.dll/sp.html#37794
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\gloxk.dll/sp.html#37794
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\gloxk.dll/sp.html#37794
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {E85D9E44-13DD-F6F9-1A2F-57B4D4A67617} - C:\WINDOWS\mslm.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Telemeter 3.0] "C:\Program Files\Telemeter 3.0\telemeter3.exe"
O4 - HKLM\..\Run: [Mirabilis ICQ] C:\PROGRA~1\ICQ\ICQNet.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [ntmw.exe] C:\WINDOWS\system32\ntmw.exe
O4 - HKLM\..\Run: [mpzqawmphl] C:\WINDOWS\System32\ludcvm.exe
O4 - HKLM\..\RunOnce: [bbzsq] C:\WINDOWS\ODBCINST.INI:bbzsq
O4 - HKCU\..\Run: [Ashampoo PopUpBlocker] C:\PROGRA~1\Ashampoo\ASHAMP~1\PopUpKiller.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Ailb] C:\Documents and Settings\Kurt\Application Data\apor.exe
O4 - HKCU\..\Run: [Pohs] C:\WINDOWS\System32\ghgo.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted Zone: *.05p.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.scoobidoo.com
O15 - Trusted Zone: *.searchmiracle.com
O16 - DPF: Dexia netbanking - http://netbanking.dexia.be/PC//Dynamic/Shared/Applet//DexiaIIA.cab
O16 - DPF: {297F2B65-017C-11D5-A128-00D0B7869AD6} (SpectorPhotoUploader Control) - http://www.extrafilm.be/import/spu.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/09e51a918a060dde6614/netzip/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1093281436281
O16 - DPF: {706F3805-27D7-478D-80E5-E25D2BB030B3} (VacPro.internazionale_ver3) - http://www.advnt01.com/dialer/internazionale_ver3.CAB
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - http://www.telenet.be/sites/epgweb/setup.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
O18 - Protocol: icoo - {4A8DADD4-5A25-4D41-8599-CB7458766220} - C:\WINDOWS\msopt.dll (file missing)


Thanks for all the help you are about to give me and great respect to the work you are doing .

Comments

  • DexterDexter Vancouver, BC Canada
    edited September 2004
    Sorry to take so long to get to your thread, it has been busy in here of late :)

    If the problem will not go away, you may not have stopped the service. Please refer to Post#2 of the guide to generate an active services log, and post that here for review.

    Dexter...
  • edited September 2004
    This is what I get when I run 'get active services' in safe-mode. I didn't disable system restore to run the program but when I followed the guide earlier I disabled system restore.

    These are the Current Active Services:

    Services voor cryptografie: CryptSvc
    C:\WINDOWS\system32\svchost.exe -k netsvcs

    Help en ondersteuning: helpsvc
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    System Restore-service: srservice
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Windows Management Instrumentation: winmgmt
    C:\WINDOWS\system32\svchost.exe -k netsvcs

    Event Log: Eventlog
    C:\WINDOWS\system32\services.exe

    Plug and Play: PlugPlay
    C:\WINDOWS\system32\services.exe

    Remote Procedure Call (RPC): RpcSs
    C:\WINDOWS\system32\svchost -k rpcss


    Please don't say sorry for the late reply, I'm glad that I get some help, even if it takes a few days :)
  • DexterDexter Vancouver, BC Canada
    edited September 2004
    You need to run Get Active Service in NORMAL MODE, just like it says in Post #2 of the HSA Removal Guide.

    Please do that again in normal mode, and re-post the log.

    Dexter...
  • edited September 2004
    This is the log in Normal Mode :

    These are the Current Active Services:

    Windows Audio: AudioSrv
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Computer Browser: Browser
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Services voor cryptografie: CryptSvc
    C:\WINDOWS\system32\svchost.exe -k netsvcs

    DHCP Client: Dhcp
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Service voor het rapporteren van fouten: ERSvc
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    COM+-gebeurtenissysteem: EventSystem
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Help en ondersteuning: helpsvc
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Server: lanmanserver
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Workstation: lanmanworkstation
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Network Connections: Netman
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Network Location Awareness (NLA): Nla
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Verbindingsbeheer voor RAS: RasMan
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Task Scheduler: Schedule
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    System Event Notification: SENS
    C:\WINDOWS\system32\svchost.exe -k netsvcs

    Shell Hardware Detection: ShellHWDetection
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    System Restore-service: srservice
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Telephony: TapiSrv
    C:\WINDOWS\System32\svchost.exe -k netsvcs
  • mmonninmmonnin Centreville, VA
    edited September 2004
    Not sure what several of those services are, they are not even in english.

    Services voor cryptografie: CryptSvc
    C:\WINDOWS\system32\svchost.exe -k netsvcs

    Service voor het rapporteren van fouten: ERSvc
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Help en ondersteuning: helpsvc
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Verbindingsbeheer voor RAS: RasMan
    C:\WINDOWS\System32\svchost.exe -k netsvcs
  • edited September 2004
    Sorry, I will try to translate (I use a dutch version of windows xp)

    Services voor cryptografie: CryptSvc Sevices for cryptography
    C:\WINDOWS\system32\svchost.exe -k netsvcs

    Service voor het rapporteren van fouten: ERSvc Services for reporting errors
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Help en ondersteuning: helpsvc Help and support
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Verbindingsbeheer voor RAS: RasMan Connection management for RAS
    C:\WINDOWS\System32\svchost.exe -k netsvcs
  • mmonninmmonnin Centreville, VA
    edited September 2004
    Oh ok those are all fine. I was wondering if you spoke a different language. Those are all default XP services, I have all of them.
  • DexterDexter Vancouver, BC Canada
    edited September 2004
    Those services all seem legitimate - did you ever locate one of the known bad ones when doing the steps in the guide?

    Maybe you just missed an entry on removal. When following the steps in the guide make sure to fix these entries and quarantine the associated files:


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\gloxk.dll/sp.html#37794
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\gloxk.dll/sp.html#37794
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\gloxk.dll/sp.html#37794
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\gloxk.dll/sp.html#37794
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\gloxk.dll/sp.html#37794
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\gloxk.dll/sp.html#37794
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\gloxk.dll/sp.html#37794
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {E85D9E44-13DD-F6F9-1A2F-57B4D4A67617} - C:\WINDOWS\mslm.dll



    O4 - HKLM\..\Run: [ntmw.exe] C:\WINDOWS\system32\ntmw.exe
    O4 - HKLM\..\Run: [mpzqawmphl] C:\WINDOWS\System32\ludcvm.exe
    O4 - HKLM\..\RunOnce: [bbzsq] C:\WINDOWS\ODBCINST.INI:bbzsq


    O4 - HKCU\..\Run: [Ailb] C:\Documents and Settings\Kurt\Application Data\apor.exe
    O4 - HKCU\..\Run: [Pohs] C:\WINDOWS\System32\ghgo.exe
    O15 - Trusted Zone: *.05p.com
    O15 - Trusted Zone: *.clickspring.net
    O15 - Trusted Zone: *.mt-download.com
    O15 - Trusted Zone: *.my-internet.info
    O15 - Trusted Zone: *.scoobidoo.com
    O15 - Trusted Zone: *.searchmiracle.com

    O18 - Protocol: icoo - {4A8DADD4-5A25-4D41-8599-CB7458766220} - C:\WINDOWS\msopt.dll (file missing)


    Give that a try and let us know.

    Dexter...
Sign In or Register to comment.