Antivirus Protection
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationAntivirus Protection

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
You don't need a fax machine to get faxes. Get a fax-to-email fax number from CallWave. Try it free.
  #1  
Old May 23rd, 2004, 12:53 AM
ecenter ecenter is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2004
Posts: 2 ecenter User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Angry Your-Searcher home page hijack help

I have a your-searcher homepage hijacker. Please help. The following is my Hijack this log

Logfile of HijackThis v1.97.7
Scan saved at 11:41:23 PM, on 5/22/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\Wintab32.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\hidserv.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\surfmonkey\smproxy.exe
C:\WINNT\SYSTEM32\3cmlink.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Internet Explorer\IEengine.exe
C:\Program Files\EarthLink TotalAccess\TaskPanl.exe
C:\WINNT\SYSTEM32\3cshtdwn.exe
C:\WINNT\SYSTEM32\3cmlink.exe
C:\Program Files\U.S. Robotics\ControlCenter\Reminder.exe
C:\WINNT\system32\rundll32.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\winlogin.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\EarthLink\spamBlocker\ELSBLaunch.exe
C:\unzipped\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
O2 - BHO: EarthLink Popup Blocker - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Pop-Up Blocker - {D7F30B62-8269-41AF-9539-B2697FA7D77E} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ELNKProxy] C:\WINNT\surfmonkey\smproxy.exe
O4 - HKLM\..\Run: [EarthLink Installer] "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\EarthLinkTotalAccess2004\Windows\access\program files\EarthLink TotalAccess\_Setup.exe" /C
O4 - HKLM\..\Run: [3c1807pd] C:\WINNT\SYSTEM32\3cmlink.exe RunServices \Device\3cpipe-3c1807pd
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [IEengine] C:\Program Files\Internet Explorer\IEengine.exe
O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart
O4 - Global Startup: ELSBLaunch.lnk = C:\Program Files\EarthLink\spamBlocker\ELSBLaunch.exe
O4 - Global Startup: Instant Update Reminder.lnk = C:\Program Files\U.S. Robotics\ControlCenter\Reminder.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O4 - Global Startup: winlogin.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - URL
O16 - DPF: {F5C90925-ABBF-4475-88F5-8622B452BA9E} (Compaq System Data Class) - URL
O17 - HKLM\System\CCS\Services\Tcpip\..\{8EACD75D-6FD9-4828-90FB-B39D035760ED}: NameServer = 207.69.188.187 207.69.188.186

Reply With Quote
  #2  
Old May 23rd, 2004, 04:03 AM
yukon12 yukon12 is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2004
Posts: 3 yukon12 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
I have spent I don't know how many countless hours reading message boards and have heard so many different ideas for the removal of this little bastard that I am practically sick, but the good news is that I have found a solution that works and maybe this can save some one a great deal of time.
This your-searcher is an IE homepage hijacker that even when removed from the registry comes right back over and over again. Especially on restarting your computer. Here is the solution that I found that worked. I am not much of a computer whizz so please forgive me if I lack the proper terminology.
First of all, SPYBOT and Adaware were no match for this POS. It just kept coming back. You may run these after to eliminate other things, but for the your-searcher hijack it really did nothing. You can also forget Symantec finding it or Pandasoftware Anti-virus either. This is not just a IE hijacker, it is being reborn over and over again by a Trojan Virus. You must eliminate the Trojan and then wipe away the IE registry keys after.
I know you must be wanting to know how, so here is what worked for me. I first of all turned off my System Restore. This is located in the My Computer icon on the desktop and then click on the Local Disk C: , then click on the View System Information to the left of it and System Restore and then turn it off.
Now you must first go and get a program called "HijackThis 1.97.7" you can find it at URL You must get this file and intstall it. Create a file folder for the install on your desktop for it and then run it.
After you have run hijackthis, you will have a list of registry keys and .exe programs that are possible problems. Here you may delete all of the ones that have "your-searcher " listed. This will temporarily clean your IE browser and allow you to reset your homepage. Within about 30 seconds the Trojan will take it back over so you must act quickly and go open up a browser and go to URL Here you will download the Trojan Remover software. This is what found the Trojan that even Norton (symantec) and all others couldn't find and eliminate. Download it and install it. You can use the trial version to remove the Trojan. I ran it and my file infected with a Trojan was C:\WINDOWS\system32\winlogin.exe This is the Global startup winlogin.exe file that you have in your list. Trojan Remover changed the name of the file and then asked me to reboot. After rebooting I ran Hijackthis again to clear my IE one more time and this time there was no Trojan to reset it!! Thank God! Who ever created this virus should be shot!
Finally, I turned my system restore back on. You can now look for other ads with Spybot or Adaware. Good Luck!

Reply With Quote
  #3  
Old May 23rd, 2004, 11:17 PM
ecenter ecenter is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2004
Posts: 2 ecenter User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Smile Thanks

Thanks, so much. I have spent countless hours trying to fix this problem. I did everyting you said, it worked like perfect. This thing is finally gone. Thanks!!!!!

Reply With Quote
  #4  
Old May 25th, 2004, 03:05 AM
yukon12 yukon12 is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2004
Posts: 3 yukon12 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Smile Congrats!

Glad I could help!

Reply With Quote
  #5  
Old May 25th, 2004, 03:16 AM
yukon12 yukon12 is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2004
Posts: 3 yukon12 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Talking One more thought

And if you want to beat a dead horse, you can find what is left of the dead trojan in your C:/WINDOWS/System32/Winlogin.Ex$ You can now highlight this file and send it to your recycle bin and give it a proper burial. Eventhough the file is harmless, it still felt good kicking its a$$ a second time by deleting it from the recycle bin.

Last edited by yukon12 : May 25th, 2004 at 03:18 AM. Reason: spelling

Reply With Quote
  #6  
Old June 3rd, 2004, 04:32 PM
spiff711 spiff711 is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jun 2004
Posts: 1 spiff711 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Many Thanks

Thanks. You saved my machine from a size 13 shoe. Appreciate it.

Reply With Quote
  #7  
Old August 11th, 2004, 02:20 PM
xanaxbarre xanaxbarre is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Aug 2004
Posts: 1 xanaxbarre User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Help!!!!!!!!

I tried the steps you listed and It won't go away!!!
I run the hijacker and it finds the searcher hijack, but when I run the trojan it doesnt find any thing. PLeas help this is driving me crazy!!!!!!

Reply With Quote
  #8  
Old August 11th, 2004, 03:41 PM
edwinbrains's Avatar
edwinbrains edwinbrains is offline
Retired Moderator
Dev Shed God 4th Plane (6500 - 6999 posts)
 
Join Date: Jan 2004
Location: London, UK
Posts: 6,670 edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)  Folding Points: 85411 Folding Title: Advanced FolderFolding Points: 85411 Folding Title: Advanced FolderFolding Points: 85411 Folding Title: Advanced FolderFolding Points: 85411 Folding Title: Advanced FolderFolding Points: 85411 Folding Title: Advanced Folder
Time spent in forums: 1 Week 6 Days 23 h 29 m 46 sec
Reputation Power: 92
If you want help I suggest you create a HijackThis log for your own computer then create a new thread in this forum, rather than replying to someone else's thread.
__________________
- Edwin -

The General Rules Thread | The General FAQ Thread

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationAntivirus Protection > Your-Searcher home page hijack help


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump

 Free IT White Papers!
 
Accelerating Trading Partner Performance
One in five. That's how many partner transactions have at least one error. That is an amazing statistic, particularly given the extraordinary leaps in innovation across the global supply chain during the past two decades. Download this white paper to learn more.

 
Competing on Analytics
This Tech Analysis is designed to help identify characteristics shared by analytics competitors, and includes information about 32 organizations that have made a commitment to quantitative, fact-based analysis.

 
Cost Effective Scaling with Virtualization and Coyote Point Systems
An overview of the industry trend toward virtualization, how server consolidation has increased the importance of application uptime and the steps being taken to integrate load balancing technology with virtualized servers.

 
Five Checkpoints to Implementing IP Telephony
Implementation planning for IP PBX software and IP telephony has become vital as businesses replace discontinued legacy PBX phone systems. This informative whitepaper outlines five "checkpoints" for any implementation plan that will help make IP communications a successful proposition.

 
Hosted Email Security: Staying Ahead of New Threats
In the last two years, email has become a fierce battleground between the nefarious forces of spam and malware, and the heroes of messaging protection. The spam volumes increased alarmingly every month, bringing clever new forms of phishing and virus propagation attacks.

 

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 1 hosted by Hostway