Member Panel


Sponsors and Ads

Noticeboard

[Fixed] Hijackthis! Logs - [FIXED] Registry posted in the Security & Safety forums; I get this annoying pop up thats call "MyWebSearch". I checked in the registry and I see the thing its under? HKEY_LOCAL_MACHINE\software\microsoft\windows\curr ent version\run. Will it hurt anything if I ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 08-26-2005
Elite Member
 
Join Date: Aug 2005
Posts: 417
PC Experience: PC Illiterate
PraiseJah - See this Members User comments on their Profile page
Send a message via AIM to PraiseJah
Default [FIXED] Registry

I get this annoying pop up thats call "MyWebSearch". I checked in the registry and I see the thing its under? HKEY_LOCAL_MACHINE\software\microsoft\windows\curr ent version\run. Will it hurt anything if I delete it? and will it stop the pop up?


  #2  
Old 08-26-2005
merlin's Avatar
Trusted Security Analyst
My PC
 
Join Date: Jul 2005
Location: Wisconsin
Posts: 2,622
PC Experience: Computers Fear Me
merlin - See this Members User comments on their Profile page merlin - See this Members User comments on their Profile page
Send a message via Yahoo to merlin
Default Re: Registry

Welcome to PCHF.

You more than likely have been infected with websearch..Can you download cwsshredder in my signature make sure all browswers are closed and run it.. Afte that download cleanup (also in my sig) adn run it.. After that post back what cws found..


__________________
QuickTime Alternative..Hijackthis..SpeedFan..ATI Tool..Whats Running..Everest..Absolute Control..All Drivers
If you feel we saved you some money please help support this site by DONATING as this site is funded by great people like you

OUT FOR LUNCH


  #3  
Old 08-26-2005
Elite Member
 
Join Date: Aug 2005
Posts: 417
PC Experience: PC Illiterate
PraiseJah - See this Members User comments on their Profile page
Send a message via AIM to PraiseJah
Default Re: Registry

I ran both programs and the clean up got rid of 1 GIG of stuff. and the other program said it got rid of 3 things but I cant remember what they were.


  #4  
Old 08-26-2005
merlin's Avatar
Trusted Security Analyst
My PC
 
Join Date: Jul 2005
Location: Wisconsin
Posts: 2,622
PC Experience: Computers Fear Me
merlin - See this Members User comments on their Profile page merlin - See this Members User comments on their Profile page
Send a message via Yahoo to merlin
Default Re: Registry

ok..well cleanup did a good job huh lol... Next download hijackthis and save it to your document's and click scan and save log.. and save it as a text file and upload it on your next post...


__________________
QuickTime Alternative..Hijackthis..SpeedFan..ATI Tool..Whats Running..Everest..Absolute Control..All Drivers
If you feel we saved you some money please help support this site by DONATING as this site is funded by great people like you

OUT FOR LUNCH


  #5  
Old 08-26-2005
Elite Member
 
Join Date: Aug 2005
Posts: 417
PC Experience: PC Illiterate
PraiseJah - See this Members User comments on their Profile page
Send a message via AIM to PraiseJah
Default Re: Registry

I hope this is what you were looking for lol.

Logfile of HijackThis v1.99.1
Scan saved at 3:23:44 PM, on 8/26/2005
Platform: Windows XP? (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2800.1106)
Attached Files
File Type: txt hijackthis.txt (15.3 KB, 2 views)


  #6  
Old 08-26-2005
merlin's Avatar
Trusted Security Analyst
My PC
 
Join Date: Jul 2005
Location: Wisconsin
Posts: 2,622
PC Experience: Computers Fear Me
merlin - See this Members User comments on their Profile page merlin - See this Members User comments on their Profile page
Send a message via Yahoo to merlin
Default Re: Registry

Yes it was what I was looking for.. givee me a bit to look over it.. Its a long one..whiel I am looking over it can you do these things


Before using Hijack This Can you please do this for me:


Show hidden files and folders:


For XP:

1.On the Tools menu in Windows Explorer, click Folder Options.
2.Click the View tab.
3.Under Hidden files and folders, click Show hidden files and folders.
4.If you see a warning message, click Yes.
5.Click Apply.
6.Click OK.



Then disable system restore to prevent re-infection.
(if you have/use it.)
(you can turn it back on when youre pc is clean).


How to disable system restore:

WinXP.

Click the Start button.
Right-click My Computer, and then click Properties.
On the System Restore tab, check Turn off System Restore or Turn off System Restore on all drives.



Please download ewido Security Suite[list] [*]Install ewido security suite [*]When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu." [*]Launch ewido, there should be a big "E" icon on your desktop, double-click it. [*]The program will prompt you to update click the "OK" button [*]The program will now go to the main screen

You will need to update ewido to the latest definition files.
[*]On the left hand side of the main screen click update [*]Click on Start

The update will start and a progress bar will show the updates being installed. After the updates are installed, exit ewido.

Once the updates are installed do the following:
[*]If you have an "always on" connection to the internet, physically disconnect that connection until you are finished with Safe Mode and have rebooted back into normal mode.
[*]Reboot into Safe Mode, you can do this by restarting your computer, then contiunally tapping F8 until a menu appears. Use your up arrow key to highlight Safe Mode, then hit enter. Then, run ewido.
[*]Close all open windows/programs/folders. Have nothing else open while ewido performs its scan!
[*]Click on scanner [*]Click on Settings
  • Under "How to scan" all boxes should be selected
  • Under "Possibly unwanted software" all boxes should be selected
  • Under "What to scan" select scan every file
  • Click OK
[*]Click on Complete system scan [*]Let the program scan the machine
[*]If ewido finds anything, it will pop up a notification. NOTE: We have been finding some cases of false positives with the new version of Ewido, so we need to step through the fixes one-by-one. If Ewido finds something that you KNOW is legitimate (for example, parts of AVG Antivirus, AOL, pcAnywhere and the game "Risk" have been flagged. In particular, watch for alerts that have the word "Heuristic" in them - if you recognize the file name as "friendly," these may actually be false positives) select "none" as the action. DO NOT check "Perform action with all infections." If you are unsure of an entry, select "none" for the time being. I'll see that in the log you will post later and let you know if ewido needs to be run again.

Once the scan has completed, there will be a button located on the bottom of the screen named Save report.
[*]Click Save report [*]Save the report to your desktop [*]Exit ewido

and post back the log of what ewido found..


__________________
QuickTime Alternative..Hijackthis..SpeedFan..ATI Tool..Whats Running..Everest..Absolute Control..All Drivers
If you feel we saved you some money please help support this site by DONATING as this site is funded by great people like you

OUT FOR LUNCH


  #7  
Old 08-26-2005
Elite Member
 
Join Date: Aug 2005
Posts: 417
PC Experience: PC Illiterate
PraiseJah - See this Members User comments on their Profile page
Send a message via AIM to PraiseJah
Default Re: Registry

I have to brin my dad to work fast but I'll do that as soon as I get back. I shouldnt be toooo long.



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 04:25 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top