Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

how remove aaawebsearch and 69sexserach ?


  • Please log in to reply

#1
toutou21

toutou21

    Member

  • Member
  • PipPip
  • 18 posts
hi, i have many problems in my computer, aaawebsearch and 69sexsearch always start and appears !!!, also i can't run hijackthis in windows sessions, only in safe mode ??, i run adaware sepersonal, delete all critical files and run hijackthis in safe mode this is the log file...please help me to delete this problems !!! :tazz:

Logfile of HijackThis v1.99.0
Scan saved at 20:05:53, on 24/12/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\dmadmin.exe
D:\WINDOWS\explorer.exe
D:\WINDOWS\System32\svohost.exe
D:\Documents and Settings\Benteboula Toufik\Bureau\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://aaawebsearch.com/?a=2
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://aaawebsearch.com/?a=2
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://D:\WINDOWS\system32\mvdkd.dll/sp.html#12345
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://D:\WINDOWS\system32\mvdkd.dll/sp.html#12345
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://D:\WINDOWS\system32\mvdkd.dll/sp.html#12345
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://D:\WINDOWS\system32\mvdkd.dll/sp.html#12345
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://D:\WINDOWS\system32\mvdkd.dll/sp.html#12345
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://D:\WINDOWS\system32\mvdkd.dll/sp.html#12345
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://D:\WINDOWS\system32\mvdkd.dll/sp.html#12345
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://aaawebsearch.com/?a=2
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://aaawebsearch.com/?a=2
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:1030
R3 - URLSearchHook: (no name) - {B49B93C9-5858-EEBC-E5AA-630DE144418C} - D:\WINDOWS\system32\etevui1.exe
F2 - REG:system.ini: Shell=explorer.exe D:\WINDOWS\System32\svohost.exe
O2 - BHO: (no name) - {1A6D58F4-E71D-D6FB-84AC-D4C24EE5EA24} - D:\WINDOWS\system32\d3re32.dll
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O4 - HKLM\..\Run: [addzg.exe] D:\WINDOWS\system32\addzg.exe
O4 - HKLM\..\Run: [Registry Server] regsrv32.exe
O4 - HKLM\..\Run: [load32] D:\WINDOWS\System32\swchost.exe
O4 - HKLM\..\Run: [Microsoft WinUpdates] serm32.exe
O4 - HKLM\..\Run: [AFF148C6] D:\WINDOWS\system32\avk3lsa.exe
O4 - HKLM\..\Run: [A3CF9566] D:\WINDOWS\system32\etevui1.exe
O4 - HKLM\..\Run: [A5D315D3] D:\WINDOWS\system32\inrappru.exe
O4 - HKLM\..\Run: [XPSP2 Firewall] D:\WINDOWS\system32\xpsp2fw.exe
O4 - HKLM\..\Run: [Spool] C:\windows\system32\install.exe
O4 - HKLM\..\RunServices: [Registry Server] regsrv32.exe
O4 - HKLM\..\RunServices: [Microsoft WinUpdates] serm32.exe
O4 - HKCU\..\Run: [Registry Server] regsrv32.exe
O4 - HKCU\..\Run: [AFF148C6] D:\WINDOWS\system32\avk3lsa.exe
O4 - HKCU\..\Run: [A3CF9566] D:\WINDOWS\system32\etevui1.exe
O4 - HKCU\..\Run: [A5D315D3] D:\WINDOWS\system32\inrappru.exe
O4 - HKCU\..\Run: [Windows Update Client ] D:\WINDOWS\system32\wuclient.exe
O4 - HKCU\..\RunServices: [Registry Server] regsrv32.exe
O4 - Startup: svchost.exe
O8 - Extra context menu item: Download All by FlashGet - D:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - D:\Program Files\FlashGet\jc_link.htm
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.static.topconverting.com
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O15 - Trusted Zone: *.static.topconverting.com (HKLM)
O15 - Trusted IP range: 206.161.125.149
O15 - Trusted IP range: static.topconverting.com
O15 - Trusted IP range: frame.crazywinnings.com
O15 - Trusted IP range: 206.161.125.149
O15 - Trusted IP range: static.topconverting.com
O15 - Trusted IP range: slotch.com
O15 - Trusted IP range: searchmiracle.com
O15 - Trusted IP range: searchbarcash.com
O15 - Trusted IP range: scoobidoo.com
O15 - Trusted IP range: my-internet.info
O15 - Trusted IP range: mt-download.com
O15 - Trusted IP range: frame.crazywinnings.com
O15 - Trusted IP range: flingstone.com
O15 - Trusted IP range: clickspring.net
O15 - Trusted IP range: blazefind.com
O15 - Trusted IP range: awmdabest.com
O15 - Trusted IP range: 05p.com
O15 - Trusted IP range: 206.161.125.149 (HKLM)
O15 - Trusted IP range: my-internet.info (HKLM)
O15 - Trusted IP range: mt-download.com (HKLM)
O15 - Trusted IP range: frame.crazywinnings.com (HKLM)
O15 - Trusted IP range: flingstone.com (HKLM)
O15 - Trusted IP range: clickspring.net (HKLM)
O15 - Trusted IP range: blazefind.com (HKLM)
O15 - Trusted IP range: awmdabest.com (HKLM)
O15 - Trusted IP range: 05p.com (HKLM)
O15 - Trusted IP range: static.topconverting.com (HKLM)
O15 - Trusted IP range: frame.crazywinnings.com (HKLM)
O15 - Trusted IP range: 206.161.125.149 (HKLM)
O15 - Trusted IP range: static.topconverting.com (HKLM)
O15 - Trusted IP range: slotch.com (HKLM)
O15 - Trusted IP range: searchmiracle.com (HKLM)
O15 - Trusted IP range: searchbarcash.com (HKLM)
O15 - Trusted IP range: scoobidoo.com (HKLM)
O17 - HKLM\System\CCS\Services\Tcpip\..\{A760F5A3-BB80-4D42-862C-AB65B3D2B149}: NameServer = 81.22.91.164 81.22.90.29
O23 - Service: Service d'administration du Gestionnaire de disque logique - Unknown - D:\WINDOWS\System32\dmadmin.exe
O23 - Service: Journal des événements - Unknown - D:\WINDOWS\system32\services.exe
O23 - Service: Service COM de gravage de CD IMAPI - Unknown - D:\WINDOWS\System32\imapi.exe
O23 - Service: Partage de Bureau à distance NetMeeting - Unknown - D:\WINDOWS\System32\mnmsrvc.exe
O23 - Service: DDE réseau - Unknown - D:\WINDOWS\system32\netdde.exe
O23 - Service: DSDM DDE réseau - Unknown - D:\WINDOWS\system32\netdde.exe
O23 - Service: Plug-and-Play - Unknown - D:\WINDOWS\system32\services.exe
O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance - Unknown - D:\WINDOWS\system32\sessmgr.exe
O23 - Service: Prise en charge des cartes à puces - Unknown - D:\WINDOWS\System32\SCardSvr.exe
O23 - Service: Carte à puce - Unknown - D:\WINDOWS\System32\SCardSvr.exe
O23 - Service: Srv32 - Unknown - D:\WINDOWS\system32\srv32.exe (file missing)
O23 - Service: Journaux et alertes de performance - Unknown - D:\WINDOWS\system32\smlogsvc.exe
O23 - Service: Cliché instantané de volume - Unknown - D:\WINDOWS\System32\vssvc.exe
O23 - Service: Carte de performance WMI - Unknown - D:\WINDOWS\System32\wbem\wmiapsrv.exe
O23 - Service: Network Security Service (NSS) - Unknown - D:\WINDOWS\javaqr.exe
  • 0

Advertisements


#2
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 31,676 posts
Download and run About:Buster from http://www.majorgeek...wnload4289.html
It usually takes two run to get you cleaned.

Download CWShredder from http://www.intermute...r_download.html
Use the Fix button.

Check the following items in HijackThis.
Close all windows except HijackThis and click Fix checked:

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://aaawebsearch.com/?a=2
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://aaawebsearch.com/?a=2
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://D:\WINDOWS\system32\mvdkd.dll/sp.html#12345
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://D:\WINDOWS\system32\mvdkd.dll/sp.html#12345
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://D:\WINDOWS\system32\mvdkd.dll/sp.html#12345
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://D:\WINDOWS\system32\mvdkd.dll/sp.html#12345
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://D:\WINDOWS\system32\mvdkd.dll/sp.html#12345
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://D:\WINDOWS\system32\mvdkd.dll/sp.html#12345
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://D:\WINDOWS\system32\mvdkd.dll/sp.html#12345
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://aaawebsearch.com/?a=2
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://aaawebsearch.com/?a=2

R3 - URLSearchHook: (no name) - {B49B93C9-5858-EEBC-E5AA-630DE144418C} - D:\WINDOWS\system32\etevui1.exe
F2 - REG:system.ini: Shell=explorer.exe D:\WINDOWS\System32\svohost.exe
O2 - BHO: (no name) - {1A6D58F4-E71D-D6FB-84AC-D4C24EE5EA24} - D:\WINDOWS\system32\d3re32.dll
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O4 - HKLM\..\Run: [addzg.exe] D:\WINDOWS\system32\addzg.exe
O4 - HKLM\..\Run: [Registry Server] regsrv32.exe
O4 - HKLM\..\Run: [load32] D:\WINDOWS\System32\swchost.exe
O4 - HKLM\..\Run: [Microsoft WinUpdates] serm32.exe
O4 - HKLM\..\Run: [AFF148C6] D:\WINDOWS\system32\avk3lsa.exe
O4 - HKLM\..\Run: [A3CF9566] D:\WINDOWS\system32\etevui1.exe
O4 - HKLM\..\Run: [A5D315D3] D:\WINDOWS\system32\inrappru.exe
O4 - HKLM\..\Run: [XPSP2 Firewall] D:\WINDOWS\system32\xpsp2fw.exe
O4 - HKLM\..\Run: [Spool] C:\windows\system32\install.exe
O4 - HKLM\..\RunServices: [Registry Server] regsrv32.exe
O4 - HKLM\..\RunServices: [Microsoft WinUpdates] serm32.exe
O4 - HKCU\..\Run: [Registry Server] regsrv32.exe
O4 - HKCU\..\Run: [AFF148C6] D:\WINDOWS\system32\avk3lsa.exe
O4 - HKCU\..\Run: [A3CF9566] D:\WINDOWS\system32\etevui1.exe
O4 - HKCU\..\Run: [A5D315D3] D:\WINDOWS\system32\inrappru.exe
O4 - HKCU\..\Run: [Windows Update Client ] D:\WINDOWS\system32\wuclient.exe
O4 - HKCU\..\RunServices: [Registry Server] regsrv32.exe
O4 - Startup: svchost.exe
O8 - Extra context menu item: Download All by FlashGet - D:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - D:\Program Files\FlashGet\jc_link.htm


O23 - Service: Srv32 - Unknown - D:\WINDOWS\system32\srv32.exe (file missing)

O23 - Service: Network Security Service (NSS) - Unknown - D:\WINDOWS\javaqr.exe

Then download http://www.mvps.org/.../DelDomains.inf , rightclick and choose install.

Then reboot and do an online virusscan for example here: http://housecall.trendmicro.com/
Post a new HijackThis log when you are done.

Regards,

Pieter
  • 0

#3
toutou21

toutou21

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts
ok, i don all that you told me to do, and this is my new hijacksthis log, for the moment my system is appear to be clean !!

Logfile of HijackThis v1.99.0
Scan saved at 10:59:28, on 25/12/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\system32\netdde.exe
D:\WINDOWS\System32\imapi.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\vssvc.exe
D:\WINDOWS\System32\wbem\wmiapsrv.exe
D:\WINDOWS\System32\dmadmin.exe
D:\WINDOWS\Explorer.EXE
C:\Program Files\InterMute\SpySubtract\SpySub.exe
D:\Documents and Settings\Benteboula Toufik\Bureau\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:1030
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\SpySub.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A760F5A3-BB80-4D42-862C-AB65B3D2B149}: NameServer = 81.22.91.164 81.22.90.29
O23 - Service: Service d'administration du Gestionnaire de disque logique - Unknown - D:\WINDOWS\System32\dmadmin.exe
O23 - Service: Journal des événements - Unknown - D:\WINDOWS\system32\services.exe
O23 - Service: Service COM de gravage de CD IMAPI - Unknown - D:\WINDOWS\System32\imapi.exe
O23 - Service: Partage de Bureau à distance NetMeeting - Unknown - D:\WINDOWS\System32\mnmsrvc.exe
O23 - Service: DDE réseau - Unknown - D:\WINDOWS\system32\netdde.exe
O23 - Service: DSDM DDE réseau - Unknown - D:\WINDOWS\system32\netdde.exe
O23 - Service: Plug-and-Play - Unknown - D:\WINDOWS\system32\services.exe
O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance - Unknown - D:\WINDOWS\system32\sessmgr.exe
O23 - Service: Prise en charge des cartes à puces - Unknown - D:\WINDOWS\System32\SCardSvr.exe
O23 - Service: Carte à puce - Unknown - D:\WINDOWS\System32\SCardSvr.exe
O23 - Service: Journaux et alertes de performance - Unknown - D:\WINDOWS\system32\smlogsvc.exe
O23 - Service: Cliché instantané de volume - Unknown - D:\WINDOWS\System32\vssvc.exe
O23 - Service: Carte de performance WMI - Unknown - D:\WINDOWS\System32\wbem\wmiapsrv.exe

thanks to tell me if is it clean !!!
  • 0

#4
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 31,676 posts
Excellent job. :tazz:

Enjoy the holidays.

Regards,

Pieter
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP