Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
When i search google for anything i get this along with other results
Find PASSWORD on Crawler.com with Free Websearch Tools
Click here to download WebSearch Tools and search 15 engines for PASSWORD at once now with free
pop-up blocker, yellow/white pages, free games, maps, skins, cursors and more.
http://download.websearch.com/ - 54kFind PASSWORD With Free Websearch Tools
Click here to download WebSearch Tools and search 15 engines for PASSWORD at once now with free
pop-up blocker, yellow/white pages, free games, maps, skins, cursors and more.
http://download.websearch.com/ - 39kFind PASSWORD Using the Free 2020 Search Toolbar
Having trouble finding PASSWORD? Get the 2020Search toolbar and say good-bye to those annoying pop-ups.
Many other useful features such as: text highlighter, multi-search engine, drag & drop,
e-mail results and more.
http://www.2020search.com/ - 48kwhere PASSWORD is the string i searched for.
i dont think this is right. i dont think google should be giving these results. they come on every results page. ihave uses cwsshredder,adaware and spybot. please let me know if yu have any more ino on this one

Run a HiJackThis scan of your system and post the results back here so we can see what's on your system. HiJackThis and Instructions

Logfile of HijackThis v1.97.7
Scan saved at 7:38:21 PM, on 3/21/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\carpserv.exe
D:\Program Files\Synaptics\SynTP\SynTPLpr.exe
D:\Program Files\Synaptics\SynTP\SynTPEnh.exe
D:\Program Files\NavNT\vptray.exe
D:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
D:\Program Files\HPQ\One-Touch\OneTouch.exe
C:\WINDOWS\System32\drivers\CDAC11BA.exe
D:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
D:\Program Files\NavNT\defwatch.exe
C:\WINDOWS\system32\HPConfig.exe
D:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
D:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
C:\WINDOWS\System32\ctfmon.exe
D:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.exe
D:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\System32\nutsrv4.exe
D:\Program Files\Common Files\Mercury Interactive\TDAPIServer\SendAllQualifiedApp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\MsgSys.exe
D:\Program Files\MSN Messenger\msnmsgr.exe
D:\Program Files\Microsoft Office 2003\OFFICE11\OUTLOOK.exe
D:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
E:\installers\hijackthis1977\HijackThis.exeR3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {297caf50-e4f7-11d1-a380-00600896eccc} - D:\Program Files\Segue\SilkTest\qaphlpr.dll
O2 - BHO: (no name) - {474264BC-9571-47C1-85B9-780F756DC9CE} - C:\WINDOWS\System32\BHOManager.dll
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINDOWS\2_0_1browserhelper2.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {71ED4FBA-4024-4bbe-91DC-9704C93F453E} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [SynTPLpr] D:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] D:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [vptray] D:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [QT4HPOT] D:\Program Files\HPQ\One-Touch\OneTouch.exe
O4 - HKLM\..\Run: [Display Settings] D:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [AdaptecDirectCD] "D:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [SoDA Startup] D:\Program Files\Rational\SoDAWord\Wizards\SodaStartup.exe StartUp
O4 - HKLM\..\Run: [NuTCSetupEnviron] D:\Program Files\Rational\Rational Test\nutcroot\bin\ncoeenv.exe
O4 - HKLM\..\Run: [Zone Labs Client] D:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Acrobat Assistant.lnk = D:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.exe
O8 - Extra context menu item: &Google Search - res://D:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://D:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://D:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://D:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://D:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Research (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/11d073ecb46e21475c19/netzip/RdxIE601.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38027.8304050926
O16 - DPF: {CDBD9968-7BF1-11D4-9D36-0001029DEBEB} (Loader Class) - http://sv-laptop/TDBIN/Spider.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F5C90925-ABBF-4475-88F5-8622B452BA9E} (Compaq System Data Class) - http://ipgweb.cce.hp.com/bus-nacons/caller/SysQuery.cab

Hello!
I've got exactly the same problem:
I've got many answers with yahoo, google containing: http://downloads.websearch.com
(and when I search exactly the same thing on another computer, the results are correct)
I tried adaware, spybot, norton, and nothnig works.
I even tried to make a new install of Windozs xp, but it doesn't correct the problem...Please help!
Thanks in advance,
Christophe

I have the same problem!
I've tried about 6 spyware removal programs but the search results in Google and Altavista still contain "http://download.websearch.com"-references.
Did anyone have this problem and solved it?

ah, i have the same problem!!!! this also happens on other search engines, yahoo.com, msn.com, etc (just to name a few)
i took a screen grab of what it looks like, you can see it here:
http://www.geocities.com/keyosrk/search-hijack.htmlthe properties on the link shows it directing to a blazefind.com URL
would be great if you guys have a solution in removing this.
many thanks!

okay nevermind, i found a solution
use hijack this n remove this one
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINDOWS\2_0_1browserhelper2.dll
good luck!

OK, make sure HJT is running from inside of it's own folder so backups can be made and with it only running fix these:
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINDOWS\2_0_1browserhelper2.dll
O3 - Toolbar: (no name) - {71ED4FBA-4024-4bbe-91DC-9704C93F453E} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.exe <----------- Resource hog - up to you - not neededO16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/11d073ecb46e21475c19/netzip/RdxIE601.cab
*********************************************************Reboot and find and delete this file or the whole folder:
D:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
*********************************************************
For the 08s: They look OK to me just double check them, same for the 09s:If you don't recognize the name of the item in the right-click menu in IE, have HijackThis fix it.
For 09s:
If you don't recognize the name of the button or menuitem, have HijackThis fix it.
*****************************************************Clean up the system also (this is for 98 and ME but should be close for XP)
Open up IE, from the drop down menu choose Tools, Internet Options, Delete Temporary Internet Files and cookies. (cookies optional)
Go to Start, Run, type temp , delete all the files in that folder
Do the same for recent
Delete all the .tmp and .chk files you can find. To do so, click Start/Find and in the search box (field) type *.tmp and this will search for all your temporary files. Repeat for chk files by typing *.chk in the search field, make sure you are looking in 'C'. Empty recycle bin.
Good luck, let me know, MrC

The rest of you people who still have a problem, run Spybot, CW-Shredder and cleanup the system. Then if you still have a problem, post a HJT log back here and I will look at it, but be patient. MrC

![]() |
update available for adaw...
|
Win2000 Prof - Winlogon, ...
|

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |