Computing.Net > Forums > Security and Virus > Google results

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Google results

Reply to Message Icon

Name: sanvish23
Date: March 20, 2004 at 22:12:37 Pacific
OS: win xp
CPU/Ram: 512mb
Comment:

When i search google for anything i get this along with other results

Find PASSWORD on Crawler.com with Free Websearch Tools
Click here to download WebSearch Tools and search 15 engines for PASSWORD at once now with free
pop-up blocker, yellow/white pages, free games, maps, skins, cursors and more.
http://download.websearch.com/ - 54k

Find PASSWORD With Free Websearch Tools
Click here to download WebSearch Tools and search 15 engines for PASSWORD at once now with free
pop-up blocker, yellow/white pages, free games, maps, skins, cursors and more.
http://download.websearch.com/ - 39k

Find PASSWORD Using the Free 2020 Search Toolbar
Having trouble finding PASSWORD? Get the 2020Search toolbar and say good-bye to those annoying pop-ups.
Many other useful features such as: text highlighter, multi-search engine, drag & drop,
e-mail results and more.
http://www.2020search.com/ - 48k

where PASSWORD is the string i searched for.
i dont think this is right. i dont think google should be giving these results. they come on every results page. ihave uses cwsshredder,adaware and spybot. please let me know if yu have any more ino on this one



Sponsored Link
Ads by Google

Response Number 1
Name: MrCharlie
Date: March 21, 2004 at 04:13:14 Pacific
Reply:

Run a HiJackThis scan of your system and post the results back here so we can see what's on your system. HiJackThis and Instructions


0

Response Number 2
Name: MrCharlie
Date: March 21, 2004 at 04:18:59 Pacific
Reply:

You can download HJT here:

CW-Shredder-Spybot-HJT


0

Response Number 3
Name: sanvish23
Date: March 21, 2004 at 19:39:38 Pacific
Reply:

Logfile of HijackThis v1.97.7
Scan saved at 7:38:21 PM, on 3/21/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\carpserv.exe
D:\Program Files\Synaptics\SynTP\SynTPLpr.exe
D:\Program Files\Synaptics\SynTP\SynTPEnh.exe
D:\Program Files\NavNT\vptray.exe
D:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
D:\Program Files\HPQ\One-Touch\OneTouch.exe
C:\WINDOWS\System32\drivers\CDAC11BA.exe
D:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
D:\Program Files\NavNT\defwatch.exe
C:\WINDOWS\system32\HPConfig.exe
D:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
D:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
C:\WINDOWS\System32\ctfmon.exe
D:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.exe
D:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\System32\nutsrv4.exe
D:\Program Files\Common Files\Mercury Interactive\TDAPIServer\SendAllQualifiedApp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\MsgSys.exe
D:\Program Files\MSN Messenger\msnmsgr.exe
D:\Program Files\Microsoft Office 2003\OFFICE11\OUTLOOK.exe
D:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
E:\installers\hijackthis1977\HijackThis.exe

R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {297caf50-e4f7-11d1-a380-00600896eccc} - D:\Program Files\Segue\SilkTest\qaphlpr.dll
O2 - BHO: (no name) - {474264BC-9571-47C1-85B9-780F756DC9CE} - C:\WINDOWS\System32\BHOManager.dll
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINDOWS\2_0_1browserhelper2.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {71ED4FBA-4024-4bbe-91DC-9704C93F453E} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [SynTPLpr] D:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] D:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [vptray] D:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [QT4HPOT] D:\Program Files\HPQ\One-Touch\OneTouch.exe
O4 - HKLM\..\Run: [Display Settings] D:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [AdaptecDirectCD] "D:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [SoDA Startup] D:\Program Files\Rational\SoDAWord\Wizards\SodaStartup.exe StartUp
O4 - HKLM\..\Run: [NuTCSetupEnviron] D:\Program Files\Rational\Rational Test\nutcroot\bin\ncoeenv.exe
O4 - HKLM\..\Run: [Zone Labs Client] D:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Acrobat Assistant.lnk = D:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.exe
O8 - Extra context menu item: &Google Search - res://D:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://D:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://D:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://D:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://D:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Research (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/11d073ecb46e21475c19/netzip/RdxIE601.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38027.8304050926
O16 - DPF: {CDBD9968-7BF1-11D4-9D36-0001029DEBEB} (Loader Class) - http://sv-laptop/TDBIN/Spider.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F5C90925-ABBF-4475-88F5-8622B452BA9E} (Compaq System Data Class) - http://ipgweb.cce.hp.com/bus-nacons/caller/SysQuery.cab



0

Response Number 4
Name: CHRIS256
Date: March 22, 2004 at 09:36:01 Pacific
Reply:

Hello!

I've got exactly the same problem:
I've got many answers with yahoo, google containing: http://downloads.websearch.com
(and when I search exactly the same thing on another computer, the results are correct)
I tried adaware, spybot, norton, and nothnig works.
I even tried to make a new install of Windozs xp, but it doesn't correct the problem...

Please help!
Thanks in advance,
Christophe


0

Response Number 5
Name: mtb-rider
Date: March 22, 2004 at 11:39:31 Pacific
Reply:

I have the same problem!
I've tried about 6 spyware removal programs but the search results in Google and Altavista still contain "http://download.websearch.com"-references.
Did anyone have this problem and solved it?


0

Related Posts

See More



Response Number 6
Name: Keyo
Date: March 22, 2004 at 13:55:58 Pacific
Reply:

ah, i have the same problem!!!! this also happens on other search engines, yahoo.com, msn.com, etc (just to name a few)

i took a screen grab of what it looks like, you can see it here:
http://www.geocities.com/keyosrk/search-hijack.html

the properties on the link shows it directing to a blazefind.com URL

would be great if you guys have a solution in removing this.

many thanks!


0

Response Number 7
Name: Keyo
Date: March 22, 2004 at 14:14:36 Pacific
Reply:

okay nevermind, i found a solution

use hijack this n remove this one

O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINDOWS\2_0_1browserhelper2.dll

good luck!


0

Response Number 8
Name: MrCharlie
Date: March 22, 2004 at 15:03:40 Pacific
Reply:

OK, make sure HJT is running from inside of it's own folder so backups can be made and with it only running fix these:

R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINDOWS\2_0_1browserhelper2.dll

O3 - Toolbar: (no name) - {71ED4FBA-4024-4bbe-91DC-9704C93F453E} - (no file)

O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe

O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.exe <----------- Resource hog - up to you - not needed

O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/11d073ecb46e21475c19/netzip/RdxIE601.cab
*********************************************************

Reboot and find and delete this file or the whole folder:
D:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe

*********************************************************
For the 08s: They look OK to me just double check them, same for the 09s:

If you don't recognize the name of the item in the right-click menu in IE, have HijackThis fix it.

For 09s:
If you don't recognize the name of the button or menuitem, have HijackThis fix it.

*****************************************************

Clean up the system also (this is for 98 and ME but should be close for XP)
Open up IE, from the drop down menu choose Tools, Internet Options, Delete Temporary Internet Files and cookies. (cookies optional)
Go to Start, Run, type temp , delete all the files in that folder
Do the same for recent
Delete all the .tmp and .chk files you can find. To do so, click Start/Find and in the search box (field) type *.tmp and this will search for all your temporary files. Repeat for chk files by typing *.chk in the search field, make sure you are looking in 'C'. Empty recycle bin.

Good luck, let me know, MrC



0

Response Number 9
Name: MrCharlie
Date: March 22, 2004 at 15:15:22 Pacific
Reply:

The rest of you people who still have a problem, run Spybot, CW-Shredder and cleanup the system. Then if you still have a problem, post a HJT log back here and I will look at it, but be patient. MrC


0

Response Number 10
Name: CHRIS256
Date: March 25, 2004 at 02:02:26 Pacific
Reply:

Thanks MrCharlie!

This works for me. The problem is solved!

Bye!
Christophe


0

Response Number 11
Name: sanvish23
Date: March 28, 2004 at 11:15:15 Pacific
Reply:

thanks Mr Charlie.
fixed it.


0

Sponsored Link
Ads by Google
Reply to Message Icon

update available for adaw... Win2000 Prof - Winlogon, ...



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Google results

Strange Google Results www.computing.net/answers/security/strange-google-results/11875.html

Redirecting from Google Results www.computing.net/answers/security/redirecting-from-google-results/25318.html

Trogan Affecting Google Searc www.computing.net/answers/security/trogan-affecting-google-searc/16010.html