Computing.Net > Forums > Security and Virus > Registry cure for Searchv hijacker

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

Registry cure for Searchv hijacker

Reply to Message Icon

Original Message
Name: Solarian
Date: October 15, 2003 at 10:16:52 Pacific
Subject: Registry cure for Searchv hijacker
OS: XP
CPU/Ram: P4 256 MB
Comment:

Here's a registry cure if your browser's been hijacked by Searchv:

1. Click Start | Run and type regedit to open the Registry Editor.

2. Navigate to this key: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main.

3. In the right pane, look for an entry called Start Page. Double click it.

4. In the Value Data box, if the URL is http://www.searchv.com/, that's your culprit. Change it to your desired start page.

5. Click OK and close the Registry Editor.

Courtesy of WinXPnews. Naturally, back-up your registry before making any changes. 8-)

Solarian



Report Offensive Message For Removal


Response Number 1
Name: BriMc
Date: October 15, 2003 at 18:16:19 Pacific
Reply:

OK, any ideas what to do if that doesn't work?

I've tried that approach and also I then cleared www.searchv.com from the default search entry and other place I can find it within the registry.

Every time I restart the computer, it's back.

I found another method that had me go into msconfig and do a selective startup. By process of elimination I'm pretty sure the problem is in the "Load Startup Items", because if it remains unchecked I'm OK, my chosen homepage is there. But once rechecked, searchv.com is back upon restart.

Any help would be greatly appreciated.


Report Offensive Follow Up For Removal

Response Number 2
Name: BriMc
Date: October 15, 2003 at 18:24:34 Pacific
Reply:

Here's my logfile, if this is of any help. What do I need to do?

Logfile of HijackThis v1.97.3
Scan saved at 7:39:37 AM, on 10/15/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\System32\hphmon04.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\PROGRA~1\AWS\WEATHE~1\Weather.exe
C:\Program Files\hp center\137903\Shadow\ShadowBar.exe
C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\WINDOWS\System32\HPHipm11.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http:/www.searchv.com/w/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.searchv.com/w/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.excite.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchv.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.searchv.com/w/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.searchv.com/w/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.searchv.com/w/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.searchv.com/w/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchv.com/w/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchv.com/w/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://us7.hpwis.com/
O1 - Hosts: 209.66.114.130 sitefinder.verisign.com
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: WinShow module - {6CC1C918-AE8B-4373-A5B4-28BA1851E39A} - C:\Documents and Settings\Owner\Application Data\winshow\winshow.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [WT GameChannel] C:\Program Files\WildTangent\Apps\GameChannel.exe
O4 - HKLM\..\Run: [sys] regedit /s C:\WINDOWS\sys.reg
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [KAZAA] C:\Program Files\Kazaa\kazaa.exe /SYSTRAY
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon04.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [BlockTracker] c:\hp\bin\BlockTracker.exe
O4 - HKLM\..\Run: [AutoTBar] C:\hp\bin\autotbar.exe
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: hp center UI.lnk = C:\Program Files\hp center\137903\Shadow\ShadowBar.exe
O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: MSupdater.exe
O9 - Extra button: MktBrowser (HKLM)
O9 - Extra 'Tools' menuitem: MarketBrowser (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: ChatSpace Full Java Client 3.1.0.218 - http://64.85.20.117:8152/Java/cfs31218.cab
O16 - DPF: ChatSpace Java Client 2.1.0.90L - http://64.85.20.117:8152/Java/cs4msl090.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - http://www.xblock.com/download/xclean_micro.exe
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37844.7452893518
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-000000000000} - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab



Report Offensive Follow Up For Removal

Response Number 3
Name: smithdk
Date: October 15, 2003 at 19:18:46 Pacific
Reply:

These are not good:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http:/www.searchv.com/w/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.searchv.com/w/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchv.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.searchv.com/w/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.searchv.com/w/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.searchv.com/w/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.searchv.com/w/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchv.com/w/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchv.com/w/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O1 - Hosts: 209.66.114.130 sitefinder.verisign.com
O2 - BHO: WinShow module - {6CC1C918-AE8B-4373-A5B4-28BA1851E39A} - C:\Documents and Settings\Owner\Application Data\winshow\winshow.dll
O4 - Global Startup: MSupdater.exe


Report Offensive Follow Up For Removal

Response Number 4
Name: BriMc
Date: October 15, 2003 at 20:52:19 Pacific
Reply:

I was able to delete all of those, but unfortunately, the problem still occurs after re-start.

Any ideas?


Report Offensive Follow Up For Removal

Response Number 5
Name: Tom41
Date: October 16, 2003 at 00:21:59 Pacific
Reply:

Fix all those that smithdk has listed plus this one:
O4 - HKLM\..\Run: [sys] regedit /s C:\WINDOWS\sys.reg

Reboot and delete C:\WINDOWS\sys.reg.


Report Offensive Follow Up For Removal


Response Number 6
Name: Spotter001
Date: October 16, 2003 at 17:09:28 Pacific
Reply:

I have done all of the things done above to destroy the EVIL searchv.com infestation in my machine.....upon bootup it just comes back every time.....I did a search and did not find the sys.reg file on my computer....I am running win 2000 prof......more suggestions????



Report Offensive Follow Up For Removal

Response Number 7
Name: BriMc
Date: October 16, 2003 at 17:46:51 Pacific
Reply:

Tom41 -

That did the trick. Finally.

Everyone's help is much appreciated.

BTW, when I rebooted, I never found the C:\WINDOWS\sys.reg file, but searchv is gone, so hopefully that's the end of it.

Thanks again.


Report Offensive Follow Up For Removal

Response Number 8
Name: thankful
Date: October 18, 2003 at 12:39:46 Pacific
Reply:

Tom41

I just want to say THANK YOU for your posting. Because of great guys like you, millions normal users can have beeter sleeps.

sys.reg is the bomb in my case, once it is deleted, serchv is done. Before that I tried all antispyware, none of them worked.

So far, your method is the only solution, PERIOD!

:)



Report Offensive Follow Up For Removal

Response Number 9
Name: dethtung
Date: October 20, 2003 at 01:46:49 Pacific
Reply:

Sadly i'm living with this "searchv" plague also, i understand how to navigate through the registry to find the keys, unfortunately i don't know what "O4 or O3" means so i'm still stuck with this hijacker....


Report Offensive Follow Up For Removal

Response Number 10
Name: fresh17
Date: October 20, 2003 at 11:15:10 Pacific
Reply:

Thanks for all the info and tips!! Here's some more info on SearchV pasted from the PestPatrol site, updated yesterday:

Overview
Vendor Notes: from the web site: 'SearchV is a Performance-Based Advertising Network that reaches millions of consumers daily, via our partnerships with top quality web sites. We offer Cost-Per-Click (CPC) advertising solutions, so you only pay for unique visitors that have clicked on your specific ad. What's more, you choose the price that you want to pay for each click and you can change this price at any time. Our easy to use, on-line tools allow you to manage your ad campaign in real-time!'

Alias:W32/Dumaru trojan

See Also:Winshow

Category: Hijacker: A trojan that may reset your browser's home page and/or search settings to point to other sites. Such sites are sometimes porn sites, often loaded with advertisting. Homepage Hijackers may prevent you from changing your browsers's homepage.

Similar Pests:
Hijacker

Origins
Groups:[First Aid], First Aid
By These Groups:Searchv.com
Mailing Address:First Aid PO BOX 5874 Gasa, 541245 WS
EMail:support@searchv.com
URL:http://www.searchv.com/

Distribution
Prevalence:0.0% of all pest reports (14 per 100,000 reports) More Info

Clot Factor:On average, 3 objects detected in each machine [The "Clot Factor" is a measure of how much a pest "gums up" a machine by adding registry entries, files, and directories. As more objects are placed in a machine, manual removal becomes more difficult and more error-prone.]

Countries Affected:
In the past three months, we have received reports of SearchV in Canada, Israel, United States.
Growth:Decreased 100.0% over the last 90 days

Operation
Storage Required:at least 317KB
Browser Performance:Likely to slow performance of Internet Explorer.

Risks
Privacy Policy:http://www.searchv.com/privacy.html

Detection and Removal
Automatic Removal:PestPatrol detects this.
PestPatrol removes this.


Manual Removal:
Close all browser and all Windows Explorer windows before proceeding...
1. Click Start | Run and type regedit to open the Registry Editor.
2. Navigate to this key: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main.
3. In the right pane, look for an entry called Start Page. Double click it.
4. In the Value Data box, if the URL is http://www.searchv.com/, that's your culprit. Change it to your desired start page.
5. Click OK and close the Registry Editor.
SearchV may modify your hosts file to redirect searches to http://209.66.114.130/ Search for 209.66.114.130 and remove this line if found.

Stop Running Processes:

Kill (see further info below) these running processes with Task Manager:
systemroot+\updreg.exe
systemroot+\system32\vxdmgr32.exe
systemroot+\system32\load32.exe
systemroot+\dllreg.exe
profilepath+\start menu\programs\startup\rundllw.exe
profilepath+\application data\iebs.exebelt.exe
msupdater.exe

Unregister (see below) DLLs:

Unregister these DLLs with Regsvr32, then reboot:
systemroot+\iempg.dll
systemroot+\system32\dreplace.dllwinshow.dll

Remove Files:

Remove these files (if present) with Windows Explorer:
systemroot+\updreg.exe
systemroot+\sys.reg
systemroot+\iempg.dll
systemroot+\system32\vxdmgr32.exe
systemroot+\system32\load32.exe
systemroot+\dllreg.exe
profilepath+\start menu\programs\startup\rundllw.exe
profilepath+\application data\iebs.exe
systemroot+\system32\dreplace.dllbelt.exe
winshow.dll
winshow.cfg
msupdater.exe-04f9ec8b.pf
msupdater.exe


Delete Registry Items
The registry is a hierarchical configuration database maintained by Windows and your applications. The database is stored on disk, and a copy in memory is created when you boot.
Most applications, including pests you want to remove, will modify the registry in some way, adding their own entries and changing some previous entries. Complete removal of an application includes registry edits.
The registry can be edited with Regedit.

Kill Running Processes
Many programs cannot be deleted if they are currently running. Use Task Manager to stop any process that is running. (In Windows 2000 and XP, Task Manager lists all processes; in earlier versions of Windows, only visible processes will be listed.) Invoke Task Manager via Ctrl-Alt-Del. In NT/2000/XP, choose the Processes tab to list all programs. Find the exe of interest, highlight it, and end it.
Background: Windows can run many programs at the same time, but with just a single CPU, can only perform one task at a time. In your computer, Windows gives the illusion that several programs are running in parallel by switching rapidly from one to the next, giving each a time-slice of the CPU. But if any program hangs, Windows may get stuck on that task, and be unable to switch to the other running programs, causing everything to hang.
A task or process is a program (such as an exe file) that is being executed or run. When a program is started, Windows loads it into memory (RAM), adds it to an internal list of running processes, and provides the process with the memory and other resources it needs. Windows tracks what processes are using what resources, and when one of these processes is terminated, Windows can usually return its resources to the general pool, for redistribution to other processes.
Example: For some pests such as CommonName, if you edit the registry while one of their processes is running, that process will "repair" the registry, undoing your work. In the case of CommonName, you must first kill the 'winnet.exe' process (otherwise, it will keep setting itself up to run automatically). In Task Manager, choose 'winnet.exe' and end the process.

Remove AutoStart
The registry contains defines several procedures for automatically starting software when you boot your machine. One of these is in HKEY_LOCAL_MACHINE at \Software\Microsoft\Windows\CurrentVersion\Run. You may use RegEdit to find this key. Do not delete the entire branch -- just the key over on the right-hand side of your screen.
Example: Many pests such as CommonName will start running when you boot. To prevent CommonName from automatically restarting, go to the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run. There will be a value here titled 'Zenet' or 'Winnet'. Delete it and reboot the machine immediately.
For more info on AutoStarting methods used by pests, click here.

Remove Files and Directories
Many programs create one or more directories, at the time of installation, for the convenient organization of their files. Such directories are logical containers. Complete removal of a pest may require removal of files in various locations, and may require removal of one or more directories.
Both Files and Directories may be found and removed using Windows Explorer:
1. Right-click on the Start button (lower left of your screen).
2. Choose Explore.
3. Locate the file or directory of interest and highlight it.
4. Right-click to invoke the popup menu, and choose Delete.

UnRegister DLLs
You can use the Regsvr32 tool (Regsvr32.exe) to register and unregister object linking and embedding (OLE) controls such as dynamic-link library (DLL) or ActiveX Controls (OCX) files that are self-registerable.
RegSvr32.exe has the following command-line options:
Regsvr32 [/u] [/n] [/i[:cmdline]] dllname

/u - Unregister server<BR/>
/i - Call DllInstall passing it an optional [cmdline]; when used with /u calls dll uninstall
/n - do not call DllRegisterServer; this option must be used with /i

When you use Regsvr32.exe, it attempts to load the component and call its DLLSelfRegister function. If this attempt is successful, Regsvr32.exe displays a dialog indicating success. If the attempt is unsuccessful, Regsvr32.exe returns an error message, which may include a Win32 error code.
Example: To unregister Winshow's winshow.dll:
1. Click the Start button, and select Run
2. Enter this command line:
regsvr32 /u [systemroot]\winshow.dll
For example, in a Windows XP machine in which your systemroot was at c:\winnt, you would enter:
regsvr32 /u c:\winnt\winshow.dll


Report Offensive Follow Up For Removal

Response Number 11
Name: sundevilrock
Date: October 21, 2003 at 17:01:17 Pacific
Reply:

I, unfortunately, am having troubles, still, too. After I reboot, a lot of the keys that I'd changed from searchv.com are back the way they were before I rebooted. Do I have to save, or confirm or something? I deleted sys.reg, and the scans say that I'm clean now, but I still get searchv.com as my home and as my search defaults.

Tom, should I have completely deleted that key that references sys.reg? I tried just blanking it, and that didn't work, and I tried deleting it, and that didn't work.

Help, anyone?

dethtung - the "O4 - HKLM\..\Run: [sys] regedit /s C:\WINDOWS\sys.reg " stuff in Tom's message just refers you to the registry entry "HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Run\" keys

thanks in advance, all...

sundevilrock


Report Offensive Follow Up For Removal

Response Number 12
Name: sundevilrock
Date: October 21, 2003 at 22:23:08 Pacific
Reply:

ah-ha... it had hidden MSUpdater.exe in the All Users\Start Menu\Programs\Startup folder - no wonder it happened each time I restarted... lol - sorta.

Anybody have any information on how we can shut searchv.com down, and keep them from doing it to others?

- sundevilrock


Report Offensive Follow Up For Removal

Response Number 13
Name: Mattin
Date: October 25, 2003 at 05:25:30 Pacific
Reply:

each time you restart your computer there is /windows/sys.reg added to your registry which adds searchv newly.

delete all regestry-entries and this file to get rid of searchv

or

use the program hijackthis from http://www.spywareinfo.com/~merijn/

fix all entries with searchv AND the entry adding sys.reg each time you restart you


Report Offensive Follow Up For Removal

Response Number 14
Name: Doug K
Date: October 30, 2003 at 09:38:36 Pacific
Reply:

Great site and good advise. thanks guys.
I'm almost in the clear. My settings are my own again, but I get one error on start up.

"Cannot import C:\winnt\sys.reg:
Error opening the file. There may be a disk or file system error."

the file is gone. I toasted it. But what is telling it to go there on start up? And how do I stop it?


Report Offensive Follow Up For Removal






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home



Results for: Registry cure for Searchv hijacker

need help with searchv.com
    Summary: Computer dummy, For Searchv hijacks, run Hijack This from http://tomcoyote.org/hjt/ and tick all lines that have this in it. R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://...
www.computing.net/answers/security/need-help-with-searchvcom/6859.html

Homepage Hijack
    Summary: For Searchv hijacks, run Hijack This and tick all lines that have this in it. R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.searchv.com/w/search.html Look down the list ...
www.computing.net/answers/security/homepage-hijack/6906.html

searchv -- Please Help!
    Summary: Billm1, this is another one O4 - HKLM\..\Run: [sys] regedit /s C:\WINNT\sys.reg plpoteet,try this Check the item below in HijackThis, close all windows except HijackThis and click Fix checked: O2 - BH...
www.computing.net/answers/security/searchv-please-help/6856.html








Which MP3 player do you have?

iPod/iPhone
Zune
Something Else
None


View Results

Poll Finishes Today.
Discuss in The Lounge
Poll History






Data Recovery Software