Computing.Net > Forums > Security and Virus > Searchdot.net bug

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Searchdot.net bug

Reply to Message Icon

Name: knadel77
Date: October 30, 2003 at 20:28:14 Pacific
OS: Win XP
CPU/Ram: 1.2/512
Comment:

I can't get rid of searchdot.net as my IE homepage upon reboot. I have tried Spybot and it didn't help. I have tried Ad aware already.

Here is my HijackThis logfile, now what:
Thanks!
Logfile of HijackThis v1.97.3
Scan saved at 10:42:50 PM, on 10/30/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\llass.exe
C:\WINDOWS\System32\DRIVERS\dcfssvc.exe
C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Altnet\DOWNLO~1\asm.exe
C:\Program Files\Internet Explorer\IEXPLORE.exe
C:\Documents and Settings\Kevin Nadel\Local Settings\Temp\Temporary Directory 6 for hijackthis[1].zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us.f206.mail.yahoo.com/ym/login?.rand=a39ro6bmqaphq
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchdot.net
N3 - Netscape 7: user_pref("browser.search.defaultengine", "http://www.google.com/"); (C:\Documents and Settings\Kevin Nadel\Application Data\Mozilla\Profiles\default\k099y4ee.slt\prefs.js)
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O16 - DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} - http://download.microsoft.com/download/vizact2000/Install/10/WIN98Me/EN-US/msorun.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab



Sponsored Link
Ads by Google

Response Number 1
Name: only one i see
Date: October 30, 2003 at 20:46:23 Pacific
Reply:

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.searchdot.net


0

Response Number 2
Name: knadel77
Date: October 30, 2003 at 21:07:12 Pacific
Reply:

It only reappears if I get rid of the R0 line.
Here is my log file upon reboot:

Logfile of HijackThis v1.97.3
Scan saved at 12:08:21 AM, on 10/31/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\llass.exe
C:\WINDOWS\System32\DRIVERS\dcfssvc.exe
C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Altnet\DOWNLO~1\asm.exe
C:\Program Files\Internet Explorer\IEXPLORE.exe
C:\Program Files\Internet Explorer\IEXPLORE.exe
C:\Documents and Settings\Kevin Nadel\Local Settings\Temp\Temporary Directory 7 for hijackthis[1].zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchdot.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchdot.net
N3 - Netscape 7: user_pref("browser.search.defaultengine", "http://www.google.com/"); (C:\Documents and Settings\Kevin Nadel\Application Data\Mozilla\Profiles\default\k099y4ee.slt\prefs.js)
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O16 - DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} - http://download.microsoft.com/download/vizact2000/Install/10/WIN98Me/EN-US/msorun.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab



0

Response Number 3
Name: smithdk
Date: October 31, 2003 at 09:36:08 Pacific
Reply:

http://www.compunet1.com/security/securityBulletin_.asp?bulletin=6

You have this file running:
C:\WINDOWS\system32\llass.exe

Do a virus scan:

http://housecall.trendmicro.com/


0

Response Number 4
Name: sxshep
Date: October 31, 2003 at 16:58:11 Pacific
Reply:

This is an obvious option, like it would actually work, but what the heck:

http://www.searchdot.net/remove/index.html

Sure you been there but...

hth
shep


0

Response Number 5
Name: knadel77
Date: November 1, 2003 at 18:37:15 Pacific
Reply:

Still having problems. I ran the virus scan and got rid of llass.exe. Is lsass.exe a problem? I also had a virus Winshow, which I have eliminated to the point that it doesn't reappear when I virus scan with Trend Micro.
I also tried the link above but I went to a screen that says "please wait..." but nothing happens.
What else can I try?
Also, why can't I erase the history on Internet Explorer?
Here is my most recent Hijack This logfile:

Logfile of HijackThis v1.97.3
Scan saved at 9:34:52 PM, on 11/1/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\DRIVERS\dcfssvc.exe
C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
C:\program files\altnet\points manager\points manager.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Altnet\DOWNLO~1\asm.exe
C:\Program Files\Internet Explorer\IEXPLORE.exe
C:\Program Files\Internet Explorer\IEXPLORE.exe
C:\Program Files\Internet Explorer\IEXPLORE.exe
C:\Documents and Settings\Kevin Nadel\Local Settings\Temp\Temporary Directory 2 for hijackthis[1].zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
N3 - Netscape 7: user_pref("browser.search.defaultengine", "http://www.google.com/"); (C:\Documents and Settings\Kevin Nadel\Application Data\Mozilla\Profiles\default\k099y4ee.slt\prefs.js)


0

Related Posts

See More



Response Number 6
Name: knadel77
Date: November 1, 2003 at 19:08:15 Pacific
Reply:

Problem solved!
I found this finally from another person who had this problem. I removed from Regedit and deleted the file msoffice.hta.
Finally searchdot.net is gone.


0

Response Number 7
Name: meltdown81
Date: November 1, 2003 at 22:41:21 Pacific
Reply:

I have this same problem. Where in the registry is the file msoffice.hta? Thanks.


0

Response Number 8
Name: meltdown81
Date: November 1, 2003 at 22:45:36 Pacific
Reply:

I have this same problem. Where in the registry is the file msoffice.hta? Thanks.


0

Response Number 9
Name: Methois
Date: November 3, 2003 at 22:40:39 Pacific
Reply:

This bug was just a lame attempt by a web designer to force people to use his search engine. The msoffice.hta is a hidden file that, unless you search specifically for it with the "Find Files and Folders" in the start menu. You will never see it. It's not in your registry. If I remember right though, it should be in your windows folder. Anyway, hope this helps you out.

Regards,
~Methois


0

Response Number 10
Name: Nick
Date: November 5, 2003 at 17:13:30 Pacific
Reply:

There are many differnt versions of this type of trojan. Trojan.Ghost.(A & B) Trojan.bootconf, and the one we are dealing with is VBS.Bootconf. Symantec knows nothing about this file, although most of you above have found the answers.

Turn off your system restore.
Click Start.
Right-click My <nobr><a class="iAs" style="border-bottom:darkgreen 1px solid;text-decoration:underline;color:darkgreen;background-color:transparent;" href="http://itxt.vibrantmedia.com/al.asp?ipid=7&cc=us&cf=1&ai=1450402&di=100688&ts=20031105172709" target="_blank" oncontextmenu="return false;" onmouseover="kwE(event,100688);" onmouseout="kwL(event);" onmousemove="kwM(100688);">Computer</nobr>, and then click Properties.
Click the System Restore tab.
Select "Turn off System Restore" or "Turn off System Restore on all drives" check box
Click Apply.
As noted in the message, this will delete all existing restore points. Click Yes to do this.
Click OK.
Proceed with my instructions below.

The easier way to rid of this annoying virus is locate the msoffice.hta file. You can do a search or an easy way to find this is go to Start > Run > and type MSCONFIG. A box pops up, but do not change anything in this box that pops up, it is your System Configuration, and if you change somethign you shouldnt, your computer might not boot up. Click on the start up tab. Scroll down untill you find a start up item labeled msoffice. To ensure this is the correct file look at the Command line. The command line should inclued the following C:\Windows\.....\msoffice.hta. In my case it was hidding in the Fonts(C:\Windows\Fonts\msoffice.hta. Now that you are aware that this is the correct file, Uncheck it. Click ok, then Click Exit without Restart. What this does is stops that file from being loaded when windows is booted up. When this file loads, it restores the virus to its original state, and eliminates any changes to made to the registry, and internet explorer options.

Now that you made changes in your MSCONFIG, you can navigate to where the msoffice.hta is located. This file might be hidden, so in your explorer click tools > folder options > View > Show hidden files and folders > click ok. Once you have done this you will be able to see the msoffice.hta file. Delete it.

Now you need to edit your registry.
Click Start, and then click Run. (The Run dialog box appears.)
Type regedit

Then click OK. (The Registry Editor opens.)


Navigate to the key:

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer


In the right pane, delete the values:

"Search" = <encoded URL> (i just replaced these values with www.msn.com)
"SearchURL" = <encoded URL>


Navigate to the key:

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search


In the right pane, delete the values:

"SearchAssistant" = <encoded URL>
"CustomizeSearch" = <encoded URL>


Exit the Registry Editor.

Now this should rid you of this annoying virus. reboot your computer.

Once you have rebooted a message will pop up from the configuration we made in your MSCONFIG. check the available check box and click ok.

now you should be good to go, you might need to change your internet settings in internet explorer. Connect to the Internet and go to the page that you want to set as your home page.
Click Tools, and then click Internet Options.
In the Home page section of the General tab, click Use Current, and then click OK.

now you need to turn your system restore back on.

Turn on your system restore.
Click Start.
Right-click My Computer, and then click Properties.
Click the System Restore tab.
Clear the "Turn off System Restore" or "Turn off System Restore on all drives" check box.
Click Apply, and then click OK


0

Response Number 11
Name: nick
Date: November 5, 2003 at 17:24:02 Pacific
Reply:

For some reason html coding go stuck in my first part of my message/instructions so here is how to turn off the system restore.

Click Start.
Right-click My Computer, and then click Properties.
Click the System Restore tab.
Select "Turn off System Restore" or "Turn off System Restore on all drives" check box
Click Apply.
As noted in the message, this will delete all existing restore points. Click Yes to do this.
Click OK.
Proceed with my instructions below.


0

Response Number 12
Name: Jerome
Date: November 6, 2003 at 22:48:47 Pacific
Reply:

Anyone still having problems? I was until about 1 minute ago. http://www.spywareinfo.com/~merijn/files/cwshredder.zip
That should do it , it did it for me. Its a program written to fix this problem =)


0

Response Number 13
Name: samosh
Date: November 8, 2003 at 14:06:08 Pacific
Reply:

NO NO NO !!!!
You have a hijacker virus.
read the following notes.
I was able to FINALLY get rid of a very sneaky trojan/hijacker/virus. It has something to do with http:/tooncomics.com/main/b1.php For me. But it couls be diff pages for you but resulst the sam. Anyways This virus was able to beat Spybot!! It could even reset BHO's that you lock inside spybot and reset the homeage after every reboot and add porn links to your favorites file!! Not only that but it runs IE in the background and visits porn Hosts/sites. This activity can only be seen in task manager. THE FIX;
Get HIJACKTHIS.exe and run it.
DELETE everything that hijackthis shows you that has tooncomics in it.
ESPECIALLY DELETE following files.
O4 - HKCU\..\Run: [iedll] C:\WINDOWS\iedll.exe
O4 - HKCU\..\Run: [loader] C:\WINDOWS\loader.exe

AND this is where the virus actually hides. You can rename these files as .txt file and open them in notepad and see for yourself its all there.
C:\WINDOWS\iedll.exe
C:\WINDOWS\loader.exe

Good luck !


0

Response Number 14
Name: Pleo
Date: November 30, 2003 at 17:47:12 Pacific
Reply:

Alright. I have searchdot.net as well, including times that it changes to search.com and allneedsearch and others.

I have done all the stuff listed above, dug through registry, changed stuff and deleted MSoffice.hta, to the dot. However i still have this damn bug. Unfortanitly now, not sure if it is from this, when i am online i am auto forwarded to various porn sites.
Can anyone offer sum help on removing this?



0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Searchdot.net bug

searchv & searchdot www.computing.net/answers/security/searchv-amp-searchdot/6838.html

Comwiz.exe and Winnet.exe www.computing.net/answers/security/comwizexe-and-winnetexe/6701.html

AIM info virus www.computing.net/answers/security/aim-info-virus/7758.html