Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
I can't get rid of searchdot.net as my IE homepage upon reboot. I have tried Spybot and it didn't help. I have tried Ad aware already.
Here is my HijackThis logfile, now what:
Thanks!
Logfile of HijackThis v1.97.3
Scan saved at 10:42:50 PM, on 10/30/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\llass.exe
C:\WINDOWS\System32\DRIVERS\dcfssvc.exe
C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Altnet\DOWNLO~1\asm.exe
C:\Program Files\Internet Explorer\IEXPLORE.exe
C:\Documents and Settings\Kevin Nadel\Local Settings\Temp\Temporary Directory 6 for hijackthis[1].zip\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us.f206.mail.yahoo.com/ym/login?.rand=a39ro6bmqaphq
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchdot.net
N3 - Netscape 7: user_pref("browser.search.defaultengine", "http://www.google.com/"); (C:\Documents and Settings\Kevin Nadel\Application Data\Mozilla\Profiles\default\k099y4ee.slt\prefs.js)
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O16 - DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} - http://download.microsoft.com/download/vizact2000/Install/10/WIN98Me/EN-US/msorun.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

It only reappears if I get rid of the R0 line.
Here is my log file upon reboot:Logfile of HijackThis v1.97.3
Scan saved at 12:08:21 AM, on 10/31/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\llass.exe
C:\WINDOWS\System32\DRIVERS\dcfssvc.exe
C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Altnet\DOWNLO~1\asm.exe
C:\Program Files\Internet Explorer\IEXPLORE.exe
C:\Program Files\Internet Explorer\IEXPLORE.exe
C:\Documents and Settings\Kevin Nadel\Local Settings\Temp\Temporary Directory 7 for hijackthis[1].zip\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchdot.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchdot.net
N3 - Netscape 7: user_pref("browser.search.defaultengine", "http://www.google.com/"); (C:\Documents and Settings\Kevin Nadel\Application Data\Mozilla\Profiles\default\k099y4ee.slt\prefs.js)
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O16 - DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} - http://download.microsoft.com/download/vizact2000/Install/10/WIN98Me/EN-US/msorun.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

http://www.compunet1.com/security/securityBulletin_.asp?bulletin=6
You have this file running:
C:\WINDOWS\system32\llass.exeDo a virus scan:
http://housecall.trendmicro.com/

This is an obvious option, like it would actually work, but what the heck:
http://www.searchdot.net/remove/index.html
Sure you been there but...
hth
shep

Still having problems. I ran the virus scan and got rid of llass.exe. Is lsass.exe a problem? I also had a virus Winshow, which I have eliminated to the point that it doesn't reappear when I virus scan with Trend Micro.
I also tried the link above but I went to a screen that says "please wait..." but nothing happens.
What else can I try?
Also, why can't I erase the history on Internet Explorer?
Here is my most recent Hijack This logfile:Logfile of HijackThis v1.97.3
Scan saved at 9:34:52 PM, on 11/1/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\DRIVERS\dcfssvc.exe
C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
C:\program files\altnet\points manager\points manager.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Altnet\DOWNLO~1\asm.exe
C:\Program Files\Internet Explorer\IEXPLORE.exe
C:\Program Files\Internet Explorer\IEXPLORE.exe
C:\Program Files\Internet Explorer\IEXPLORE.exe
C:\Documents and Settings\Kevin Nadel\Local Settings\Temp\Temporary Directory 2 for hijackthis[1].zip\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
N3 - Netscape 7: user_pref("browser.search.defaultengine", "http://www.google.com/"); (C:\Documents and Settings\Kevin Nadel\Application Data\Mozilla\Profiles\default\k099y4ee.slt\prefs.js)

Problem solved!
I found this finally from another person who had this problem. I removed from Regedit and deleted the file msoffice.hta.
Finally searchdot.net is gone.

This bug was just a lame attempt by a web designer to force people to use his search engine. The msoffice.hta is a hidden file that, unless you search specifically for it with the "Find Files and Folders" in the start menu. You will never see it. It's not in your registry. If I remember right though, it should be in your windows folder. Anyway, hope this helps you out.
Regards,
~Methois

There are many differnt versions of this type of trojan. Trojan.Ghost.(A & B) Trojan.bootconf, and the one we are dealing with is VBS.Bootconf. Symantec knows nothing about this file, although most of you above have found the answers.
Turn off your system restore.
Click Start.
Right-click My <nobr><a class="iAs" style="border-bottom:darkgreen 1px solid;text-decoration:underline;color:darkgreen;background-color:transparent;" href="http://itxt.vibrantmedia.com/al.asp?ipid=7&cc=us&cf=1&ai=1450402&di=100688&ts=20031105172709" target="_blank" oncontextmenu="return false;" onmouseover="kwE(event,100688);" onmouseout="kwL(event);" onmousemove="kwM(100688);">Computer</nobr>, and then click Properties.
Click the System Restore tab.
Select "Turn off System Restore" or "Turn off System Restore on all drives" check box
Click Apply.
As noted in the message, this will delete all existing restore points. Click Yes to do this.
Click OK.
Proceed with my instructions below.The easier way to rid of this annoying virus is locate the msoffice.hta file. You can do a search or an easy way to find this is go to Start > Run > and type MSCONFIG. A box pops up, but do not change anything in this box that pops up, it is your System Configuration, and if you change somethign you shouldnt, your computer might not boot up. Click on the start up tab. Scroll down untill you find a start up item labeled msoffice. To ensure this is the correct file look at the Command line. The command line should inclued the following C:\Windows\.....\msoffice.hta. In my case it was hidding in the Fonts(C:\Windows\Fonts\msoffice.hta. Now that you are aware that this is the correct file, Uncheck it. Click ok, then Click Exit without Restart. What this does is stops that file from being loaded when windows is booted up. When this file loads, it restores the virus to its original state, and eliminates any changes to made to the registry, and internet explorer options.
Now that you made changes in your MSCONFIG, you can navigate to where the msoffice.hta is located. This file might be hidden, so in your explorer click tools > folder options > View > Show hidden files and folders > click ok. Once you have done this you will be able to see the msoffice.hta file. Delete it.
Now you need to edit your registry.
Click Start, and then click Run. (The Run dialog box appears.)
Type regeditThen click OK. (The Registry Editor opens.)
Navigate to the key:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer
In the right pane, delete the values:"Search" = <encoded URL> (i just replaced these values with www.msn.com)
"SearchURL" = <encoded URL>
Navigate to the key:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search
In the right pane, delete the values:"SearchAssistant" = <encoded URL>
"CustomizeSearch" = <encoded URL>
Exit the Registry Editor.Now this should rid you of this annoying virus. reboot your computer.
Once you have rebooted a message will pop up from the configuration we made in your MSCONFIG. check the available check box and click ok.
now you should be good to go, you might need to change your internet settings in internet explorer. Connect to the Internet and go to the page that you want to set as your home page.
Click Tools, and then click Internet Options.
In the Home page section of the General tab, click Use Current, and then click OK.now you need to turn your system restore back on.
Turn on your system restore.
Click Start.
Right-click My Computer, and then click Properties.
Click the System Restore tab.
Clear the "Turn off System Restore" or "Turn off System Restore on all drives" check box.
Click Apply, and then click OK

For some reason html coding go stuck in my first part of my message/instructions so here is how to turn off the system restore.
Click Start.
Right-click My Computer, and then click Properties.
Click the System Restore tab.
Select "Turn off System Restore" or "Turn off System Restore on all drives" check box
Click Apply.
As noted in the message, this will delete all existing restore points. Click Yes to do this.
Click OK.
Proceed with my instructions below.

Anyone still having problems? I was until about 1 minute ago. http://www.spywareinfo.com/~merijn/files/cwshredder.zip
That should do it , it did it for me. Its a program written to fix this problem =)

NO NO NO !!!!
You have a hijacker virus.
read the following notes.
I was able to FINALLY get rid of a very sneaky trojan/hijacker/virus. It has something to do with http:/tooncomics.com/main/b1.php For me. But it couls be diff pages for you but resulst the sam. Anyways This virus was able to beat Spybot!! It could even reset BHO's that you lock inside spybot and reset the homeage after every reboot and add porn links to your favorites file!! Not only that but it runs IE in the background and visits porn Hosts/sites. This activity can only be seen in task manager. THE FIX;
Get HIJACKTHIS.exe and run it.
DELETE everything that hijackthis shows you that has tooncomics in it.
ESPECIALLY DELETE following files.
O4 - HKCU\..\Run: [iedll] C:\WINDOWS\iedll.exe
O4 - HKCU\..\Run: [loader] C:\WINDOWS\loader.exeAND this is where the virus actually hides. You can rename these files as .txt file and open them in notepad and see for yourself its all there.
C:\WINDOWS\iedll.exe
C:\WINDOWS\loader.exeGood luck !

Alright. I have searchdot.net as well, including times that it changes to search.com and allneedsearch and others.
I have done all the stuff listed above, dug through registry, changed stuff and deleted MSoffice.hta, to the dot. However i still have this damn bug. Unfortanitly now, not sure if it is from this, when i am online i am auto forwarded to various porn sites.
Can anyone offer sum help on removing this?

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |