Computing.Net > Forums > Windows XP > removing searchcentrix

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

removing searchcentrix

Reply to Message Icon

Name: SusanLong
Date: November 26, 2003 at 21:44:15 Pacific
OS: WINXP PRO
CPU/Ram: AMD Duron/256 mb
Comment:

How do I remove searchcentrix from my computer? I am a novice on computers



Sponsored Link
Ads by Google

Response Number 1
Name: Tom41
Date: November 26, 2003 at 21:48:46 Pacific
Reply:

Hi Susan,
Download 'Hijack This!'. Unzip, doubleclick HijackThis.exe, and hit "Scan".
When the scan is finished, click "Save Log", and copy and paste it in a reply.
HijackThis!


0

Response Number 2
Name: bobhome1941
Date: November 26, 2003 at 22:18:56 Pacific
Reply:

Hi
Download Ad-Aware delete everything it finds
Here

BOB


0

Response Number 3
Name: channa@swqlaw.com
Date: December 1, 2003 at 09:34:52 Pacific
Reply:

Logfile of HijackThis v1.97.7
Scan saved at 12:30:48 PM, on 12/1/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\eTrust\InoculateIT\InoRpc.exe
C:\Program Files\CA\eTrust\InoculateIT\InoRT.exe
C:\Program Files\CA\eTrust\InoculateIT\InoTask.exe
C:\WINDOWS\LogWatNT.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\ofps.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Nextel\Desktop Assistant\vdac.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\CA\eTrust\InoculateIT\realmon.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\CMEII\CMESys.exe
C:\PROGRA~1\eCopy\Desktop\PCLprint\mrmlnc32.exe
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\ScanSoft\OmniPagePro12.0\Opware12.exe
C:\PAPRPORT\pptd40nt.exe
C:\Program Files\Nextel\Desktop Assistant\vdac.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\RUNDLL32.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\E-Color\Colorific\hgcctl95.exe
C:\Program Files\E-Color\True Internet Color\TICIcon.exe
C:\Program Files\Intuit\QuickBooks Pro\Components\QBAgent\qbdagent2002.exe
C:\Palm\HOTSYNC.exe
C:\Program Files\PrecisionTime\PrecisionTime.exe
C:\Program Files\Date Manager\DateManager.exe
C:\Program Files\Acroprint\TimeStationPC Network\tsClientMenu.exe
C:\Program Files\Common Files\GMT\GMT.exe
C:\Program Files\Acroprint\TimeStationPC Network\tsmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\unzipped\hijackthis[1]\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchcentrix.com/sidecat.jsp?p=98567&id=1109001921681114
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://66.223.10.199/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.comcast.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchcentrix.com/sidecat.jsp?p=98567&id=1109001921681114
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast High-Speed Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http://HOMEBASE:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://swqlaw
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
O2 - BHO: (no name) - {000006B1-19B5-414A-849F-2A3C64AE6939} - C:\WINDOWS\bi.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-DFF7-EC6BF4D5FA7D} - C:\WINDOWS\gsim.dll
O2 - BHO: Hotbar - {B195B3B3-8A05-11D3-97A4-0004ACA6948E} - C:\Program Files\Hotbar\bin\4.2.14.0\HbHostIE.dll (file missing)
O3 - Toolbar: &Hotbar - {B195B3B3-8A05-11D3-97A4-0004ACA6948E} - C:\Program Files\Hotbar\bin\4.2.14.0\HbHostIE.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SystemTray] SysTray.exe
O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\Corel\WordPerfect Office 2002\Programs\QFSCHD100.exe"
O4 - HKLM\..\Run: [Realtime Monitor] "C:\Program Files\CA\eTrust\InoculateIT\realmon.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [hpppta] C:\Program Files\Hewlett-Packard\HP PrecisionScan\PrecisionScan Pro\hpppta.exe /ICON
O4 - HKLM\..\Run: [CMESys] "C:\Program Files\Common Files\CMEII\CMESys.exe"
O4 - HKLM\..\Run: [eCopy Desktop Printer Service] C:\PROGRA~1\eCopy\Desktop\PCLprint\mrmlnc32.exe
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [PaperPort] C:\PAPRPORT\runppdrv.exe
O4 - HKLM\..\Run: [Opware12] "C:\Program Files\ScanSoft\OmniPagePro12.0\Opware12.exe"
O4 - HKLM\..\Run: [PaperPort PTD] C:\PAPRPORT\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\PAPRPORT\IndexSearch.exe
O4 - HKLM\..\Run: [Hotbar] C:\Program Files\Hotbar\bin\4.2.14.0\HbInst.exe /Upgrade
O4 - HKLM\..\Run: [DesktopAssistant] "C:\Program Files\Nextel\Desktop Assistant\vdac.exe" /client /tray
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Belt] C:\WINDOWS\Belt.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Microsoft Works Update Detection] ???????\WkDetect.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.exe C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Startup: HotSync Manager.LNK = C:\Palm\HOTSYNC.exe
O4 - Global Startup: Instant Update Reminder.lnk = C:\Program Files\U.S. Robotics\ControlCenter\Reminder.exe
O4 - Global Startup: Aveo Attune.lnk = ?
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: SonnReg.lnk = C:\Program Files\E-Color\Colorific\Colorific.exe
O4 - Global Startup: Colorific.lnk = C:\Program Files\E-Color\Colorific\hgcctl95.exe
O4 - Global Startup: True Internet Color Icon.lnk = C:\PROGRA~1\E-COLOR\TRUEIN~1\TICICON.exe
O4 - Global Startup: CorelCENTRAL 10.lnk = ?
O4 - Global Startup: Firewall Client Connectivity Monitor.LNK = C:\Program Files\Microsoft Firewall Client\ISATRAY.exe
O4 - Global Startup: QuickBooks 2002 Delivery Agent.lnk = C:\Program Files\Intuit\QuickBooks Pro\Components\QBAgent\qbdagent2002.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.exe
O4 - Global Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\PrecisionTime.exe
O4 - Global Startup: Date Manager.lnk = C:\Program Files\Date Manager\DateManager.exe
O4 - Global Startup: Configuration Utility.lnk = C:\Program Files\Linksys\Configure Utility\Config.exe
O4 - Global Startup: TimeStationPC Client Menu.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.exe
O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
O9 - Extra button: Net2Phone (HKLM)
O9 - Extra 'Tools' menuitem: Net2Phone (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .jpg: C:\Program Files\Internet Explorer\Plugins\NP_PRIZM32P.dll
O12 - Plugin for .lst: C:\Program Files\Internet Explorer\Plugins\NP_PRIZM32P.dll
O12 - Plugin for .pzm: C:\Program Files\Internet Explorer\Plugins\npPrizmPrint.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O15 - Trusted Zone: www.swqlaw.com
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=Compaq
O16 - DPF: {0B391518-327A-4F0B-B45C-2E3A818B0620} - http://66.159.131.40/SIinside/search/install/install.cab
O16 - DPF: {10000273-8230-4DD4-BE4F-6889D1E74167} - http://download.abetterinternet.com/download/cabs/TUR38106/turbo.cab
O16 - DPF: {20000273-8230-4DD4-BE4F-6889D1E74167} - http://download.abetterinternet.com/download/cabs/TUR38106/payload2.cab
O16 - DPF: {30000273-8230-4DD4-BE4F-6889D1E74167} - http://download2.abetterinternet.com/download/cabs/FON19106/flash.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37418.4254861111
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = swqlaw.com
O17 - HKLM\Software\..\Telephony: DomainName = swqlaw.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = swqlaw.com


0

Response Number 4
Name: Toureng
Date: December 10, 2003 at 10:06:47 Pacific
Reply:

There are a few steps you should take before having your log looked at again. I'm not sure about most of this, but I do know the following need to be 'checked' then fixed.

O16 - DPF: {10000273-8230-4DD4-BE4F-6889D1E74167} - http://download.abetterinternet.com/download/cabs/TUR38106/turbo.cab
O16 - DPF: {20000273-8230-4DD4-BE4F-6889D1E74167} - http://download.abetterinternet.com/download/cabs/TUR38106/payload2.cab
O16 - DPF: {30000273-8230-4DD4-BE4F-6889D1E74167} - http://download2.abetterinternet.com/download/cabs/FON19106/flash.cab

Also, before one the the experts here goes through this log, you should download Ad Aware and/or Spybot Search & Destroy. Download the most recent updates, scan and remove anything either find. Once this is done, then scan with Hijack again, and post your much cleaner log. The rest will be up to the experts. Sorry for not being of much help.

Good Luck


0

Response Number 5
Name: krazybaddude
Date: December 25, 2003 at 21:53:19 Pacific
Reply:

Hi guys,

I now have been trying to remove searchcentrix for about 4 days now to no avail. I run AVG, AdAware, Spybot S&D, HijackThis (removed the entries). No mattter what i do IT KEEPS COMING BACK!!!!

The thing that really made me mad was the fact that i manually deleted the registry keys for searchcentrix, and every time i refresh (f5), they are back again!!!!!!!!!!

GRRRR ..........Can anyone help .... PLEASE, im getting SOOO frustrated!


0

Related Posts

See More



Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows XP Forum Home


Sponsored links

Ads by Google


Results for: removing searchcentrix

Removing Read Only Access www.computing.net/answers/windows-xp/removing-read-only-access-/3837.html

dwwin removal www.computing.net/answers/windows-xp/dwwin-removal/85139.html

unable to open add/remove programs www.computing.net/answers/windows-xp/unable-to-open-addremove-programs/134485.html