View Full Version : Spyware that I can't get rid of
I've tried a few different removal tools and can't seem to remove it.
On my taskbar, "Search the Web" search bar. I can turn it off but can't find anywhere to remove it and none of the stuff I try, spybot, spyhunter, etc. seem to get rid of it.
It too is getting on my nerves. ideas?
I had a similar problem with a PC in my office and I tried anything .. i even tried to delete it from the registry myself with no luck. You might have some corrupted dlls which generate that plug-in everytime you load IE
2 options:
- Either install Mozilla or Netscape
- Re-format computer
Reformatting should be your last resort, of course. There's a good source for spyware removal tools at http://www.spywareinfo.com/~merijn/downloads.html
If Ad-Aware and Spybot don't do the trick, try CWShredder for sure. The site above should have some additional advice for choosing a tool by the symptoms you experience. Good luck!
I hate when people do this and I've deleted the items I do recognize; perhaps an additional set of eyes looking over the list may spot the issue.
Hijack report:
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\carpserv.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\WindowsSA\omniscient.exe
F2 - REG:system.ini: UserInit=C:\Windows\System32\wsaupdater.exe,
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Popup Manager - {08E74C67-99A6-45C7-94DA-A397A8FD8082} - (no file)
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINDOWS\2_0_1browserhelper2.dll
O2 - BHO: (no name) - {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} - (no file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [Belt] C:\WINDOWS\Belt.exe
O4 - HKLM\..\Run: [bcmwltry] bcmwltry.exe
O4 - HKLM\..\Run: [RemoveCpl] RemoveCpl.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [Windows SA] C:\Program Files\WindowsSA\omniscient.exe
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\System32\sti_ci.dll,WiaCreateWizardMenu
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: ICQ Pro (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: {60EFC337-15C2-4369-B2A0-3429B071D8B8} (WebProgramManager Class) - http://isupport4.hp.com/awebui/jsp/answerweb/applets/HPISWebManager.CAB
O16 - DPF: {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} - http://www2.flingstone.com/cab/2000XP/bridge-c1.cab
or you can run Mozilla and dump IE like I did a few months back. I got tired of IE always getting hijacked and decided to try Mozilla, works great and never looked back
Croc Hunter
6-4-04, 04:49 AM
It's on the taskbar.. Did you run CW Shredder Skunk?
yes I ran cwshredder :( still no luck.
I'm one of the crazy people who puts their taskbar up top - here's a screen shot of what I've got:
Hi,
Here's another vote for the Mozilla (http://www.mozilla.org/) Browsers, they are great. I use Mozilla Firefox (http://www.mozilla.org/products/firefox/) and enjoy the tabbed browsing, great pop-up add blocking, and never getting adware taking over the browser. :D
-Nick
Firefox is a great browser but the thing that I've got the issues with doesn't show in the browser, its on my main taskbar - which is startin' to drive me crazy.
Hmm... so it's one of those nice little trojans for Windows :rolleyes:.
Well then I don't have much more to suggest than what's already been mentioned, as my experience with them usually lead me to just reinstalling Windows (which was always a pain in the a$$). Oh and I'm speaking in past tense because I use Linux, in which this sort of situation doesn't occur. :D
Hi,
After looking at your picture above again, I checked out my brother's laptop (which to my dismay has Windows XP on it), and noticed that you can place a web address bar on the taskbar by right-clicking on the taskbar, selecting theToolbars menu, then clicking on Address. The bar that showed up on the taskbar looked like the same one you have.
Although this seems like too easy of a solution to me, so just ignore this if you already checked to see if that optional toolbar is turned on or not :D
right, I knew about that :) but its actually listed as "Search Assistant" in the toolbars section.
I've got 4gig available on a 40gig hard drive :( and no way to back up all of it. I can't afford to reformat... especially due to a 12gig video file (uncompressed avi - yes.)
here are the ones I would delete.
F2 - REG:system.ini: UserInit=C:\Windows\System32\wsaupdater.exe,
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINDOWS\2_0_1browserhelper2.dll
O2 - BHO: (no name) - {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [Belt] C:\WINDOWS\Belt.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [Windows SA] C:\Program Files\WindowsSA\omniscient.exe
if you don't have wireless running delete this these too
O4 - HKLM\..\Run: [RemoveCpl] RemoveCpl.exe
O4 - HKLM\..\Run: [bcmwltry] bcmwltry.exe
hope that helps some.
actually no, but I have seen it. long time ago.
I suppose that is one of the characters name?
Skunkboy
7-26-04, 12:35 PM
FINALLY!!!
After searching for how to remove BlazeFind Search Assistant, trying everything I could find as far as removing files, removing reg keys, etc... I finally found it stated to Add/Remove Programs - "Windows SA"
Gone! Clean - FINALLY! :D
Upgraded to SpyBot 1.3 and ran to remove several items. Also found SpySweeper which did remove all the remaining and has an option to keep my home page locked on my favorite. Though SpySweeper can be bought/registered, they do have a free download which will work well enough to remove stuff
vBulletin v3.6.0, Copyright ©2000-2009, Jelsoft Enterprises Ltd.