Topsearch10 still won't let go

B

benice

I DL'd Microsoft Antispyware Beta1 while my system was
infected with a browser hijacker that appears to be
called Topsearch10. It's a nasty program that includes
placing inappropriate links in my favorites and
redirecting all my searches. I can tell that Microsoft's
Antispyware Beta1 is trying to deal with the browser
hijack attempts but it didn't recognize the program in
the deep scan, nor does it seem to be recognizing that
everytime I delete the links it placed in my favorites,
they keep returning immediately. I DL'd this program to
try to contend with this spyware/hijacker but it has only
been mildly successful. Any input about ridding myself of
this pest would be greatly appreciated! I have tried
running Hijackthis, Spybot Search & Destroy, Bazooka,
Spyware Doctor, Adaware SE, and my own tricks using safe
mode but nothing has been completely successful.
 
A

AndyManchesta

Hi Mate Its tricky if you have tried everything in safe
mode but will try help if i can.If you have service pack
2 installed first open a internet window and go to tools
the check the manage add ons page and check in there for
any suspicious entries,disable any you know you havent
intentionally installed.Then download both of these if
you dont already have them

CCleaner (removes unused and temporary files from your
system)

http://majorgeeks.com/downloadget.php?
id=4191&file=11&evp=a12d758b021af1a4f0a6bfe45b0c7a82


CWShredder (Unrelated to your problem but well worth
having)

http://cwshredder.net/bin/CWShredder.exe


Then reboot into safe mode and follow these advise tips
before doing anything else:

ALWAYS do these when trying to remove a bug.

First: Turn off Windows XP System Restore (Start,Right
click my computer,Properties,then system restore and
disable and apply)

Next: Show hidden files and folders. (Start,Search,Then
tools at the top bar,choose folder options then go to the
second page View,and tick show hidden files and folders)

Next: Delete Temp Internet files :
Open a internet browser window, click Tools then Internet
Options.
Click on the Delete Cookies and the Delete Files buttons,
then click OK and close the browser window.

Next: Close all open internet browser windows.

Next: Delete Windows Temporary Files - (start,run then
type %temp% delete all files you can in this folder
The Windows temporary directory (usually located at
C:\windows\temp).
This directory should not be confused with the Internet
Explorer "Temporary Internet Files Directory".
The Windows temporary directory stores temporary files
that are used during installation of programs and at
other various times.
Cleaning this directory regularly is generally a good
idea.

Start by scanning again with MS antispy,Adaware,Spybot
all in safe mode with the system restore off then reboot
and see if its gone if not then carry on with these:

Manual Removal

Follow these steps to remove TopSearch from your
machine. Begin by backing up your registry and your
system, and/or setting a Restore Point, to prevent
trouble if you make a mistake.

Stop Running Processes:

Kill these running processes with Task Manager:

points manager.exe
programfilesdir+\altnet\download manager\adm4005.exe

Go to start then Run and type in msconfig. Then select
the startup tab.

End These Processes if found

kazaa.exe
mmod.exe
pgmonitr.exe
topsearch.dll
adm.exe

Now reboot and go back to safe mode :


UnRegister DLLs
You can use the Regsvr32 tool (Regsvr32.exe) to register
and unregister object linking and embedding (OLE)
controls such as dynamic-link library (DLL) or ActiveX
Controls (OCX) files that are self-registerable.

RegSvr32.exe has the following command-line options:

Regsvr32 [/u] [/n] [/i[:cmdline]] dllname

/u - Unregister server<BR/>
/i - Call DllInstall passing it an optional [cmdline];
when used with /u calls dll uninstall
/n - do not call DllRegisterServer; this option must be
used with /i

When you use Regsvr32.exe, it attempts to load the
component and call its DLLSelfRegister function. If this
attempt is successful, Regsvr32.exe displays a dialog
indicating success. If the attempt is unsuccessful,
Regsvr32.exe returns an error message, which may include
a Win32 error code.

Example: To unregister Winshow's winshow.dll:

Click the Start button, and select Run
Enter this command line:
regsvr32 /u [systemroot]\winshow.dll (Only a example)

Unregister these .dlls then reboot

asmps.dll
programfilesdir+\altnet\points manager\sysdetect.dll
programfilesdir+\kazaa lite\topsearch.dll
programfilesdir+\kazaa\topsearch.dll

Clean Registry:

Most applications, including pests you want to remove,
will modify the registry in some way, adding their own
entries and changing some previous entries. Complete
removal of an application includes registry edits.

The registry can be edited with regedit(Start > Run >
type regedit )

Remove these registry items (if present) with RegEdit:

HKEY_CURRENT_USER\software\microsoft\internet
explorer\toolbar\webbrowser\{6ad2f325-2f86-473e-908f-
9d4d30698a62}
HKEY_LOCAL_MACHINE\software\microsoft\internet
explorer\toolbar\{6ad2f325-2f86-473e-908f-9d4d30698a62}

Remove Files:

Either search or use Windows explorer

Go to search > then tools at the top bar > then folder
options > go to the second page which is view then make
sure there is a tick next to 'show all files and folders'

Remove these files (if present) with Windows Explorer:

asmps.dll
peer points manager.lnk
points manager.exe
points manager.exe-33e92ffa.pf
programfilesdir+\altnet\download manager\adm4005.exe
programfilesdir+\altnet\points
manager\localpages\altnet.css
programfilesdir+\altnet\points
manager\localpages\local_firstuse.html
programfilesdir+\altnet\points
manager\localpages\local_points.html
programfilesdir+\altnet\points
manager\localpages\local_redeem.html
programfilesdir+\altnet\points
manager\localpages\local_start.html
programfilesdir+\altnet\points
manager\localpages\local_wallet.html
programfilesdir+\altnet\points manager\sysdetect.dll
programfilesdir+\kazaa lite\topsearch.dll
programfilesdir+\kazaa\topsearch.dll



Remove Directories:

Remove these directories (if present) with Windows
Explorer:

profilepath+\start menu\programs\altnet
programfilesdir+\altnet
programfilesdir+\altnet\points manager\localpages
programfilesdir+\altnet\points manager\skin
systemroot+\temp\altnet

Then finally run Ccleaner and follow the onscreen promts
to remove all unused files and temp files

Then switch system restore back on

You can also use Spyware Blaster to help prevent more
attacks it runs in the background and blocks blacklisted
sites in the same way the spybot Search & Destroys
Immunize part does

SpywareBlaster

http://majorgeeks.com/downloadget.php?
id=2859&file=11&evp=61b0e8ad41924a03c37615f4682b4cef

Regards

Andy







Regards Andy
 
A

AndyManchesta

I noticed a slight mistake in my last post,When searching
for files just make sure there is a tick next to 'show
hidden files and folders' I put 'all files and folders'
in my original mail plus signed it twice but apart from
that everything else should be correct and if you need
anymore help just repost and i will help where i can mate

Good Luck Andy
 
I

Ivan

hey, I'm having the same problem too, only mine is called
CoolWebSearch. I've got an anti-spyware program called
xoftspy that removed every spyware on my system except
this one.

I asked them and they said that no anti-spyware is
currently able to delete this type of spyware. Xoftspy
keep detecting it but everytime i run it and delete it,
it keeps popping back. They said that it has a 'variant'
that keeps changing (I have no idea what variant
means...). Ppl at xoftspy are still working on it.

Anyway, one thing for sure you can do is FORMAT....
ahhh....that never fails.... =)

PS: Hijackthis is a great tool if you know what files you
need to delete.
 
R

Ron Chamberlin

Hi Ivan,
If it's CWS, then boot from safe mode (f*8) and try it from there. Should
that fail, Google for CWShredder.

Ron Chamberlin
MS-MVP
 
P

plun

Ron said:
Hi Ivan,
If it's CWS, then boot from safe mode (f*8) and try it from there. Should
that fail, Google for CWShredder.

For both of this "pests" I recommend a antispyware forum
with guidance.

Download Adaware and try first.

http://www.download.com/Ad-aware-SE-Personal-Edition/3000-8022_4-10045910.html?tag=prod

Dont forget "Check for updates"


If this doesnt work, go to Lavasofts forum, they will help you.
http://www.lavasoftsupport.com/index.php?showforum=120

Settings for correct logfiles if needed:
http://www.lavasoftsupport.com/index.php?showtopic=48134
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top