Search feature hijacked

P

Paul W

My IE6 browser's search feature has been hijacked by
something called "Quick Search". When I go to reset the
search options, the customize radio button is disabled.
I can go to <Internet Options>, <Program Tab>, <Reset to
IE Default> and I see the standard search bar again, but
only for a minute, then it resets back to "Quick
Seach"(which is a very limited search tool). All I can
find out about the program source is that is is from a
place called: seekseek.com

How can I get rid of this search program that's taken-
over my IE search feature?

Thanks
 
J

Jim Byrd

Hi Paul - Download and run:
http://www.kellys-korner-xp.com/regs_edits/RestoreSearch2.REG to restore
your search functions.

Note that this symptom often indicates the possibility of other malware.
You might want go to this page at Jim Eshelman's site, here:
http://aumha.org/a/noads.htm and wait a little bit (be patient), while an
analysis of a number of possible parasites on your machine will be made to
help you identify and remove them. NOTE: You will need to disable Ad
Blocking in Zone Alarm 3.x, if present or any other Ad Blocking software
which interferes with Java Scripting for this scan to work. You should get
a message between the two lines of **** giving the results of the scan.

For the general hijack case, the best way to start is to get Ad-Aware 6.0,
Build 181 or later, here: http://www.lavasoftusa.com/support/download/.
UPDATE and run this regularly to get rid of most "spyware/hijackware" on
your machine. If it has to fix things, be sure to re-boot and rerun
AdAware again and repeat this cycle until you get a clean scan. The reason
is that it may have to remove things which are currently "in use" before it
can then clean up others.

Another excellent program for this purpose is SpyBot Search and Destroy
available here: http://security.kolla.de/ SpyBot Support Forum here:
http://www.net-integration.net/cgi-bin/forums/ikonboard.cgi. I recommend
using both normally. After UPDATING and fixing things with SpyBot S&D, be
sure to re-boot and rerun SpyBot again and repeat this cycle until you get a
clean "no red" scan. The reason is that SpyBot sometimes has to remove
things which are currently "in use" before it can then clean up others.


Note that sometimes you need to make a judgement call about what these
programs report as spyware. See here, for example:
http://www.imilly.com/alexa.htm


A currently common parasite which can cause this symptom is some malware
called CoolWebSearch. Do the following:

Download and run: http://www.merijn.org/files/cwshredder.zip to remove the
parasite. Be sure to close all instances of IE and OE. Always download a
new copy of this application, as it is updated almost daily.,

Then download and run:
http://www.kellys-korner-xp.com/regs_edits/iegentabs.reg to restore your
tabs and remove any restrictions that the parasite has put in place.

Be sure that you also download and install hotfix Q816093, here:

http://support.microsoft.com/?kbid=816093

which blocks the exploit upon which this parasite family depends.


Once you get things cleaned up, you might want to consider installing the
SpywareBlaster and SpywareGuard here to help prevent this kind of thing from
happening in the future:
http://www.javacoolsoftware.com/spywareblaster.html (Prevents malware Active
X installs) (BTW, SpyWare Blaster is not memory resident ... no CPU or
memory load - but keep it UPDATED) The latest version as of this writing
will prevent installation or prevent the malware from running if it is
already installed, and it provides information and fixit-links for a variety
of parasites.
http://www.wilderssecurity.net/spywareguard.html (Monitors for attempts to
install malware) Keep it UPDATED. Both Very Highly Recommended.


--
Please respond in the same thread.
Regards, Jim Byrd, MS-MVP



In
 
S

Scott

Hi Paul - Download and run:
http://www.kellys-korner-xp.com/regs_edits/RestoreSearch2.REG to restore
your search functions.

Note that this symptom often indicates the possibility of other malware.
You might want go to this page at Jim Eshelman's site, here:
http://aumha.org/a/noads.htm and wait a little bit (be patient), while an
analysis of a number of possible parasites on your machine will be made to
help you identify and remove them. NOTE: You will need to disable Ad
Blocking in Zone Alarm 3.x, if present or any other Ad Blocking software
which interferes with Java Scripting for this scan to work. You should get
a message between the two lines of **** giving the results of the scan.

For the general hijack case, the best way to start is to get Ad-Aware 6.0,
Build 181 or later, here: http://www.lavasoftusa.com/support/download/.
UPDATE and run this regularly to get rid of most "spyware/hijackware" on
your machine. If it has to fix things, be sure to re-boot and rerun
AdAware again and repeat this cycle until you get a clean scan. The reason
is that it may have to remove things which are currently "in use" before it
can then clean up others.

Another excellent program for this purpose is SpyBot Search and Destroy
available here: http://security.kolla.de/ SpyBot Support Forum here:
http://www.net-integration.net/cgi-bin/forums/ikonboard.cgi. I recommend
using both normally. After UPDATING and fixing things with SpyBot S&D, be
sure to re-boot and rerun SpyBot again and repeat this cycle until you get a
clean "no red" scan. The reason is that SpyBot sometimes has to remove
things which are currently "in use" before it can then clean up others.


Note that sometimes you need to make a judgement call about what these
programs report as spyware. See here, for example:
http://www.imilly.com/alexa.htm


A currently common parasite which can cause this symptom is some malware
called CoolWebSearch. Do the following:

Download and run: http://www.merijn.org/files/cwshredder.zip to remove the
parasite. Be sure to close all instances of IE and OE. Always download a
new copy of this application, as it is updated almost daily.,

Then download and run:
http://www.kellys-korner-xp.com/regs_edits/iegentabs.reg to restore your
tabs and remove any restrictions that the parasite has put in place.

Be sure that you also download and install hotfix Q816093, here:

http://support.microsoft.com/?kbid=816093

which blocks the exploit upon which this parasite family depends.


Once you get things cleaned up, you might want to consider installing the
SpywareBlaster and SpywareGuard here to help prevent this kind of thing from
happening in the future:
http://www.javacoolsoftware.com/spywareblaster.html (Prevents malware Active
X installs) (BTW, SpyWare Blaster is not memory resident ... no CPU or
memory load - but keep it UPDATED) The latest version as of this writing
will prevent installation or prevent the malware from running if it is
already installed, and it provides information and fixit-links for a variety
of parasites.
http://www.wilderssecurity.net/spywareguard.html (Monitors for attempts to
install malware) Keep it UPDATED. Both Very Highly Recommended.
I wanted to thank you for your tip on the .reg file! That cured my problem
with searching as well!
 
J

Jim Byrd

YW, Scott - Glad it helped. You may want to check out the other stuff also.
:)

--
Please respond in the same thread.
Regards, Jim Byrd, MS-MVP



In
 
S

siljaline

Paul W said:
My IE6 browser's search feature has been hijacked by
something called "Quick Search". When I go to reset the
search options, the customize radio button is disabled.
I can go to <Internet Options>, <Program Tab>, <Reset to
IE Default> and I see the standard search bar again, but
only for a minute, then it resets back to "Quick
Seach"(which is a very limited search tool). All I can
find out about the program source is that is is from a
place called: seekseek.com

How can I get rid of this search program that's taken-
over my IE search feature?

Thanks

http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=ADW_SCANPORTAL.A

HTH
~Silj

--
siljaline

MS MVP - Windows (IE/OE)
________________________
Anti-Parasite Definition Updates
http://forum.aumha.org/viewforum.php?f=31

(Reply to group, as return address
is invalid - that we may all benefit)
 
S

Scott

YW, Scott - Glad it helped. You may want to check out the other stuff also.
:)
Oh I did that too. I always keep ad-aware and spybot up to date and run
them daily. I'm thinking of upgrading and using ad-watch. I've also gone
through and locked down some of the more vulnerable IE settings.
:)
 
G

Gary

Paul - if someone provides you with a solution could you
email it to me. I posted a similar problem. I'm not at
my home computer so I don't know if it is the exact same
hijacker as you but the outcome sounds identical.

my email is (e-mail address removed)

thanks
 
J

Jim Byrd

Hi Gary - This fixed things for Paul.

Download and run:
http://www.kellys-korner-xp.com/regs_edits/RestoreSearch2.REG to restore
your search functions.

Note that this symptom often indicates the possibility of other malware.
You might want go to this page at Jim Eshelman's site, here:
http://aumha.org/a/noads.htm and wait a little bit (be patient), while an
analysis of a number of possible parasites on your machine will be made to
help you identify and remove them. NOTE: You will need to disable Ad
Blocking in Zone Alarm 3.x, if present or any other Ad Blocking software
which interferes with Java Scripting for this scan to work. You should get
a message between the two lines of **** giving the results of the scan.

For the general hijack case, the best way to start is to get Ad-Aware 6.0,
Build 181 or later, here: http://www.lavasoftusa.com/support/download/.
UPDATE and run this regularly to get rid of most "spyware/hijackware" on
your machine. If it has to fix things, be sure to re-boot and rerun
AdAware again and repeat this cycle until you get a clean scan. The reason
is that it may have to remove things which are currently "in use" before it
can then clean up others.

Another excellent program for this purpose is SpyBot Search and Destroy
available here: http://security.kolla.de/ SpyBot Support Forum here:
http://www.net-integration.net/cgi-bin/forums/ikonboard.cgi. I recommend
using both normally. After UPDATING and fixing things with SpyBot S&D, be
sure to re-boot and rerun SpyBot again and repeat this cycle until you get a
clean "no red" scan. The reason is that SpyBot sometimes has to remove
things which are currently "in use" before it can then clean up others.


Note that sometimes you need to make a judgement call about what these
programs report as spyware. See here, for example:
http://www.imilly.com/alexa.htm


A currently common parasite which can cause this symptom is some malware
called CoolWebSearch. Do the following:

Download and run: http://www.merijn.org/files/cwshredder.zip to remove the
parasite. Be sure to close all instances of IE and OE. Always download a
new copy of this application, as it is updated almost daily.,

Then download and run:
http://www.kellys-korner-xp.com/regs_edits/iegentabs.reg to restore your
tabs and remove any restrictions that the parasite has put in place.

Be sure that you also download and install hotfix Q816093, here:

http://support.microsoft.com/?kbid=816093

which blocks the exploit upon which this parasite family depends.


Once you get things cleaned up, you might want to consider installing the
SpywareBlaster and SpywareGuard here to help prevent this kind of thing from
happening in the future:
http://www.javacoolsoftware.com/spywareblaster.html (Prevents malware Active
X installs) (BTW, SpyWare Blaster is not memory resident ... no CPU or
memory load - but keep it UPDATED) The latest version as of this writing
will prevent installation or prevent the malware from running if it is
already installed, and it provides information and fixit-links for a variety
of parasites.
http://www.wilderssecurity.net/spywareguard.html (Monitors for attempts to
install malware) Keep it UPDATED. Both Very Highly Recommended.


--
Please respond in the same thread.
Regards, Jim Byrd, MS-MVP



In
 
G

Guest

Just wanted to say thanks for the link for the fix for the search bar. I have spent about 4-5 hours yesterday and today trying to clean and fix my PC, but still couldn't get the search function back until I read your post and tried the fix. It worked

Thanks

Lynne
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads


Top