Can someone pls help me out...
I tried running Ad-aware, Spybot S&D, Spy Sweeper, even MS antispyware, but to no avail... :sad:
The IE home page still changes back to the damn searchingall.com...
Not just that, everytime I open a new webpage, that damn thing automatically creates whole lot of internet shortcuts on my desktop, and the quicklink bar, taking random keywords from the website opened. :(

Can someone point me to a way to permanently remove this bugger WITHOUT formatting and reinstalling the system... :confused:

Dani AI

Generated

Good to see the problem was solved — thanks to for confirming KillBox removed the active component, and to for recommending thorough scanning. A couple of quick follow-up checks will confirm the machine is truly clean and reduce the chance of reinfection.

Verify these items now: check the IE shortcut Target for any appended URL (remove if present); examine proxy settings (Internet Options → Connections → LAN settings) to ensure no proxy is set; open the hosts file at C:\Windows\System32\drivers\etc\hosts and remove unexpected entries; look in the Startup folders and the registry Run/RunOnce keys (HKCU\Software\Microsoft\Windows\CurrentVersion\Run and the HKLM equivalents) for unfamiliar entries. Inspect HKCU\Software\Microsoft\Internet Explorer\Main (and the HKLM mirror) for Start Page/Search values and export any key before editing. Use a tool that shows drivers, services, BHOs and scheduled tasks to find leftovers.

A recommended next step is a second-opinion scan and an autorun inspection. Autoruns (Sysinternals) is useful for spotting persistent startup hooks and shell extensions. Also: temporarily disable System Restore and delete old restore points (malware can hide there), then re-enable and create a clean restore point. Reset Internet Explorer settings and clear temp files and cookies. After cleaning, change web passwords (especially if logins were used while infected) and update Windows, browser and plugins.

If unexpected redirects, recreated shortcuts, or unknown scheduled tasks persist after these checks, post detailed startup/autorun logs to a malware-help forum or consider a fresh install as a last resort. Always back up important data first and avoid running as an administrator for daily use to limit future hijacker impact.

Recommended Answers

All 2 Replies

Hi,
Download and install it. Then run, you will receive a warning message saying "Database not found", click "OK" for this. Next in the main screen, click "Update" and click "Start Update".
After the update process, click on the "Scanner" button in the left menu, then click on the "Complete System Scan" button.
If ewido finds anything, it will pop up a notification. You can select "Clean" and check the boxes "Perform action with all infections" and "Create encrypted backup" before clicking on OK.
When the scan finishes, click on "Save Report". This will create a text file.


Download HijackThis and unzip it to dedicated folder (like C:\HijackThisFolder\hijackthis.exe).
Then run it and click the button Do a System scan and save log file. HijackThis will perform a scan and saves the log file as hijackthis.log in the same folder where it is installed and it also opens the file automatically.
Copy the entire contents of the file and post it here, along with the Ewido log.

Hello Swatcat,
Thanks a lot for your advice. I really appreciate it.
Well, in the meanwhile, after I logged this msg here, I just happenned to stumble upon another page
:cool:
The tool used there is Pocket Killbox version , and it actually worked like charm...
After 2 restarts, my machine is finally free of that bugger hijacker...

But anyway, thanks again for your kind gesture, Swatcat! :D

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.