shawn_mck
asked on
mysearchnow
how do i get rid of the mysearchnow and other toolbars in internet explorer
you can go to control panel --> add/remove programs and remove "mysearchnow" there
Sunray
Sunray
hey guys.. pretty slow on EE tonight, eh? Looks like this one is under control. Think I will head off to bed.
FE
FE
ASKER
when i go to my internet explorer and click view > toolbars... it has the standard list of toolbars and one which is titled "rfglglqucho".
I uninstalled msg plus and i ran spybot but the bar is still there.
I uninstalled msg plus and i ran spybot but the bar is still there.
Fatal_Exception,
Hey I was just playing ping-pong for an hr and just coming now. Yeah everything is damn slow today . I believe questioners and experts have gone out of town on vacation. But I wont be .. LOL!!!
Thanks,
Sunray
Hey I was just playing ping-pong for an hr and just coming now. Yeah everything is damn slow today . I believe questioners and experts have gone out of town on vacation. But I wont be .. LOL!!!
Thanks,
Sunray
Hey I have got this error once. Go to start --> run --> type "regedit"
registry will open
press ctrl + F ( search window will open)
give the term "rfglglqucho" and search for it. If you find , delete that key.
Once you do one search , delete it and then press F3 and it will look for the same word in another location
Surnay
registry will open
press ctrl + F ( search window will open)
give the term "rfglglqucho" and search for it. If you find , delete that key.
Once you do one search , delete it and then press F3 and it will look for the same word in another location
Surnay
shawn_mck,
Also download and run this tool
HijackThis : http://www.webattack.com/download/dlhijackthis.shtml
and post us the log file it creates
Thanks,
Sunray
Also download and run this tool
HijackThis : http://www.webattack.com/download/dlhijackthis.shtml
and post us the log file it creates
Thanks,
Sunray
You are a diehard Sunray.... Going to leave it with you.
Think I will pick up my MCSE books and let them put me to sleep.
G'nite all.
FE
Think I will pick up my MCSE books and let them put me to sleep.
G'nite all.
FE
>> You are a diehard Sunray
Excellant comment that I have got in a while.. Thanks ..
I will be going to bed with " Your memory - How it works and how to improve it ".. Looks pretty good ..
Sunray
Excellant comment that I have got in a while.. Thanks ..
I will be going to bed with " Your memory - How it works and how to improve it ".. Looks pretty good ..
Sunray
shawn_mck,
Hey did you check Hijackthis..
or go to registry and look for mysearch at this location
"R1 - HKLM\Software\Microsoft\In ternet Explorer\Main,Search Bar = http://mysearchnow.com/searchbar.html "
Thanks,
Sunray
Hey did you check Hijackthis..
or go to registry and look for mysearch at this location
"R1 - HKLM\Software\Microsoft\In
Thanks,
Sunray
ASKER
Running processes:
C:\WINDOWS\System32\smss.e xe
C:\WINDOWS\system32\winlog on.exe
C:\WINDOWS\system32\servic es.exe
C:\WINDOWS\system32\lsass. exe
C:\WINDOWS\system32\svchos t.exe
C:\WINDOWS\System32\svchos t.exe
C:\WINDOWS\system32\spools v.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tf swctrl.exe
C:\WINDOWS\System32\DSentr y.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Real\RealPlayer\Real Play.exe
C:\program files\mcafee.com\vso\mcvss hld.exe
C:\Program Files\Common Files\Dell\EUSW\Support.ex e
c:\PROGRA~1\mcafee.com\vso \mcvsrte.e xe
C:\WINDOWS\System32\nvsvc3 2.exe
c:\PROGRA~1\mcafee.com\vso \mcshield. exe
C:\WINDOWS\system32\winlog on.exe
C:\WINDOWS\system32\winlog on.exe
C:\WINDOWS\System32\svchos t.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\FaT-TaY SCRiPT\FaT-TaY SCRiPT.exe
C:\Program Files\Kazaa Lite K++\KazaaLite.kpp
C:\WINDOWS\regedit.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\WINZIP\winzip3 2.exe
C:\Documents and Settings\FaT\Local Settings\Temp\HijackThis.e xe
R1 - HKCU\Software\Microsoft\In ternet Explorer\Main,Search Bar = http://mysearchnow.com/searchbar.html
R1 - HKCU\Software\Microsoft\In ternet Explorer\Main,Search Page = http://mysearchnow.com/searchbar.html
R1 - HKCU\Software\Microsoft\In ternet Explorer\Main,Default_Page _URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\In ternet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\In ternet Explorer\Main,Search Bar = http://mysearchnow.com/searchbar.html
R1 - HKLM\Software\Microsoft\In ternet Explorer\Main,Search Page = http://mysearchnow.com/searchbar.html
R1 - HKLM\Software\Microsoft\In ternet Explorer\Main,Default_Page _URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\In ternet Explorer\Search,SearchAssi stant = http://mysearchnow.com/searchbar.html
R1 - HKCU\Software\Microsoft\In ternet Connection Wizard,Shellnext = http://www.dell.com/
O2 - BHO: (no name) - {11ce0f27-85b9-45ed-b9c9-8 e081b63760 0} - C:\DOCUME~1\FaT\APPLIC~1\s tiblshstto u.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-0 00874180BB 3} - (no file)
O2 - BHO: (no name) - {5CA3D70E-1895-11CF-8E15-0 0123456789 0} - C:\WINDOWS\system32\dla\tf swshx.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-2 09B6AD74AC C} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0 0A0C908246 7} - C:\WINDOWS\System32\msdxm. ocx
O3 - Toolbar: (no name) - {2ab7a4d0-f738-4d80-b049-b 56ec3a9ca6 b} - C:\DOCUME~1\FaT\APPLIC~1\s tiblshstto u.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl. dll,NvStar tup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tf swctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentr y.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\Real Play.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vs o\mcmnhdlr .exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\age nt\mcagent .exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\age nt\McUpdat e.exe
O4 - HKLM\..\Run: [VirusScan Online] c:\program files\mcafee.com\vso\mcvss hld.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.ex e
O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
O4 - HKLM\..\Run: [McRegWiz] c:\PROGRA~1\mcafee.com\age nt\mcregwi z.exe /autorun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 - DPF: {74D05D43-3236-11D4-BDCD-0 0C04F9A3B6 1} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003120501/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4 DFAD1796A8 D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-4 7A8489BB47 F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37977.4044212963
O16 - DPF: {E4961D20-6367-4C75-BCF3-5 213C29A827 B} (llamapro) - https://www.pimpwar.com/crew/llamapro/llamapro.cab
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\spools
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tf
C:\WINDOWS\System32\DSentr
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Real\RealPlayer\Real
C:\program files\mcafee.com\vso\mcvss
C:\Program Files\Common Files\Dell\EUSW\Support.ex
c:\PROGRA~1\mcafee.com\vso
C:\WINDOWS\System32\nvsvc3
c:\PROGRA~1\mcafee.com\vso
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\winlog
C:\WINDOWS\System32\svchos
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\FaT-TaY SCRiPT\FaT-TaY SCRiPT.exe
C:\Program Files\Kazaa Lite K++\KazaaLite.kpp
C:\WINDOWS\regedit.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\WINZIP\winzip3
C:\Documents and Settings\FaT\Local Settings\Temp\HijackThis.e
R1 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
O2 - BHO: (no name) - {11ce0f27-85b9-45ed-b9c9-8
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-0
O2 - BHO: (no name) - {5CA3D70E-1895-11CF-8E15-0
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-2
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
O3 - Toolbar: (no name) - {2ab7a4d0-f738-4d80-b049-b
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tf
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentr
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\Real
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vs
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\age
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\age
O4 - HKLM\..\Run: [VirusScan Online] c:\program files\mcafee.com\vso\mcvss
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.ex
O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
O4 - HKLM\..\Run: [McRegWiz] c:\PROGRA~1\mcafee.com\age
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 - DPF: {74D05D43-3236-11D4-BDCD-0
O16 - DPF: {8E0D4DE5-3180-4024-A327-4
O16 - DPF: {9F1C11AA-197B-4942-BA54-4
O16 - DPF: {E4961D20-6367-4C75-BCF3-5
remove these
R1 - HKCU\Software\Microsoft\In ternet Explorer\Main,Search Bar = http://mysearchnow.com/searchbar.html
R1 - HKCU\Software\Microsoft\In ternet Explorer\Main,Search Page = http://mysearchnow.com/searchbar.html
R1 - HKLM\Software\Microsoft\In ternet Explorer\Main,Search Bar = http://mysearchnow.com/searchbar.html
R1 - HKLM\Software\Microsoft\In ternet Explorer\Main,Search Page = http://mysearchnow.com/searchbar.html
R0 - HKLM\Software\Microsoft\In ternet Explorer\Search,SearchAssi stant = http://mysearchnow.com/searchbar.html
Sunray
R1 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
Sunray
Get Kazaa off there and you will be in better shape... :)
Now I am going to bed!
FE
Now I am going to bed!
FE
refresh the registry after you delete the entries.
Now open IE and check if it is still there.
If it is not , restart your machine and again open IE and check if it is still there
Sunray
Now open IE and check if it is still there.
If it is not , restart your machine and again open IE and check if it is still there
Sunray
ASKER
Ok I restarted my computer and i opened my IE and clicked view > toolbars and now there is a blank space under "Links" and when i click on it the bar appears again
Hope you deleted all the keys as I had said ..
OK did you download and installed Spybot as War1 suggested.
Sunray
OK did you download and installed Spybot as War1 suggested.
Sunray
ASKER
Ok i checked over the keys that you had told me to delete and they are gone and i installed the spybot software and ran it. I had used spybot a few hours ago and fixed all the problems it found.
I seen this key under the hijackthis log and i was wondering if maybe this could be the problem?
O3 - Toolbar: (no name) - {2ab7a4d0-f738-4d80-b049-b 56ec3a9ca6 b} - C:\DOCUME~1\FaT\APPLIC~1\s tiblshstto u.dll
I seen this key under the hijackthis log and i was wondering if maybe this could be the problem?
O3 - Toolbar: (no name) - {2ab7a4d0-f738-4d80-b049-b
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Next, reset the Search Engine. Click the Search button in the toolbar > Customize > AutoSearch Settings > Select a provider from the list.
Open Internet Explorer > Tools > Options > Programs > "Reset Web Settings"
Open Internet Explorer > Tools > Options > Programs > "Reset Web Settings"
ASKER
Ok the toolbar is gone totally now... Thanks to everyone that helped me :)
-Shawn
-Shawn
Shawn, Which procedure helped you. Also, please close this Q if your problem is solved.
I myself also had this problem, and from this thread i got rid of the toolbar (thanks guys). But i have another problem now. I use google toolbar, and when i used to have mysearchnow, it would turn google off and turn itsself on. Now there's no mysearchnow, but google still automatically turns off every time i refresh the page. How can i fix this?
Becky.. probably best to open a new thread for your question.. That way you are sure to get a response...
FE
FE
If anyone encounteer this problem... (as I did)... run this out...
http://lop.com/toolbar_uninstall.exe
RyD
http://lop.com/toolbar_uninstall.exe
RyD
avast immediately blocked this download, this is a trojan...
yeah.. might be now... but wasn't almost a year ago! I might still have the exe hidden deep down in some back up..
Cheers!
Cheers!
or maybe avast just is configured too sverely over here, wouldn't be surprised :P
On topic: the browser extension of mysearchnow is caused by installation of MSN Messenger Plus (3)
Control Panel -> add/remove software/remove messenger. You get the option to keep messenger plus extension, but it removes the adware.
Cheers
On topic: the browser extension of mysearchnow is caused by installation of MSN Messenger Plus (3)
Control Panel -> add/remove software/remove messenger. You get the option to keep messenger plus extension, but it removes the adware.
Cheers
Check for virus and adware
Housecall Online Scan
http://housecall.antivirus.com
SpyBot S&D searches your harddisk for so-called spy- or adbots;
http://security.kolla.de/
or
Adaware
http://www.lavasoftusa.com/software/adaware/
or
CW Shredder
http://www.spychecker.com/program/cwshredder.html
Best wishes, war1