Hi Frank;
I did a Grep on my system, and found an offending file on
my computer C:/system.reg
System.reg contains the following:
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer]
"SearchURL"="
http://www.searchxl.com/ie/"
[HKEY_CURRENT_USER\Software\Microsoft\Internet
Explorer\Main]
"Use Search Asst"="no"
"Use Custom Search URL"=dword:00000001
"Default_Search_URL"="
http://www.searchxl.com/ie/"
"Search Page"="
http://www.searchxl.com/ie/"
"Search Bar"="
http://www.searchxl.com/ie/"
"SearchURL"="
http://www.searchxl.com/ie/"
[HKEY_CURRENT_USER\Software\Microsoft\Internet
Explorer\Search]
"SearchAssistant"="
http://www.searchxl.com/ie/"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet
Explorer\Search]
"SearchAssistant"="
http://www.searchxl.com/ie/"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet
Explorer\Main]
"Search Page"="
http://www.searchxl.com/ie/"
"Default_Search_URL"="
http://www.searchxl.com/ie/"
[HKEY_CURRENT_USER\Software\Microsoft\Internet
Explorer\Toolbar\WebBrowser]
"ITBarLayout"=hex:11,00,00,00,4c,00,00,00,00,00,00,00,30,00
,00,00,1b,00,00,00,\
64,00,00,00,01,00,00,00,a0,06,00,00,e9,02,00,00,05,00,00,00
,62,04,00,00,26,\
00,00,00,02,00,00,00,a1,06,00,00,f7,02,00,00,04,00,00,00,a1
,00,00,00,11,03,\
00,00,03,00,00,00,a9,02,00,00,0b,03,00,00,00,00,00,00,00,00
,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,01,24,d0,30,81,6a,d0,11
,82,74,00,c0,4f,\
d5,ae,38,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersi
on\Run]
"SystemSearch"="REGEDIT.EXE -S c:\\system.reg"
I deleted this plus all the offending registry entries. i
suspect that this will kill this parasite, but...
Kind rgds
Paulo
-----Original Message-----
Did you run cwshredder?
--
Frank Saunders, MS-MVP IE/OE
http://www.fjsmjs.com
Reply to Newsgroup. I won't answer email
Protect Your PC
http://www.microsoft.com/security/protect/
the first step.
.