Solved! Use 6XSRCHMN.EXE (Adware MyWebSearch) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

6XSRCHMN.EXE – Adware MyWebSearch removal

FileMD5Virus Alias
6XSRCHMN.EXE 466af3fbfdd028b3d90238425c367b7e Adware MyWebSearch
6XSRCHMN.EXE 466af3fbfdd028b3d90238425c367b7e Trojan Buzus

6XSRCHMN.EXE size: 55368 bytes
6XSRCHMN.EXE hash: 466AF3FBFDD028B3D90238425C367B7E

Created files:

%Program Files%\ReadingFanatic_6x\bar\1.bin\6xauxstb.dll
%Program Files%\ReadingFanatic_6x\bar\1.bin\6xauxstb64.dll
%Program Files%\ReadingFanatic_6x\bar\1.bin\6xbar.dll
%Program Files%\ReadingFanatic_6x\bar\1.bin\6xbarsvc.exe
%Program Files%\ReadingFanatic_6x\bar\1.bin\6xbprtct.dll
%Program Files%\ReadingFanatic_6x\bar\1.bin\6xbrmon.exe
%Program Files%\ReadingFanatic_6x\bar\1.bin\6xbrmon64.exe
%Program Files%\ReadingFanatic_6x\bar\1.bin\6xbrstub.dll
%Program Files%\ReadingFanatic_6x\bar\1.bin\6xbrstub64.dll
%Program Files%\ReadingFanatic_6x\bar\1.bin\6xdatact.dll
%Program Files%\ReadingFanatic_6x\bar\1.bin\6xdlghk.dll
%Program Files%\ReadingFanatic_6x\bar\1.bin\6xdlghk64.dll
%Program Files%\ReadingFanatic_6x\bar\1.bin\6xfeedmg.dll
%Program Files%\ReadingFanatic_6x\bar\1.bin\6xhighin.exe
%Program Files%\ReadingFanatic_6x\bar\1.bin\6xhkstub.dll
%Program Files%\ReadingFanatic_6x\bar\1.bin\6xhtmlmu.dll
%Program Files%\ReadingFanatic_6x\bar\1.bin\6xhttpct.dll
%Program Files%\ReadingFanatic_6x\bar\1.bin\6xidle.dll
%Program Files%\ReadingFanatic_6x\bar\1.bin\6xieovr.dll
%Program Files%\ReadingFanatic_6x\bar\1.bin\6xmedint.exe
%Program Files%\ReadingFanatic_6x\bar\1.bin\6xmlbtn.dll
%Program Files%\ReadingFanatic_6x\bar\1.bin\6xPlugin.dll
%Program Files%\ReadingFanatic_6x\bar\1.bin\6xradio.dll
%Program Files%\ReadingFanatic_6x\bar\1.bin\6xregfft.dll
%Program Files%\ReadingFanatic_6x\bar\1.bin\6xreghk.dll
%Program Files%\ReadingFanatic_6x\bar\1.bin\6xregiet.dll
%Program Files%\ReadingFanatic_6x\bar\1.bin\6xscript.dll
%Program Files%\ReadingFanatic_6x\bar\1.bin\6xskin.dll
%Program Files%\ReadingFanatic_6x\bar\1.bin\6xskplay.exe
%Program Files%\ReadingFanatic_6x\bar\1.bin\6xSrcAs.dll
%Program Files%\ReadingFanatic_6x\bar\1.bin\6xSrchMn.exe
%Program Files%\ReadingFanatic_6x\bar\1.bin\6xsrchmr.dll
%Program Files%\ReadingFanatic_6x\bar\1.bin\6xtpinst.dll
%Program Files%\ReadingFanatic_6x\bar\1.bin\APPINTEGRATOR.EXE
%Program Files%\ReadingFanatic_6x\bar\1.bin\AppIntegrator64.exe
%Program Files%\ReadingFanatic_6x\bar\1.bin\APPINTEGRATORSTUB.DLL
%Program Files%\ReadingFanatic_6x\bar\1.bin\AppIntegratorStub64.dll
%Program Files%\ReadingFanatic_6x\bar\1.bin\ASSISTMONITOR.DLL
%Program Files%\ReadingFanatic_6x\bar\1.bin\ASSISTMONITOR64.DLL
%Program Files%\ReadingFanatic_6x\bar\1.bin\assists\ie_default_search_provider\ARBITER.DLL
%Program Files%\ReadingFanatic_6x\bar\1.bin\assists\ie_default_search_provider\ARBITER64.DLL
%Program Files%\ReadingFanatic_6x\bar\1.bin\assists\ie_default_search_provider\ASSIST.EXE
%Program Files%\ReadingFanatic_6x\bar\1.bin\CREXT.DLL
%Program Files%\ReadingFanatic_6x\bar\1.bin\CrExtP6x.exe
%Program Files%\ReadingFanatic_6x\bar\1.bin\DPNMNGR.DLL
%Program Files%\ReadingFanatic_6x\bar\1.bin\EXEMANAGER.DLL
%Program Files%\ReadingFanatic_6x\bar\1.bin\FF-NativeMessagingDispatcher.dll
%Program Files%\ReadingFanatic_6x\bar\1.bin\Hpg64.dll
%Program Files%\ReadingFanatic_6x\bar\1.bin\NP6xStub.dll
%Program Files%\ReadingFanatic_6x\bar\1.bin\T8EPMSUP.DLL
%Program Files%\ReadingFanatic_6x\bar\1.bin\T8EXTEX.DLL
%Program Files%\ReadingFanatic_6x\bar\1.bin\T8EXTPEX.DLL
%Program Files%\ReadingFanatic_6x\bar\1.bin\T8HTML.DLL
%Program Files%\ReadingFanatic_6x\bar\1.bin\T8RES.DLL
%Program Files%\ReadingFanatic_6x\bar\1.bin\T8TICKER.DLL
%Program Files%\ReadingFanatic_6x\bar\1.bin\TPIMANAGERCONSOLE.EXE
%Program Files%\ReadingFanatic_6x\bar\1.bin\UNIFIEDLOGGING.DLL
%Program Files%\ReadingFanatic_6x\bar\1.bin\VERIFY.DLL
%Temp%\00001f34T8SETUP.EXE
%Temp%\00001f34T8SETUP.EX_

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\ReadingFanatic_6xService\Type: 10000000
HKLM\System\CurrentControlSet\Services\ReadingFanatic_6xService\Start: 02000000
HKLM\System\CurrentControlSet\Services\ReadingFanatic_6xService\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\ReadingFanatic_6xService\DisplayName: ReadingFanaticService
HKLM\System\CurrentControlSet\Services\ReadingFanatic_6xService\ImagePath: %Program Files%\ReadingFanatic_6x\bar\1.bin\6xbarsvc.exe

Detected by UnHackMe:

6XSRCHMN.EXE
Default location: %PROGRAM FILES%\READINGFANATIC_6X\BAR\1.BIN\6XSRCHMN.EXE

Dropper information:
MD5: 4badcd69bdc1986ec8e85696299f87a3
File size: 6072712 bytes

Leave a Reply