File: do-search.xml
Location of do-search.xml and Associated Malware
Check whether do-search.xml is present in the following locations:
do-search.xml file locations that are Windows version independent:
- C:\Program Files\Mozilla Firefox\browser\searchPlugins\do-search.xml
Windows 2000, Windows XP, Windows Server 2003 specific do-search.xml file locations:
- C:\Documents And Settings\USER_NAME\Application Data\mozilla\firefox\profiles\[%PROFILE_FOLDER%]\searchPlugins\do-search.xml
Windows Vista, Windows Server 2008, Windows 7, Windows 8 specific do-search.xml file locations:
- C:\Users\USER_NAME\AppData\Roaming\mozilla\firefox\profiles\[%PROFILE_FOLDER%]\searchPlugins\do-search.xml
If you find do-search.xml file in any of these locations, your computer is very likely to be infected with the following malware:
Notes:
- You can check if do-search.xml is associated with the malware listed above by running a Exterminate It! Free Scan.
- You can easily remove all the files listed above with Exterminate It! Antimalware.
Different Variations of do-search.xml File^
File Size | File Md5 | Last Seen |
---|---|---|
557 | C26EC35DCD7CA5CCEF3558DD51B5A4BD | Nov 29, 2013 |
558 | 6090864C401ADE621C69070554A56094 | Nov 29, 2013 |
558 | 66DC78A552C424C4B1A700CA8450C813 | Dec 7, 2013 |
555 | 6EBCD130DBF6E38BCECB8A4693404610 | Dec 10, 2013 |
554 | 6B3A4E155084353B89FAD5B6B54DB0F0 | Feb 3, 2014 |
556 | 3956D711B76752A1D744417AF337C807 | Feb 15, 2014 |
559 | 90575210B94CF494FDAD31756A6474F7 | Apr 13, 2014 |
562 | EE0BB87E8179920E4E7CA59BCA61582F | May 10, 2014 |
553 | AA8E5D29D06FE4C564CB4765945E878B | Sep 5, 2014 |
548 | 2734F51EDEB8D5845112687FDD654511 | Apr 28, 2015 |
561 | 71632095643523C2026F6FC765624252 | Jun 8, 2015 |
554 | DFBE4E08BEB402F17AA9EC4E0DC6D8A4 | Jul 26, 2015 |
554 | 20108BB87504995CA927FA6CD196F6D1 | Sep 17, 2015 |
2069 | E906BA0BB06FCD84EF84375D352B394A | Apr 23, 2015 |
2122 | B9B87522C41FDEB4CC3E98E351DDF05C | May 7, 2015 |
2059 | C7714DF0DE5BC6CDDC55F2834E4F6389 | May 9, 2015 |
2110 | A4B9126E01BD4FB1F5F7E459C0F8C49C | May 24, 2015 |
2120 | 6C6F7BEAE46B3C7E954B89ADB1592351 | May 31, 2015 |
2120 | D8697FC3556492CBEAC17728523AA6D1 | Jul 17, 2015 |
2120 | 2436F8A6154A3F0F9CCE19B272F42001 | Jul 18, 2015 |
2059 | 124E8B29C6561D161D2B4C0DF956D7D2 | Sep 4, 2015 |
2122 | 356590BF484D8F0115B73D40C3398DAC | Sep 16, 2015 |
2071 | C7F3D1D554686B5E9FC0F68BA70B28A0 | Oct 19, 2015 |
2098 | 0C78D24F79DE573FE689D2C4355976BB | Nov 8, 2015 |
2072 | BEA243CD5D03345B2F7BAD729CD127E6 | Nov 26, 2015 |
2111 | 815BB7556B7BB6484E0698CFBB356C00 | Jan 16, 2016 |
2074 | 7C10CD77D1074D1E31E4E7D9594426F6 | Feb 2, 2016 |
2071 | 64DD5716D51997DCBEAD570CFB697EA1 | Apr 28, 2016 |
2160 | 913614D680166965DB11C553CA7D7168 | May 7, 2016 |
2068 | 57083A74ECFCD8B1121E8F5EF0F7180F | May 12, 2016 |
2122 | FB0C4D1CA275326E15344CFF9E901283 | May 31, 2016 |
2121 | D3402C9CB3A8B52F13887F0B533EC823 | Aug 8, 2016 |
2062 | 9F922DDC1A9451BAB0714D5E66CB9FE1 | Oct 29, 2016 |
556 | 61D523779A15758C40C6BF4A412A2A8F | Dec 7, 2016 |
2163 | 40C0EBC841F8BAA70E67C564BBE7839C | Dec 10, 2016 |
2123 | 416557038FA665F390797632D6C19C90 | Jan 27, 2017 |
Why Is It Important to Remove Malware Files?^
It is imperative that you delete malware-associated files as soon as possible because they can be used - or are already being used - to inflict serious damage on your PC, including:
- Disrupting the normal functioning of the operating system or rendering it completely useless.
- Hijacking valuable private information (credit card numbers, passwords, PIN codes, etc.)
- Directing all your Web searches to the same unwanted or malicious sites.
- Dramatically slowing down your computer.
- Gaining total control of your PC to spread viruses and trojans and send out spam.
How to Remove do-search.xml^
- To enable deleting the do-search.xml file, terminate the associated process in the
Task Manager as follows:
- Right-click in the Windows taskbar (a bar that appears along the bottom of the Windows screen) and select Task Manager on the menu.
- In the Tasks Manager window, click the Processes tab.
- On the Processes tab, select do-search.xml and click End Process.
- Using your file explorer, browse to the file using the paths listed in Location of do-search.xml and Associated Malware.
- Select the file and press SHIFT+Delete on the keyboard.
- Click Yes in the confirm deletion dialog box.
- Repeat steps 2-4 for each location listed in Location of do-search.xml and Associated Malware.
- The deletion of do-search.xml will fail if it is locked; that is, it is in use by some application (Windows will display a corresponding message). For instructions on deleting locked files, see Deleting Locked Files.
- The deletion of do-search.xml will fail if your Windows uses the NT File System (NTFS) and you have no write rights for the file. Request your system administrator to grant you write rights for the file.
Notes:
Deleting Locked Files^
You can delete locked files with the RemoveOnReboot utility. You can install the RemoveOnReboot utility from here.
After you delete a locked file, you need to delete all the references to the file in Windows registry.
To delete a locked file:
- Right-click on the file and select Send To -> Remove on Next Reboot on the menu.
- Restart your computer.
The file will be deleted on restart.
To remove all registry references to a do-search.xml malware file:
- On the Windows Start menu, click Run.
- In the Open box, type regedit and click OK. The Registry Editor window opens.
- On the Edit menu, select Find.
- In the Find dialog box, type do-search.xml. The name of the first found registry value referencing do-search.xml is highlighted in the right pane of the Registry Editor window.
- Right-click the registry value name and select Delete on the menu.
- Click Yes in the Confirm Value Delete dialog box.
- To delete all other references to do-search.xml, repeat steps 4-6.
After scanning my computer many times using big name anti-virus and malware programs I still had several problems. Finally Exterminate It found multiple infections from NetSky. I sent Exterminate It a sample and the next day I received an e-mail instructing me to update and rescan. After following the instructions ZAP the worm/trojan was gone. My computer seems to be completly back to normal now. Good Job Exterminate It!