Ad Toolbar APpears on Startup, Help Appreciated

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Pennyman, Dec 26, 2005.

  1. Pennyman

    Pennyman Private E-2

    Hey everyone, wow, what a great site.

    I ran through your basic malware removal system, but my problem remains. In theory I would think it would be easy to get rid of.

    Every time I restart the computer, or simply log off and then back on to my desktop, a sort of ad-toolbar appears vertically allong the right hand side of the screen (Toolbar meaning I run the mouse over each of the 6 images shown and a small menu with internet links shows up.). it seems to have downloaded itself onto my desktop when my computer was unprotected.

    My computer thinks everything is fine, I have BSafe Online protection running (problem appeared before installing BSafe), but this toolbar still remains. I can close it and it goes away instantly, but whenever I restart, or log out and then in again, it shows up again. (BTW, this ad does NOT appear on any of the other usernames for my computer.)

    If it's any help, I traced the images the ad-toolbar uses to C:Windows/system32, but I'm not sure where the rest of the problem lies. If you guys need additional info or descriptions, please let me know.

    ANY help whatsoever is appreciated!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to MG's!

    Post the logs requested in the READ & RUN ME sticky. That is the Bitdefender, PandaActiveScan, and HijackThis log. All of them must be posted as attachments.
     
  3. Pennyman

    Pennyman Private E-2

    Ok, so I ran Panda ActiveScan, and it found nothing, said my computer had no objectionable files.

    I have the Hijack This log for you. I'm working on getting the Bitdefender to work but it won't open through Mozilla Firefox, so I must open it seperately in Internet explorer.

    Tell me what you think about the Log, I'm so sick of having this ad pop up upon startup.

    Thanks a billion for the help.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is very unusual for Panda to find nothing.

    The READ & RUN ME states:
    You need to run BitDefender. You have a Wareout infection. After running Bitdefender attach the log per the directions and then continue with the below.


    It looks like your Bsecure program installation is broken based on the below:
    O10 - Broken Internet access because of LSP provider 'inetcntrl.dll' missing

    Look in Add/Remove programs for UnSpyPC and uninstall if found.

    Please download FixWareout from one of these sites:
    http://downloads.subratam.org/Fixwareout.exe
    http://swandog46.geekstogo.com/Fixwareout.exe

    • Save it to your desktop and then run it by double clicking on it. It creates a folder named c:\fixwareout.
    • Click Next, then Install.
    • Then make sure Run fixit is checked (this runs C:\fixwareout\fixit.bat). And then click Finish.
    • The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so.
    • Your system may take longer than usual to load; this is normal.
    • When your system reboots, follow the prompts. Afterwards, HijackThis will launch. Please click Scan, and check the following items if they still exist:
    O17 - HKLM\System\CCS\Services\Tcpip\..\{0CDE919A-42A0-4401-8149-0C334F43F028}: NameServer = 85.255.115.3,85.255.112.11
    O17 - HKLM\System\CCS\Services\Tcpip\..\{463F5CC7-7438-4C50-B75D-40BEE36E1CA4}: NameServer = 85.255.115.3,85.255.112.11
    O17 - HKLM\System\CCS\Services\Tcpip\..\{7F048DAE-E9B9-43A3-850C-29F084CEDFDC}: NameServer = 85.255.115.3,85.255.112.11
    O17 - HKLM\System\CS1\Services\Tcpip\..\{0CDE919A-42A0-4401-8149-0C334F43F028}: NameServer = 85.255.115.3,85.255.112.11


    After click Fix Checked, close HijackThis, and click OK to proceed.

    At the end of the fix, you may need to restart your computer again.

    Now please attach the contents of the logfile C:\fixwareout\report.txt
    Also attach a new HijackThis log.
     
    Last edited: Dec 26, 2005
  5. Pennyman

    Pennyman Private E-2

    Here's the BitDefender report you requested. Sorry about missing the point of just using IE for those scans, will do.

    Let me know if there's any new info you can sift from this report.
     
  6. Pennyman

    Pennyman Private E-2

    Sorry, the report is too large to post! 276kb, not 250kb or less as required.
     
  7. Pennyman

    Pennyman Private E-2

    OK, I split it down the middle into two parts for your convenience.

    Thanks again, I appreciate the help.

    Also running one more PandaActive Scan just in case.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to complete the other steps I gave you for fixing Wareout. Then perhaps we will disable system restore to see if we can remove much of what BitDefender is complaining about.
     
  9. Pennyman

    Pennyman Private E-2

    Ran through procedure, ad is now gone, here are the requested reports.

    I will restart computer and see what happens.
     

    Attached Files:

  10. Pennyman

    Pennyman Private E-2

    OK guys, I am humbled. Thank God this site exists! You guy's are amazing. The ad is gone, and I am quite impressed at the skill and expertice you've shown toward me. It was going to cost $70 for one incident of Dell On Call, but you guys just helped me though it. Amazing. *Bows down*

    If I have any more troubles, I know where to go. Thanks again.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Just a couple more things. Double check to make sure you BeSecure application is working okay. HJT is reporting that 'inetcntrl.dll' is missing. I'm not sure that this report is valid. Search your PC to see if the file is there. It could be anywhere or could be in c:\windows\system32

    You have one more problem process that showed up:

    O4 - HKLM\..\Run: [dmehl.exe] C:\WINDOWS\system32\dmehl.exe


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [dmehl.exe] C:\WINDOWS\system32\dmehl.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delet
    e:
    C:\WINDOWS\system32\dmehl.exe


    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now run Ccleaner (installed while running the READ ME FIRST).


    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds