Huntbar, IBIS Toolbar and Bargain Buddy

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by evilevets, Jun 27, 2005.

  1. evilevets

    evilevets Sergeant Major

    Win XP home, SP1 -

    Followed the Read Me First as best as I could, as this PC does not currently have Internet access, so I couldn't do the on-line scans.

    Trojan Hunter - clean (found something on first run, but was deleted and has not come back)

    Avast Cleaner Tool - clean

    Spybot - Continually finds and cannot remove Huntbar in HKLM\Software\BTIEIN

    Ad-Aware - continually finds and cannot remove IBIS Toolbar in HKLM\Software BTIEIN

    Spysweeper - continually finds and cannot remove Bargain Buddy and WebSearch Toolbar.

    Also:

    Not sure if it is a Hijack, but the Run box in the Start menu does not work.


    Thanks in advance,

    -Steve
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the steps below exactly:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. evilevets

    evilevets Sergeant Major

    Here it the HTJ log...


    Thanks, Steve
     

    Attached Files:

  4. Hey i think i know what to do about ibis toolbar and bargainbuddy. I had the same exact trouble on my pc. Heres a fast easy way to get rid of those two suckers once and for all. Go to add/remove in windows and uninstall both. Just do what it says to do to uninstall it. Then they will ask you to restart. Do that and then run adaware and do a full system scan. (They go deeper than the qucks scan or whatever its called) and it will remove any other traces of it and they will be down and out for good. But i never had huntbar and cant help you with that. Sorry :( But what i suggeseted could help you with the other two. If you cant get rid of them make sure you are running the latest version of adaware and have the latest definitions file.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://xlonhcld.xlontech.net/100125/201002/202231/zoom.html
    R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - (no file)
    O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)

    After clicking Fix, exit HJT.

    Make sure you have the current version and updates for Microsoft® Windows AntiSpyware but do not run a scan yet.

    Now reboot into safe mode with no network support, make sure you have no browsers opened and then run a full scan with MS Antispyware and let it fix what it finds.

    While still in safe mode, run Windows Explorer and delete:
    C:\Program Files\Web_Rebates <--- the whole folder
    C:\Program Files\AWS <--- the whole folder

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  6. Yeah do what chasalang said too. He know much more than most of us with spyware. Let me know if my suggestion on IBIS toolbar and bargain buddy helped.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds