Security Toolbar/Security Toolbar 7.1 removal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Badgeroonie, Nov 24, 2008.

  1. Badgeroonie

    Badgeroonie Private E-2

    My PC has gained te dreaded Scurity Toolbar. Originally it was Security Toolbar 7.1 but now just states Security Toolbar. It redirects my browser to 'blank page' but I cannot access the internet. The page just hangs, and if I type a different address into the address bar, it just hangs. Because of this I am unable to download programs from this site to help clear the problem. I have attempted to access this site from my PSP using a neighbour's wireless connection, but for whatever reason I am unable to do so. I am thinking the best thing for me to do is to take my PC to someone else's house, and use their PC to download the tools and then transfer them to my PC using a memory device. The problems I foresee here are the extra time this would take (not really an issue as otherwise I have no internet access) and the possibility that I will infect my friend's PC in some way.

    Is this a feasible solution to my situation?
     
  2. Badgeroonie

    Badgeroonie Private E-2

    I can now access the site with my PSP so if there's anything worth doing from home please tell me
     
  3. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Welcome to Major Geeks!


    Reason you likely cannot connect to neighbours wireless is that they likely have WEP or WPA encryption on it to stop others using their internet.

    Best best is to print out the guides below and the lists of software you need or at a friends PC connect to this forum and download the needed software, pop them onto CD or USB pen and take back to your home and run, or if friend has time as malware removal may take a few days or so indeed take PC to a friends, but I would try grabbing the software and popping onto CD/USB and trying the guide from home first.



    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    Notes:

    1. If you run into problems trying to run theREAD & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.


    plus a guide on how to attach the logs HOW TO: Attach Items To Your Post
     
  4. Badgeroonie

    Badgeroonie Private E-2

    I've been working my way through the procedures and have got as far as the 'Windows XP Cleaning Procedure', having just completed the 'SUPERAntiSpyware - running & getting a log'. However, I am unable to access the internet, receiving a blank page. If I try to direct the browser directly to a website, I get an error message prompting me to check connectivity. When I do this, it says there is a problem with a file and I have to reboot my PC.

    Unfortunately, I cannot remember the error message or the file: I should've written it down I guess. I'm now at work so won't be able to get the info until later.

    I've tried the section within 'SUPERAntiSpyware - running & getting a log' about what to do in the event that the internet doesn't perform correctly, but it hasn't resolved the issue. So what's next.

    BTW - I have my neighbour's permission to use his wireless in this instance. I'm not sure why my PSP wouldn't allow me to log in originally, but it seems to let me do so now, so I should be able to update this thread from home tonight.
     
  5. Badgeroonie

    Badgeroonie Private E-2

    OK, all done. Due to the fact I currently am unable to access the net, I was only able to complete the logs for SuparAnti-spyware, malwarebytes and MGtools, which have all been attached.

    When I try to go online, the browser no longer shows the Security Toolbar, but still redirects to a blank page. If I then attempt to view any page, I get the standard 'unable to connect' message. If I run the diagnostic, it says my firewall settings are too high, although I have checked them and they are all at the original default levels.

    Thanks in advance for any help.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program
    Click Start > Run and type in cmd
    • Click OK.
    • This will open a command prompt.
    • Type or copy and paste the following line in the command window:
      ipconfig /flushdns
    • Hit Enter
    • Exit the command window

    Now let's flush the Java Cache
    • Click Start > Settings > Control Panel
    • Double click the Java icon (be patient, it may take a while to open)
    • Now click the General tab and under the Temporary Internet File area
    • Click the Settings button and then click the Delete Files... button.
    • In the next popup click OK.
    If you have multiple Java plugin icons in Control Panel follow the above to clear all their caches.

    Now let's flush the Internet Explorer Cache


    To flush your Internet Explorer Cache:
    • click Tools
    • Internet Options
    • Now on the General tab and click Delete Files and select Delete all Offline content too
    • Click OK.
    • When it finishes Click OK.
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9090
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
    O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
    O9 - Extra button: (no name) - {3B8FB116-D358-48A3-A5C7-DB84F15CBB04} - http://www.ietoolexpress.com/redirect.php (file missing)
    O9 - Extra 'Tools' menuitem: IExplorer Security - {3B8FB116-D358-48A3-A5C7-DB84F15CBB04} - http://www.ietoolexpress.com/redirect.php (file missing)

    After clicking Fix, exit HJT.




    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • If you see a message on reboot about adding a file (IEFIX.reg) to your registry, make sure you allow it to be added to the registry since we are the ones adding it.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Dell\Local Settings\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. Badgeroonie

    Badgeroonie Private E-2

    All done.

    When I ran the 'ipconfig /flushdns' command prompt, I got the message 'Could not flush the DNS Resolver Cache: Function failed during execution'.

    When the system re-booted after running avenger.exe, I got an error message: 'Windows - No Disk. Exception Processing Message c0000013 Parameters 75b6bf7c 4 75b6bf7c 75b6bf7c'.

    Whilst CCleaner was running, I got the message 'C:\MGtools\sed.exe is not a valid Win32 applicarion'.

    I've attached the two logs, as requested. It appears that I can now access the internet from my PC.

    Thanks in advance.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then run Malwarebytes and update it since you were way out of date. Then run a new scan and attach the new log.


    Are you having any malware problems now?
     
  9. Badgeroonie

    Badgeroonie Private E-2

    I've attached the log. I don't appear to be having any more problems. The 'Security Toolbar' has gone.

    Should I remove any of the programns installed during my cleanup process?
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  11. Badgeroonie

    Badgeroonie Private E-2

    When I do this bit:




      • I get this message:

        Some installation files are corrupt.
        Please download a fresh copy and retry the installation.

        Do I need to try something else instead, or can I carry on with the other things you listed?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try downloading a new copy of combofix.exe to your Desktop. You don't need to run it. Just run the steps I gave to uninstall it an make sure you copy and paste the command exactly as written.
     
  13. Badgeroonie

    Badgeroonie Private E-2

    Thanks, I've followed all the instructions. It all seems to be ok now, with only the suggested programs remaining.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds