Spysweeper found blazefind,orbit,websearch toolbar

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by kris pyro, Sep 14, 2004.

  1. kris pyro

    kris pyro Private E-2

    gateway 2ghz,ms windows xp home edition, everytime i run spysweeper i find blazefind,orbit exp.,web search t.b. , i have not had any trouble since fix'n errorplace redir. I have followed all steps outlined in read me first, getting preped and down loaded all tools and ran with the exception of hjt.Done the scanning and cleaning steps in safe mode as directed.... I have not noticed any problem yet with my computer but was wondering why it keeps showing up? and how to get rid of it? Also in add remove programs i have something called AccountLOgon is this something to worry about? Lastly spybot keeps finding adroar plug in and dosnt get rid of it (HKEY_USERS\S-1-5-18\SOFTWARE\ADROARPLUGIN )AND (HKEY_USERS\DEFAULT\SOFTWARE\ADROARPLUGIN ). Any help would be greatly appreciated..
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. kris pyro

    kris pyro Private E-2

    hello chaslang, in response i looked at account logon in add remove programs, when i click add remove it trying to (load) set up files for a hp printer, so i let it just to see if i would find a uninstall...no luck .
    On the adroar plug in i found no uninstall for cpr..
     
  4. kris pyro

    kris pyro Private E-2

    Re: still no luck on blazefind or orbit or web search

    i went ahead and did a hjt log and am waiting for a go ahead to send it as attach. txt. unless you want me to try something else..
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But is it the AccountLogon program that I gave a link to? Do you think you or someone else may have installed it?

    Yes post a HJT log attachment.
     
  6. kris pyro

    kris pyro Private E-2

    i dont think i need it for anything. i dont use it and all it does is try to set up a hp printer.. ok on the log
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not follow the directions completely in the HijackThis tutorial. You have HJT running from the ZIP file. See this line in your log.

    C:\DOCUME~1\Owner\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

    You must put it into its own folder as indicated in the tutorial before we try to fix things with it. Extract it from the ZIP into its own folder (like c:\program files\hjt )
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you use SpyBot or SpySweeper to protect your Internet Explorer\Control Panel with the below line:
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    Run HijackThis and select each item list below and the before clicking Fix shut down all browser sessions first including the one you are reading from right now.
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided by Cox High Speed Internet
    O2 - BHO: jimmyhelp.CBrowserHelper - {7A5F0F88-11BB-43AE-B4E7-FEF22315FB14} - C:\WINNT\xxqlex.dll
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O16 - DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} (RunExeActiveX.RunExe) - hcp://system/RunExeActiveX.CAB

    Check out these other links on Adroar:
    http://www.kephyr.com/spywarescanner/library/adroar/index.phtml
    http://www.pestpatrol.com/pestinfo/a/adroar.asp
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also try this for fixing the Adroar problem:
    Click Start, and then click Run. (The Run dialog box appears.)

    Type, or copy and paste, the following text:
    regsvr32 /u AdRoar.dll
    then click OK. If a dialog box confirming this action appears, click OK.

    Reboot in safe mode and delete (if found):
    c:\windows\AdRoar.dll or c:\windows\system32\AdRoar.dll
    c:\windows\ARUpdate.exe or c:\windows\system32\ARUpdate.exe
     
  10. kris pyro

    kris pyro Private E-2

    Chaslang i am at the fire station today, i will try your fix's Thursday thanks for the help. kris
     
  11. kris pyro

    kris pyro Private E-2

    Yes is the answer for IE control panel protection from spysweeper. On line R1 on HJT Cox is my ISP, should i still fix this line???? NOT EVEN CLOSE TO BEING A GEEK BUT IAM TRYING,,,,,THANKS FOR THE HELP KRIS
     
  12. kris pyro

    kris pyro Private E-2

    Yes I saw the hjt in the temp folder, but i put it in c:/programfiles/highjackthis is this not right?? maybe i have another download of it somehow, shoot anythings possible with me at the keyboard..........
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can fix it! Why give them free advertisement? It's only a window title and you can change them to anything you like with no impact. If you want to keep it, that's fine.

    Keep them fires in control! Can you make me an honorary fireman? I keep putting out fires here all the time. ;)
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you just check another log on your PC and do not get:
    C:\DOCUME~1\Owner\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

    But rather something like:

    C:\Program Files\HijackThis\HijackThis.exe

    then you are okay!
     
  15. kris pyro

    kris pyro Private E-2

    Chaslang i ran hjt and removed what u said yesterday. I also tried the other (regsvr etc.) and found nothing. If its ok i will post a log directly to you (in P.M. )of spysweeper and see what iam picking up in my scans. It may be from a scan log somewhere..Should I post another hjt????thanks kris

    p.s. You should be an honorary firechief not just a fireman for all the help you give to us folks that havenot and may never reach the status of M.Geek.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Kris,

    I saw your PM of SpySweeper. It looks like it fixed everything. Are you saying you still have a problem? If so, with what. Try running SpySweeper from safe mode boot.

    Sure post another HJT log attachment.
     
  17. kris pyro

    kris pyro Private E-2

    Chaslang heres the latest hjt log file..i ran spysweeper from safe mode as you said..it said it removed blazefind,orbit,web search toolbar, but i will check it agian and see if it finds it again, as in the past..Also i will run spybot and see if it picks up adroar plugin again. I went and deleted almost all of backups (logs)for adware and spyware protection..I went to Accountlogon website which is nothing like what i get when i click on add remove programs.It trys to download files for hp printer 940c which i dont have!!! I would say its corrupt?
     

    Attached Files:

  18. kris pyro

    kris pyro Private E-2

    Ok i am getting tired of this #@%*..Spybot is the only scan that picks up AdRoar Plugin. Should I just ignore it? Tried to do the online thing at Kephyr and Pestpatrol with no luck and the regsvr32.
    I ran Spysweeper after coming out of safe mode and it still picking up blazefind,orbit,websearch toolbar..It says it found 4 registry traces each..
    What do you suggest?? I Know, its Dove season, I will put a couple dove wings on the puter and blow the hell out of it!!!!!
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You HJT log is clean. Let me know it you find any other problems with SpyBot (try running it in safe mode too).

    For the AccountLogon item in the registry, we may have to fix it by hand by editing the registry.
     
  20. kris pyro

    kris pyro Private E-2

    Chaslang be sure to read my last posting @1734 just before you posted..
    I ran spybot in safe mode and it fixed SearchForlt (something new)but said "some problems could not be fixed, assoc. files are still in use (in memory). This could be fixed after a restart". I brought it out of safe and spybot ran again finding AdroarPlugin again..
    From reading other post I was wondering if SP2 may have something to do with not being able to remove these pest. I may have had them when i installed SP2..
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have SpywareBlaster installed? If yes, ignore the SearchForIt message from SpyBot. It is a bug (just like the well know DSO Exploit issue with SpyBot). It is still a great program though.

    I think most of your problems are due to fairly benign data stuck in your registry. I don't understand why SpySweeper told you it fixed the problems but they are still there. Either something is bringing them back (after a reboot or running some application) or SpySweeper is never really fixing them.

    What version is your SpyBot? And what is the date of your detection rules? Click the Help, About selections. Also do the below to fix some settings in SpyBot. At the top of the screen select Mode, Advanced mode, then on the lower left select Settings. Now select Ignore Products. Right click on lower part of the right window and select "Deselect all".

    Now if fully updated! Run SpyBot again.

    Back aways you said you did the below:

    Reboot in safe mode and delete (if found):
    c:\windows\AdRoar.dll or c:\windows\system32\AdRoar.dll
    c:\windows\ARUpdate.exe or c:\windows\system32\ARUpdate.exe

    Did you actually find those files on your PC?
     
  22. kris pyro

    kris pyro Private E-2

    yes to spywareblaster..spybot is 1.3 detection is 08-30-04..i did what u said in spybot I had nothing checked to ignore (I think)..no i found no files from those you listed..but i am going to try it again in safe mode..
     
  23. kris pyro

    kris pyro Private E-2

    I ran in safe mode and looked for those files again, no luck. I also ran spybot sd in safe mode and again it found adroar plugin with no removal...it says its a registry file..
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    4 of them were checked by default (a bug) after install. As long as you did what I said you should be okay now. Also, note some malware will sometimes disable programs like SpyBot from detecting them. So it never hurts to check.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    go here and download Registrar lite and install it: http://www.majorgeeks.com/download469.html

    Click on the Search icon (the magnifier glass) and then enter in the Text to search for box:
    adroar

    then hit return. Tell me what you get on the right side window.
    If you get a lot of them, does waste your time. Just right click on them and delete them. But first make sure it is really the Adroar that SpyBot is complaining about. See your first message with HKEY_USERS\....
     
  26. kris pyro

    kris pyro Private E-2

    okay i did what u said and found 3 listings for adroar along with roings and blaze and orbit..maybe this will stop it...thanks i will check it again...you should change your name to firchief...............kris :p
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Let me know one way or another.
     
  28. kris pyro

    kris pyro Private E-2

    if i run a scan should i do it from safe mode or dosn't matter???
     
  29. kris pyro

    kris pyro Private E-2

    spybot came out clean finally..now if i can get spysweeper to do the same....
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make a note of what SpySweeper gives you and look for the items in the registry using Registrar Lite and delete them the same way.
     
  31. kris pyro

    kris pyro Private E-2

    its asking if i want to delete keys HKEY_Current_user\software\microsoft\windows\current version\internet settings\zone map\Domain\blazefind.com
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! You don't want to. Now I think I see the problem, SpySweeper is finding lines in your registry that are used to block malware sites. SpyBot and SpywareBlaster and other programs put these there. SpySweeper is detecting the word blazefind.com, rather than determing if it is really a problem or not.

    If you bought SpySweeper, I would email them and complain. If the other things it was detecting are in the same place, ignore them.
     
  33. kris pyro

    kris pyro Private E-2

    Chief Chaslang well ok then, I guess i will call it quits with trying to remove those three items from spysweeper..i really thank you for your efforts in helping a novice..kris :p
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds