3 Adware I cannot remove? Help Please...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Homerj, Jul 29, 2004.

  1. Homerj

    Homerj Private E-2

    Hello,

    I seem to have 3 problems on my system that were found with Norton 2004. It finds the following:

    1) NULL
    2) btiein.dll
    3) crt32 v2.dll

    When I select delete from Norton it comes back as delete failed? I have Spybot 1.3, Adaware 6.0 and they do not find anything. How do I get rid of these once and for all?

    Also it could be related to these, but sometimes my Norton will not load and it seems as if my system is frozen, almost like something is running in the background. I try to open folders or windows and they start to open and then freeze. I am forced to either "end task" or wait a long time before they finally open. Norton will not open and I have to uninstall and the reinstall Norton and then everything seems fine.

    Any suggestion or help would be greatly appreciated. Please keep in mind that I am somewhat computer challenged.

    Thanks,

    Homerj
     
  2. just me

    just me Private E-2

    btiein.dll <~ did that come attached to huntbar at one time?
     
  3. Homerj

    Homerj Private E-2

    Thanks for getting back.

    I am not sure if it came from huntbar it is very possible but I do not know for sure. I have delete hundreds of items from my system once I heard about this wedsite.

    Do you know if there is a way for me to find out if it came from huntbar?

    btw I was able to get rid of crt32 v2.dll

    one down and 2 to go.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  5. Homerj

    Homerj Private E-2

    Chaslang I tried what you mentioned below but I still have only been able to remove 1 of the 3. The other two left are btiein.dll and NULL.

    Here is all the information I get from Norton:

    Detected 2
    0 infected files
    2 at-risk files

    filename: btiein.dll
    threat name: adware.websearch
    action: adware found
    status: at risk

    filename: NULL
    threat name: adware.websearch
    action: adware found
    status: at risk

    It then recommends that Norton removes it for you automatically. I then click "delete" and it then reponds under "status" column "delete failed".

    I tried removing a file called "Search Assistant - My Search" I figured this must be the problem but it does not allow me to remove or delete? It says that I should be looking for "Search Toolbar" but I cannot find it anywhere.

    It then says to remove the value "TB_setup"="<path to executable file> /dcheck" from the registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    but it is no where to be found?

    I hope this info helps. Any help regarding this matter is greatly appreciated.

    homerj
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  7. Homerj

    Homerj Private E-2

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I need better info. Then "did not work". What happen? Like you could not find the files or the registry keys mentioned.

    Did you try the kephyr stuff in safe mode?
    Did you enable view of hidden system files and folders?
    You never told me what OS you are running either?

    I may not be around the rest of tonight and possibly tomorrow until late. So I'm going to give you somethings to do.
    Make sure you have updated Ad-Aware to referencefile 01R334 24.07.2004.
    Now configure Ad-aware for fullscan: http://www.lavahelp.com/howto/fullscan/index.html
    Run Ad-aware fullscan! Clean up what it finds.

    Run the following online scans:
    http://housecall.trendmicro.com/housecall/start_corp.asp <--- Select Auto Clean
    http://www.pandasoftware.com/activescan/com/activescan_principal.htm

    Download and run (select fix not scan) CWShredder

    See this link and read about HijackThis and posting log as an attachment! If still having problems post your Hijack This log attachment (when you save the log set the save as type to all files and then save as a .txt file instead of .log)
     
    Last edited: Jul 30, 2004
  9. Homerj

    Homerj Private E-2

    The only one left is filename: btiein.dll, all others have been removed.

    I have tried your link to enable full scan of adaware but when I click on it, it says that the site is under construction. I would certainly like to know how to do the full scan. Other than that I have tried everything you mentioned in your previous post.

    I have read in other threads about VX2 plug in and I am going to try that as well.

    I just wanted to say how much I have appreciated your help, suggestions and solutions. This website and message board is excellent and I have strongly recommended this to many people.

    Homerj
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The Lavasoft site recently changed their URL slightly. Here is the correct one: http://www.lavahelp.net/howto/fullscan/index.html

    Do that fullscan.

    You still did not answer my questions from a previous message.

    What do you mean it did not work?
    Did you try the kephyr stuff in safe mode?
     
    Last edited: Aug 5, 2004
  11. suesman

    suesman First Sergeant

    If he's running XP, could it not be reinstalling everytime he reboots threw the "System Restore" thingy? I've had this issue many times in the past, now I know it has to be deleted while "System Restore" is turned off. I'm by no means an expect on this, but I've been threw the whole RASSIN@&$(*FRASSIN thing myself.

    Just a thought.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    While system restore can bring back problems from a restore point, this is not the cause here. At least not based upon the limited feedback being supplied. The only answer I got was the file could not be removed. Homer did not say it was removed but has come back after a reboot.

    I have yet to see any answers for all the things that I asked to be done. Like the online scans and CWShredder. Still need the fullscan with Ad-aware but the link I gave previously had changed and thus that could not be completed. It's about 6 days since I asked for that stuff to be run but no feedback has been provided. (Are you reading this Homer? You have to help me to help you. Or my time will be better spent elsewhere.)
     
  13. Homerj

    Homerj Private E-2

    I apologize for not providing enough information, this is as much frustrating for me as it is for you.

    When I indicated that it did not work I meant to say that the scans performed accordingly however they did not find the btiein.dll. It seems that only Norton discovers this object and then is unable to delete it from my system. My system is custom built, about 4 years old. I am running windows 98 and I have the most recent updates.

    The following items/scans have been completed:

    CW Shredder - did not find btiein.dll
    http://housecall.trendmicro.com/hou.../start_corp.asp <--- Select Auto Clean - did not find btiein.dll
    http://www.pandasoftware.com/active...n_principal.htm - did not find btiein.dll

    I am pretty sure that I ran kephyr in safe mode, but to make sure I will do that again this evening. From the link you provided I tried everyting listed, manually searched the registry for 'HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ {63B78BC1-A711-4D46-AD2F-C581AC420D41}. 'HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Browser Helper Objects \ {63B78BC1-A711-4D46-AD2F-C581AC420D41}. The stuff in the squiggle brackets was found and I did delete it from the registry. I restarted my computer and as mentioned started windows explorer to find this problem but was not able to locate it. From this site I also downloaded "Bazooka" and ran it and it did not find btiein.dll.

    I then ran Norton 2004 again and sure enough if found btiein.dll and then Norton was unable to remove it.

    As mentioned tonight I will try a full scan with Adaware 6.0 and kephyr in safe mode, hopefully this will work.

    Is there anything that I missed or did not mention?

    In an earlier post I mentioned that I tried removing a file called "Search Assistant - My Search" I figured this must be the problem but it does not allow me to remove or delete? It says that I should be looking for "Search Toolbar" but I cannot find it anywhere. Does this have something to do with btiein.dll or is it something different all together. When I go to control panel/add remove it is listed but cannot be removed, it provides an error message.

    homerj
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All of the items I was asking you to run were not chosen in an attempt to just look for btiein.dll. I wanted you to run them to make sure there were no other problems that were being missed. You keep saying they did not find btiein.dll, but what about anything else? Are you saying none of these found anything else in your system?

    Did you ever once try the following:
    - boot in safe mode: http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406?OpenDocument&src=sec_doc_nam
    - make sure you have enabled viewing of hidden files and folders in Windows Explorer
    http://forums.majorgeeks.com/showthread.php?t=37650 also make sure you do not have a check mark on the option to hide extensions for known file types.
    - with Windows Explorer goto c:\windows\system and look for btiein.dll and delete it.
    - if not found there, search for it and delete it

    You keep saying "I then ran Norton 2004 again and sure enough if found btiein.dll and then Norton was unable to remove it." But where did it find it? Didn't they give you the full path? If so, you should have put that it you message.
     
  15. Homerj

    Homerj Private E-2

    Good point.

    I was able to find a few other items that Norton did not find, as for what they were I do not remember except that one or two of them were some type of trojan as well as the other 2 items I listed earlier.

    I did both links you mentioned below and when I selected show hidden files that is when I found the "NULL" item and deleted it. I was unable to find the btiein.dll and when I did a system search it was not found either.

    I will try going to c:\windows\system and look for btiein.dll using explorer and if it is there I will delete it.

    Unfortunately Norton says it find it but does not indicate where? Do you know if Norton 2004 has a way of displaying where the virus is located? I have checked the manuals and no where can I find a way to do this.

    Homerj
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Where were you looking initially for btiein.dll if not in c:\windows\system?

    I think you may need to search the registry to see if it is indicated in there someplace.
    So use regedit and have it Find btiein (don't put the dll just look for matches to btiein.
    If you find it, delete it.

    If that does not work, download Win98Fix and StartDreck.

    Unzip them to a place where you can find them later to run. Preferably put each of them in their own directories. We are only going to run StartDreck right now.

    This step is very important - you must be completely disconnected from the internet (physically disconnecting the line to your analog modem or ethernet cable from your computer is best way to be positive).
    What we are going to try to do is use StartDreck to possibly locate the hidden file that is causing the problem. So now we are ready.

    - Run StartDreck.exe
    - Click on: Config
    - Click on: Unmark all
    - Check only the following boxes:
    - Registry | run keys
    - System/drivers | Running processes
    - Click on OK

    Reconnect your internet connection and get back here and post the log of results AS A TEXT ATTACHMENT.
     
  17. Homerj

    Homerj Private E-2

    Finally I am rid of all spyware, thank you chaslang for all of your help and patience.

    A virus was detected during a safe mode scan with Norton, not sure if you have heard of this one. It is called "swix.ocx (Bloodhound.packed)". Norton is the only product that you mentioned me to try that found the problem. It is located in C:\Windows\swix.ocx. Norton indicated that the delete failed but it looks like it was successful in quarentining the item. I did send them the file for analysis hopefully this will help. I know that NAV indicated that this is unknown and may not be a virus.

    I tried using "AntiVir" one of the free downloads and it was unable to find during a regular scan and in safe mode, both times all hidden files were shown.

    Is this something I need to worry about?

    homerj
     
  18. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    A Google search turned up nothing, odds are it was a random filenamed virus, often hard to spot. You need to be worried only if your surfing habits are questionable. This would include, typing wrong web addresses, porn, MP# and other file sharing clients, etc.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you try just booting in safe mode and deleting C:\Windows\swix.ocx Or if it is in quarantine now, can you delete the quaratine files while in safe mode?
     
  20. Homerj

    Homerj Private E-2

    The file was quarantined and I was able to delete it while in regular mode, should I have deleted the file in safe mode?

    I just ran another Norton scan, Adaware, Spy Bot and Spy Sweeper and no items were found.

    Major Attitude suggested that I need to be worried if my searching habits are questionable. If I happen to be on a website that was questionable does it mean I should worry and that I may still be infected? I do use Kazaa Lite could that be the source?

    Thanks,

    homerj
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I personally would not go near Kazaa or Kazaa Lite. While the lite version is not as spyware ridden, their servers and the users that share stuff do not take very good care of their systems and you are susceptable to picking up any malware/virus etc they have when you download from them. Plus at the time you are connected your harddisk is a shared drive. You do not even have to download to get infected. The fact that your drive is shared is sufficient.

    At any rate, sounds like you are clean now. But you should really take a look at your Add/Remove programs list and see what else is in there that you did not install (just in case).
     
    Last edited: Aug 11, 2004
  22. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    What I was saying was going to porn sites, typing in wrong web addresses, downloading files with file sharing programs, rushing around put you at greater risk. Theres no guarantee, of course either way. If you need to go to places like that, you should be using Mozilla Firefox for your browser or buying a program to protect you like Ad-Aware or Pest Patrol.
     
  23. Homerj

    Homerj Private E-2

    Thanks again for all of your help, you guys are great.

    I guess this is the end of my thread.

    homerj

    btw I will have a look at the add/remove and see if "Search Assistant - My Search" is still there.
     
  24. mlmusto

    mlmusto Private E-2

    help i have the crt32_v2.dll file that i can't remove.

    running win 98 SE.

    ideas?
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please start your own thread for this problem but the first steps you need to take are to please follow all the steps in this Sticky thread < READ ME FIRST: Basic Spyware, Trojan And Virus Removal >

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds