Attempted Browser Hijack & a Search Bar toolbar that won't go away

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by shewolf, Sep 26, 2004.

  1. shewolf

    shewolf Specialist

    I am having a major problem with malware by the vendor Lop that will not leave my computer. I keep getting the Search Bar that is on top of my internet explorer page (just below my yahoo search bar) and also one on the bottom portion of my screen just above the taskbar. This Search Bar will not go away even when I scan with Ad-Aware, Spybot S&D, or NoAdaware. The Search Bar comes up when I click on my internet explorer to view web pages etc.. I can disable the one on top of my screen but it comes back eventually and its not listed in my Ad/Remove programs either.
    My browser (homepage) has been under repeated attack all day long by Search Bar. I have a program called spyguard installed and it keeps warning me when Search Bar tries to takeover my homepage. I also get some icons on my desktop from this Search Bar malware those icons are Travel, Printer Cartridges, Poker, Internet, Casino Online, & Website Hosting. The only way I can stop these attempts is to scan with Ad-Aware and it will stop the attempts for a period of time then they start back up again.
    I have downloaded hijack this and below is my log from the scan I would appreciate any help anyone can give me on this as I am at wits end. My computer worked just fine yesterday and then bam all of a sudden today I get nothing but homepage hijack attempts by Search Bar and I have unwanted toolbars (Search Bar) on my computer when I open Internet Explorer to check yahoo emails or visit websites. I have not downloaded any new programs since 9-22 but that was for my new Sony digital camera. My computer is up to date on Windows Updates & my Norton Systemworks and Firewall are up to date as well. I have tried to do a system restore to 9-22 & 9-25 but my computer will not restore to an earlier point in time.
    Here we go again the hijack attempts just started again it is now 11pm for me and the last attempt was at 10:15pm. I do have a log file from my spyguard showing the information from the hijack attempts if anyone wants to read those I can post those.
    If anyone can help me out with this problem I would really appreciate it as I said before I am at wits end and not sure what else to do.
    Thanks...
    shewolf

     

    Attached Files:

    Last edited by a moderator: Sep 27, 2004
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We have guidelines about posting HJT log that must be followed.

    Please follow all the steps in this Sticky thread < READ ME FIRST: Basic Spyware, Trojan And Virus Removal >

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.


    NOTE: You should read the tutorial in this Sticky thread < Hijack This Tutorial And How To Post Your Log File >

    Do not post a HijackThis log until we ask you to and when we do it must be text document attachment to your message. When, and if, we ask you to post your log file, please attach it as a file. To do this save the log file and select manage attachments in a new thread to upload it. All running programs should be closed, including your web browser, e-mail, items in the tray, anything you can close... Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder or choose run from the download. Place it in its own folder, for example C:\Program Files\HJT

    And the most likely reason that you have a LOP problem is because you installed Messenger Plus 3. You should have read the license agreement. This is software should be uninstalled immediately. I'm not sure if it will clean up all the crap it put on your system.
     
    Last edited: Sep 27, 2004
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should uninstall NoAdaware. It is a rogue/suspect spyware remover program. See this link:
    http://www.spywarewarrior.com/rogue_anti-spyware.htm

    Also are you sure you mean spyguard? Did you mean SpywareGuard? Be very careful of names you refer to. Be exact with names. Even the spaces are important. There are a load of bad programs out there that use similar names to good programs.

    I'll get you started fixing some items but make sure you run all the steps in the READ ME FIRST.
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.jalegmhliteetjeiae.info/...YSwLh8c0G7f.cgi
    O2 - BHO: (no name) - {C3110939-40BF-9650-D2A5-8602A13BFD39} - (no file)
    O4 - HKLM\..\Run: [Support cdrom] C:\PROGRA~1\README~1\Bin Store.exe
    O4 - HKLM\..\Run: [locks soap close beep] C:\Documents and Settings\All Users\Application Data\global soft locks soap\magsup.exe
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - (no file)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - (no file)
    Per the READ ME tutorial, make sure system restore is disabled and you have viewing of hidden files enabled.
    Boot in safe mode and delete:

    C:\PROGRA~1\README~1\Bin Store.exe
    C:\Documents and Settings\All Users\Application Data\global soft locks soap <--- the whole directory
     
    Last edited: Sep 27, 2004
  4. shewolf

    shewolf Specialist

    I will give this all a try and let you know what happens. I am sorry about posting the HJT and also not reading the other information to begin with. I had just been in front of the computer for about 6 hours trying to solve my problem and I felt like I was going crazy at 11pm.
    Thanks for your time and help..
    shewolf
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Let us know the results.
     
  6. shewolf

    shewolf Specialist

    Ok I have done the steps for preparing and cleaning and removal. Prior to doing all that I did uninstall the Messenger Plus3 and the NoAdware.
    With the cleaning and removal the trend micro found 4 items which I deleted from my system as they were non cleanable (I knew what these items were and did not need them so deemed it safe to delete them from my system) I did another scan and nothing was found.
    Symantec scan produced all safe results
    AVERT stinger scan nothing found
    CC cleaner ran
    ran my main spyware scans
    Ad-AwareSE nothing found
    Spybot S&D found 2 problems & fixed those 1=DSO Exploit 2=spyferret
    ran secondary scans
    CWshredder, kill2me, etc and nothing was found
    rebooted to normal mode as I am running XP and soon as I restarted my computer the attempted browswer hijack alert from spywareguard (yes it is spywareguard I mistyped it in my very first post) came up I can post the description from that if you want me to. However this time it came up a few times each with 3 different value nameswas for start page, search page, and Default_Search_URL . I clicked keep old value which is my yahoo sign in page that I have had set for my home page for several months now. So, I am hoping that this most recent hijack attempt was just because I had done all the cleaning and removal steps and was in safe mode prior to rebooting to normal mode. If I continue to get the browser hijack attempts I will let you know and I have ran another HJT and can attach the log if you want to see it.
    Currently I do not have that search bar on my internet explorer either and I hope it stays away.
    Thank you for your time and help I appreciate it. :)
    shewolf
     
  7. shewolf

    shewolf Specialist

    Update to HJT scan and log and to my previous problems. So far so good my browser hijack attempts have stopped (knock on wood). I have ran fixed and re ran the HJT and did the analyse that was given on this site. Now I have a few questions regarding an entry that the analyse says is Nasty. It is C:\WINDOWS\system32\slserv.exe the tip says If you have SiS Drivers installed, this entry is normal. It could also mean that you have been infected by the W32/Gaobot.CR virus. Use an Antivirus to check this.
    First yes I have ran my Norton AV (which is up to date) and no viruses were detected.
    Now my questions regarding the slserv.exe are:
    1) what is an SiS Driver?
    2) Should I delete this?
    3) If deleting what steps do I need to take to delete? Such as turn off System Restore & run in safe mode or what?
    4) How do I delete a C: file as it does not show up on the HJT with a checked box to delete??
    If you want to see my HJT log let me know and I will attach it..
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    SIS = Silicon Integrated Systems. They make chipsets for mother boards. They have graphics card, wireless LAN, audio etc drivers. You need to check out your mother boards documentation. But I would be willing to bet its is okay. That HijackThis analyzer is not perfect. You need to be careful using it.

    For question #4 (which you don't need to do for this file), you would run Windows Explorer and delete the file using it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds