Bearshare

Discussion in 'Malware Help (A Specialist Will Reply)' started by BFLeigh, Mar 3, 2005.

  1. BFLeigh

    BFLeigh Corporal

    Hey all, I'm back.

    1. Plebs in the family downloaded Bearshare. I find it's put spyware on the PC.

    Something called WhenU or Save.exe I think. I need concrete info on what it is Bearshare contains/brings with it and what it is doing to the PC.

    2. I can use MS Antispyware; Spybot; and Ad-aware to locate and eradicate the spy/malware on the system no problem.

    However, my first hurdle is what if bearshare stops working/needs to be uninstalled along with the spy/malware?

    3. Can the program still run fine if I find and delete all the spy/malware?

    4. If so, is there a chance of Bearshare re-installing the spyware?

    If not, then I should uninstall Bearshare and spend time to make sure 110% that I've delete all the spyware that came with it. Tell me about Bearshare Lite.

    5. I recently installed MS Antispyware and love it, but it saw fit to delete important components of Kazaa Lite and therefore it became inoperable. I have uninstalled K-Lite altogether but still wondered why the program said it contained spyware in the first place.

    6. If I download and install Bearshare Lite; could I face the same problems with MS Antispyware?

    Thanks guys!
     
  2. TheOldThug

    TheOldThug First Sergeant

    Here is some info.

    Bearshare
    Bearshare2

    We feel that most P2P programs are asking for trouble.
     
  3. BFLeigh

    BFLeigh Corporal

    Hmmm, that hasn't helped me at all really.

    I did get a Lavasoft thing for removing WhenU.

    I don't want to start any attempts at removal until I know more about what I'm up against. Can I scrub the negative stuff away and keep this program? Deleting it is an absolute last resort at the moment.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you really must have a P2P program, try the below available on MG's. Free and free from malware.

    eMule
     
  6. BFLeigh

    BFLeigh Corporal

    I wholeheartedly agree that ps2 programs are bad news full stop. But like I said computer illiterates in the family got it and have been using it for a while without me knowing.

    What do I need to know about emule?

    Will I download and install spyware along with it?

    Will it slow down the PC in anyway?

    Will it irk my firewall (SP2's put a firewall on my PC, charming update it is), or any of my spyware programs?

    I run my MS antispyware/spybot/adaware trio every three days. You guys helped me great last time but I can't be around every time other people who use the PC inadvertently put spyware/malware on the system. One the best things I can do is put preventative tools in place.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I already told you in my previous message that Emule contains no malware. If it did, it would not be available on MGs!

    As far as a firewall is concerned, NO PC SHOULD BE RUNNING WITHOUT ONE! The one in SP2 is not sufficient. You should download one from the link below and install it. After that disable the built-in one of SP2's (you must only use one software firewall - and as said the one in SP2 is not good enough).

    How to Protect yourself from malware!
     
  8. BFLeigh

    BFLeigh Corporal

    Thanks chaslang.

    What is MGs' take on WinMX?

    Or Shareaza?

    I have given them both a trial run tonight and they seem fine. When I get a chance I will post a HJT log to help you guys help me get rid of WhenU/Bearshare - should I do that in here or start a new thread?
     
  9. TheOldThug

    TheOldThug First Sergeant

    Stay in this thread. Post HJT when you have it.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We also have WinMx on MG's but not Shareaza! As TheOldThug said post you HJT log here in this thread, but if you want opinions on which P2P programs are good or which is better, you should try the Software Forum. In this forum what you will normally get is a warning that they are all dangerous to use and that some of them are really bad and put malware on your PC.
     
  11. BFLeigh

    BFLeigh Corporal

    Here it is. I know the dangers of rebooting the PC before I get help so I'll probably post another one when I am more ready.

    WinMX seems to be fine - the reason I am asking so much is we are on dial-up, therefore need one for our modem. There are apparently ones which are geared towards broadband, and it is these ones which get more spy/malware protection.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are running multiple antivirus applications:
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE

    You must only run one AV package. Pick the one you prefer and uninstall the other. If you want us to pick for you, keep AVG and uninstall Norton!

    Are the below links your expected Start and Default pages? If not, what do you expect?
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.theage.com.au/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.smh.com.au
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.theage.com.au/

    Have you looked in Add/Remove programs for When U Save or Save Now? If you find them, uninstall them.

    Do you use the below Desksite application?
    O4 - HKLM\..\Run: [Desksite CMA] C:\Program Files\desksite\bin\cma.exe

    Just in case an uninstall for When U Save does not exist, you can use the steps below.

    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Look for the below process(es) and if found, End them:
    C:\Program Files\Save\Save.exe

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O1 - Hosts: 64.91.255.87 www.dcsresearch.com
    O4 - HKLM\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\Save <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  13. BFLeigh

    BFLeigh Corporal

    We had people over who decided to clean the PC. I've done another log for you. Tell me if bearshare/whenU/save is still there please.

    I'll do away with Norton 2002 I think.

    I found Save in Add/Remove, and when I said remove it, it said that there was an error/it could already have been moved - do you want to remove it from the list? I said yes.

    I don't know what the cma.exe is.
     

    Attached Files:

  14. Norby

    Norby Private First Class

    When I do downloads, I only do them from "MajorGeeks" or "Cnet.com" there are trusted sites. I like Cnet because there downloads are tested first,have good reviews and if they contain Spyware or Adware they tell you.
    Always do research before you download,play it safe...
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are still running multiple antivirus applications! You must fix this now!

    cma.exe has to do with DeskSite CMA siftware - "retrieves new content from the DeskSite Data Center"

    Are you using this for something to do with music downloads?

    You can have HJT fix the below line:

    O1 - Hosts: 64.91.255.87 www.dcsresearch.com

    dcsresearch is not a bad site. But they do not need to be in your hosts file and should not be adding it when you install their software.... but they do.
     
  16. BFLeigh

    BFLeigh Corporal

    I will take care of the antivirus stuff once I know I have these outstanding issues taken care of.

    HJT will eradicate whatever dcsresearch has on my PC right?

    More importantly, this Desksite thing is completely alien to me. The only thing I'm prepared to let do anything like what you it is doing is WinMX.

    How do I get rid of cma.exe?
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The antivirus problem should be repaired first. Having two can cause neither of them to work properly.

    dcsresearch is not a bad company. They make some valuable tools. Having the host line entry is not necessary nor is it desired. Having HJT fix that line just removes that entry from your hosts files. Nothing else.

    Look for Desksite or something like it in Add/Remove programs and uninstall it if found. If you cannot find it in Add/Remove programs, have HJT fix the below line:

    O4 - HKLM\..\Run: [Desksite CMA] C:\Program Files\desksite\bin\cma.exe

    And then boot into same mode and delete the below folder:
    C:\Program Files\desksite

    Now reboot back to normal mode.
     
  18. BFLeigh

    BFLeigh Corporal

    Here's the log.

    Tell me what I need to do to uninstall Norton - just go to add/remove programs?

    I am reluctant because maybe there's something that Norton 2002 (old program it is) is doing something that AVG still isn't and therefore Norton's worthwhile keeping around. For now I'm happy to have AVG as the only one.

    For example, Norton tells me that my MS Outlook emails are screened and checked as they come in and go out - AVG doesn't, all it does is add a small line to the bottom of received mail 'this has been checked by AVG.' Same thing I know, but the Norton one just seems more thorough. I could attribute this to its overtness (a pop-up dialog box and all) and the fact I've become attached the program over the long amount of time I've had it.
     

    Attached Files:

  19. Marlene3369

    Marlene3369 Private First Class

    Just a little coment,personally I would stay with Norton's ( esp. 2002 the newer versions suck ) I've had Nortons for 8 years now and it's never let me down...Just putting in my two cents,,,,,I hope you guys don't mind.
    Marlene,
    Hugs
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are not paying for the updates to Norton (and I don't know if they even support the 2002 version anymore) then it is out of date and not reliable. If you are able to get updates for Norton and you pay for them yearly and don't mind that then keep Norton and uninstall AVG.

    Our experience is that AVG and Avast work just as well (if not better), they use less system resources, and they have free versions. You can buy more advanced versions if desired.
     
  21. BFLeigh

    BFLeigh Corporal

    How does it look now?
     

    Attached Files:

  22. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  23. BFLeigh

    BFLeigh Corporal

    Ah, I was wondering when that would come out.

    This site's download pages aren't seeming to load for me all the way, can someone give me a direct link please?

    The header loads fine but then all I get is a dark green background and the Loading Page....' message at the bottom of IE just stays there. Yes I'm on dial-up.
     
  24. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Its been out a while now, since the middle of Feb. I cant belive noone caught this :p

    The direct link is below:)

    http://216.180.233.162/~merijn/files/HijackThis.exe
     
  25. BFLeigh

    BFLeigh Corporal

    Thanks.
     

    Attached Files:

  26. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Log is clean! :)

    Have Hijack This fix the below entry:

    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u

    Note: After removing this entry, reboot and do another scan with HJT. If it comes back follow the below steps.

    Right click on My Computer and select Properties. Now click on the Advanced Tab, at the bottom locate Startup & Recovery and click Settings. Now, where it says "Write debugging information" you want it set at the following:
    • Small memory dump (64 KB)

    Note: If its already set at this before you change it, then set it to NONE.

    Chaslang or Thug will check back when time permits:)
     
  27. BFLeigh

    BFLeigh Corporal

    Did the first one, it was still there. So I set it to none. I immediately did HJT and it says it's still there. I haven't rebooted though.

    Something strange happened when I rebooted, it isn't new either - I am not sure how long it's been happening but I can't remember it happening before the WhenU etc got on the PC. In the next post I shall try and post a screen capture.
     

    Attached Files:

  28. BFLeigh

    BFLeigh Corporal

    Here:
     

    Attached Files:

  29. BFLeigh

    BFLeigh Corporal

    Here #2:
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  31. BFLeigh

    BFLeigh Corporal

    Ah, a hardware issue. At least I've isolated the problem.

    Log H:
     

    Attached Files:

  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does that mean you have actually found the problems now and you have not fixed it yet?
     
  33. BFLeigh

    BFLeigh Corporal

    Yes. It's unfeasible at this point in time. If it was software than it'd be no worries.
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't understand why?
     
  35. BFLeigh

    BFLeigh Corporal

    I can't do that kind of work (hardware removal/re-installation; fooling around with the computer's connection ports) at this point in time (perhaps around the end of April, I reckon should be able to) because of how many people use this particular computer and the way our office is set-up/computer is placed in and around our furniture.

    I'll keep in mind that I am able to fix THIS issue by spending a little while with the hardware out all over the place but for now, are there any other problems I need to deal with?
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based upon your last HJT log, you were clean!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds