Begin2search & toolbar.desktoptraffic.net?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by quintesscence, Nov 26, 2004.

  1. quintesscence

    quintesscence Private E-2

    Hi all. This is my first post so go easy on me.... ;)

    I have that damned begin2search toolbar in my browser and I also have a problem with lots of words on any random web page turning into lime green colored links (toolbar.desktop.traffic.net?). I have run: Norton Antivirus 2002 (yes, I manually updated my virus definitions), Adaware 6.0, and Spybot Search and Destroy. As far as I can tell, neither of these programs found anything relevant to the problems I've been having. Furthermore, my webpages hang before loading. I've just dowloaded Hijackthis and will be happy to post an attachment log upon request.

    Thanks so much!!

    Kelly
     
  2. PhilliePhan

    PhilliePhan Guest

    Hi Kelly,

    Welcome to MG's.
    Generally, we like people to start with the Cleanup Tutorial HERE:
    READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan and Virus Removal

    This will remove a lot of stuff that would otherwise clog a HJT log.

    You may also want to try this tool. Make sure to put it in its own folder - C:\Program Files\OKSM and run it Twice: OmegaKillerSM v1.2

    When working the Tutorial, Please note the steps that you are able to complete and the ones that give you problems. Note that you need to be in Safe Mode with System Restore OFF (if you have it - you didn't give OS) and have the Viewing of Hidden Files ENABLED as per the instructions in the link. Make sure to do the Online Scans.

    Post back and let us know how you fared. Also, send us a HijackThis Log. Make sure to follow the instructions below:

    Note that your HijackThis should be up-to-date (v1.98.2) and MUST be extracted to its own safe folder - C:\Program Files\HijackThis!

    If you need a Fresh Download of HJT, get it HERE: HijackThis 1.98.2

    Also note that, before you scan, you MUST close all running programs including your web browser, e-mail and items in the system tray.

    Please save your HJT Log and attach it via the "Manage Attachments" tool in the Additional Options section when you post.

    Somebody will take a look when they get a chance.

    Best luck :)
    PP
     
  3. quintesscence

    quintesscence Private E-2

    Wow. That was quite the experience. Okay, so I followed the instructions in the "Basic Spyware, Trojan, and Virus Removal" tutorial. Trend Micro's Free Online virus scan showed 9 viruses and they were all deleted. McAfee AVERT stinger showed that my system was clean. CCleaner removed 1,407.6 MB of data. Ad-Aware showed about 500 infected files and I quarentined those files which I recognized as unhealthy. Spybot detected a few things and successfully removed them all. Both CWShredder and Kill2me showed a clean system. I then booted my computer up again normally and the green link problem was still there and the browser was still hanging. Also, there was an error at startup--a file could not be found. I don't remember off the top of my head what the file was but I can restart in a minute and get that info.

    Attached is my hijackthis log. Thanks so much for all of the help.
     

    Attached Files:

  4. quintesscence

    quintesscence Private E-2

    addendum

    Okay so I just restarted and the error message that I'm getting is: "Error loading C:\programfiles\wildtangent\apps\cda\cdaengine0400.dll The specified module could not be found". One more thing that I forgot to mention--I did run the OmegaKiller twice and it came up clean. Thanks!
     
  5. PhilliePhan

    PhilliePhan Guest

    Re: addendum

    Hi Kelly,

    You should uninstall any remnants of Wild Tangent as it is just begging to give you problems. Use Add or Remove Programs. Then, delete the folder, if it remains: C:\programfiles\wildtangent

    I am heading out the door, but Chaslang or I will take a look at your HJT Log when one of us gets a chance and see what else needs to be done.

    ***I took a quick glance and there is still a bunch that needs to go! Hang in there!

    PP :)
     
  6. quintesscence

    quintesscence Private E-2

    Well, there were no remnants of Wild Tangent in either the Add/Remove Programs list or in the Program Files folder. However, I ran a search for "Wild Tangent" and found a file called "wildtangent.jar" in C:\ProgramFiles\java\j2re1.4.1\lib\ext. I didn't delete it, I just left it alone.

    I don't know if that info is relevant but I thought I'd mention it. Thanks again for all of the help. :) I'll check back tomorrow!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have system restore disabled and viewing of hidden files enabled (per the tutorial).


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.begin2search.com/sidesearch.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.begin2search.com/sidesearch.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.begin2search.com/sidesearch.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    O2 - BHO: ohb - {CB5B2BC6-F957-4D8A-BE67-83F3EC58BA01} - C:\WINDOWS\System32\dsktrf.dll

    I don't have any info on this wdankl.exe file but I would suspect that it is bad. Unless you know otherwise, fix it too.
    O4 - HKLM\..\Run: [wdankl] C:\WINDOWS\wdankl.exe

    O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
    O16 - DPF: {6A4747FD-877D-4074-9C4F-2F5FF0164B7A} - http://connect.tickle.com/hub/jump.html?d=address_importer_install_IE&c=oFFuu6jXY9EWCeM8OgZQ2xnDjxEkYbnj
    O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl) - http://secure2.comned.com/signuptemplates/ActiveSecurity.cab

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\dsktrf.dll
    C:\Program Files\WildTangent <--- the whole directory if found.

    Let's hold off on deleting C:\WINDOWS\wdankl.exe, until we are sure you do not need it.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  8. PhilliePhan

    PhilliePhan Guest

    Darn it Chas, I'm last again! No need to post my fix, I guess. Drat!!

    Surprised you didn't mention the LimeWire and the dangers of P2P? ;)

    PP
     
  9. quintesscence

    quintesscence Private E-2

    Hi again,

    Okay so I followed the instructions and fixed the problems that you suggested using hijack this. I did not, however, find:

    C:\WINDOWS\System32\dsktrf.dll or
    C:\Program Files\WildTangent

    when I booted up in safe mode.

    The browser seems to be working fine now--those pesky green links are gone and so far there is no hanging. woooooohooooo!! Oh, and as I mentioned before, the only wildtangent file that I can find is located in C:\ProgramFiles\java\j2re1.4.1\lib\ext

    Is this file legit? Oh, and I uninstalled Limewire PhilliePhan--I've been meaning to do that for a while. I usually use suprnova or other torrent sites for downloading. This is safe, yes?

    Thank you both SO much for all of the help. I'm so glad I found this site. You guys are the best!!

    Kelly

    P.S. most recent hijack this log attached
     

    Attached Files:

  10. PhilliePhan

    PhilliePhan Guest

    Hi Kelly,

    Your HJT Log looks OK :) Chas will probably be along to doublecheck it.

    Go ahead and Delete that wildtangent.jar - WT like to install itself everywhere, it seems!

    While you are here, I suggest that you take a look at some of his recommendations: How to Protect yourself from malware!

    Happy Computing :)

    PP
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Confirmed clean log!
     
  12. quintesscence

    quintesscence Private E-2

    Thanks for all the help guys...everything seems to be running smoothly!! :)

    Kelly
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome again! We love smooth running systems! ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds