Can't get rid of a toolbar caused by a spyware program!! Please help!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by GStam66, Jul 3, 2005.

  1. GStam66

    GStam66 Private First Class

    This toolbar just came out of nowhere! It appears in windows such as recycle bin, my pictures, my computer, Internet Explorer, etc. , but doesnt appear in Mozilla Firefox. I have tried Spybot and Ad-Aware, but they didnt help at all.

    I cant edit what toolbars i can view, and im losing more free space on my hard drive every day! There is a button that is for removing the toolbar, but the company (STOPzilla) wants $20 to remove it!!

    Also, when i close a window, it sometimes changes to an about:blank window, and then it closes normally.

    Please Help!!!
     
  2. tblue

    tblue Corporal

    Hi GStam66,
    The below thread is a good place to start. Make sure you follow the directions. Post your results and Chas or BJ will be happy to assist you from there.
    Good Luck, :D
    T.Blue

    [thread=35407]PLEASE READ THIS BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal ![/thread]

    -Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as
    suggested? Etc
     
  3. GStam66

    GStam66 Private First Class

    Will do. I will have the results up soon. I am curious, how often are problems with toolbars related to spyware? Is this a common problem?
     
  4. tblue

    tblue Corporal

    From what I have seen ....yes. I guess alot of programs have there own?? Tool bars aggravate the crap outta me :eek:
     
  5. GStam66

    GStam66 Private First Class

    strange... I ran Trend Micro, and it closed all my windows after fixing something...

    I have Trend Micro PCCillin, will that do the same thing?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    '

    That's a little vague. What did it remove? And if it removed the problem, it may have been necessary for it to close all windows to fix the problem. What windows are you referring too? It is always best to have nothing running except the scanners (online or others) when performing these steps.

    Complete the remaining steps of the READ ME FIRST and then report back on all steps and on what problems remain.

    Question: Are you saying you have a problem with StopZilla and you do not want to have StopZilla? If so, uninstall it using Add/Remove programs.
     
  7. GStam66

    GStam66 Private First Class

    The file it fixed was a temporary internet file, just a garbled mass of letters after H:/...../TemporaryInternetFiles/...

    STOPzilla is the company that is charging $20 to remove the toolbar. I cant remove it through Add/Remove Programs, but my sister has a "uninstall viewpoint toolbar" icon in her folder, but when i click it, nothing happens except a dialogue box asking if im sure about uninstalling. I hit "yes", but its still there.

    My friend i can fix this through regedit, do you guys think i should try that?

    as far as Trend Micro,im gonna try that again, and then ill post my results.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Viewpoint Toolbar is installed by AOL with both there standard software and when you install AIM. Even though you do not ask for it they install it anyway. Look in Add/Remove programs for a variety of Viewpoint stuff (like Viewpoint Manager and Viewpoint Toolbar) and just uninstall them.

    If you just finish running the READ ME FIRST steps we can get around to fixing all of your problems. They are easy to fix. Just finish the READ ME FIRST and then I will give you the next steps.

    While you are at it, why don't you uninstall StopZilla. Sounds like you only have the demo version anyway and the program is not really needed. Browsers like Mozilla Firefox have built in popup protection.
     
  9. GStam66

    GStam66 Private First Class

    i never had STOPzilla, STOPzilla is the name of the site/company that wants money to remove the toolbar. I assume that stopzilla puts out those tolbars with spyware, so they can make money off of removing them.

    i will have the scan results shortly.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay you said that back in message 3. Are your talking about results from the whole READ ME FIRST?

    Is it Viewpoint Manager and Viewpoint Toolbar that you are having problems with?
     
  11. GStam66

    GStam66 Private First Class

    i am doing the scans required as per READ ME FIRST. Those are the results im talking about. I have Trend Micro PCCillin, and i ran that before i read the READ ME FIRST page.

    Viewpoint is not the problem. The problem is some random toolbar that appeared one day, and it appears on almost every window, except for mozilla firefox. I cant find any way to remove it, and it prevents me from editing any toolbars.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your previous message said "but my sister has a "uninstall viewpoint toolbar"

    Just complete the READ ME FIRST which was the first thing explained to you and then follow the steps below exactly:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).


    By the way it could also be possible that the following would help you: Toolbarcop
     
  13. GStam66

    GStam66 Private First Class

    Alright, Trend Micro is still scanning, but i read ahead a bit in the READ ME FIRST page. I dont have Ad Aware SE. (Every time i try to run it, it keeps telling me to insert a disk into the drive, when i dont have a disk because i downloaded it.) Is Ad Aware 6 good enough?

    Also, i tried that toolbarcop program, and i have no idea what i should and shouldnt keep or what toolbars are good and what toolbars are bad... Do you want me to post a list of the toolbars Toolbarcop found?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No Ad-ware 6 is too old. If you installed Ad-Aware SE from a removeable drive or had one installed at any point, you may need to reboot your PC to remove references to the external drive from your registry. Ad-Aware is trying to scan ALL drives. If you cannot get it to work, just skip it and continue.

    You can post what Toolbar Cop found but don't you know which toolbars you use and which you do not use/need. Are you running Win XP SP2?

    You know you really are not supposed to be logged in and running anything else while running the READ ME FIRST. They only time you should even be connected is while running the online scanners. After that, you should be in safe mode and disconnected from the internet.

    Are you running Ad-Aware SE while in safe mode?
     
  15. GStam66

    GStam66 Private First Class

    I guess i will have to skip the Ad-aware step...

    As far as toolbarcop, i just want to see if there are any toolbars that you guys have seen before, and are sure that they are from malware/spyware programs. I attached a word document, that shows the toolbars ToolbarCop found.

    Trend micro is done, and there were only 3 files, all of which "couldnt be accessed":

    TROJ STRTPAGE.I H:\WINDOWS\system32\sysp.dll
    TROJ STRTPAGE.H H:\WINDOWS\system32\systemp.dll
    TROJ STARTER.B H:\WINDOWS\system32\systemp.exe

    I am not using SP2, because it was causing a lot of problems, and i had to uninstall it.

    I tried running ad-aware SE from safe mode, but i still got the "no disk" message.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's ignore Toolbar Cop stuff for now. You need to complete the READ ME FIRST steps and then do what I gave you in message # 12. Don't waste any more time posting until you have completed ALL of those steps (include message # 12).
     
  17. GStam66

    GStam66 Private First Class

    ok, i did what you said in READ THiS FIRST, ran HijackThis, and here is the log file. if the first one doesnt work, the second one should.
     

    Attached Files:

    Last edited by a moderator: Jul 5, 2005
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First thing to do is to uninstall all but one antivirus application. You have AVG and PC-Cillin. Pick which one you prefer and uninstall the other.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your OS and IE versions are way out of date and represent a major security risk. After fixing your current problems you MUST get updated. We will cover that later.

    You must remember to exit all browsers ( H:\Program Files\Internet Explorer\iexplore.exe ) before using HJT.

    Goto Add/Remove programs and look for uninstalls to the below and uninstall if found:
    H:\Documents and Settings\George\Desktop\dlc\SpySweeper v3.0 b113 with crack\Crack\SpySweeper.exe <--- do not use cracked software. You are asking for trouble.
    Ares <--- contains malware and is a possible source for many of your problems
    WinTools
    Media Access
    Internet Optimizer
    SpyFighter <--- this is a rogue

    I'm working on the rest of the fixes.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    H:\Program Files\Common Files\WinTools\WToolsS.exe
    H:\Program Files\Media Access\MediaAccK.exe
    H:\Program Files\Media Access\MediaAccess.exe
    H:\WINDOWS\System32\systemp.exe
    H:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
    H:\Program Files\Common Files\WinTools\WSup.exe
    H:\Program Files\Ares\Ares.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch.com/ie.aspx?tb_id=50245
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50245
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50245
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - H:\WINDOWS\nem220.dll (file missing)
    O2 - BHO: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - H:\WINDOWS\System32\phvub.dll
    O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - H:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
    O3 - Toolbar: YourSiteBar - {86227D9C-0EFE-4f8a-AA55-30386A3F5686} - H:\PROGRA~1\YOURSI~1\ysb.dll
    O3 - Toolbar: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - H:\WINDOWS\System32\phvub.dll
    O4 - HKLM\..\Run: [SpyFighterMonitor] "H:\Documents and Settings\George\Desktop\George's Folder\SpyFighter\SpyFighterScanner.exe" monitor
    O4 - HKLM\..\Run: [wuviewer] H:\WINDOWS\System32\wuviewer.exe
    O4 - HKLM\..\Run: [WinTools] H:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
    O4 - HKLM\..\Run: [Media Access] H:\Program Files\Media Access\MediaAccK.exe
    O4 - HKLM\..\Run: [[01]##############################################################################################################################] H:\Program Files\Internet Optimizer\update\rogue.exe
    O4 - HKLM\..\Run: [onfsmta] h:\windows\system32\gsavqwc.exe r
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - H:\Program Files\PartyPoker\PartyPoker.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - H:\Program Files\PartyPoker\PartyPoker.exe (file missing)
    O16 - DPF: {11212111-2121-1311-1141-115611111222} - ms-its:mhtml:file://d: oo.mht!http://195.95.218.82/users/zoom/web/axe/x.chm::/update.exe
    O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/ClickYesToContinue/ie/bridge-c356.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/028d2a69c1a7ed27f920/netzip/RdxIE601.cab
    O21 - SSODL: systemp - {C7961D6B-B6ED-4C49-BEA8-590A8EF243F9} - systemp.dll (file missing)
    O23 - Service: WinTools for IE service (WinToolsSvc) - Unknown owner - H:\Program Files\Common Files\WinTools\WToolsS.exe

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    H:\Program Files\Common Files\WinTools <--- the whole folder
    H:\Program Files\Media Access <--- the whole folder
    H:\Program Files\Internet Optimizer <--- the whole folder
    H:\Program Files\Ares <--- the whole folder
    H:\Program Files\YOURSI~1 <--- the whole folder, probably really named YourSiteBar
    H:\Documents and Settings\George\Desktop\George's Folder\SpyFighter <--- the whole folder
    H:\Program Files\PartyPoker <--- the whole folder
    H:\WINDOWS\System32\systemp.exe
    H:\WINDOWS\System32\phvub.dll
    H:\WINDOWS\System32\wuviewer.exe
    h:\windows\system32\gsavqwc.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.


    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    If the O23 Service is still there for WinTools, do the below before posting the HijackThis log.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.

    On the page that opens, scroll down to WinTools for IE service or WinToolsSvc. Then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, open up HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    WinToolsSvc
     
  21. GStam66

    GStam66 Private First Class

    WOW! My computer runs so much faster, my free space on my hard drive doubled more than doubled, and that damn toolbar is gone!!!!

    THANK YOU SO MUCH!!!

    oh yeah, i attached the new logfile you wanted to see.

    THANK YOU AGAIN!!!
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    You still must remember to exit browsers ( H:\Program Files\Internet Explorer\IEXPLORE.EXE ) before using HijackThis.

    Also you still have both AVG and PC-Cillin installed. You MUST pick the one you want to keep and uninstall the other. This will also speed things up.

    You still have some problems. Please answer the below questions:

    Did you find WinTools in Add/Remove programs last time? Are you sure you selected it in the HJT lines I gave you to remove?

    Did you use the procedure I gave you at the end to remove the O23 service if the line was still in your log? It does not look like it.

    Did you actually Reset Web Settings as requested? It does not look like it, otherwise Majorgeeks would be your home page. And websearch would be gone? If you did, then something reset it back.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After answer my previous questions and uninstall one of the antivirus applications, continue with the below:

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes. (You probably will not find the below but I want to be sure just incase they came back.)
    H:\Program Files\Common Files\WinTools\WToolsS.exe
    H:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
    H:\Program Files\Common Files\WinTools\WSup.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch.com/ie.aspx?tb_id=50245
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50245
    O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - H:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll (file missing)
    O4 - HKLM\..\Run: [WinTools] H:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
    O23 - Service: WinTools for IE service (WinToolsSvc) - Unknown owner - H:\Program Files\Common Files\WinTools\WToolsS.exe (file missing)

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    H:\Program Files\Common Files\WinTools <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and CHECK your HJT log for the O23 service entry for WinTools. If it is still there run the steps below in the quote box to fix this. And tell us how things are working.
    Now post a new HJT log and tell us how things are working.
     
  24. GStam66

    GStam66 Private First Class

    After sending the last report, I was able to find the remnants of WinTools, and I deleted them.

    I did indeed reset my web settings, but i kept my homepage as www.gmail.google.com. Sorry for not telling you before.

    I didnt have any WinTools processes to kill, they werent there at all.

    The O23 service was gone, but the others were still there.

    As far as uninstalling an antivirus program, which do you think is better? PCCillin has a realtime scanner, but AVG has a lot more updates and it updates more often than PCCillin.

    I am running HJT again, and i will post the results soon.
     
  25. GStam66

    GStam66 Private First Class

    Here are the final (hopefully) results:
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is now clean (just the two antivirus issue remains). The decision on what to keep is up to you. Both are good. I assume you have a paid version of PC-Cillin? Keep what you prefer. If you prefer free, keep AVG.
     
  27. GStam66

    GStam66 Private First Class

    I got a special "Windows Utilities" disk when I bought my computer from CompUSA. It included a free copy of PCCillin, Adobe Acrobat Reader, a bunch of drivers, and tons of other helpful freebies.

    I guess I'll keep PCCilin because of the realtime scanner, and if i want AVG back, I can always go to the Grisoft site.

    Thanks for all your help! You guys are awesome! Especially you chaslang, you're a genius!
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your free copy of PC-Cillin is not free forever. Eventually you will need to pay to keep it updated.

    AVG can also be downloaded from MG's and it is list in the link below. You should now follow the steps in that link to help keep you clean:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds