Help with BHO removal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Fishhead, Aug 26, 2004.

  1. Fishhead

    Fishhead Private First Class

    I am in need of some help. I use McAfee anti-virus and Spam Killer, along with Ad-Aware, SpyBot, and SpyGuard.

    This week I began receiving a "Spyware Guard Browser Protection Alert" that states "An attempt to change Internet Explore settings has been detected". The notice provides information about the file location and name and then asks "What would you like to do?". The choices are "Remove the BHO" and "Keep the BHO".

    When I respond by clicking remove the BHO, within a few minutes I receive the same message once again. This can be repeated over and over.

    If I click on Keep the BHO, the message stop appearing.

    I have no idea what this BHO is all about and therefore do not wish to keep it. I then use "Hijack this" and remove it.

    Within minutes I receive a new Spyware Guard notice about an attempted IE change with a new file name. Each time I keep the BHO and then delete it. The Spyware Guard message reapears and each time the file has a new file name.

    Clicking on properties for the file, the size is always 91.3 KB with a size on the disk of 92.0 KB. There is no other information about the file.

    My question is how can I find and remove the program that is generating these BHO addition attempts?

    Thanks.
     
  2. IOStream

    IOStream Private E-2

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    IOStream, while it is nice to try to help, please do not just guess. There are 1000's of BHO's out there. Some good some bad. Just point to random link that has nothing to do with Fishhead's problem will not help.

    First we need to identify the BHO. But before we even do that, procedures must be followed.


    Fishhead,

    Please follow all the steps in this Sticky thread < READ ME FIRST: Basic Spyware, Trojan And Virus Removal > If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    After following those steps, let me know if you still have a problem and we will see how to proceed. It may be that a HijackThis log will be needed but I will tell you when I want that.

    You can read up on HJT posting requirements too. Read the tutorial in this Sticky thread < Hijack This Tutorial And How To Post Your Log File > Do not post a HijackThis log until we ask you to and when we do it must be text document attachment to your message.

    Update! Due to Hijack This logs destroying search engine and web site searches, we now ask you do not post your Hijack This log file unless requested by us. It is for advanced users, so if you do not understand how to use it, you do not need it....yet. Instead, please tell us in your post what symptoms you are experiencing so we can try and resolve it that way. When, and if, we ask you to post your log file, please attach it as a file. To do this save the log file and select manage attachments in a new thread to upload it. All running programs should be closed, including your web browser, e-mail, items in the tray, anything you can close... Close before running Hijack This!


    Do NOT run Hijack This from the Desktop, a temp folder or choose run from the download. Place it in its own folder, for example C:\Program Files\HJT
     
  4. Fishhead

    Fishhead Private First Class

    Chaslang

    Thank you for the reply. I stepped through your suggestions and found that by disabling "Network Security Service" the process to add the BHO was stopped. When I enabled the service the BHO addition would once again begin.

    Is "Network Security Sevice" something that was added to my computer via a virus or trojan, or is this a Window feature that has been altered? In either case, how can I correct the situation.

    When I have opened services.msc and examine the properties for "Network Security Service", the listed service name is a bunch of characters most which are not on my keyboard. The path to executable is "C:\Windows\system32\javagj32.exe /s". Is this file the culprit that has been causing the problem? and if so would deleting it help?

    Thanks again.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have the either the HSA or About:Blank hijacker. The NSS is not a normal process that should be running. You can try just running About:Buster as indicated on the Readme First link I gave you but it may or may not work to completely remove this. If that is the case, my Generic Solution thread my help:
    http://forums.majorgeeks.com/showthread.php?t=38772
     
  6. glennk721

    glennk721 MajorGeek

    Just a quick question,,,are you running XP..if so you may have to disable system restore,,,,remove the bug,,,and reboot,,in safe mode,,,enable the system restore,,reboot,,and then it may not rewrite itself to the disk,,,Glenn


    Just a thought,,,,,chas what do ya think ???
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Glenn,

    About:Blank and HSA hijacks cannot be fixed too easily. As part of the Generic Solution I point to, system restore (for WinMe or XP) is disabled in the first step. But the "remove the bug" part is not so simple as you will see by looking at the link I gave.
     
  8. glennk721

    glennk721 MajorGeek


    Yes browsing through it now,,,learning as I go,,,,just was a passing thought,,,smiles,,,Glenn
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem! It's good to learn! You never know when you may need to use some of these procedures.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds