http://lop.com/passthrough/newpass2.html

Discussion in 'Malware Help (A Specialist Will Reply)' started by janiea, Jun 22, 2005.

  1. janiea

    janiea Private E-2

    I have read the details from Hunter McCormack Feb 2005. I have this similar toolbar which only disappears when you put a couple of random characters in and press enter. I have run all the stuff in READ ME FIRST BEFORE ASKING FOR SUPPORT but not run nything in safe mode. The toolbar is so annoying. I have got rid of pop ups successfully but seem to be stuck with this toolbar. I have downloaded Hijack in case you need to see the logs. Can you help please?
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    This particular toolbar usually comes from Messenger Plus! 3. You can remove this by going into Control Panel, Add/Remove Programs and uninstalling Messeger Plus 3!.

    After you uninstall the above (if it remains) procede with the below:

    http://www.majorgeeks.com/images/grenade.gif Download HijackThis 1.99.1

    http://www.majorgeeks.com/images/grenade.gif Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    http://www.majorgeeks.com/images/grenade.gif Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the ZIP file as your backups will not be safely stored.

    http://www.majorgeeks.com/images/grenade.gifBefore running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    http://www.majorgeeks.com/images/grenade.gifRun HijackThis and save your log file.

    http://www.majorgeeks.com/images/grenade.gif Post your log as an ATTACHMENT to your next post. (Do NOT copy/paste the log into your post as it will be removed).

    http://www.majorgeeks.com/images/grenade.gifNeed help with HJT? See this thread: NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting
     
  3. janiea

    janiea Private E-2

    Cant find messenger plus 3 in add/remove programs although I know my son downloaded it a couple of months ago. thought I had deleted it. Have attached HJT log, ran it from program files but saved the log on desktop. hope this is ok. Many thanks
     
  4. janiea

    janiea Private E-2

    have tried again to attach log but cant seem to succeed. Can you help please
     
  5. janiea

    janiea Private E-2

    Trying again to attach HJT log file. ( closed everything before I ran HJT) Looks okay this time. thanks again
     

    Attached Files:

  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, just to clean some of those ActiveX controls scan with HJT and have it fix the below entries:

    O16 - DPF: {07446F2A-FE9C-11D1-8E31-08005AAA630C} (IFS_Data Control) - http://tescoonline.co.uk/dbpc2/controls/2.6.11.0/IFS_Serv.cab
    O16 - DPF: {1096842F-FEE6-11D2-965E-0010E3622565} (IFS_Lib00) - http://tescoonline.co.uk/dbpc2/controls/2.6.11.0/IFS_OLB.cab
    O16 - DPF: {219CF65A-B13C-11D2-8D4A-0004ACF74B57} (IFS_Lib04) - http://tescoonline.co.uk/dbpc2/controls/2.6.11.0/IFS_Lb04.cab
    O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) - http://www.miniclip.com/platypus/miniclipGameLoader.dll
    O16 - DPF: {29548124-B145-11D3-BC1B-0010E3624141} (IFS_Lib18) - http://tescoonline.co.uk/dbpc2/controls/2.6.11.0/IFS_Lb18.cab
    O16 - DPF: {35831956-96AF-11D3-BC12-0010E3624141} (IFS_Wizard10 Control) - http://tescoonline.co.uk/dbpc2/controls/2.6.11.0/IFS_Wz10.cab
    O16 - DPF: {498439C0-0921-11D3-9484-0001FAF8503C} (IFS_Lib10) - http://tescoonline.co.uk/dbpc2/controls/2.6.11.0/IFS_Lb10.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/048c4dfa292f77745f21/netzip/RdxIE601.cab
    O16 - DPF: {5915C16A-F555-11D1-8E31-08005AAA630C} (IFS_Wizard5 Control) - http://tescoonline.co.uk/dbpc2/controls/2.6.11.0/IFS_Wz05.cab
    O16 - DPF: {5B2FD039-D08C-11D2-9FFD-0004ACF74B57} (IFS_Lib08) - http://tescoonline.co.uk/dbpc2/controls/2.6.11.0/IFS_Lb08.cab
    O16 - DPF: {5DD1BBF5-E4B2-11D1-9211-0004ACF75CFC} (IFS_Wizard2 Control) - http://tescoonline.co.uk/dbpc2/controls/2.6.11.0/IFS_Wz02.cab
    O16 - DPF: {6CAE02B8-EB30-11D1-8CE5-0004ACF74B57} (IFS_List Control) - http://tescoonline.co.uk/dbpc2/controls/2.6.11.0/IFS_List.cab
    O16 - DPF: {770941A0-11BD-11D3-8E92-0001FAF8D90D} (IFS_Lib09) - http://tescoonline.co.uk/dbpc2/controls/2.6.11.0/IFS_Lb09.cab
    O16 - DPF: {8F78C964-B20B-11D2-8D4A-0004ACF74B57} (IFS_Lib01) - http://tescoonline.co.uk/dbpc2/controls/2.6.11.0/IFS_Lb01.cab
    O16 - DPF: {9D24756B-CBFC-11D2-9FFB-0004ACF74B57} (IFS_Lib13) - http://tescoonline.co.uk/dbpc2/controls/2.6.11.0/IFS_Lb13.cab
    O16 - DPF: {9E2D89BB-D888-11D2-A002-0004ACF74B57} (IFS_Lib12) - http://tescoonline.co.uk/dbpc2/controls/2.6.11.0/IFS_Lb12.cab
    O16 - DPF: {A3186A8D-134F-11D3-BBAE-0010E3624141} (IFS_Wizard8 Control) - http://tescoonline.co.uk/dbpc2/controls/2.6.11.0/IFS_Wz08.cab
    O16 - DPF: {BBAE9E7E-3F7D-11D3-94B7-0001FAF8503C} (IFS_Lib16) - http://tescoonline.co.uk/dbpc2/controls/2.6.11.0/IFS_Lb16.cab
    O16 - DPF: {C0E10B5C-DA42-11D3-9FED-0004ACF74B57} (IFS_Lib02) - http://tescoonline.co.uk/dbpc2/controls/2.6.11.0/IFS_Lb02.cab
    O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.sc-server1.bt.com/broadband/MotivePreQual.cab
    O16 - DPF: {C6726AD0-E1E0-11D2-929E-0004ACF75CFC} (IFS_Lib03) - http://tescoonline.co.uk/dbpc2/controls/2.6.11.0/IFS_Lb03.cab
    O16 - DPF: {C6C07D4E-3911-11D2-8708-0001FAF8D5C4} (IFS_Wizard7 Control) - http://tescoonline.co.uk/dbpc2/controls/2.6.11.0/IFS_Wz07.cab
    O16 - DPF: {D6CD9D82-AC85-11D3-878A-0010E36241AE} (IFS_Lib19) - http://tescoonline.co.uk/dbpc2/controls/2.6.11.0/IFS_Lb19.cab
    O16 - DPF: {D71A2028-D578-11D2-9FFF-0004ACF74B57} (IFS_Lib14) - http://tescoonline.co.uk/dbpc2/controls/2.6.11.0/IFS_Lb14.cab
    O16 - DPF: {EC5A4E7B-02EB-451D-B310-D5F2E0A4D8C3} (webhelper Class) - http://register.btinternet.com/templates/btwebcontrol023.cab
    O16 - DPF: {F0FB4064-2940-11D3-92B1-0004ACF75CFC} (IFS_Lib06) - http://tescoonline.co.uk/dbpc2/controls/2.6.11.0/IFS_Lb06.cab
    O16 - DPF: {F3A16EEE-39B4-11D3-8E96-0001FAF8D90D} (IFS_Lib15) - http://tescoonline.co.uk/dbpc2/controls/2.6.11.0/IFS_Lb15.cab
    O16 - DPF: {F3DAE1EA-01DA-11D2-8E33-08005AAA630C} (IFS_Wizard4 Control) - http://tescoonline.co.uk/dbpc2/controls/2.6.11.0/IFS_Wz04.cab

    After you remove the above controls, procede with the below online scans:

    Bitdefender online scan
    RavAntivirus online scan <-- select Auto Clean then click Scan My PC
    TrojanScan online scan
    Panda Online Scan

    After you complete the above, reboot and post a fresh HJT log.
     
  7. janiea

    janiea Private E-2

    Hi again

    Have followed all your instructions. However Bit Defender didn't work: it came up with 'this website is not authorised to host this Active X Control'. all the other checks worked fine. i have attached my HJT log after reboot. The toolbar is still with me!

    Thanks

    Janiea
     

    Attached Files:

  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    In order to remove this TB you MUST close all browsers while running and fixing items with HJT.

    C:\Program Files\Internet Explorer\iexplore.exe

    Now scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1

    O2 - BHO: (no name) - {0B682DD4-4AAD-84A6-6FD0-6D579DDED088} - (no file)

    O4 - HKLM\..\Run: [Meow Thunk Error Bias] C:\Documents and Settings\All Users\Application Data\TITLEOWNSMEOWTHUNK\Ford Sect.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKCU\..\Run: [signmapi] C:\DOCUME~1\JANETR~1\APPLIC~1\CHINSO~1\RdrThatMeet.exe

    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    (These were added from Spybot S&D most likely and need to be removed)

    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

    O16 - DPF: {EC5A4E7B-02EB-451D-B310-D5F2E0A4D8C3} (webhelper Class) -http://register.btinternet.com/templates/btwebcontrol023.cab

    Again, make sure All Browser Windows are Closed when you Click FIX.

    NOW:
    Please boot into Safe Mode with the Viewing of Hidden Files & Folders Enabled and navigate to and DELETE the following if they should remain:


    C:\Documents and Settings\All Users\Application Data\TITLEOWNSMEOWTHUNK ←–– Delete this whole folder if it exist!

    C:\Documents and Settings\JANETR~1\Application Data\CHINSO~1 ←–– Delete this whole folder if it exist!

    NEXT:
    Run CCleaner and Spybot S&D and have Spybot fix what it finds.
    Note: Dont forget to update Spybot S&D by selecting "Search For Updates"

    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.


    Reboot to Normal Windows , Scan with HijackThis and attach the new log.
     
  9. janiea

    janiea Private E-2

    Have followed everything exactky as you asked. Found both folders TITLEOWNSMEOWTHUNK and CHINSO and have deleted. HJT log attached. Toolbar seems to have gone hopefully.

    Huge thanks

    janiea
     

    Attached Files:

  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your HJT log is clean, are you having any further problems?
     
  11. janiea

    janiea Private E-2

    No more probelems at all. Thanks so much for your time and expertise bjgarrick. cant believe I have found this site, truly brilliant. Have a good day

    Regards

    janiea :)
     
  12. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds