please help me .....

Discussion in 'Malware Help (A Specialist Will Reply)' started by nigdeb2002, Apr 7, 2007.

  1. nigdeb2002

    nigdeb2002 Private E-2

    Hi i have adaware_bhot_iehelper/estalive on the pc. I have ran numerous spyware/adaware scans to eliminate this problem with no success. I would be grateful for any help you can give me :)
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. nigdeb2002

    nigdeb2002 Private E-2

    Hi thanks for replying ... i am half way through the scans at the moment and will attatch the results when they are all done :)
     
  4. nigdeb2002

    nigdeb2002 Private E-2

    please find scan results attatched........

    hi i have now gone through the steps as requested.
    the pandascan would not scan after numerous attempts to get it going so there is not a file for this one but everything else has been completed.
     

    Attached Files:

  5. nigdeb2002

    nigdeb2002 Private E-2

    Re: please find scan results attatched........

    the other scan results
     

    Attached Files:

    Last edited: Apr 9, 2007
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: please find scan results attatched........

    Did you setup some kind of strange DriveConfiguration policy? See the registry key info in your runkeys.txt log. Search for DriveConfiguration and you will see what I mean. On most systems, this key does not exist by default.

    Is the below something you knowingly installed?

    C:\HEROSOFT\Hero3000\SYSEXPLR.EXE

    My scanners report this as malware or adware at best. The sysexplr.exe file name is even showing as a trojan but that is normally when it is in a different folder. You may want to uninstall Herosoft 3000

    I see you have all of the below installed. Are these paid versions or free trials?
    • AOL AntiSpyware
    • AVG Anti-Spyware 7.5
    • CounterSpy
    • Spyware Doctor
    • SUPERAntiSpyware
    What scanner is detecting the malware you mentioned in your first message? Attach a log that shows what it being found.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Attach a new log from GetRunKey!

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
     
  7. nigdeb2002

    nigdeb2002 Private E-2

    C:\HEROSOFT\Hero3000\SYSEXPLR.EXE

    this may have been installed as a program by my partner but is now uninstalled.

    AOL AntiSpyware
    AVG Anti-Spyware 7.5
    CounterSpy
    Spyware Doctor
    SUPERAntiSpyware

    the aol anti spyware comes unfortunately with the package i believe
    spyware doctor is the only one that is paid for the others are programs i have been using to try and get rid of the problems. Aol is the only one that is bringing up the estalive warning via a pop up message stating that estalive has been found and is now blocked.

    i have merged the fixME.reg, attatched the runkeys log and uninstalled what was requested and reinstalled the new java version.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As far as I know it can be remove or disabled separately and I also believe it is known for false positives. Is there a log or does it give more information? Check your system for items mentioned here: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453099221

    Uninstall all the other programs except Spyware Doctor but note make sure you keep your Spyware Doctor up to date.
     
    Last edited: Apr 11, 2007
  9. nigdeb2002

    nigdeb2002 Private E-2

    i have disabled the aol anti spyware ... it was giving no further information as to where the estalive was to be found only that it had been detected and this was via a pop up. One of the registry strings as listed via your link was in the registry which has now been deleted.

    I uninstalled most of the extra programs after they were commented on in the last message from yourself .... apart from the superanti spyware free edition as i cannot find the uninstall link anywhere or it in the remove/add program's list ... any help on that one would be appreciated.Spyware Doctor is upto date.

    The adaware_bhot_iehelper came up with the online housecall scan by trend micro ..... i am re running that scan at the moment and it has found it again. Is there a way to obtain a report from this scan so the path can be traced?

    Thanks for all your help and patience so far.
     
    Last edited by a moderator: Apr 11, 2007
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The easiest approach may be to try reinstalling it and then after that uninstall it via Add/Remove Programs. if that does not work, tell me and we will manually remove it.

    Attach a new log from ShowNew!

    It's been a long time since I bother using Housecall. I thought there was a save log type button somewhere. If not, just copy and paste the info it shows after the scan!
     
  11. nigdeb2002

    nigdeb2002 Private E-2

    hi,
    super anti spyware has been removed ... thanks for that bit of advice.
    the housecall gave no options to find out where the adaware_bhot_iehelper was so i deleted that file, toggled the system restore off/on while rebooted.
    enabled the aol spyware (curiosity killed the cat i know) to see if it came back with estalive and yes it did so i disabled it again. I managed to get the pandascan to work at last but it came up with nothing found.
    please find attached the new 'show new' log.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you enable AOL again, you also allowed it to put the below adware/malware back on your PC:
    Viewpoint Media Player

    I suggest you run this:ViewpointKiller

    Also delete the below folders:
    C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
    C:\Program Files\SUPERAntiSpyware

    Your problem adaware_bhot_iehelper/estalive being detected may just be an insignificant benign registry key. Without a log showing exactly what and where something is being found all I can say are two things:
    1. The creator of program detecting it should be complained to about why they do not remove what they detect and why there is no useful log.
    2. uninstall this program and do not use since it is not useful

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  13. nigdeb2002

    nigdeb2002 Private E-2

    I have ran the veiwpoint killer and it either didnt detect what it was looking for and deleted one of the files that existed. One file it detected came up with an error code 32 when attempting to delete but when looking for the file to delete it manually it wasnt there!
    As for aol spyware i am uninstalling the program but i did get in touch with technical support and apparently the source of the 'infection' is deleted when detected! but they couldnt answer the question when i asked 'but why does it keep coming back?'

    A big thankyou for your time and effort in this situation :)
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Typical of AOL's experts! It normally means that they tried to delete it but it really did not work. They just thought they deleted based on the attempt alone and did not bother to verify that it truly was fixed. Much like when many antivirus or antispyware tools mistakenly say they fixed something that is in System Restore. They cannot fix something in System Restore and should be saying that they did.

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds