Possible Hi-Wire, WebSearch Toolbar, and ISTbar infection, please help.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Gaming Insider, Sep 9, 2005.

  1. Gaming Insider

    Gaming Insider Private First Class

    Hello all, I am here in search of getting the problems listed in the title removed from my computer. I have run all of the steps that were required in the READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal thread but all of the scans came back clean. I had to take it further by downloading and running PestPatrol, which is where all those programs were found.

    I am running Windows ME with 128MB RAM on a P3 733 MHZ processor with a 25.9GB hardrive. Any help will be greatly appreciated.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Post the Pest Patrol log and also follow the steps below exactly:


    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. Gaming Insider

    Gaming Insider Private First Class

    Hello Chaslang, here is my Pest Patrol log and my Hijack This log.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have Limewire installed? Or did you have it at one time?

    Most of what PestPatrol is detecting is Limewire. Supposedly the new version of Limewire no longer has malware but older versions did. Perhaps you should save your MP3s elsewhere and uninstall Limewire and delete its folder.

    Let's see if we can cleanup some more hidden baddies.

    - First run CCleaner before doing the below.

    - Download this trial version of Ewido Security Suite
    • Install ewido security suite
    • Launch ewido, there should be an icon on your desktop double-click it.
    • The program will have a window come up. One of the buttons on the left is to Update. Click the Update button.and then Start the Update. The update will start and a progress bar will show the updates being installed.
    • After it completes the update, click the Scanner button

    Now exit Ewido. Now print the below instructions or save them locally because I want you do have no browsers opened and also have no connection to the internet (unplug your cable) while doing the below.

    Okay, reboot into safe mode and follow the steps below. (If you have any problems at all trying to get into safe mode to complete these steps, just run them in normal boot mode and make sure you tell me when you come back.)

    Open up Ewido and do the following:

    • Click on Scanner
    • Then click Settings
    • Under What to Scan? Select Scan every file
    • Then click OK
    • Click on Complete System Scan and the scan will start.
    • Let the program scan the machine
    While the scan is in progress you will be prompted to clean files that are infected. Leave the defaults selections (to Remove and backup) and click OK. To save yourself some time, you can select Perform action with all infections and then click OK. With the option to scan every file, a lot of cookies will be removed.

    Once the scan has completed, there will be a button located on the bottom of the screen named Save report

    • Click Save report
    • Save the report to your desktop or anyplace you will be able to find it to upload here.
    Reboot into normal mode and reconnect to the internet.

    Come back here and post the Ewido Scan Report. And tell me if you are still having any problems. This log could get quite large and you may need to compress it into a ZIP file to upload it.


    Post this Ewido log.

    Also do a PestPatrol scan now and post its log.

    Download and install the below. We may have to use it to delete some hidden files if the above does not get them all.

    ExplorerXP
     
    Last edited: Sep 10, 2005
  5. Gaming Insider

    Gaming Insider Private First Class

    Sorry for the inconvenience, but Ewido Security Suite 3.5 and ExplorerXP cannot be installed onto my computer as they require Windows 2000/XP to run, I am running Windows ME, if there are any alternates, that would be great, and thank you for the help that you are providing.

    I also uninstalled the latest version of LimeWire that I had as per your request.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that! I have too many threads going an just overlooked what your OS was.
    Let's see a new Pest Patrol log to see what we still may need to cleanup.
     
  7. Gaming Insider

    Gaming Insider Private First Class

    Here is the new Pest Patrol Log, it still shows everything but LimeWire.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's see if we can make Pestscan happy.

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file cleanit.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the cleanit.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.


    Now open a command prompt window by clicking Start, Run and enter command and click OK. Enter the below commands each followed by the enter key:

    cd C:\WINDOWS\Downloaded Program Files\
    attrib -r -h -s popcaploader.dll
    del popcaploader.dll
    attrib -r -h -s hwreal.exe
    del hwreal.exe
    exit

    The exit command will close the command prompt window. Now boot into safe mode.
    In safe mode run Windows Explorer and locate the below folder and delete it:

    C:\Program Files\common files\totem shared

    Now reboot in normal mode and get anothe Pestscan log.
     
  9. Gaming Insider

    Gaming Insider Private First Class

    Ok, I would just like to say that the registry entry went smooth, the deletion of Totem Shared went smooth as well, but trying to enter those command lines is starting to get to me.

    The first line cd C:\WINDOWS\Downloaded Program Files\ gives mea too many parameters - program message and I don't know if that is supposed to happen.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's been awhile since I played much with older OS's. You may need to put quotes around the directory path like below:

    cd "C:\WINDOWS\Downloaded Program Files\"

    or maybe leave of the ending \ and use quotes like:

    cd "C:\WINDOWS\Downloaded Program Files"
     
  11. Gaming Insider

    Gaming Insider Private First Class

    Well, it seems that Pest Patrol still finds Hi-Wire and WebSearch Toolbar in the directory. However, running the command lines throught the command prompt, it comes back file not found for hwreal.exe, a Pest Patrol log has been posted.
     

    Attached Files:

  12. Gaming Insider

    Gaming Insider Private First Class

    UPDATE: After making my daily spyware and registry cleaning scans, Crap Cleaner managed to remove the last remaining trace of Hi-Wire which was reported in my Pest Patrol 4 log. The only one that remains is WebSearch Toolbar which is also in that log, I just wish I could find out how to get rid of the damn thing.

    Also, in response to post #10, the cd "C:\WINDOWS\Downloaded Program Files\" was the right command. Again, I appreciate the help that you providing and just want to say thank you.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your welcome!


    Now please do the below:
    1) Download Registrar Lite and install it!
    2) Run it, copy and paste this line to Reglite's address bar:
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\installer\userdata
    3) Click the "go" tab
    4) See if you can locate this tuid item from WebSearch Toolbar
    5) If you can, then right click on it and select Delete

    Let me know if that works!
     
  14. Gaming Insider

    Gaming Insider Private First Class

    Alrighty, even though I could see the tuid from Start > Run > regedit.exe, I went ahead and downloaded Registrar Lite and deleted the registry entry from there. Deleting it was easy as it was only one of two items in that registry folder. Also, from what I can tell even though these items were in my computer, they were of no real threat as I actually never had any hijacker or adware problems with any of the browsers and what not that I have used over the years.

    I also just ran another Pest Patrol scan and it is not finding anything at all now. My computer has been running a lot smoother since we cleaned this stuff along with everything else that I have cleaned up. Also, I was wondering if I could maybe go ahead and post another Hijack This log so as I can get that cleaned up as well, but only if it is okay with you?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Many things found by scanners are just dormant registry keys and they can quite often be annoying to totally cleanup.

    What do you mean another log? Do you mean for another PC? If so, you need to make sure you follow all steps in the READ ME FIRST on that PC and then start a new thread indicating what you have done and what problems you have. Based on that, one of us will request (if necessary) a HJT log.

    Note: If your current PC is running fine now, you should refer to the below thread to help keep it that way:

    How to Protect yourself from malware!
     
  16. Gaming Insider

    Gaming Insider Private First Class

    I guess what I am trying to say is that I would like to clean up the Hijack This list for my computer, but to do so, I would like some help as I don't want to mess anything up that shouldn't be messed with. Also, I am and have been running 99% of the items listed in the How to Protect yourself from malware! since before I came upon MajorGeeks.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Post a current log but there was not too much in there last time.

    Did you want about:blank for your Start Page?
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

    And why does the below Proxy Server entry exist?
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.*.*.*
     
  18. Gaming Insider

    Gaming Insider Private First Class

    I have since added some security to Internet Explorer via the Yahoo toolbar.

    As for
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    This is not my startup page, it should look a little something like this
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.9news.com/

    As for this
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.*.*.*

    I have no idea why it even exists.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.*.*.*
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present


    After clicking Fix, exit HJT.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  20. Gaming Insider

    Gaming Insider Private First Class

    Well, according to your post, you want me to post a new HJT log, after the fixes, so, here it is. Also, my computer is running much, much better now thanks to you guys/gals here at MajorGeeks. If it weren't for you, I would probably not have a computer right now seeing as how my computer did not come with an operating software cd.

    Now that I have the malware problems solved, I now have to make a run over to the software forum and get some help there, unless you people here would know how to delete some entries from the right-click context menu for the start button.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You log is now clean. TIme to work thru the following: How to Protect yourself from malware!

    Sorry but your other question is not a topic for this forum. We are just too busy here to also address non-malware related topics.
     
  22. Gaming Insider

    Gaming Insider Private First Class

    OK, it's good to here that my log is now clean, also, I had a funny feeling that my other question would not be able to be worked on here, seeing as how you all have to fix people's malware problems and babysit people who do not know how to follow the posting guidelines along with the how to threads as well.

    Anyway, thanks for the help and I hope that the recent string of virtumundo, winfixer, and look2me threads die down so as not to put to much strain on you and D3 and the rest of the crew.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. There are no signs of the Virtumundo/Winfixer problems dying down. I would like to know where the heck everyone is getting this from.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds