sitebar or some crazy program

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Hyperbomb64, Oct 3, 2005.

  1. Hyperbomb64

    Hyperbomb64 Private E-2

    I honestly don't know what's wrong with my system. I think the problem is sitebar since that's what I saw when I first clicked the link from a trusted friend and my computer went crazy. I've tried all sorts of spyware removal programs and it never works. My friend said to run the scanners in safe mode, but my computer refused to start in safe mode after a while and I can't shutdown. I think it's all because of the program because it keeps making pop ups appear on my screen. I'll hear the error ding when I try to shutdown and then the shutdown process just stops.

    I've deleted several .exe programs that have a dog bone sort of icon. I thought I had gotten rid of it but the pop ups keep appearing even when IE isn't open. Also I don't use IE at all. I either use Firefox or Opera. I reinstalled IE when the pop ups stopped showing up, but my windows kept going out of focus and I couldn't make it stop. Sort of interrupts FFXI when I'm trying to cure someone and my window goes out of focus.

    Most of the pop ups include ads about spyware being on my computer and in my registry and wanting to search, or something about a casino. A bar has been added to IE that I can't move or take off. I took a screenshot of my IE window and attached the file here.

    I'm new to this site so I don't completely know how to use anything on it. A friend passed me on to HijackThis and I installed it and used it like I saw on a tutorial and how it said on one of the stickies here. If there's a tutorial on how to remove this program here could you please direct me to it. My e-mail is Hyperbomb64@msn.com so you can e-mail me as well as reply here. Any help would be greatly appreciated.

    Thank you,
    Reggie
     

    Attached Files:

  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.

    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. Hyperbomb64

    Hyperbomb64 Private E-2

    Thank you so much. Took me a while to get all the things done, but I finished them and it looks like everything is up and running rather smooth now. I still have to get rid of Java if its still on my computer, but other than that there's no more bar and no more pop ups.
     
  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Please attach a HijackThis log, and I can double check that there isn't something still lurking on your system.
     
  5. Hyperbomb64

    Hyperbomb64 Private E-2

    Sorry for the late response. Here's the HJT log.
     

    Attached Files:

  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Using Add or Remove Programs from the Control Panel; please look for and uninstall the following if they exist:
    Download and run the following:
    EliteToolbar Remover

    Post a new HJT log. And tell us how things are working.
     
  7. Hyperbomb64

    Hyperbomb64 Private E-2

    Didn't find any of those programs installed in the add/remove programs window. Ran the elite toolbar remover and have the HJT file attached here.
     

    Attached Files:

  8. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Scan with HihackThis and fix the following:
    You can uninstall Logitech Desktop Messenger, it is an uneccessary service.

    Open Windows Explorer an dlete this directory C:\WINDOWS\etb

    Post a new HJT log.
     
  9. Hyperbomb64

    Hyperbomb64 Private E-2

    I did all that you said and a new HJT log is attached, but I didn't find the C:\WINDOWS\etb directory. Is it hidden somewhere or could it just not be on there?
     

    Attached Files:

  10. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Your log is clean.

    The etb directory may no longer be on your drive.

    Configure Windows XP search per: Searching for Hidden Files on WinXP

    Search All files and folderds for etb on the local hard drive using the search function in the Start Menu. Delete all directories if found.
     
  11. Hyperbomb64

    Hyperbomb64 Private E-2

    Well the directory wasn't there so I guess it just wasn't on my system. I did the search and it didn't show up. So is my system all squeaky clean now? ^^
     
  12. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Your log is clean.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds