Spyware at Startup

Discussion in 'Malware Help (A Specialist Will Reply)' started by SaleenS7, Mar 2, 2005.

  1. SaleenS7

    SaleenS7 Private E-2

    I have a problem. Everytime I turn on my computer, I'm bombarded by ads and stuff I don't want to see. It's like this for about 5 minutes then it just stops and almost nothing comes through. Everytime I use something like Ad-Aware, Spybot S&D, or Microsoft, it get worse. Much worse. I don't know why this is happening. I read the READ THIS BEFORE... and it helped for a few hours then it happened again. I have DSL service. Thank You.
     
  2. PhilliePhan

    PhilliePhan Guest

    Hi SaleenS7,

    If you have exhausted the options in the ReadMe Tutorial (including the Online Scans), please send us a HijackThis Log. Please be sure to follow the instructions below:

    Note that your HijackThis should be up-to-date (v1.99.1) and MUST be extracted to its own safe folder – C:\Program Files\HijackThis! Should you need a Fresh Download of HJT, get it HERE: HijackThis v1.99.1

    Also note that, before you scan, you MUST close all running programs including your web browser, e-mail and items in the system tray.

    Please save your HJT Log as a .txt File and attach it via the "Manage Attachments" tool in the Additional Options section when you post.

    Somebody will take a look as time permits.

    Best luck :)
    PP
     
  3. SaleenS7

    SaleenS7 Private E-2

    Here you go. I think I did it right. I hope...
     

    Attached Files:

  4. PhilliePhan

    PhilliePhan Guest

    Hi SaleenS7,

    How many active User Accounts are on your machine?


    Please look in Add or Remove Programs for the following and Uninstall it if found:

    WeatherBug

    ALSO: Please look for Elite ToolBar, Elite SideBar, Elitum or any other Elite entries and note them for me!


    Please print out these instructions so that you can operate with All Browser Windows CLOSED.
    Please make sure System Restore is OFF and the Viewing of Hidden Files is Enabled as per the tutorial.

    Now scan with HijackThis and Check the Boxes for the following:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com

    O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~2\tools\iesdsg.dll (file missing)
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing)
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)

    O4 - HKLM\..\Run: [antiware] C:\windows\system32\elitefbh32.exe
    O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1

    O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540002} - http://www.wildtangent.com/webdrivers/webinstall/shockwave/Install.cab
    O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} - http://install.wildtangent.com/ActiveLauncher/ActiveLauncher.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/14ff9db68a96730ac519/netzip/RdxIE601.cab
    O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} - http://install.wildtangent.com/bgn/partners/wildgames/blackhawkstriker/install.cab

    Again, make sure All Browser Windows are Closed when you Click FIX.


    NOW:
    Please boot into Safe Mode with the Viewing of Hidden Files Enabled and navigate to and DELETE the following if they should remain:

    C:\windows\system32\elitefbh32.exe --> Again, look for other Elite entries and note them!!
    C:\Program Files\AWS --> The Folder

    NEXT:
    Run CCleaner and Spybot S&D and have Spybot fix what it finds.

    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    Reboot to Normal Windows and Scan with HijackThis and attach that log.
    Let me know of any problems you may have encountered with the above instructions and how your computer is running now. I will try to check back when time permits.

    Best luck :)
    PP
     
  5. SaleenS7

    SaleenS7 Private E-2

    It didn't work. The only one's now are ad1.revenue and searchmiracle. Spybot finds Elite everytime but everytime I run it it's still there. We have 2 accounts on our computer but only use one because we can't delete the other one for some reason.
     

    Attached Files:

  6. TheOldThug

    TheOldThug First Sergeant

    Your running your HJT from the zip now and you didn't close your browser.

    C:\DOCUME~1\MAXTAN~1\LOCALS~1\Temp\Temporary Directory 4 for hijackthis.zip\HijackThis.exe
    C:\Program Files\Internet Explorer\iexplore.exe

    PP won't want you to do that.
     
  7. PhilliePhan

    PhilliePhan Guest

    Hi SaleenS7,

    As Old Thug notes, please run HijackThis from the location you ran it from before - C:\hijackthis\HijackThis.exe

    Try running this tool in Safe Mode for both user accounts: Elite ToolBar remover

    Were you able to find and delete C:\windows\system32\elitefbh32.exe??


    Try fixing these lines with HJT in Safe Mode:
    O4 - HKLM\..\Run: [antiware] C:\windows\system32\elitefbh32.exe
    O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -


    Then make sure Delete C:\windows\system32\elitefbh32.exe in Safe Mode.

    Then, please submit HJT logs from Both User Accounts so we can see where you stand. Let me know how the deleting process went.

    PP :)
     
  8. SaleenS7

    SaleenS7 Private E-2

    Is this site usually slower than most? Or is it just me?
     
  9. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Some days its like that for me to and I'm on a 3mb cable connection. Probably all the users online.
     
  10. SaleenS7

    SaleenS7 Private E-2

    Ok. I turned the connection off so it should be right. I can't access the other account in safe mode. Only Administator and Max showed up. I ran elitebar remover and deleted the file C:\windows\system32\elitefbh32.exe. Attached is my HJT log.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to post HJT logs from normal boot mode. The last log looks to be from safe mode. PP wanted you to fix some items using HJT in safe mode. But always post HJT logs from normal boot mode unless specifically requested otherwise. So please post a new one for normal boot mode.

    In safe mode you may need to scroll down to see other user accounts. Use the mouse wheel or the down arrow key while your mouse cursor is over the user account area.
     
  12. SaleenS7

    SaleenS7 Private E-2

    oOo! Ok
     
  13. SaleenS7

    SaleenS7 Private E-2

    Got it. I'm pretty sure that I'm good now though. No popups or ads.

    BTW: Is AdServer spyware? It comes up when I use www.howstuffworks.com
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Those are tracking cookies! No big deal.

    You need to uninstall one of the AV packages you have. You must not run multiple AV applications and you have two McAfee and Symantec/Norton (both of which are resource hogs). Pick which one you prefer and uninstall the other.
     
  15. SaleenS7

    SaleenS7 Private E-2

    Which do you think is better? McAcfee or Norton.
     
  16. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Personally, I use Norton AntiVirus 2005 and have not had any problems. Never used McAfee but from what I have heard I wouldnt give it a chance.

    This article will help you with some choices.

    How to Protect yourself from malware!
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    A debateable topic!

    I don't use either of them anymore because they have become way to bloated trying to offer every kind of package possible. They have some many processes running it borders on ridiculous. They also slow down some PCs so much that they become similar to some malware problems. Also they can sometimes be difficult to completely remove (another malware like trait). Now that being said (I bit of a rant). It does not mean they are bad programs and it does not mean they do not work. If I had to choose between them, I would choose McAfee.

    The thing is there are several free programs (Avast, AVG, AVPersonal) out there that work just as well and find many things McAfee and Norton do not. In addition the free ones are not such resource hogs.
     
  18. TheOldThug

    TheOldThug First Sergeant

    Ok Chas - Which is your favorite. What do you use for AV, firewall, protection, etc.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Avast or AVG for an AV (I experiment with both).

    ZoneAlarmPro for a firewall. However it is now starting to get the Symantec and McAfee bloat syndrome.

    I do have McAfee (but only the antivirus app) on a few PCs I use at home too but that is because I use them for access stuff at work and it is a required application on our networks. We have full site licenses and get autoupdates. But even here I notice slow downs due to McAfee.
     
  20. SaleenS7

    SaleenS7 Private E-2

    Our McAcfee hasn't done anything in like a year. Its just sitting there
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your subscription has expired! You need to pay to get updates each year!
     
  22. SaleenS7

    SaleenS7 Private E-2

    Oh well. I deleted it. I didn't like it anyway.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  24. SaleenS7

    SaleenS7 Private E-2

    Ok. I got AVG and a Kerio Firewall and I have the Spybot S&D. I should be good right? I also got rid of the Norton because it hasn't been updates since 03
     
  25. SaleenS7

    SaleenS7 Private E-2

    BTW. If you use AVG, how long does it take to scan the computer? It seems to take a long time.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Scanning time is based upon scanning option, speed of PC, number of files etc. Everyone's time will be different. Doing a complete scan of a system does take a while.

    Make sure you have done all steps in the How to protect thread.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds