Spyware Problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by Hartsville, Jan 5, 2005.

  1. Hartsville

    Hartsville Private E-2

    Hello All. I've got a lovely little problem on my hands. I 've got an annoying Search Bar on my Browser and also got the virus/bug that highlights certain words on websites. I have run Hijack This and Spybot Search and Destroy. Both have found problems but I will not post Hijack This untill asked.


    Please help. Thanks very much.


    Hartsville.
     
  2. PhilliePhan

    PhilliePhan Guest

    Hi Hartsville,

    Sounds like you might have Ezula and one of the PITA toolbars that are floating around. Do you know which toobar it is? Ex. EliteBar, MySearch Bar, etc...

    Generally, it is a good idea to start with the Cleanup Tutorial HERE:

    READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan and Virus Removal

    There are only a few of us Volunteers who regularly offer advice in this forum. Running through the above Tutorial will remove a lot of stuff that would otherwise clog a HijackThis Log and save us valuable time.

    Please let us know the steps that you are able to complete and the ones that give you problems. Note that you need to be in Safe Mode with System Restore OFF (if you have it - you didn't give OS) and have the Viewing of Hidden Files ENABLED as per the instructions in the link. Make sure to do the Online Scans.

    Post back and let us know how you fared. Also, send us a HijackThis Log. Please be sure to follow the instructions below:

    Note that your HijackThis should be up-to-date (v1.99) and MUST be extracted to its own safe folder – C:\Program Files\HijackThis!
    Should you need a Fresh Download of HJT, get it HERE: HijackThis v1.99

    Also note that, before you scan, you MUST close all running programs including your web browser, e-mail and items in the system tray.

    Please save your HJT Log as a .txt File and attach it via the "Manage Attachments" tool in the Additional Options section when you post.

    I’m not around this forum too often these days, but somebody will try to take a look when they get a chance.

    Best luck :)
    PP
     
  3. Hartsville

    Hartsville Private E-2

    PhilliePhan,

    I believe that I have the Begin2Search Toolbar. I am running Windows 2000. I have read through the tutorial and am about to start the cleanup process. I need to desperately b/c my computer is running slower than ever. These virus must be taking up a LOT of memory. Thanks.


    Will let you know what happens.

    Hartsville
     
  4. Hartsville

    Hartsville Private E-2

    I've run through all the processes in the previous post and to no avail. Here is the run down on what happended throughout the clean-up process.

    The Trend Micro' Free Scan found this:
    C:/Winnt/System32/nethv32.dll


    Adware Found 26 problems and "fixed" what was found.

    Spybot found 1 problem and "fixed" what was found.

    I ran all the other cleaners as instructed in Safe Mode, CC Cleaner, CWShredder and Kill2Me.

    I am posting my HiJackThis Log as instructed.

    Thank all of you kind and generious people on this website.
     

    Attached Files:

  5. Hartsville

    Hartsville Private E-2

    Chaslang,

    You helped me with a previous issue with my computer and I found you to be unbelievably helpful(my old sign-in name was Computer Elliterat, I've lost my password info so I changed names). If you have a minute please see if their is anything you could suggest to help me out of this quandry.

    I have not nor will I shut my computer off untill I am instructed to do so.


    Thank you.


    Hartsville, South Carolina
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First you MUST ALWAYS remember to exit Internet Explorer sessions before running HJT. You still had it running.

    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file move.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.)

    Double-click on the move.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to merge say yes.

    Download LSP-Fix from here: http://www.majorgeeks.com/download4180.html
    Unzip it and run it. Check the Box labeled "I know what I'm doing" and then click on the tasp.dll file (in the ā€œKeepā€ section) to select it.
    Then, Select the >> button to move tasp.dll into the Remove section.
    Now, click the Finish Button. When the Repair Summary box appears, click OK.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side.
    Look for the following process (or processes) and one at a time kill them by selecting it
    and then click "Kill process". Then click yes.
    C:\Program Files\Windows ServeAd\WinServAd.exe
    C:\Program Files\Windows ServeAd\WinServSuit.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.popupsearches.com/sidesearch.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.popupsearches.com/sidesearch.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.popupsearches.com/sidesearch.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.popupsearches.com/sidesearch.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.popupsearches.com/sidesearch.html
    R3 - URLSearchHook: (no name) - {1C78AB3F-A857-482e-80C0-3A1E5238A565} - (no file)
    O2 - BHO: ohb - {4D568F0F-8AC9-40AB-88B7-415134C78777} - C:\WINNT\system32\winb2s32.dll
    O2 - BHO: ohb - {CB5B2BC6-F957-4D8A-BE67-83F3EC58BA01} - C:\WINNT\system32\dsktrf.dll
    O3 - Toolbar: Begin2Search.com Bar - {52FE5233-367C-4EFB-BDD7-0BE4D212C107} - C:\WINNT\system32\winb2s32.dll
    O4 - HKLM\..\Run: [Tsl] C:\PROGRA~1\COMMON~1\tsa\tsl.exe
    O4 - HKLM\..\Run: [Windows ServeAd] C:\Program Files\Windows ServeAd\WinServAd.exe
    O4 - HKLM\..\Run: [MSNSysRestore] C:\WINNT\system32\pc32.exe bg
    O10 - Broken Internet access because of LSP provider 'tasp.dll' missing <--- this should be gone already
    O15 - Trusted Zone: *.frame.crazywinnings.com
    O15 - Trusted Zone: *.static.topconverting.com
    O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
    O15 - Trusted Zone: *.static.topconverting.com (HKLM)
    O15 - Trusted IP range: 206.161.125.149
    O15 - Trusted IP range: 206.161.124.130 (HKLM)
    O16 - DPF: {07E9CDF4-20D2-46B1-B681-663968F527CE} (iiittt Class) - http://www.begin2search.com/toolbar/winb2s32.cab
    O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=fab19f64c271dfd5b772fcfb344ed4d5f8217f7b03e9b7145eeb15c7b73869070b857bc819ac1ca41787ff055d83fcb743482bfaec:0a002003c3f6d5950937c6314a45eb37
    O16 - DPF: {1C78AB3F-A857-482E-80C0-3A1E5238A565} - http://toolbar.isearch.com/general/initial.cab
    O16 - DPF: {469C7080-8EC8-43A6-AD97-45848113743C} - http://akamai.downloadv3.com/binaries/IA/nethv32_EN.cab
    O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.lizardtech.com/software/expressview/webinstall/isetup.cab
    O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup152.cab
    O16 - DPF: {FF65677A-8977-48CA-916A-DFF81B037DF3} - http://download.overpro.com/WildApp.cab

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\Windows ServeAd <--- the whole folder
    C:\WINNT\system32\winb2s32.dll
    C:\WINNT\system32\dsktrf.dll
    C:\Program Files\Common Files\tsa <-- the whole folder
    C:\WINNT\system32\pc32.exe

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  7. Hartsville

    Hartsville Private E-2

    God Almighty is it good to see you Mr. Chaslang. In the world of Spyware and viruses I must say that you Sir are a bad man. I ran through the processes that you outlined in your post. I skipped a couple of steps b/c they simply were not there.

    I could not find:

    O4-HKLM\..Run:[Windows Srve Ad]C:\ProgramFiles\Windows ServeAd\WinServAd.exe

    or


    C:\WINNT\system32\winb2s32.dll
    C:\Program Files\Windows ServeAd


    My Computer is "running" a heck of a lot faster now and does not have the search toolbar attatched to it any longer. However, I still can not seem to access my e-mail address. This may happen to be my service providers fault(Adelphia, they have very bad service and it black outs happen quite frequently).

    Please find attatched my latest and greatest HiJack This Log Attatched.

    I know that many persons have offered to buy you a beer or the like but please let me know what I can do to somehow begin to repay the debt I have accrued with you and this website. I work out of the home and you have saved me a considerablramount of money in helping me get over me virus/spyware issues. God bless you and Thank you so much.

    Sincerely,

    Wade P. O'Kelley
    Hartsville, South Carolina
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hello Wade,

    Almost done! Exit all browsers and run HJT and have it fix:

    O2 - BHO: ohb - {CB5B2BC6-F957-4D8A-BE67-83F3EC58BA01} - C:\WINNT\system32\dsktrf.dll (file missing)

    Then you should be clean. Make sure you check out: How to Protect yourself from malware!

    I'm not sure what has happened with your email! Malware can cause all kinds of strange problems. You may have to start with your ISP. How do you read email? Is it thru IE or via an email program?

    I don't drink but if I did I would never be allowed to drive with all those free beers in me! :)
    Thanks is good enough! Drop the owners a message of thanks if you like! ( http://www.majorgeeks.com/page.php?id=2 )
     
  9. Hartsville

    Hartsville Private E-2

    Chaslang,

    I ran HJThis and fixed O2 - BHO: ohb - {CB5B2BC6-F957-4D8A-BE67-83F3EC58BA01} - C:\WINNT\system32\dsktrf.dll (file missing)


    Everything seems normal, except I still can not get into my e-mail and it seems that my CD-Rom is screwed up. When I insert a CD it can not read it.

    I have a web-based e-mail provider. I log onto the site
    www.adelphiapowerpage.com, enter my e-mail address and password and normally go on from there. It appears to be dependent upon my computer b/c I was able to access my e-mail from another persons computer.

    Please let me know if I need to pose these questions/probelms in a different forum.

    Thank you for all your help.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I repeat my questions:

    How do you read email? Is it thru IE or via an email program?


    And did you ever have to install anything for this email account to work?
     
  11. Hartsville

    Hartsville Private E-2

    Chaslang,

    Here is waht I wrote in the previous post. I am not trying to be a smart aleck but this is the extent of my computer savy.

    I log onto the site
    www.adelphiapowerpage.com, enter my e-mail address and password and normally go on from there. It appears to be dependent upon my computer b/c I was able to access my e-mail from another persons computer

    I beleive that technicians from Adelphia may have installed something on my computer to allow it to work. I am planning on calling them on Monday for help.

    Any ideas????????????

    Thanks
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's what I getting at! I'm trying to determine whether you need to run any particular software application to connect to them or if you just use Internet Explorer or any other browser.

    If you can log in from another computer, nothing is wrong with your account. We also did not see any obvious spyware, so I was assuming some software you require is broken or missing.
     
  13. Hartsville

    Hartsville Private E-2

    10-4 Will be trying to get in touch with my ISP. Thanks.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem! Let me know what you find out.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds