Spyware, server busy, pop-ups, etc..

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by redhotangeldevil, Sep 13, 2005.

  1. redhotangeldevil

    redhotangeldevil Private E-2

    I have done what was recommend by Chaslang and mw7734 by If you have run ALL the steps in the READ ME (including the online scanners) then follow the steps below exactly, like a good girl. However I did not seem to make a dent in the problems this computer is having. I have a compac and running XP. I have attached the hijack this file. I am eagerly awaiting your next round of knowledge to be bestowed upon me. Thanks! :eek:
     

    Attached Files:

  2. theefool

    theefool Geekified

    A quick question. Did you upgrade the os from ME to xp on this computer?

    Other than that:

    Within HJT, remove the following, while disconnected from the internet(may require you to unplug the ethernet connection to your computer, or turn off the modem/router).

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://files.cc.cometsystems.com/assist/cc/1.0/assist_st.html?src_id=312
    O2 - BHO: (no name) - {35E78239-811E-4c3f-B37D-F339AC16C2C0} - C:\PROGRA~1\Comet\bin\autosearch.dll (file missing)
    O2 - BHO: Need2Find Bar BHO - {4D1C4E81-A32A-416b-BCDB-33B3EF3617D3} - C:\Program Files\Need2Find\bar\1.bin\ND2FNBAR.DLL
    O2 - BHO: InstaFinderK - {4E7BD74F-2B8D-469E-90F0-F66AB581A933} - C:\PROGRA~1\INSTAF~1\INSTAF~1.DLL (file missing)
    O2 - BHO: (no name) - {7163811B-40FC-127F-8F9B-46D1EA6AC5C9} - C:\WINDOWS\system32\ubutyeb.dll
    O3 - Toolbar: RX Toolbar - {25D8BACF-3DE2-4B48-AE22-D659B8D835B0} - C:\Program Files\RXToolBar\RXToolBar.dll
    O8 - Extra context menu item: &Search - http://ka.bar.need2find.com/KA/menusearch.html?p=KA
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

    Once this is done, go ahead and go to add/remove programs and remove:

    Comet cursor
    Search Assistant
    Need2find
    RXbar
    Instafind

    This may require multiple reboots. Some may refuse to be removed, because they require internet access (just ignore these, but post which ones are troublesome). Once all this is done, rerun HijackThis, reconnect to the internet (turn on your modem/router, replug your ethernet cable). And post (as an attachment) your HJT log.
     
  3. redhotangeldevil

    redhotangeldevil Private E-2

    No darlin... no ME in tha house!!! ;) thanks I will get on your instructions asap. xoxo
     
  4. redhotangeldevil

    redhotangeldevil Private E-2

    I have done all that you requested. Although in the search for add/remove programs there were two programs not present, (comet cursor and search assistant). The rest were done with little to no difficulty. I have not had an opportunity to see if doing so has had either a positive or no effect on the computer yet. Here is the newest hijack this log. Thank you!
     

    Attached Files:

  5. redhotangeldevil

    redhotangeldevil Private E-2

    I did, however, upgrade from windows 98 recently (past year)
     
  6. theefool

    theefool Geekified

    Sorry, for being late. I'm a busy guy at work, in the past I've had much free time (during work ;) ).

    Anyway, let me see what ye got.

    I see a few items within HJT that are pretty stubborn.

    Do the following:

    Click and hold: CTRL + ALT + ESC
    This should bring up task manager. Now, within the tab "Processes" find explorer and click on the button "End Process".

    Explorer (desktop with all your icons and the start bar) should shut down (vanish).

    Now, within the "Windows Task Manager", click File, then Run, type in CMD (press enter).

    Next, type in the following:

    cd\ (press enter)
    cd Program Files (press enter)
    rd /s rxtoolbar (press enter)
    start explorer (press enter)

    Note: if your desktop does not reappear, simply type in the following:
    shutdown -r (press enter) this will reboot your machine.

    Once your machine is rebooted, rerun hijackthis and remove the following:

    O2 - BHO: RXResultTracker Class - {59879FA4-4790-461c-A1CC-4EC4DE4CA483} - C:\Program Files\RXToolBar\sfcont.dll
    O4 - HKLM\..\RunOnce: [Need2FindBar Uninstall] rundll32 C:\PROGRA~1\UNINST~1.DLL,O -2

    Then post a new Hijackthis log.






    next type in:

    reg
     
  7. redhotangeldevil

    redhotangeldevil Private E-2

    Ok, I have finished the last instructions given to me and some of the things you posted have me a little confused. First when you said to hit cntrol+alt+esc, all that does it switch between tabs in task bar. Did you mean contrl+alt+delete? and all I did was right click on task bar to get the task manager. Also, at the end you put "next type in: reg", I have no idea what that is or where to put that. But, I did go to hijack this and the first one listed was there and I got rid of it. However, the second was not on the list. I did save the hijack this log and this is what I got. Thank you again for your guidance and knowledge.
     

    Attached Files:

  8. redhotangeldevil

    redhotangeldevil Private E-2

    After further snooping into the depths of this computer, mw7734 and I have deleted some programs and re ran the hijack this. Not knowing if this is going to be any different than the previous one, I decided to go ahead and attach it again. We did find my web search and got rid of it since chaslang had me get rid of it on the other computer. Thank you again. By the way, mw7734 is on his way to the high ranks in the trojan wars!!! He is a regular helpy helperton!!! Thank you my dear friend for your assistance as well.
     

    Attached Files:

  9. redhotangeldevil

    redhotangeldevil Private E-2

    Hello... I know we cant be done. My computer is slower than ever and it is still freezing up. What else can I do? Help!!! I am about to throw this computer out the window!!! ;) Can anyone plz advise? I appreciate the assistance.
     
  10. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Have HJT fix the following lines:

    O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://winfixer.com/pages/scanner/WinFixer2005ScannerInstall.cab
    O18 - Filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - C:\Program Files\RXToolBar\sfcont.dll


    Next boot into Safe Mode, open Windows Explorer, navigate to and delete the following:
    C:\Program Files\RXToolBar <---- DELETE the entire directory

    Next run CCleaner.

    Reboot and post a new HJT log as an attachment.
     
  11. redhotangeldevil

    redhotangeldevil Private E-2

    Thank you!!! I live in Texas, so I have been MIA thanks to RITA, I will get right on that asap!
     
  12. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    We'll be here.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds