Uninstalling MSN Toolbar

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by zdouble, Jun 5, 2005.

  1. zdouble

    zdouble Private E-2

    I get the "Buffer Overrun Detected" message every time I or one of my programs that use automatic updating (such as McAfee AntiVirus or ZoneAlarm) launch IE. I don't know exactly when the problem began. At first, I couldn't get my McAfee Anti-Spyware software to update, and eventually I couldn't update AntiVirus or ZoneAlarm.

    I had done all the things listed by MajorAttitude on the "Read Me First before asking for support on Basic Spyware, Trojan, and Virus Removal" thread. The only exception was Symantec Security Check, which requires IE to use. The other problem was that I use Windows ME, which, as far as I can tell does not have a "safe mode with networking support," so I just used "safe mode"

    The only three items of interest I found in performing all of the steps were using Ad-Aware: Hi-Wire, Alexa, and Backweb Lite. I quarantined Hi-Wire and Alexa and kept Backweb Lite.

    I got to the point where I began using HiJack This! I'm obviously not an expert, so at this point I got scared of what I was going to blow up.

    I deleted one R1 and three BHO's that were obviously not necessary (just a bunch of ???? and random characters with no files associated). I think I need to delete the MSN Toolbar BHO based on postings I have seen here and in other places, but wanted to check with someone before I did. I tried removing MSN toolbar from my Add/Remove programs, but that did not work. I also went to the MSN Toolbar uninstall website, but I don't think Microsoft will let you uninstall using Firefox because I got an error message. There are two 02's one 03, and two 09's that I believe are associated with MSN toolbar. Should I delete these also?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have all of your Microsoft Windows (and other software) updates? Do you use MSN Toolbar? That should be the deciding factor on whether to remove it or not.

    If you still have problems that you need help with, follow the steps below:


    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. zdouble

    zdouble Private E-2

    Logfile is attached. Thanks for your help.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to answer my questions:

    First you need to disable Spybot's Teatimer process because it may block some of the changes we need to make.

    To disable TeaTimer, run Spybot and click Mode and select Advanced Mode. Then click Tools and select Resident. Now in the right window pane, uncheck TeaTimer.
    Also while this is open, in the left column now select IE Tweaks and then in the right pane make sure all the Miscellaneous locks are unchecked.
    Now quit Spybot!



    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - ???d?d????ò - (no file)
    O2 - BHO: (no name) - ???????????????????????????f? - (no file)
    O2 - BHO: (no name) - ???????????????????????????d? - (no file)
    O2 - BHO: (no name) - ????????@ - (no file)

    After clicking Fix, exit HJT.
    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  5. zdouble

    zdouble Private E-2

    Sorry about not answering the questions. In my haste to get you the logfile, I forgot to write my responses.

    I do NOT have the latest Windows Updates since I cannot use MS Internet Explorer, and I cannot find a way to check for and find Windows updates using Firefox.

    I do NOT use the Microsoft Toolbar since I switched over to Firefox. I use the Google Toolbar.

    I did as you asked and unchecked TeaTimer in Spybot, checked to see that the IE tweaks were unchecked and exited Spybot.

    I ran HJT and fixed the four lines. I then rebooted and ran HJT (logfile is attached).

    As for how things are working, I still get a "Buffer Overrun Detected" message when attempting to start MS IE.

    Thanks again,
    Zdouble
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First let's try going to Add/Remove programs and uninstalling MSN TOOLBAR

    Let me know if you find it and are able to uninstall it. If so, now try running Internet Explorer.

    If you cannot uninstall it, have HJT fix the below lines (make sure all browser windows are closed first):


    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.3000.1001\EN-US\MSNTB.DLL
    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\PROGRAM FILES\MSN APPS\ST\01.02.3000.1002\EN-XU\STMAIN.DLL
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.3000.1001\EN-US\MSNTB.DLL
     
  7. zdouble

    zdouble Private E-2

    I was not able to uninstall IE through the normal means, so I used HJT to uninstall. That worked and I am now able to launch IE.

    I tried a few simple websites to see if the connection works, but could not connect (google, yahoo). The only connection I can now make through IE to the internet is to the Windows Update page. Unfortunately, I still cannot do a scan of my computer to check for necessary updates.

    My automatic updates,such as ZoneAlarm and VirusScan are also still not working.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try doing the following:
    - Open a command prompt by click Start, Run, and enter cmd and click OK
    - at the command prompt enter the below commands each followed by the enter key
    ipconfig /flushdns
    exit


    Also download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    Any improvement?
     
  9. zdouble

    zdouble Private E-2

    I'm on Windows ME, so I had to use the methodology on the following website to renew my ip configuation: http://northtechs.com/ipconfig.htm

    Since I couldn't flush my DNS cache from the command prompt, I used the method from the following webpage to delete offline content through IE options: http://www.computing.net/windowsme/wwwboard/forum/45436.html

    I ran hoster as requested, but didn't notice any change to the websites I had tried previously (yahoo and google, and microsoft windows update). I tried other websites, and they load properly; however, I cannot click on any of the text boxes within a web site to enter text. I cannot connect to nearly all of the large search engine websites - Google, Yahoo, AltaVista, askJeeves - and the only one I can, Lycos, does not load completely and I have the same text box entry problem.

    Zdouble
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you use dial-up, cable, or ADSL (or something else)?
    Do you use a router?

    Since IE now works, can you get you Windows updates from: Windows Update

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixIE.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixIE.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes
     
  11. zdouble

    zdouble Private E-2

    I use a Motorola Surfboard Cable Modem and a Linksys Router (for VOIP and security). However, I only have the one computer on the network.

    IE is still giving me the problems mentioned previously. No, I cannot get Windows Update to work due to this problem. When I try to select "Scan for Updates" nothing happens.

    I added the file into the registry, but did not notice any improvements.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So let's see if I understand your problem.

    You can access some websites with IE but not all?

    If you temporarily disable your firewall (Zonealarm) can you access the websites?

    Can you access all websites using Firefox?
     
  13. zdouble

    zdouble Private E-2

    Correct, I can access some websites, but not all through IE. I also cannot access majorgeeks.com. Of the websites I can access, I can click links, however, I cannot click on any of the text boxes that require me to enter text.

    I shut down ZoneAlarm, but nothing changed.

    I cannot think of any problems on Firefox. Firefox has worked so well that I think I have been neglecting IE and not checking for Windows Updates often enough.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download DelDomains and unzip it to your desktop.

    Find the files from deldomains.zip on your Desktop and RightClick on the deldomains.inf file and select Install.

    Now repeat what I gave you in message number 8 for using Hoster.

    Any change?
     
  15. zdouble

    zdouble Private E-2

    I installed Deldomains and reran Hoster. No change noticed. One other thing I noticed was that when I go to the IE Tools, Security tab, when I click on "Custom Level" for each of the zones, there is nothing displayed in the "Settings" window. I think I have a virus that I didn't find when I went through the tutorial. Should I try going through it again? I stopped at the part where it starts using HJT because I didn't want to screw anything up. I did not do any of the following alternative scans listed in the tutorial:

    BitDefender
    RavAntivirus
    TrojanScan
    a2 free edition
    avast!
    ads spy
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If there is nothing at all appearing in the Settings window, it sounds like something is wrong with your IE installation. I would suggest you discuss this in the Software Forum as it sounds like you may need to re-install or repair IE some how.

    The below link may be useful too:

    http://www.pcmag.com/article2/0,1759,1559298,00.asp
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds