Compatible Support Forums: Please help I have spyware and loads of toolbars!!!!

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Please help I have spyware and loads of toolbars!!!!

#1 User is offline   pretzel1 

  • stranger
  • Group: Members
  • Posts: 3
  • Joined: 21-March 05

Posted 21 March 2005 - 07:23 PM

Pleas help me I have an annoying blue toolbar at the bottom of my screen which I think is called "Search now" and I think I got it when i downloaded msn 7.0 Beta. Does anyone know how to get rid off it or anything more about it. If so please contact me at jonygyte@hotmail.com or post it here.
Also can anyone tell me any good free programs for removing spyware as I have loads of it on my PC I have tryed search and destroy and spyware docotr but they have been no use. I also have zonealarm firewall and AVG anti-virus but they dont seem to be doing much good can anybody tell me any beter ones?
0

#2 User is offline   theefool 

  • enthusiast
  • Group: Members
  • Posts: 352
  • Joined: 28-March 03

Posted 21 March 2005 - 07:52 PM

adaware, Giant antispyware (if you are using windows 9x) or MS antispyware if you are using NT based machines (NT4?, 2k, xp).

Have you tried uninstalling your BETA program and see if this "spyware" disappears?
0

#3 User is offline   pretzel1 

  • stranger
  • Group: Members
  • Posts: 3
  • Joined: 21-March 05

Posted 21 March 2005 - 08:21 PM

Yes I got rid of msn 7.0 Beta and now have MSN 6.2 but ever since I have had the toolbar I have been gettin pop-ups and all the pop up blockers I have tried have never worked.
0

#4 User is offline   Wilhelmus 

  • old hand
  • Group: Members
  • Posts: 1032
  • Joined: 21-December 04
  • LocationFinland

Posted 22 March 2005 - 08:24 AM

Originally posted by pretzel1:
Quote:
Pleas help me I have an annoying blue toolbar at the bottom of my screen which I think is called "Search now" and I think I got it when i downloaded msn 7.0 Beta. Does anyone know how to get rid off it or anything more about it. If so please contact me at jonygyte@hotmail.com or post it here.

Get program called Hijack this, unzip it for example to "c:\hijack". Start it, click Scan. Then save the logfile and post it here.

Quote:

Also can anyone tell me any good free programs for removing spyware as I have loads of it on my PC I have tryed search and destroy and spyware docotr but they have been no use.

Removing: Spybot - Search and Destroy, Adaware, BHODemon.
Preventing: SpywareBlaster.

These are what I have used.
Do these scans in safe mode.

Quote:

I also have zonealarm firewall and AVG anti-virus but they dont seem to be doing much good can anybody tell me any beter ones?

Get AV called Avast! Home Edition. It is freeware and with it comes protections for IM, P2P, Email programs and limited "webshield".

0

#5 User is offline   pretzel1 

  • stranger
  • Group: Members
  • Posts: 3
  • Joined: 21-March 05

Posted 22 March 2005 - 07:07 PM

ok this is what I found when I scanned my PC with hijack this.
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [flag proxy curb anti] C:\Documents and Settings\All Users\Application Data\bits ante flag proxy\BOOBSAFE.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - Global Startup: Shortcut to Startup.lnk = C:\WINDOWS\Startup.cmd
O10 - Broken Internet access because of LSP provider 'xfire_lsp_11078.dll' missing
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk
O16 - DPF: cpcScanner - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://portal.kpmg.co.uk/dana-cached/setup/NeoterisSetup.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4F4CBD3A-9EB7-46D5-84E2-54E3F1156724}: NameServer = 195.92.195.95 195.92.195.94



0

#6 User is offline   Wilhelmus 

  • old hand
  • Group: Members
  • Posts: 1032
  • Joined: 21-December 04
  • LocationFinland

Posted 22 March 2005 - 08:31 PM

OK.. Start in Safe mode. Then start hijack, rescan and Fix these:
Originally posted by pretzel1:
Quote:


Fix and delete this folder ("bits ante flag proxy")
O4 - HKLM\..\Run: [flag proxy curb anti] C:\Documents and Settings\All Users\Application Data\bits ante flag proxy\BOOBSAFE.exe

O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE

Gaobot Worm, delete this file and scan your system in safe mode with your AV scanner!
Removal instructions, read the section "5. Deleting the values from the registry":

http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.ee.html
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h

Hmm.. check this file contents... or have you placed this here?
O4 - Global Startup: Shortcut to Startup.lnk = C:\WINDOWS\Startup.cmd

Get program called lspfix to fix this
O10 - Broken Internet access because of LSP provider 'xfire_lsp_11078.dll' missing

O16 - DPF: cpcScanner - http://www.crucial.com/controls/cpcScanner.cab

O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://portal.kpmg.co.uk/dana-cached/setup/NeoterisSetup.cab

O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab


Now still in safe mode, scan your system with AV, SpyBot, adaware, e.g.

0

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users