Go to Post Are you confused yet? - Andy Grady [more]
Home
Go Back   Chief Delphi > Technical > IT / Communications
CD-Media   CD-Spy  
portal register members calendar search Today's Posts Mark Forums Read FAQ rules

 
Closed Thread
Thread Tools Rate Thread Display Modes
  #1   Spotlight this post!  
Unread 06-10-2004, 22:01
mgreenley
 
Posts: n/a
Assisance with Win98

I am basically computer incompetent. With that said, my family members are worse, and after reciving an infected e-mail our computer has been swamped with "fecal matter". I've installed and run Ad-aware, SpyBot S&D, and I reguarly use Notron AV/Firewall, but to no avail. After cleaning out my computer (and after 4+ hours on the phone with microsoft tech support), Mostly everything is fixed (or theres programs that are hidden and I cant find). Mostly. there is a toolbar that got installed (The "Begin2Search.com" toolbar) and it just won't die. I have no idea what a Hijack this log is, haven't run(?, is used a better word?) one, but this toolbar runs as a component program, so its not shown an the add/remove programs list. It doesn't even show in the running processes list. For that matter, I've searched that IE folder and cant find it. I'm basically a babe in the woods and could use some help.
Now, when, with your help, I finally get deleted, is there any way to make certain that all of that malware/spyware/adware/trojan horses and what-not are actually gone and not just residing in some hidden file?
I realize that this type of problem has come up on Delphi before, but I've checked and it does not apply to this (I've already used all the suggested AV programs without any sucess). You might be able to ID this problem by a file named "o". It is a .bat file and runs a MS-DOS screen that searches for a non-existant file, then overruns the search buffer (As I understand) and writes 19 different adware/spyware programs to your computer. Any help at all is appreciated, and if you need more info, please say so.
Thank you all very much.

Michael Greenley, Team 341
  #2   Spotlight this post!  
Unread 06-10-2004, 22:06
Matt Attallah's Avatar
Matt Attallah Matt Attallah is offline
Now at sub 14's in a 5000lb vehicle
AKA: Maher Attallah
FRC #0005 (Robocards)
Team Role: Alumni
 
Join Date: Sep 2001
Rookie Year: 2000
Location: Detroit area, Michigan
Posts: 1,660
Matt Attallah has a reputation beyond reputeMatt Attallah has a reputation beyond reputeMatt Attallah has a reputation beyond reputeMatt Attallah has a reputation beyond reputeMatt Attallah has a reputation beyond reputeMatt Attallah has a reputation beyond reputeMatt Attallah has a reputation beyond reputeMatt Attallah has a reputation beyond reputeMatt Attallah has a reputation beyond reputeMatt Attallah has a reputation beyond reputeMatt Attallah has a reputation beyond repute
Send a message via AIM to Matt Attallah Send a message via MSN to Matt Attallah Send a message via Yahoo to Matt Attallah
Re: Assisance with Win98

Ad-Aware not pick it up?!

Are your .Dat files up to date? Ad-Aware has "Ad-Aware SE" now out - running version 1.05. (As of 9-29-05). That is what I run and it picks up EVERYTING...

I couldn't help ya out any other way...sorry!
__________________
That rug really tied the room together...
  #3   Spotlight this post!  
Unread 06-10-2004, 22:42
Jay H 237 Jay H 237 is offline
Down at the railroad
AKA: Jason Hartmann
FRC #0237 (Black Magic)
Team Role: Mentor
 
Join Date: Dec 2003
Rookie Year: 1999
Location: Watertown,CT
Posts: 3,331
Jay H 237 has a reputation beyond reputeJay H 237 has a reputation beyond reputeJay H 237 has a reputation beyond reputeJay H 237 has a reputation beyond reputeJay H 237 has a reputation beyond reputeJay H 237 has a reputation beyond reputeJay H 237 has a reputation beyond reputeJay H 237 has a reputation beyond reputeJay H 237 has a reputation beyond reputeJay H 237 has a reputation beyond reputeJay H 237 has a reputation beyond repute
Send a message via AIM to Jay H 237
Re: Assisance with Win98

This thread will be of interest to you. There's a lot of excelleny programs mentioned in there including Highjack This. I had to use some of these programs on a laptop I bought off Ebay.
I would run Highjack This and BHO Demon and that should fix it. I'm guessing Begin2Search.com is coming from a .dll file somewhere.
__________________
2006 Maryland Delphi "Driving Tomorrow's Technology" award
2006 Connecticut General Motor's Industrial Design award
2005 Finalists-----------New Jersey (along with our alliances again, 56 & 303)
2005 WINNERS of the Radio Shack Innovation in Control Award (not once, but twice! )
2004 WINNERS ------ Johnson & Johnson Mid-Atlantic Regional (also thanks to our alliances 56 & 303)
2004 General Motors Industrial Design Award Winners
2004 Archimedes Quarterfinalists (also thanks to our alliances 121 & 386)

NEMO _________ NonEngineering Mentor Organization
"Make it idiot proof and someone will make a better idiot!" - author unknown
  #4   Spotlight this post!  
Unread 06-10-2004, 22:49
gobeavs's Avatar
gobeavs gobeavs is offline
linux advocate
AKA: Ross
None #1425 (Wilsonville Robotics)
Team Role: Alumni
 
Join Date: Sep 2004
Rookie Year: 2004
Location: Oregon
Posts: 71
gobeavs will become famous soon enoughgobeavs will become famous soon enough
Send a message via AIM to gobeavs
Re: Assisance with Win98

Besides what has already been said I can't help you remove the problem, but once you do that I have some advice. Use Opera or Firefox. Some spyware and stuff like the toolbars come through flaws in Internet Explorer, if you use Firefox or Opera they don't have those holes. They also are just better browser in my opinion.
__________________
"Never in the face of human conflict has so much been owed by so many to so few."
- Winston Churchill on the RAF in WWII
  #5   Spotlight this post!  
Unread 06-10-2004, 23:13
sanddrag sanddrag is offline
On to my 16th year in FRC
FRC #0696 (Circuit Breakers)
Team Role: Teacher
 
Join Date: Jul 2002
Rookie Year: 2002
Location: Glendale, CA
Posts: 8,516
sanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond reputesanddrag has a reputation beyond repute
Re: Assisance with Win98

The simple fix would be to get an Apple.

Seriously now, check everything in your tasklist against this "dictionary" http://www.answersthatwork.com/Taskl...s/tasklist.htm Be careful with capitalization and "L"s looking like "I"s and stuff like that.

Also, I used to work in the Technology Services department of a school district. With a case like yours, we would have done everything you did, and if that didn't work, we would have gone straight for a re-image. Since this is probably not an option in your case, I'm not really sure what to tell you to fix it. Do you have the Windows CD and all your program CDs? If so, you could back up your files to an external HD and reinstal Windows and your programs.

To keep spyware/adware/malware off, we would use SpywareBlaster http://www.download.com/SpywareBlast...ml?tag=lst-0-1 Also, be sure to keep up with Windows Updates. After you install, restart and go back to check for more. Some updates trigger more updates. You might also want to bump up your IE security settings. Last, the best way to prevent this stuff is to simply be careful of what you are clicking on and what sites you go to. Anything from C2 media or Gator Corporation while you are online is bad for your comp. Anything that says "Your computer may be infected with spyware" is bad for your comp. A lot of times they will have popups that look like they are real Windows message boxes. Be careful and pay close attention to what the cursor looks like. A pointing finger is a linked popup, not a real message.

You also may want to try Google toolbar with popup blocker since many popups lead to spyware. While some say the toolbar itself is "spyware" because it reports back the sites you go to (for category listings and rankings and the such) and it updates itself automatically, it does nothing harmful to the computer, performance, or security and it is made by a reputable company. I have found the Google toolbar to be the ONLY safe search toolbar to have installed. I have used it for over 2 years with much success and no problems.
__________________
Teacher/Engineer/Machinist - Team 696 Circuit Breakers, 2011 - Present
Mentor/Engineer/Machinist, Team 968 RAWC, 2007-2010
Technical Mentor, Team 696 Circuit Breakers, 2005-2007
Student Mechanical Leader and Driver, Team 696 Circuit Breakers, 2002-2004
  #6   Spotlight this post!  
Unread 06-10-2004, 23:46
evulish's Avatar
evulish evulish is offline
1010100
AKA: Grant Harding
#0084 (WATTNESS (bot: Chuck))
Team Role: Alumni
 
Join Date: Jul 2002
Location: Towanda/Wysox, PA
Posts: 1,434
evulish is just really niceevulish is just really niceevulish is just really niceevulish is just really nice
Send a message via AIM to evulish
Re: Assisance with Win98

If you run Hijack This! and paste the log here, I can probably help you get rid of all the junk. It's one of the most useful tools I have ever used, but can cause some problems if you don't know what you're deleting. I've become the computer guy for my dorm's floor so I've been the one to disinfect people's computers and get rid of spyware. It's getting annoying :/
__________________
I'm a professional web developer. I'm good with PHP, Perl, Java/JSP, some RoR, XML, Javascript (AJAX as well), (x)HTML, CSS, etc.. Validated code is good; fully cross-browser code is better (you comply to your users and the software they use, not the other way around. Sorry!)
  #7   Spotlight this post!  
Unread 06-10-2004, 23:50
Unsung FIRST Hero
Nate Smith Nate Smith is offline
FRC Key Volunteer Trainer
AKA: CrazyNate
no team
 
Join Date: Jun 2001
Rookie Year: 1998
Location: Old Town, Maine
Posts: 1,029
Nate Smith is a splendid one to beholdNate Smith is a splendid one to beholdNate Smith is a splendid one to beholdNate Smith is a splendid one to beholdNate Smith is a splendid one to beholdNate Smith is a splendid one to beholdNate Smith is a splendid one to beholdNate Smith is a splendid one to behold
Send a message via AIM to Nate Smith Send a message via Yahoo to Nate Smith
Re: Assisance with Win98

I'm assuming the toolbar you're referring to shows up in IE, so here's a way around it...go into control panel, internet options...and go to the advanced tab. Look for the "Enable 3rd Party Browser Extensions" option and get rid of the check mark in it, then close out all IE windows and restart the computer. That should at least help the toolbar from doing anything, even if you can't get rid of it...
__________________
Nate Smith
nsmith@smythsoft.com
12 seasons, 4 teams, and more time logged behind the scorekeeper's table than I care to remember...
returning for 2011? only time will tell...
  #8   Spotlight this post!  
Unread 07-10-2004, 00:00
Elgin Clock's Avatar
Elgin Clock Elgin Clock is offline
updates this status less than FB!
AKA: the one who "will break into your thoughts..."
FRC #0237 (Black Magic)
Team Role: Mentor
 
Join Date: May 2001
Rookie Year: 2001
Location: H20-Town, Connecticut
Posts: 7,773
Elgin Clock has a reputation beyond reputeElgin Clock has a reputation beyond reputeElgin Clock has a reputation beyond reputeElgin Clock has a reputation beyond reputeElgin Clock has a reputation beyond reputeElgin Clock has a reputation beyond reputeElgin Clock has a reputation beyond reputeElgin Clock has a reputation beyond reputeElgin Clock has a reputation beyond reputeElgin Clock has a reputation beyond reputeElgin Clock has a reputation beyond repute
Send a message via AIM to Elgin Clock
Re: Assisance with Win98

For pop-ups.. Downloading the Google toolbar helps. It's one more line on your IE window bar, but it prevents lots of pop-ups from coming over the internet.

It's not 100% effective, but looking at my google toolbar now, I have 1811 pop-ups that were blocked since I installed this toolbar and I have only had it since maybe march or april.
__________________
The influence of many leads to the individuality of one. - E.C.C. (That's me!!)

  #9   Spotlight this post!  
Unread 07-10-2004, 04:41
JohnBoucher JohnBoucher is offline
Blue Shirt
FRC #0237
 
Join Date: Jan 2004
Rookie Year: 2003
Location: Watertown, CT
Posts: 2,927
JohnBoucher has a reputation beyond reputeJohnBoucher has a reputation beyond reputeJohnBoucher has a reputation beyond reputeJohnBoucher has a reputation beyond reputeJohnBoucher has a reputation beyond reputeJohnBoucher has a reputation beyond reputeJohnBoucher has a reputation beyond reputeJohnBoucher has a reputation beyond reputeJohnBoucher has a reputation beyond reputeJohnBoucher has a reputation beyond reputeJohnBoucher has a reputation beyond repute
Re: Assisance with Win98

begin2search does show an uninstaller on their home page
http://begin2search.com/

I would start there. You might just get it off your system. Let us know how you make out.
  #10   Spotlight this post!  
Unread 07-10-2004, 07:31
Adam Y.'s Avatar
Adam Y. Adam Y. is offline
Adam Y.
no team (?????)
 
Join Date: Mar 2002
Location: Long Island
Posts: 1,979
Adam Y. is a splendid one to beholdAdam Y. is a splendid one to beholdAdam Y. is a splendid one to beholdAdam Y. is a splendid one to beholdAdam Y. is a splendid one to beholdAdam Y. is a splendid one to beholdAdam Y. is a splendid one to behold
Send a message via AIM to Adam Y.
Re: Assisance with Win98

Quote:
Originally Posted by Matt Attallah
Ad-Aware not pick it up?!

Are your .Dat files up to date? Ad-Aware has "Ad-Aware SE" now out - running version 1.05. (As of 9-29-05). That is what I run and it picks up EVERYTING...

I couldn't help ya out any other way...sorry!
Hehehe... Ad-ware doesn't pick up the more serious forms of spyware.
__________________
If either a public officer or any one else saw a person attempting to cross a bridge which had been ascertained to be unsafe, and there were no time to warn him of his danger, they might seize him and turn him back without any real infringement of his liberty; for liberty consists in doing what one desires, and he does not desire to fall into the river. -Mill
  #11   Spotlight this post!  
Unread 07-10-2004, 07:49
Raven_Writer's Avatar
Raven_Writer Raven_Writer is offline
2004 Detroit & Pittsburgh Winners
AKA: Eric Hansen
FRC #0005 (RoboCards)
Team Role: Mentor
 
Join Date: Jan 2003
Rookie Year: 2002
Location: Melvindale
Posts: 1,549
Raven_Writer is just really niceRaven_Writer is just really niceRaven_Writer is just really niceRaven_Writer is just really niceRaven_Writer is just really nice
Send a message via ICQ to Raven_Writer Send a message via AIM to Raven_Writer Send a message via MSN to Raven_Writer Send a message via Yahoo to Raven_Writer
Re: Assisance with Win98

I'd try updating all your products (virus scanner, spyware remover, etc...) to the latest database (and possibly the newest version if possible).


As for the IE Toolbar thing, I'd suggest just downloading another browser like Firefox, Opera, Mozilla, or anything like that.
__________________
AIM: wisprmylastbreth
EMail: nightskywriter@gmail.com
Y!: synsoflife

"ai yoru ga" -- "Love the nights"
  #12   Spotlight this post!  
Unread 07-10-2004, 10:09
gobeavs's Avatar
gobeavs gobeavs is offline
linux advocate
AKA: Ross
None #1425 (Wilsonville Robotics)
Team Role: Alumni
 
Join Date: Sep 2004
Rookie Year: 2004
Location: Oregon
Posts: 71
gobeavs will become famous soon enoughgobeavs will become famous soon enough
Send a message via AIM to gobeavs
Re: Assisance with Win98

Quote:
Originally Posted by Raven_Writer
As for the IE Toolbar thing, I'd suggest just downloading another browser like Firefox, Opera, Mozilla, or anything like that.
I don't see why more people use them...they have pop-up blockers, tabbed browsing, a lot more features than IE, and they don't allow a lot of the spyware that comes through with IE.
__________________
"Never in the face of human conflict has so much been owed by so many to so few."
- Winston Churchill on the RAF in WWII
  #13   Spotlight this post!  
Unread 07-10-2004, 11:01
Marc P. Marc P. is offline
I fix stuff.
AKA: βetamarc
no team
 
Join Date: Jan 2002
Rookie Year: 1999
Location: Watertown, CT
Posts: 997
Marc P. has a reputation beyond reputeMarc P. has a reputation beyond reputeMarc P. has a reputation beyond reputeMarc P. has a reputation beyond reputeMarc P. has a reputation beyond reputeMarc P. has a reputation beyond reputeMarc P. has a reputation beyond reputeMarc P. has a reputation beyond reputeMarc P. has a reputation beyond reputeMarc P. has a reputation beyond reputeMarc P. has a reputation beyond repute
Send a message via AIM to Marc P.
Re: Assisance with Win98

I've dealt with every form of spyware under the sun, from simple hosts file redirections to junkware replacing winsock DLL files, to browser hijackers and keyloggers. What you have here is a combo BHO (Browser Helper Object), and Toolbar. The first step to revival is to download HijackThis. Open it up, and click "Scan." As others have suggested, click "Save Log", open up that file, and copy/paste the results here for us to examine. Otherwise, in the checklist that comes up, check off anything that says BHO and Toolbar, and click "Fix Checked." It might warn you that you must close all IE windows for a BHO to be removed, so you'll want everything closed except HijackThis when you do that. After it's all set, try opening up IE, and see if it's gone. If it's still there, we'll have a look at the log file, and suggest some registry changes to manually remove the bugger. (I've noticed HijackThis can and does effectively remove toolbars from HKEY_LOCAL_MACHINE but not from HKEY_CURRENT_USER, and often I have to remove toolbar entries from there manually).

Good luck, and keep us informed!
  #14   Spotlight this post!  
Unread 07-10-2004, 19:09
mgreenley
 
Posts: n/a
Re: Assisance with Win98

Thanks, for all the help so far, but alas my problem is not fixed. I'm missing MSVBVM60.dll, so I can't run Hijack this. If you know of a reliable site that I can download a copy from, please post a link. The problem with this toolbar is that it doesn't show up in the processes list (In Windows 98, ctrl+alt+del doesn't bring up a complete list), and every time I turn on the internet, it trys to download all the malware again (reconfigured the firewall, so it catches most of it now at least). On the upside, I found another piece of the junk ("Abetterinternet.exe"), so as I write this list of junk, hopefully I'll eventually find the master program and nab it.
The using a different browser option actually sounds nice, but like I said, I'm really not good around computers, and I wouldn't know how to do that either or what would happen (like, does Norton AV configured for IE need to be redone?, etc...)
And trust me, the "Don't click that flashing prize window"...my little brother is never going to hear the end of this. (what type of seventh-grader goes to rumandmonkey.com anyways?).
All said, I wish I could buy a G5. or maybe install RedHat...not while the parents buy the computers though.

Thanks for all the help, keep it up! Michael Greenley, Team 341

P.S. The parent site for that is a scam that tries to download more malware from what I've gathered from reading other forums from google (which operates at my level of computer know-how)
P.P.S. something new (and not good) that started happening is that text is parsed into "Sponsored Links"...great. Like I didn't need this type of stress before the season starts (approx. 129 days until robot ship date and counting).
  #15   Spotlight this post!  
Unread 07-10-2004, 19:31
evulish's Avatar
evulish evulish is offline
1010100
AKA: Grant Harding
#0084 (WATTNESS (bot: Chuck))
Team Role: Alumni
 
Join Date: Jul 2002
Location: Towanda/Wysox, PA
Posts: 1,434
evulish is just really niceevulish is just really niceevulish is just really niceevulish is just really nice
Send a message via AIM to evulish
Re: Assisance with Win98

To get Hijack This! running, download the VBRun60.exe from here: http://support.microsoft.com/default.aspx?kbid=192461 and install it and reboot. Microsoft is a pretty reputable place to download stuff from
__________________
I'm a professional web developer. I'm good with PHP, Perl, Java/JSP, some RoR, XML, Javascript (AJAX as well), (x)HTML, CSS, etc.. Validated code is good; fully cross-browser code is better (you comply to your users and the software they use, not the other way around. Sorry!)
Closed Thread


Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 06:32.

The Chief Delphi Forums are sponsored by Innovation First International, Inc.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2017, Jelsoft Enterprises Ltd.
Copyright © Chief Delphi