Please help I have spyware and loads of toolbars!!!!

Pleas help me I have an annoying blue toolbar at the bottom of my screen which I think is called Search now and I think I got it when i downloaded msn 7. 0 Beta. Does anyone know how to get rid off it or anything more about it.

Everything New Technology 1823 This topic was started by ,


data/avatar/default/avatar28.webp

3 Posts
Location -
Joined 2005-03-21
Pleas help me I have an annoying blue toolbar at the bottom of my screen which I think is called "Search now" and I think I got it when i downloaded msn 7.0 Beta. Does anyone know how to get rid off it or anything more about it. If so please contact me at jonygyte@hotmail.com or post it here.
Also can anyone tell me any good free programs for removing spyware as I have loads of it on my PC I have tryed search and destroy and spyware docotr but they have been no use. I also have zonealarm firewall and AVG anti-virus but they dont seem to be doing much good can anybody tell me any beter ones?

Participate on our website and join the conversation

You have already an account on our website? Use the link below to login.
Login
Create a new user account. Registration is free and takes only a few seconds.
Register
This topic is archived. New comments cannot be posted and votes cannot be cast.

Responses to this topic


data/avatar/default/avatar04.webp

352 Posts
Location -
Joined 2003-03-28
adaware, Giant antispyware (if you are using windows 9x) or MS antispyware if you are using NT based machines (NT4?, 2k, xp).
 
Have you tried uninstalling your BETA program and see if this "spyware" disappears?

data/avatar/default/avatar28.webp

3 Posts
Location -
Joined 2005-03-21
OP
Yes I got rid of msn 7.0 Beta and now have MSN 6.2 but ever since I have had the toolbar I have been gettin pop-ups and all the pop up blockers I have tried have never worked.

data/avatar/default/avatar09.webp

1019 Posts
Location -
Joined 2004-12-21
Originally posted by pretzel1:

Quote:Pleas help me I have an annoying blue toolbar at the bottom of my screen which I think is called "Search now" and I think I got it when i downloaded msn 7.0 Beta. Does anyone know how to get rid off it or anything more about it. If so please contact me at jonygyte@hotmail.com or post it here.
Get program called Hijack this, unzip it for example to "c:\hijack". Start it, click Scan. Then save the logfile and post it here.
 

Quote:Also can anyone tell me any good free programs for removing spyware as I have loads of it on my PC I have tryed search and destroy and spyware docotr but they have been no use.

Removing: Spybot - Search and Destroy, Adaware, BHODemon.
Preventing: SpywareBlaster.
 
These are what I have used.
Do these scans in safe mode.
 

Quote:I also have zonealarm firewall and AVG anti-virus but they dont seem to be doing much good can anybody tell me any beter ones?
Get AV called Avast! Home Edition. It is freeware and with it comes protections for IM, P2P, Email programs and limited "webshield".
 

data/avatar/default/avatar28.webp

3 Posts
Location -
Joined 2005-03-21
OP
ok this is what I found when I scanned my PC with hijack this.
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [flag proxy curb anti] C:\Documents and Settings\All Users\Application Data\bits ante flag proxy\BOOBSAFE.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - Global Startup: Shortcut to Startup.lnk = C:\WINDOWS\Startup.cmd
O10 - Broken Internet access because of LSP provider 'xfire_lsp_11078.dll' missing
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk
O16 - DPF: cpcScanner - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://portal.kpmg.co.uk/dana-cached/setup/NeoterisSetup.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4F4CBD3A-9EB7-46D5-84E2-54E3F1156724}: NameServer = 195.92.195.95 195.92.195.94
 
 
 

data/avatar/default/avatar09.webp

1019 Posts
Location -
Joined 2004-12-21
OK.. Start in Safe mode. Then start hijack, rescan and Fix these:
Originally posted by pretzel1:

Quote: 
Fix and delete this folder ("bits ante flag proxy")
O4 - HKLM\..\Run: [flag proxy curb anti] C:\Documents and Settings\All Users\Application Data\bits ante flag proxy\BOOBSAFE.exe
 
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
 
Gaobot Worm, delete this file and scan your system in safe mode with your AV scanner!
Removal instructions, read the section "5. Deleting the values from the registry":
http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.ee.html
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
 
Hmm.. check this file contents... or have you placed this here?
O4 - Global Startup: Shortcut to Startup.lnk = C:\WINDOWS\Startup.cmd
 
Get program called lspfix to fix this
O10 - Broken Internet access because of LSP provider 'xfire_lsp_11078.dll' missing
 
O16 - DPF: cpcScanner - http://www.crucial.com/controls/cpcScanner.cab
 
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://portal.kpmg.co.uk/dana-cached/setup/NeoterisSetup.cab
 
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
 

Now still in safe mode, scan your system with AV, SpyBot, adaware, e.g.