How do I get rid of this?

2

Comments

  • kanezfankanezfan sunny south florida Icrontian
    edited September 2003
    can i suggest one thing, did you also check in add/remove programs? i mean after all it may not be spyware (even though it looks suspiciously so doesn't it?) and there may be an uninstall program for it. any program that doesn't install itself legitemately is crapware to me, but perhaps this one is so new that spyware and ad-aware aren't capaple of removing it yet are they? finally, after being in the UK for three days, will one of you brits explain o me what is this obsession you have with asking questions at the end of sentences?
  • botheredbothered Manchester UK
    edited September 2003
    msconfig startup.
    Add remove is too big and I don't see anything in there that shouldn't be.
  • KwitkoKwitko Sheriff of Banning (Retired) By the thing near the stuff Icrontian
    edited September 2003
    While you're in there, get rid of the SoundBlaster and nVidia stuff. What's KFH\launcher.exe?

    Do you have Office 2K3 beta installed? That ctfmon.exe looks familiar.
  • botheredbothered Manchester UK
    edited September 2003
    I didn't get rid of UpdReg, I renamed it then restarted. A box popped up saying it couldn't find the update server, I clicked ok then started IE, It's still here!
    Shall I stick a long thin piece of tape across the screen?;D

    You guys are brilliant, your resonding faster than I can answer.

    bothered.

    PS, I'll rename updreg later.
  • profdlpprofdlp The Holy City Of Westlake, Ohio
    edited September 2003
    See if this helps you:
  • t1rhinot1rhino Toronto
    edited September 2003
    Open Windows explorer.
    Goto C:\Program Files\Internet Explorer\Plugins

    Right click on each file, open Properties. List the plugins...
  • botheredbothered Manchester UK
    edited September 2003
    Cheers prof, Got it, Ran it. The second item in the list looks like it may be the beast, Can anybody see why I shouldn't delete it?

    bothered.
  • botheredbothered Manchester UK
    edited September 2003
    Also, Information on the above item-
  • t1rhinot1rhino Toronto
    edited September 2003
    Yeah, delete it.
  • botheredbothered Manchester UK
    edited September 2003
    Quote-
    Well, we can probably rule out the filthy rich part, eh?

    I didn't know you knew me but you're spot on :)

    bothered.
  • botheredbothered Manchester UK
    edited September 2003
    Groan,,,,, The b*****ds still here,
    arrggghhhh.
  • profdlpprofdlp The Holy City Of Westlake, Ohio
    edited September 2003
    bothered said
    Groan,,,,, The b*****ds still here,
    arrggghhhh.
    Try Garlic, a Silver Bullet, and a stake through the heart...

    Try exporting some of the other suspect registry keys (in case you need them again), then delete the fishy looking ones.

    Oh yeah, be of good cheer... :confused::p
  • TexTex Dallas/Ft. Worth
    edited September 2003
    Use registry crawler and look for all occurances of "seach".

    Tex
  • profdlpprofdlp The Holy City Of Westlake, Ohio
    edited September 2003
    Any more info on these? BHO's are Browser Helper Objects, and a likely source of your trouble.

    Send more info on the ones marked in red.

    I'm riding with prime's Spyware Posse, now - this is starting to get personal! :ninja:;D
  • botheredbothered Manchester UK
    edited September 2003
    This may be about to get Embarrassing. Daughter is on PC2 so I turn around and ask her if this blue bar is on her PC, It is. During the last week I have had a load of trouble with NTL (see my thread NT Hell) Part of trying to fix my one way internet problem I copied all the advanced settings from internet options in PC2, which was working fine, to this one. Before I go on please put those clubs down guys, Ah, thats better.
    Right so then I got IE sorted out but another part of NTLs fix was to dissconect the router and turn Zone Alarm off (no protection) These were off for 10 minites max while I registered with NTL. During this 10 mins I was infected with Blast and Welcha worms!! I cleaned them and the internet worked ok after that apart from this blue toolbar. I then started this thread and the rest as they say is history.
    Now, I did, Honestly, As Prime suggested reset IE options, I did, I really did, Honest, It's true, I really really did, Honest. Well I've just reset them again and, How can I put it? erm, the blue bars gone. I have deleted a few things the programms you guys gave me and restarted a few times so I don't know. I clicked reset defaults and it went away and hasn't come back. Maybe it isn't spyware afterall? I've got some nice little progs and learned a load of stuff again, As I frequently do when I mix with you guys, Thanks very much all of you, What a site, What a bunch of guys, Cheers.:respect:

    bothered.
  • primesuspectprimesuspect Beepin n' Boopin Detroit, MI Icrontian
    edited September 2003
    Prof, you and Tex hold him, I'll get the bullwhip.... TD was right, this new smiley WILL come in handy :rant:
  • botheredbothered Manchester UK
    edited September 2003
    Now now, no need for that, I'm only prepared to take 95% of the blame for this.
    I did, Honest, Reset it, I did.Really.

    bothered.
  • profdlpprofdlp The Holy City Of Westlake, Ohio
    edited September 2003
    primesuspect said
    Prof, you and Tex hold him, I'll get the bullwhip.... TD was right, this new smiley WILL come in handy :rant:
    bothered said
    Now now, no need for that, I'm only prepared to take 95% of the blame for this.
    I did, Honest, Reset it, I did.Really.

    bothered.
    Then we'll only beat 95% of your a**! ;D

    Glad you got it! :thumbsup:
  • edcentricedcentric near Milwaukee, Wisconsin Icrontian
    edited September 2003
    Well I am thankful that bothered had this trouble.
    I have had one for a couple of weeks that I have been trying to get rid of and you guys gave me the ticket.
    tks
  • KwitkoKwitko Sheriff of Banning (Retired) By the thing near the stuff Icrontian
    edited September 2003
    I bet the blue bar was some sort stubborn ActiveX control. Just for spit and giggles, check the C:\%SYSTEMROOT%\Downloaded Program Files folder for anything suspicious. All of it probably looks suspicious, but if you right click and choose Properties, you should be able to figure out what the ActiveX control is. It's worth a shot, just to make sure that puppy is finally exorcised.
  • botheredbothered Manchester UK
    edited September 2003
    I Just connected to check any overnight posts and it's back, I reset defaults again but it didn't remove it If I click view and un check it, it goes away and this time it stays away. I'll see if any of the spyware I removed has come back later. I would like to be rid of it but I can live with clicking it once, Don't want to drive everyone barmy with this thing.

    bothered
  • SimGuySimGuy Ottawa, Canada
    edited September 2003
    God damned annoying blue bar isn't it bothered :D

    It somehow managed to get installed one of my older systems (Inspire in the sig). The only way I could get rid of it for sure...

    Format C: :(

    Spyware programmers beware... I'm going to kick your ass if I can find you.
  • primesuspectprimesuspect Beepin n' Boopin Detroit, MI Icrontian
    edited September 2003
    It's got to be Xupiter or LOP. Those are about the worst that are out there.

    Download and run AdAware just for ****s and giggles. Again, make sure you have the very latest spyware definitions before you scan.
  • edcentricedcentric near Milwaukee, Wisconsin Icrontian
    edited September 2003
    So I have been using the tips here to clean up my travel machine. Yesterday at work a virus locked up the network. Our firewall limited the damage, but it was coming from a machine inside. Of course they checked mine first (don't know why, I travel with it a lot, just back from China).
    And it wasn't me. I may still be fighting adware, but no virus here.
  • botheredbothered Manchester UK
    edited September 2003
    GOT IT!
    It was gone yesterday but back this morning. I did a few things today and it was still there, I decided to click on a few of the buttons on it to see if I could get a name. It's a friggin search engine called 'search web now' I've no idea how it got in here!
    I ended up with a help page, One question caught my eye, 'how do I uninstall any of your products?' There is a small file to download and run and PRESTO, It's gone. It's even gone from the view toolbars. I had avoided clicking on it before because I didn't know what it was and everybody here seemed to think it was something undesirable (and anything in here which I didn't put here is)
    Thanks again all, Hopefully that is the end of it and I won't get another bullwhipping from Prime. Man he's mean with that thing.

    bothered.
  • CyrixInsteadCyrixInstead Stoke-on-Trent, England Icrontian
    edited September 2003
    LOL, it's one of those 'did you read the manual' moments!! ;D

    I think we were all so caught up about it being spyware blah blah that nobody though of checking to see if there was any kind of 'help' with the product.

    At least the people from 'Search Web Now' were kind enough to give you the option of uninstalling their product.

    Well done bothered for finally managing to get rid of the damn thing, and thanks to everyone else for keeping me amused (at bothered's expense I'm sorry to say) with this very interesting thread. :thumbsup:

    ~Cyrix
  • EnverexEnverex Worcester, UK Icrontian
    edited September 2003
    I was going to recommend "HiJack This" It should have actually showed up in there. Did you actually try it?

    NS
  • botheredbothered Manchester UK
    edited September 2003
    Yup, Prof gave it me. But as everybody thought it was spyware and we didn't have a name for it wel, We didn't know what we were looking for.
    It's yet another lesson in don't overlook the obvious. Ain't hindsight a wonderful thing?

    bothered.
  • MERRICKMERRICK In the studio or on a stage
    edited September 2003
    I just finished reading this entire thread.

    This thing should be published. I was actually on the edge of my seat wondering how it would turnout.

    A movie in the making?

    Howabout this:

    Did you see the movie?

    No I read the book!

    Becomes:

    Did you read the book?

    No I read the thread!

    ;D
  • edited October 2003
    I just fought with this irritating toolbar for 3 hours today on a client's computer without success. Thanks for going thru the drill, it was driving me nuts!
Sign In or Register to comment.