1
   

I need to remove EbatesMoeMoney & Offeroptimizer and ETC.

 
 
JoshK
 
Reply Tue 7 Dec, 2004 08:30 pm
Here is my scan of hijackthis
Logfile of HijackThis v1.98.2
Scan saved at 8:26:22 PM, on 12/7/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
C:\Program Files\Lexmark X5100 Series\lxbabmon.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe
C:\Program Files\PeerGuardian pr14\PeerGuardian_1.99b_pr14.exe
C:\Documents and Settings\Josh\Desktop\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ircspy.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ircspy.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
O2 - BHO: MultiMPPObj Class - {002EB272-2590-4693-B166-FBD5D9B6FEA6} - C:\WINDOWS\multimpp.dll
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [satmat] C:\WINDOWS\satmat.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Windows TaskAd] C:\Program Files\Windows TaskAd\WinTaskAd.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"
O4 - HKLM\..\Run: [euscagjt] C:\WINDOWS\system32\kddkjhwm.exe
O4 - HKLM\..\RunOnce: [NavExcelBar.dll] rundll32.exe "C:\WINDOWS\remover.dll",_remove@16
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\launchpd.exe"
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [Tsa2] C:\PROGRA~1\COMMON~1\tsa\tsm2.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - (no file) (HKCU)
O12 - Plugin for .php: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=925ca2de2b53e738e23fb8069526d5bb668ce3689745694e81f052
12dff28c11a62a9894fc37ebccbb2b1c579f1baf69b8b6b98919153dcae4b7c5399dfcb456eac7bd:880c508c2c6a291101f64dc3f0db6853
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll



I know where the google toolbar one is i want to get rid of that stupid thing. But where is the OfferOptimizer and there is this other popup. Can anyone tell me what programs shouldn't be running.

Thanks
  • Topic Stats
  • Top Replies
  • Link to this Topic
Type: Discussion • Score: 1 • Views: 920 • Replies: 11
No top replies

 
JoshK
 
  1  
Reply Tue 7 Dec, 2004 08:39 pm
o yeah
What is this

O4 - HKLM\..\Run: [euscagjt] C:\WINDOWS\system32\kddkjhwm.exe
0 Replies
 
Don77
 
  1  
Reply Tue 7 Dec, 2004 09:04 pm
Hi Josh and welcome to A2K.
need you to do a few things please.
First go to Add/Remove programs and remove, Windows TaskAd, and Internet Optimizer
It should ask you to reboot after removing them if it doesn't please restart your computer anyway,

Next,
Please restart HJT put a check next to the following, close all open windows and click "Fix Checked"
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
O2 - BHO: MultiMPPObj Class - {002EB272-2590-4693-B166-FBD5D9B6FEA6} - C:\WINDOWS\multimpp.dll
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll (file missing)
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [satmat] C:\WINDOWS\satmat.exe
O4 - HKLM\..\Run: [Windows TaskAd] C:\Program Files\Windows TaskAd\WinTaskAd.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"
O4 - HKLM\..\Run: [euscagjt] C:\WINDOWS\system32\kddkjhwm.exe
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [Tsa2] C:\PROGRA~1\COMMON~1\tsa\tsm2.exe
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=925ca2de2b53e738e23fb8069526d5bb668ce3689745694e81f052
12dff28c11a62a9894fc37ebccbb2b1c579f1baf69b8b6b98919153dcae4b7c5399dfcb456eac7bd:880c508c2c6a291101f64dc3f0db6853

Next reboot to safe mode ( By tapping the F8 key on start up) Make sure you can view all Hidden Files/Folders search for and delete the following in BOLD
C:\WINDOWS\multimpp.dll
C:\WINDOWS\systb.dll
C:\WINDOWS\satmat.exe
C:\Program Files\Windows TaskAd\WinTaskAd.exe < Delete Folder
C:\Program Files\Internet Optimizer\optimize.exe< Delete Folder
C:\Program Files\Web_Rebates\WebRebates0.exe< Delete Folder
C:\WINDOWS\system32\kddkjhwm.exe
C:\Program Files\Ares\Ares.exe< Delete Folder
C:\PROGRA~1\COMMON~1\tsa\tsm2.exe< Delete Folder
Restart your computer, Post back a fresh log please
0 Replies
 
JoshK
 
  1  
Reply Wed 8 Dec, 2004 11:12 am
I still need help
In my add remove programs the programs you asked me to remove are not in there. The Optimizer is not in there and the Windowstaskad. Should i still go on then?
0 Replies
 
JoshK
 
  1  
Reply Wed 8 Dec, 2004 11:23 am
O yeah and why would i want to put a check next to this one:


O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?
bt=ie&p=925ca2de2b53e738e23fb8069526d5bb668ce3689745694e81f052
12dff28c11a62a9894fc37ebccbb2b1c579f1baf69b8b6b98919153dcae4b7c5399dfcb456eac7bd
0 Replies
 
timberlandko
 
  1  
Reply Wed 8 Dec, 2004 11:56 am
JoshK wrote:
What is this

O4 - HKLM\..\Run: [euscagjt] C:\WINDOWS\system32\kddkjhwm.exe


JoshK wrote:
O yeah and why would i want to put a check next to this one:


O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} .... etc -

They are known baddies associated with OfferOptimizer. They relate to a trojan used to serve ads and to enable the download of other yuckware to your machine.

Don't worry right now if stuff isn't in Add/Remove. Just keep goin' with the HJT recomendations - checkmark the items Don recommended, click "Fix", empty your recycle bin and your caches, reboot, rescan, and post the new log back here.
0 Replies
 
JoshK
 
  1  
Reply Wed 8 Dec, 2004 03:41 pm
I deleted everything you said. But when i try to restart the computer and go into safe mode the computer tells me there is a Keyboard Failure. That happens when i tapp F8 so then i tried tapping Space bar and it does it also. So how do i get into safe mode?
0 Replies
 
JoshK
 
  1  
Reply Wed 8 Dec, 2004 04:11 pm
I don't have a systb.dll : I have a systb.exe should i delete that instead?

And i can't find the optimizer or wintaskad or webrebates could they have been deleted by HJT?
0 Replies
 
JoshK
 
  1  
Reply Wed 8 Dec, 2004 04:20 pm
Logfile of HijackThis v1.98.2
Scan saved at 4:19:31 PM, on 12/8/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Lexmark X5100 Series\lxbabmon.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Josh\Desktop\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ircspy.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ircspy.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\launchpd.exe"
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .php: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
0 Replies
 
timberlandko
 
  1  
Reply Wed 8 Dec, 2004 04:23 pm
In my experience, that "Keyboard Error" message on attempting to enter safemode via keyboard command is not uncommon, but should not prevent the system from booting into safe mode. Not real sure I remember correctly - just tried about a half dozen times to bring that error up on one of my machines, but no "success" ... you may be prompted to "strike any key to continue", if so, do so, but I think if you're patient, the machine oughtta boot into safemode on its own without your help. Might take a couple minutes, though. An alternate way to force the machine to boot into safemode would be to go to Start > Run, enter "msconfig" (without the quotes) into the dialog box, click "OK", then in The Windows Configuration Utitlity which should open in a box on your desktop, select the "BOOT.INI" tab (should be the 4th tab, I think), put a checkmark in the first option box, "/SAFEBOOT", click "Apply", then "OK" to exit. On exiting Configuration Utility, you should be presented with a notification that in order to apply your changes, you must reboot. Click the "Reboot Now" button to confirm and implement the change. The machine should now boot into safemode on its own. When you're finished in safemode, be sure to go back and unclick the "/SAFEBOOT" option before you reboot normally.

As to systb.dll / systb.exe , I would think if you have one, the other is there, whether you can see it or not. What folder is systb.exe in, and where is that folder in your folder tree? I'm thinkin' that whole folder might best be done away with, not just the file itself, but I'd like a little more info.
0 Replies
 
JoshK
 
  1  
Reply Wed 8 Dec, 2004 04:58 pm
I finally got into safe mode, but the systb.exe is just a file in c:\Windows. Its not in a folder. I would think its the same ast the systb.dll.
0 Replies
 
timberlandko
 
  1  
Reply Wed 8 Dec, 2004 05:12 pm
Well, the .dll is used by the .exe file. They're not the same thing, but they sorta pretty much go together. Don't delete the Windows folder Shocked Laughing - just get rid of the systb.exe file.

BTW - that last log was lookin' lots better.
0 Replies
 
 

Related Topics

Clone of Micosoft Office - Question by Advocate
Do You Turn Off Your Computer at Night? - Discussion by Phoenix32890
The "Death" of the Computer Mouse - Discussion by Phoenix32890
Windows 10... - Discussion by Region Philbis
Surface Pro 3: What do you think? - Question by neologist
Windows 8 tips thread - Discussion by Wilso
GOOGLE CHROME - Question by Setanta
.Net and Firefox... - Discussion by gungasnake
Hacking a computer and remote access - Discussion by trying2learn
 
  1. Forums
  2. » I need to remove EbatesMoeMoney & Offeroptimizer and ETC.
Copyright © 2025 MadLab, LLC :: Terms of Service :: Privacy Policy :: Page generated in 0.03 seconds on 05/08/2025 at 10:42:54