Recommended Driver Scanner

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
Spyware / AdWare - Cram tool bar posted in the Security & Safety forums; Hey, Thanks in advance. Everytime i log on. I get a message from the Microsoft Antispyware Program (the old GIANT program) that it finds CRAM TOOL BAR, i remove it ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 12-21-2005
Silver Member
 
Join Date: May 2005
Posts: 106
EmattE - See this Members User comments on their Profile page
Default Cram tool bar

Hey, Thanks in advance.
Everytime i log on. I get a message from the Microsoft Antispyware Program (the old GIANT program) that it finds CRAM TOOL BAR, i remove it everytime and still when i log on it comes back. The closes the internet connections when it uninstalls the Cram toolbar.
Does anyone know how to get rid of this? or know anything about it
Any help is much appreciated.
Cheers
Matt
Attached Files
File Type: log hijackthis.log (6.3 KB, 1 views)



Last edited by EmattE; 12-21-2005 at 08:22 PM.
  #2  
Old 12-22-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hi there EmattE. You also have an Lop infection on there.



Before fixing things with HijackThis Please Do the Following:

Show hidden files and folders:

For XP:
  1. On the Tools menu in Windows Explorer, click Folder Options.
  2. Click the View tab.
  3. Under Hidden files and folders, click Show hidden files and folders.
  4. If you see a warning message, click Yes.
  5. Click Apply.
  6. Click OK.


Disable System Restore to prevent re-infection.
(If you have/use it. You can turn it back on when youre PC is clean).

How to disable system restore:

WinXP.
  1. Click the Start button.
  2. Right-click My Computer, and then click Properties.
  3. On the System Restore tab, check Turn off System Restore or Turn off System Restore on all drives.


Please download CCleaner


You have a LOP infection that often comes together with Messenger Plus. To remove it we will try the simple way first.



1. Go to Add/Remove programs. Double click on "Messenger Plus!" (or click on Remove) read quote below please

2. The "Messenger Plus! - Setup" is now displayed. Click on the Uninstall button. Note: options displayed on the first screen are not related to the sponsor program.

3. The sponsor screen is now displayed (if you don't see it, search for it in your Task Bar). To prove that someone is currently reading the screen, you have to type the code that is displayed. Once you enter the code, press Uninstall.

4. If you entered the code properly, the program will ask you to confirm that you want to uninstall. You must answer "Yes" to this question, else, you won't have another chance of uninstalling.

5. To complete the uninstallation, follow the instructions that are displayed (the first one is to close all your Internet Explorer windows, that's very important). When everything is complete, restart your computer and, hopefully one nasty infection is gone.


When removing Lop.com from the Add/Remove screen it may not show up as Messenger Plus , also look for these and remove them:

Window Search
Window Searching
Lop.com
LOP SEARCH
Browser Enhancer
Ultimate Browser Enhancer

Finally there is a step in the removal process of Messneger Plus where the sponsor asks if you want to uninstall that aswell, You have to click YES to this part of the removal process
If you dont do this corretly then you will have no other choice but to reinstall Messenger Plus and then go through the whole removal process again from the start.


Also uninstall "Cram Toolbar" in add/remove programs if present there.


Then boot in safemode (hit f8 when booting up) and fix these with hjt:
(if still present)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.lvfmtlfispxm.com/YStPeAYb...902eoy0HSarCxH y907HRT9hHDs.jpg
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ptuuvekqttuna.biz/5Ab2RVV...q4DzXmc2M4.htm
R3 - URLSearchHook: (no name) - _{01E69986-A054-4C52-ABE8-EF63DF1C5211} - (no file)
R3 - URLSearchHook: (no name) - {01E69986-A054-4C52-ABE8-EF63DF1C5211} - (no file)
O2 - BHO: (no name) - {9C6F86B2-B9D7-9548-027B-B20CB62835A1} - C:\DOCUME~1\DEAN~1.DG-\APPLIC~1\AMOKCR~1\View Funk.exe
O2 - BHO: (no name) - {313A1E4F-DB6E-F718-D0AD-3C308E4CBEF3} - blank (file missing)
O2 - BHO: (no name) - {900E023C-7550-A8BC-6EFD-4C6652B2F64C} - blank (file missing)
O2 - BHO: (no name) - {910D4B64-2EA8-3077-FE15-36AF4BCDC432} - blank (file missing)
O3 - Toolbar: (no name) - {01E69986-A054-4C52-ABE8-EF63DF1C5211} - (no file)
O4 - HKCU\..\Run: [Love Type] C:\DOCUME~1\Matt\APPLIC~1\META2L~1\Setup Army Drive.exe
O15 - Trusted Zone: http://ny.contentmatch.net (HKLM)
Delete the folders in bold , and run Ccleaner. Also delete:

C:\ProgramFiles\Cram Toolbar


Copy the contents of Code box below to a notepad file. Save it to Desktop named Fixreg.reg and in the "save as" type box choose "all files".

Code:
REGEDIT4
 
[-HKEY_CLASSES_ROOT\CLSID\{01E69986-A054-4C52-ABE8-EF63DF1C5211}]
[-HKEY_CLASSES_ROOT\CLSID\{1395A06F-EEA0-4445-BA0C-E8B56B48E244}]
[-HKEY_CLASSES_ROOT\Interface\{9D5C62AE-57B0-43C3-BAE4-BA7908DF4386}]
[-HKEY_CLASSES_ROOT\Interface\{F5BB1D9A-DA7B-4C5B-8272-1554B814E97F}]
[-HKEY_CLASSES_ROOT\ToolBand.XBTB00429]
[-HKEY_CLASSES_ROOT\ToolBand.XBTB00429.1]
[-HKEY_CLASSES_ROOT\TypeLib\{256CE99C-D5E1-4ACC-A538-2ED1E2710FAE}]
[-HKEY_CLASSES_ROOT\XBTB00429.IEToolbar]
[-HKEY_CLASSES_ROOT\XBTB00429.IEToolbar.1]
[-HKEY_CLASSES_ROOT\XBTB00429.XBTB00429]
[-HKEY_CLASSES_ROOT\XBTB00429.XBTB00429.1]
[-HKEY_CURRENT_USER\Software\Maxthon]
[-HKEY_CURRENT_USER\software\XBTB00429]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks
\{01E69986-A054-4C52-ABE8-EF63DF1C5211}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
\{0E5CBF21-D15F-11D0-8301-00AA005B4383}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
\{01E69986-A054-4C52-ABE8-EF63DF1C5211}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
\{01E04581-4EEE-11D0-BFE9-00AA005B4383}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
\ITBarLayout]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
\Browser Helper Objects\{1395A06F-EEA0-4445-BA0C-E8B56B48E244}]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar
\{01E69986-A054-4C52-ABE8-EF63DF1C5211}]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
\Uninstall\XBTB00429.XBTB00429Toolbar]
Now double click Fixreg.reg and allow it to add/merge with registry when prompted.



Reset the following settings:

restore the default settings in Internet Explorer
Click Start > Settings > Control Panel
Select Internet Options
Select the Programs tab
Click Reset Web Settings
Click OK
Exit the Control Panel.

reset the Internet Explorer home page
Start Microsoft Internet Explorer.
Connect to the Internet, and then go to the page that you want to set as your home page.
Click Tools > Internet Options.
In the Home page section of the General tab, click Use Current > OK.



I see that you don't have an AV , have a look in our download section for some free ones.
Also i would recommend to do atleast one online AV scan , see for a link below.

After that please post a new hjt log to check.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
[File of the Day] Megasearch Tool Newsie IT News 0 12-06-2005 01:53 PM
[Tech News] New Microsoft Tool Helps Manage Your E-Mail Newsie IT News 0 12-02-2005 03:30 AM
[Tech News] New Microsoft Tool Helps Manage Your E-Mail Newsie IT News 0 12-02-2005 02:32 AM
Microsoft? Windows? Malicious Software Removal Tool merlin Security Watch 0 08-19-2005 05:32 AM
Microsoft Windows Malicious Software Removal Tool Zimbo Anti-Virus (AV) 0 06-06-2005 09:48 AM

All times are GMT +1. The time now is 01:54 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top