malware installed toolbar - cant remove it

  • Thread starter Thread starter Eric
  • Start date Start date
E

Eric

Hi,
My wife's computer got totally infected, (Windows media center edition) i
removed it from the network and then set out to clean it. I ran full scans
with McAfee, Spybot S&D and Adaware SE Personal and everything seemed to
clean ok. Then before i hooked it back to the net i just ran IE to see if
anything would show up and sure as the sun rises it did. IE tries to go to
toolbar6.trafficgeneration.biz and I cant figure out how to clean that out
of there.
Can anyone tell me how to clean that and also, is ther a way to know that
I'm really clean before i hook back up to the network?
Thanks
Eric
 
You can download Hijack This from here:

http://www.mjc1.com/files/merijn/hijackthis.exe

Go here:
http://mjc1.com/mirror/hjt/
For instructions on how to use it



You have to post the log it
produces here:
http://www.spywareinfo.com/forums/
so experts tell you what is good and what is malware
HijackThis Log Tutorial
http://www.aumha.org/a/hjttutor.php
HiJack This is a program that simply searches for programs that run at
boot time, and checks for browser plug-ins. The results this program
gives you are generally just informative. Most of the programs it will
come up with are valid programs that you actually want running. You'll
have to go through the results and tell the program to delete unwanted
programs. If you can't figure out what some of the programs are, don't
just delete them, research them and/or post them so experts can let
you know what the program does. Just type the program name into Google
which gets a decent answer pretty quickly.





| Hi,
| My wife's computer got totally infected, (Windows media center
edition) i
| removed it from the network and then set out to clean it. I ran full
scans
| with McAfee, Spybot S&D and Adaware SE Personal and everything
seemed to
| clean ok. Then before i hooked it back to the net i just ran IE to
see if
| anything would show up and sure as the sun rises it did. IE tries to
go to
| toolbar6.trafficgeneration.biz and I cant figure out how to clean
that out
| of there.
| Can anyone tell me how to clean that and also, is ther a way to know
that
| I'm really clean before i hook back up to the network?
| Thanks
| Eric
|
|
 
Eric said:
Hi,
My wife's computer got totally infected, (Windows media center edition)
i
removed it from the network and then set out to clean it. I ran full scans
with McAfee, Spybot S&D and Adaware SE Personal and everything seemed to
clean ok. Then before i hooked it back to the net i just ran IE to see if
anything would show up and sure as the sun rises it did. IE tries to go to
toolbar6.trafficgeneration.biz and I cant figure out how to clean that out
of there.
Can anyone tell me how to clean that and also, is ther a way to know that
I'm really clean before i hook back up to the network?
Thanks
Eric
ok, i'll go get HiJack This and give it a whirl
Thanks
 
Delete Temp files, turn off System Restore, make sure you have updated
pattern files for your virus and anti-spyware programs, run all those scans
in Safe Mode. Also download HijackThis and run it and download Microsoft's
Anti-Spyware.
 
Eric said:
Hi,
My wife's computer got totally infected, (Windows media center
edition) i
removed it from the network and then set out to clean it. I ran full
scans with McAfee, Spybot S&D and Adaware SE Personal and everything
seemed to clean ok. Then before i hooked it back to the net i just ran
IE to see if anything would show up and sure as the sun rises it did.
IE tries to go to toolbar6.trafficgeneration.biz and I cant figure out
how to clean that out of there.
Can anyone tell me how to clean that and also, is ther a way to know
that I'm really clean before i hook back up to the network?
Thanks
Eric

You still have the malware on your system. When doing scans for malware,
it is crucial that you do everything with updated tools in Safe Mode.
Although you've already done some work, I don't know the method you
used. Therefore, go through the following general malware removal
steps. You probably will need to go all the way through using
HijackThis. Links are included to places where you can post your HJT
log and get help (not here, please).

First delete all Temporary and Temporary Internet Files. For IE's
Temporary Files, go to Control Panel>Internet Options>General tab.
You'll see where you can delete cookies and files. For Firefox, clear
its cache by going to Tools>Options>Privacy>Cache> Clear. For Windows
Temporary files, Start>Run cleanmgr [enter] and then:

1) Scan in Safe Mode with current version (not earlier than 2004)
antivirus using updated definitions.

Before you remove malware, get LSPFix or WinSockFix for XP - see links
below.

2) Remove spyware with Spybot Search & Destroy and Ad-aware. These
programs are free, so use them both since they complement each other.
There is a new version of CWShredder from Intermute. I would not
install the other Intermute programs, however. Alternately, there are
CoolWebSearch malware removal steps at SilentRunners.

Be sure to update these programs before running, and it is a good idea
to do virus/spyware scans in Safe Mode. Make sure you are able to see
all hidden files and extensions (View tab in Folder Options).

If the malware remains even after you used Ad-aware and Spybot, you can
scan with HijackThis. HijackThis is an excellent tool to discover and
disable hijackers, but it requires expert skill. See below for
HijackThis links, including sites where you can post your HJT logs. A
combination of HijackThis and About:Buster works well in removing the
About:Blank homepage hijacker. Again, this is an expert tool and
novices should get help with it.

3) If you are running Windows ME or XP, you should disable/enable System
Restore after the system is clean because malware will be in the
Restore Points. With ME, you must disable System Restore completely.
With XP, you can delete all but the most recent (presumably clean)
System Restore point from the More Options section of Disk Cleanup
(Run>cleanmgr).

4) Make sure you've visited Windows Update and applied all security
patches. Do not install driver updates from Windows Update.

5) Run a firewall.

Links to help with malware:

Software/Methods:
http://www.safer-networking.org - Spybot Search & Destroy
http://www.lavasoftusa.com - Ad-aware
http://www.intermute.com/products/cwshredder.html
http://www.tomcoyote.com/hjt/ - HijackThis
http://www.intermute.com/spysubtract/cwshredder_download.html
http://www.silentrunners.org/sr_cwsremoval.html. - SilentRunners
http://www.cexx.org/lspfix.htm - Repair Winsock 2 settings after
removing spyware
http://www.spychecker.com/program/winsockxpfix.html - WinsockXPFix.exe

HijackThis:
http://www.aumha.org/a/hjttutor.htm - HijackThis tutorial by Jim
Eshelman
http://aumha.net - forums
http://spywarewarrior.com/viewforum.php?f=5 - Spyware Warrior HijackThis
forum
http://www.wilderssecurity.com/
http://forums.tomcoyote.org/

General:
http://aumha.net - look under "Security" for various forums
http://rgharper.mvps.org/cleanit.htm
http://mvps.org/winhelp2002/unwanted.htm
http://www.aumha.org/a/parasite.htm - The Parasite Fight
http://www.spywarewarrior.com/rogue_anti-spyware.htm

Malke
 
Eric,

Show hidden files, folders, and hidden system files
http://www.xtra.co.nz/help/0,,4155-1916458,00.html

Check for updates for McAfee, AdAware, and Spybot. Scan from normal
Windows mode from within all created User profiles. Reboot the system to
Safe Mode and scan once more. While in Safe Mode, delete the Temporary
Internet Files by using Windows Explorer to navigate to each Users'
Documents and Settings\Local Settings\Temporary Internet Files
folders. Do the same for the Temp folders.
Empty the Recycle Bin.

Open IE, click Tools, Manage Add-ons. Click the drop down window next to
Show:, select Add-ons that have been used by IE, then click on any
add-on that is related to toolbar6.trafficgeneration.biz, then click the
Disable button. IF you found any add-on advise you to navigate to the
WINDOWS\Download Program Files folder and delete it by right clicking it
and choosing Remove.
Restart the system to normal Windows mode, open IE to confirm the hijack
is gone.
If that doesn't resolve the issue advise you to post to a reputable
spyware forum for assistance :

http://www.bleepingcomputer.com/forums/HijackThis_Logs_and_Analysis-f22.html
http://castlecops.com/f67-Hijackthis_Spyware_Viruses_Worms_Trojans_Oh_My.html
http://forum.aumha.org/viewforum.php?f=30&sid=41ec50501fd36fc3be5c59babac5721b
http://spywarewarrior.com/viewforum.php?f=2&sid=3ce3e4c9a40b25268d1bac3189d22184

Read the guideline for the forum of your choice prior to posting to
obtain assistance as quickly as possible.


MowGreen [MVP 2004-2005]
===============
*-343-* FDNY
Never Forgotten
===============
 
Harry said:
So did i, but thats not it, it looks very similar but it definitely
is not that. None of those registry entries or files existed own
my system.
Hijack This is showing me some good info, 1 thing i am very suspicious of
is called tcmsav04.exe and i cant find any info about it. But it has a
garbage name attached to it [dw48ROcFP]

So, that i am planning on deleting but I'm waiting for someone to take a
look at my HJ log and tell me what else they might see. (I posted a request
on forums.spywareinfo.com last night)

Thanks
Eric
 
Eric said:
Hi,
My wife's computer got totally infected, (Windows media center edition)
i
removed it from the network and then set out to clean it. I ran full scans
with McAfee, Spybot S&D and Adaware SE Personal and everything seemed to
clean ok. Then before i hooked it back to the net i just ran IE to see if
anything would show up and sure as the sun rises it did. IE tries to go to
toolbar6.trafficgeneration.biz and I cant figure out how to clean that out
of there.
Can anyone tell me how to clean that and also, is ther a way to know that
I'm really clean before i hook back up to the network?
Thanks
Eric
OK, I'm finally clean, Took a lot of effort but its good to go now!
Thanks All,
Eric
 
Eric,
I did a google search for toolbar6.trafficgeneration, one hit, but not very
good and later for toolbar 6 and came up with a number of hits for removing
this issue. I suggest that you do the same and after reading several of the
hits take the action plan that best appeals. The toolbar6 does appear to
be a poorly written piece of mal ware and I wish you good luck removing it
from your system.
Richard
 
Eric said:
Hi,
My wife's computer got totally infected, (Windows media center
edition) i
removed it from the network and then set out to clean it. I ran full
scans with McAfee, Spybot S&D and Adaware SE Personal and everything
seemed to clean ok. Then before i hooked it back to the net i just ran
IE to see if anything would show up and sure as the sun rises it did.
IE tries to go to toolbar6.trafficgeneration.biz and I cant figure out
how to clean that out of there.
Can anyone tell me how to clean that and also, is ther a way to know
that I'm really clean before i hook back up to the network?
Thanks
Eric

Eric, it's very important that you do all the scans in Safe Mode. If you
didn't, then do them again. To get into Safe Mode, repeatedly tap the
F8 key as the computer is starting up. This will get you to the proper
menu.

If the Safe Mode scanning still doesn't take care of the problem, use
HijackThis and post your log in one of the specialty forums (not here,
please). I particularly recommend the AumHa forum. Here are links to
help:

http://www.aumha.org/a/hjttutor.htm - HijackThis tutorial by Jim
Eshelman
http://aumha.net - forums
http://spywarewarrior.com/viewforum.php?f=5 - Spyware Warrior HijackThis
forum
http://www.wilderssecurity.com/
http://forums.tomcoyote.org/

Malke
 
Eric said:
Hi,
My wife's computer got totally infected, (Windows media center edition) i
removed it from the network and then set out to clean it. I ran full scans
with McAfee, Spybot S&D and Adaware SE Personal and everything seemed to
clean ok. Then before i hooked it back to the net i just ran IE to see if
anything would show up and sure as the sun rises it did. IE tries to go to
toolbar6.trafficgeneration.biz and I cant figure out how to clean that out
of there.
Can anyone tell me how to clean that and also, is ther a way to know that
I'm really clean before i hook back up to the network?
Thanks
Eric
Hi Eric,

My advice in this situation is to double check your installed programs
in the control panel, re-run your virusscanner and use all-in-one
spyware tools like Hitman Pro (http://www.hitmanpro) it is a dutch tool
but i highly recommend it when you have trouble with all kinds of spyware.

Cheers,

Leander de Graaf
 
">> Can anyone tell me how to clean that and also, is ther a way to know
that
Hi Eric,

My advice in this situation is to double check your installed programs in
the control panel, re-run your virusscanner and use all-in-one spyware
tools like Hitman Pro (http://www.hitmanpro) it is a dutch tool but i
highly recommend it when you have trouble with all kinds of spyware.

Cheers,

Leander de Graaf

Further to this you might like to enter safe mode, then try the scan with
Hitman Pro .......
 
Hi

Hijack This is very good for 'toolbar problems' or you could try going into
the register yourself and doing a search for 'toolbar6' or
'trafficgeneration' but in theory, you should keep a copy of the changed key
just incase it causes other problems in which case you'll have to reinstall
it.

Good luck
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Back
Top