PDA

View Full Version : Free2020 Search Toolbar + SMARTpages spyware.....how to remove?


GooseTickler
05-04-2004, 11:00 AM
hi

when i search in google it puts a bunch of smartpages and 2020 toolbar listings first for some reason. for example if i search dvdrom, this is all that apears on google:

================================================== ====

Find dvdrom at SMARTpages.com - Online Yellow Pages
Find local business listings for dvdrom at SMARTpages.com, the online yellow pages directory of
SBC Communications. SMARTpages also offers city guides, shopping guides, white pages and more.
http://***service.bfast.com/ (http://***service.bfast.com/) - 53k

Find dvdrom Using the Free 2020 Search Toolbar
Having trouble finding dvdrom? Get the 2020Search toolbar and say good-bye to those annoying pop-ups.
Many other useful features such as: text highlighter, multi-search engine, drag & drop,
e-mail results and more.
http://***2020search.com/ (http://***2020search.com/) - 48k

================================================== ====

and they didn't use to be there before. whatever search term i put in, it always has find "x" at smartpages or 2020. why is this happening?

ive run spybot and hijackthis numerous times, but neither find a solution to the problem.

anyone experience this problem before? anyone know how to solve it?

thanks

leday
05-04-2004, 03:21 PM
Spybot S&D hasn't been updating its reference files since March as they are currently working on version 1.3, which will "be out shortly" but they don't know when.


Try downloading, UPDATING and running Adaware 6.0 from http://www.lavasoftusa.com/

Neo
05-04-2004, 03:37 PM
Pest Patrol picked it up.

GooseTickler
05-07-2004, 06:52 AM
i've tried pest petrol before, but it seems to have caused even more problems. i dont know what its done to my computer :(

on download.com it gets an even number of positive and negative feedback. its one of those hit and miss programs.

any other solution to removing this annoying problem?

any help would be appreciated

thanks.

leday
05-07-2004, 11:34 AM
Spybot S&D hasn't been updating its reference files since March as they are currently working on version 1.3, which will "be out shortly" but they don't know when.


Try downloading, UPDATING and running Adaware 6.0 from http://www.lavasoftusa.com/

Have you tried Adaware 6.0, as mentioned above? I didn't see it mentioned anywhere that it was tried yet. Maybe it will help?

gooner
05-07-2004, 01:48 PM
Download LSPfix here: http://www.cexx.org/lspfix.htm (http://www.cexx.org/lspfix.htm)
Launch the application, and click the "I know what I'm doing" checkbox.
Check all instances of inetadpt.dll (and nothing else), and move them to the "Remove" pane.
Then click Finish.

Then run a copy of hijack this and post your log back here.

Or Search google for SMART and Hijack and Spyware

GooseTickler
05-08-2004, 05:37 AM
even before i posted here i searched google for a way to get rid of this, ran spybot, adaware and hijackthis, but i still cant solve the problem.

as for LSPfix, once i run it, the only .dll files that show are:

rsvpsp.dll (protocol handler)
winrnr.dll (NTDS)
mswsock.dll (tcpip)

there is no sign of inetadpt.dll.

here is the log of HijackThis. maybe it can help:

---------------------------------------------------------------

Logfile of HijackThis v1.97.7
Scan saved at 11:32:15, on 08/05/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
C:\Program Files\F-Secure Anti-Virus\Anti-Virus\fsgk32st.exe
C:\Program Files\F-Secure Anti-Virus\backweb\4476822\program\fsbwsys.exe
C:\Program Files\F-Secure Anti-Virus\Anti-Virus\FSGK32.EXE
C:\Program Files\F-Secure Anti-Virus\Common\FSMA32.EXE
C:\Program Files\F-Secure Anti-Virus\Common\FSMB32.EXE
C:\Program Files\F-Secure Anti-Virus\Anti-Virus\fssm32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\F-Secure Anti-Virus\Common\FCH32.EXE
C:\Program Files\F-Secure Anti-Virus\Common\FAMEH32.EXE
C:\Program Files\F-Secure Anti-Virus\Anti-Virus\fsav32.exe
C:\Program Files\F-Secure Anti-Virus\FWES\Program\fsdfwd.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\taskswitch.exe
C:\Program Files\ahead\InCD\InCD.exe
C:\Program Files\F-Secure Anti-Virus\Common\FSM32.EXE
C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe
C:\WINDOWS\twain_32\1200 UB\WATCH.exe
C:\Program Files\F-Secure Anti-Virus\backweb\4476822\Program\BackWeb-4476822.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Family\Desktop\LSPFix.exe
C:\Program Files\HiJackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = localhost
O4 - Global Startup: Reboot.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O9 - Extra button: Microsoft® JavaScript® Console (HKLM)
O9 - Extra 'Tools' menuitem: JavaScript Console (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: ConferenceRoom Java Client - http://chat.webmaster.com/java/cr.cab
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/swdir.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0309.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - http://216.249.24.142/code/PWActiveXImgCtl.CAB
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab


-------------------------------------------------------------

gooner
05-08-2004, 05:57 AM
Can you run it without anything running - the log looks clean to me. Can you download CWShredder: http://www.majorgeeks.com/downloadget.php?id=4086&file=2&evp=019a2397b049dbd687dd5ae17a580376

and run it twice for me. Once - then reboot then again

GooseTickler
05-08-2004, 07:37 AM
i ran CWShredder and i deleted the problem (sorry, i forgot to note down the name of the .dll file). i ran second time after rebooting and ther were no problems.

many thanks gooner and to all that replied :D