Results 1 to 9 of 9

Thread: Toolbar 888

  1. #1
    I have one of these now Nominus Experse's Avatar
    Join Date
    Jun 2006
    Location
    Here
    Posts
    4,884

    Default Toolbar 888

    Recently, I accidently downloaded a very hazardous file. I knew it was bad news, but as things happen, sometimes you just don't think and end up doing stupid things... So such a thing happened to me...

    I now see that I have a new program in my Add/Remove Programs in my Control Panel. It's called Toolbar 888. Where I should have the option to remove it, it says Change/Remove. It then "pretends" to be rid of itself, but I think all it's doing is spreading more of its ilk. It never disappears... It simply says that it is "Complete" with whatever the hell is was "doing".

    I have noticed new processes running, notabley being called C:\WINDOWS\system32\spoolsv.exe and alg.exe etc...

    My question then, is how am I to be rid of this thing...

    I have run Spydoctor, Ad-Aware, AVG, and ewido. Nothing.

    It's rather frustrating as I will get random pop-ups that direct me to download Winantivirus Pro and other obvious hoaxes.

    I did find a site talking about the same problem, and I was wondering if it was safe and/or credible.

    Here is the link to mentioned site:
    http://forums.techguy.org/security/5...bar-888-a.html


    So, any help would be much appreciated.

    Thanks
    ...

  2. #2
    i n v i s i b l e Tech Admin o_O's Avatar
    Join Date
    Jun 2001
    Location
    New Zealand
    Posts
    2,957
    Blog Entries
    1

    FFXIV Character

    Humphrey Squibbles (Sargatanas)

    Default

    Toolbar 888 is a nasty piece of adware. A bit of Googling turned up <a href="http://defeat-rogue-spyware.com/toolbar888/info.html?gclid=CI2SmY6y8IcCFR1uTAodu1bjgA">this page</a> which has a tool called Xoftspy available to download.
    I tested the executable there and it's legitimate, so no need to worry about getting more spyware from that.

    You don't need to worry about alg.exe and spoolsv.exe; alg.exe is a Windows service which provides a network gateway, so you can't use the internet without it, and spoolsv.exe is a process which handles various printing jobs.

  3. #3
    I have one of these now Nominus Experse's Avatar
    Join Date
    Jun 2006
    Location
    Here
    Posts
    4,884

    Default

    I downloaded Xoft

    Ran the scan, and it found one major threat, which happened to be a registry change.

    It then said that I must purchase it, which would down me $40. It might fix is, and it may not. The only thing that would be certain is that I would have to spend $40, which I do not feel like doing.

    There has to be a different, and cheaper, method of being rid of this thing...
    ...

  4. #4
    Will be banned again Roto13's Avatar
    Join Date
    Nov 2005
    Location
    On the INTARWEB
    Posts
    14,570

    Default

    How much you wanna bet they're from the same people?

  5. #5
    Banned Sylvie's Avatar
    Join Date
    Aug 2004
    Location
    Hell
    Posts
    4,136
    Blog Entries
    4

    Default

    Try PrevX. It gets rid of stuff good.

  6. #6
    Steve Steve Steve Steve Iceglow's Avatar
    Join Date
    Dec 2002
    Location
    Achievement City
    Posts
    8,250
    Blog Entries
    1

    Default

    hmm panda isn't too bad at getting the difficult ones. That or there is always the time honoured tradition of whipping out the cd's and usb memory sticks and saving the documents you cannot live without then formatting the hard drive, one guaranteed fix and the best part about it if you have a restore cd (or even just access to a friends one) and the original windows xp product key you get with the computer you simply format, re-install and change the product key to your original one. Then simply place a phone call (afaik this is the only way since net validation I believe only works once) which should be free and enter in the code to activate. Believe me this manner of activation works I got the advice on it from Microsoft activation centre (from the sounds of the voices I have heard in the past based somewhere in india or bangladesh) and it has worked every time.

  7. #7
    I have one of these now Nominus Experse's Avatar
    Join Date
    Jun 2006
    Location
    Here
    Posts
    4,884

    Default

    I have solved the issue by manually going into my registry and changing my Windows Settings to allow me to see all files on my CPU, regardless if they are integral to the system or not.

    I used this in conjugation with HijackThis and VundoFix to be rid of it completely and utterly.


    A mod can delete this now, thanks.
    ...

  8. #8
    Draw the Drapes Recognized Member rubah's Avatar
    Join Date
    Dec 2004
    Location
    Now Destiny is done.
    Posts
    30,655
    Blog Entries
    21
    Contributions
    • Former Administrator
    • Former Cid's Knight

    Default

    deleting would be dumb, because someone else might have teh same problem later on xD

  9. #9
    I have one of these now Nominus Experse's Avatar
    Join Date
    Jun 2006
    Location
    Here
    Posts
    4,884

    Default

    Quote Originally Posted by rubah View Post
    deleting would be dumb, because someone else might have teh same problem later on xD
    Well, perhaps, but HijackThis requires that you know what you are doing. It finds EVERYTHING, regardless if its malware or not. Knowing what to be rid of and what to keep is quite pertinent. The average Joe would either be too confused or would simply delete everything that came up with HijackThis. HijackThis can do more harm than good if people use it improperly, so there ought to be a warning of some sort perhaps...

    However, Vundofix is worth mentioning, and all it requires is someone with patience and the ability to restart the CPU. VundoFix also allows immediate results, though it does not completely get rid of the cursed thing.
    ...

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •