Do you know fix for the "other steel site" bug?

The machines we love to hate

Moderator: Wiz Feinberg

User avatar
David Mason
Posts: 6079
Joined: 6 Oct 2001 12:01 am
Location: Cambridge, MD, USA

Do you know fix for the "other steel site" bug?

Post by David Mason »

My computer has downloaded a bunch of crap as a result of me looking at the steel site in Nick Reed's post. Does anybody know a fix for this? I have to delete a file called C\WINDOWS\SYSTB.DLL which is now part of Windows, three files that begin C:\WINDOWS\TEMP\THI and the Begin2Search thing that has attached itself to my toolbar? How do you delete a file that is part of Windows?
Tom Diemer
Posts: 244
Joined: 26 Nov 2000 1:01 am
Location: Defiance, Ohio USA

Post by Tom Diemer »


Here is a uninstall program for it.
http://www.begin2search.com/uninstall.exe

You will probably have to reset your home page after running it. If you haven't, download and run adaware and spybot.
http://www.download.com/3000-2144-10045910.html?part=69274&subj=dlpage&tag=button
http://www.download.com/3000-8022-10122137.html

Those should clean things up pretty well. Post again if this doesn't work.
Ray Minich
Posts: 6431
Joined: 22 Jul 2003 12:01 am
Location: Bradford, Pa. Frozen Tundra

Post by Ray Minich »

Thanks Tom, as you can see from my other thread I got nailed too.
User avatar
Chris Schlotzhauer
Posts: 2207
Joined: 11 Jan 1999 1:01 am
Location: Colleyville, Tx. USA

Post by Chris Schlotzhauer »

Wow Tom, thank you so much. Worked like a champ. Where do you find stuff like this?
Tom Diemer
Posts: 244
Joined: 26 Nov 2000 1:01 am
Location: Defiance, Ohio USA

Post by Tom Diemer »


Glad that helped guys Image

Chris, I do stuff like this for a living. Technically I'm a network engineer, but you can hardly be in the computer business and not know quite a bit about spyware issues these days. It would like being a car mechanic and not knowing how to change oil. lol. A lot of the common problems I know off hand, those I don't I know where to look for info. That's about it.

Really glad I was able to help Image


User avatar
David Mason
Posts: 6079
Joined: 6 Oct 2001 12:01 am
Location: Cambridge, MD, USA

Post by David Mason »

Thanks Tom, looks like that uninstall and antivirus.com got rid of it. I run ad-aware and spybot anyway, but this was an insidious little bugger.<FONT SIZE=1 COLOR="#8e236b"><p align=CENTER>[This message was edited by David Mason on 16 September 2004 at 01:35 PM.]</p></FONT>
Jeff Agnew
Posts: 741
Joined: 18 Sep 1998 12:01 am
Location: Dallas, TX

Post by Jeff Agnew »

If you used the begin2search uninstaller (UNALL.EXE) you probably didn't actually remove all the components - instead, you likely removed only the ironically named Browser Helper Object (the DLL).

This trojan is part of the IEPlugIn BHO and upon installation it:

<ul>[*]Leaves three executables, two DLLs, and two .DAT fiels on your drive.
[*]Adds over twenty keys to your registry
[*]Puts two AutoStart items in the registry
[*]Uses the contents of the .DAT files to hijack your searches anytime they match the contained keywords.[/list]
TO be sure you've deleted everything, search your drive for the following two files: KW.DAT & SYSINFO.DAT. If they're still there, you have more work to do.

And I know I harp on this constantly, but - you wouldn't have gotten this if you hadn't used IE and enabled ActiveX.

User avatar
Olli Haavisto
Posts: 2521
Joined: 4 Aug 1998 11:00 pm
Location: Jarvenpaa,Finland

Post by Olli Haavisto »

What is IE ? Ignorant mind(s) want to know...

------------------
Olli Haavisto
Polar steeler
Finland


User avatar
Olli Haavisto
Posts: 2521
Joined: 4 Aug 1998 11:00 pm
Location: Jarvenpaa,Finland

Post by Olli Haavisto »

Internet Explorer....Yeah, I feel stupid.
Ray Minich
Posts: 6431
Joined: 22 Jul 2003 12:01 am
Location: Bradford, Pa. Frozen Tundra

Post by Ray Minich »

<SMALL> hadn't used IE and enabled ActiveX.</SMALL>
I don't think people actively consciously and with malice intended, enable ActiveX. Isn't it automatically activated until someone "in the know" turns it off?

Looks like I just got "in the know" by brute force...<FONT SIZE=1 COLOR="#8e236b"><p align=CENTER>[This message was edited by Ray Minich on 17 September 2004 at 07:56 AM.]</p></FONT>