River RAT Safety Patrol - Random Access Trojans -

 

RIVER RAT SAFETY PATROL
Test Draft 2.1 Modi Class 3.0

Start: RiverRat Safety Patrol.com
Trojan Busters.Com
Baitman Pops.com.
Prelim Devl: 12/31/04 Under Construction

Copyright @ 2005
Douglas C. Killoran, Jr



"RIVER RAT SAFETY PATROL"... A Website designed to identify the RATS on your Computer. (Random Access Trojans).


PRIVATE PREVIEW FOR FRIENDS & FAMILY

GREETINGS...... I recently wrote to you a proposition that I was considering the formation of a Website that would provide a Resource for the Removal of Viruses, Trojans, Spywares, and Browser HiJacks, that simply are not timely captured by the latest Windows Updates, Norton Scanners, or Spy/Adaware programs.

--------------------------------------------------------------------------------

A ton of money is being spent everyday on these Software Protections, and after hours of downloading Security Patches, Windows Updates, Configuring Firewall Compatibility, Spyware and Pop-up protections....sooner or later a Trojan Horse will find a friendly port in you computer to call it home.

It is an Internet Fact Of Life....everytime you connect to the Internet (especially on broadband conncections), you OPEN well over 1000 ports on your PC. If you have configured a way to protect the In/Out traffic on each port...then let me know and My Website will be of no use to you.

Like the Helen of Troy Story, Trojans enter your computer because for some reason or another you Opened the Door and let them in because you wanted something that seemed OK for you at the time. By the time everyone reports it to their Norton or Spybots providers, it is too late....

Trojans are NOT warm fuzzies.....but they will love your WARM COMPUTER as your PROCESSOR fan works furiously to make your programs work.
Trojans have the capacity to worm their way into all your Internet and File activities. The really mean ones report everything they find to the HOST and soon you have lost ALL of your Personal Security Information. It is important to
Delete these Critters as they make themselves known....or you can get a new Computer and IDentification every few weeks. Starting over the Expensive way.

The purpose of my website will be to Research and Report Back to the Subscriber some tools for REMOVING the Trojans that they have encountered. Believe it or not.... There is a tool to Fix almost anything on the Intrusion. Anyone can research it themselves or contact my website service which has already compiled over 50 HiJack Fixes that still have not shown up in my 2005 Norton/Symantec or Adaware 6.0 SE.

Depending on the type of pest that plagues your computer, it may be very easy to detect an infection. That's the good news. The bad news is some of the most dangerous infections, especially from RATS or spyware, can be very difficult to detect. That's why most of the checking and removing of pests is done with software designed to do just that. Nevertheless, there are some general symptoms you should know.

SAMPLE RESPONSE TO VISITORS:

For your information....Fairly easy removal. Make sure that you have the Microsoft Patch MS 04-013. I think it it is in the IE Service pack2. If not...get it somehow.....
Trust me, this will eventually eat up your Internet explorer and you will have no access to the internet. It happened to me, but I learned a backdoor way onto the internet . Thanks to Broadband Cable, you can sneak on thru My Computer and bypass the IE. This is the only way to get the removal tools.

Your first signs of trouble will be error messages like IExplore.exe has caused problems in Mfc42.dll or something similar. Not a problem all the time, but will soon wipe you out. Download the patch and you will be okay after you reboot and scan for viruses on your virus program. and MS 03-011.

Trojan.ByteVerify

Also Known As: Exploit-ByteVerify [McAfee], Exploit.Java.Bytverify [KAV], JAVA_BYTVERIFY.A [Trend]

Type: Trojan Horse
Infection Length: various
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP

W32.Spybot.dr

W32.Spybot.dr is an installer that drops and executes W32.Spybot.Worm. It also installs a Backdoor Trojan which is detected as Backdoor.IRC.Cloner.
Type: Trojan Horse
Infection Length: 951,241 byte
Systems Affected: Windows 95, Windows 98, Windows NT, Windows 2000, Windows XP, Windows Me

---------------------------------------------------------------------

Here's a Sample Tool:

Uninstall 180 Search Assistant

I know of no one who has ever installed this piece of spyware on their systems on purpose. After an extensive search on the Internet, I could find no detailed tutorial on how to completely remove this junkware off your system, so I found out how to do it myself and documented it here.

The size of this uninstall tutorial may scare you at first, but don't worry, it's actually very easy to do. Just take your time. Everything is documented in extreme detail to help you get through this very annoying procedure. It is imperative that you uninstall this program from your system.

"180 Search Assistant" Name Variants

180 Search Assistant
180search Assistant

180searchassistant
180 search assistant Alert
n-CASE
nCASE
ncase
180 Solutions
180solutions
180solutions.com
180 Search Agent
msbb
saap
180ax
sais
Pops Buster Note: All of the above need to be removed.
Msbb master Host..... so start search there......Start: - Cont/Alt/Delete to get these Running Processes:

msbb.exe (Pops Buster Note)

Master Host, but salm.exe and
Boomerang.exe 180ax.exe are secret reinstallers.

saap.exe
180ax.exe KILL & DESTROY ALL THESE .EXE
sais.exe
lgbibsn.exe
msbbi.exe
silent.exe
jkill.exe
saie1101.exe
salm.exe
lcf.exe
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
The "automated" or non-manual uninstall (via "Add or Remove Programs) of 180 Search Assistant does not work.

There is no non-manual uninstall of 180 Search Assistant that works.

It is not a mistake. The automated uninstall was designed not to work on purpose. The uninstall found in your "Add or Remove Programs" connects you to 180solutions website which runs their supposed uninstall code right off their website. It does not work.

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

If you were to try the "Add or Remove Programs" to uninstall 180 Search Assistant, you would not only find that it does not work, but they lie to you as well:

A web page pops up and reads,

"We are sorry that you are thinking about uninstalling 180search Assistant. In case you did not realize it, 180search Assistant is permission-based search assistant application that sponsors free software and content sites. If you have 180search Assistant installed, then you have either downloaded free software we sponsored or visited a website sponsored by 180search Assistant. Removing 180search Assistant might remove or disable software applications you like and use everyday."

Do not pay attention to any of that ridiculous nonsense. What 180search Assistant does, is not assist you in any way what-so-ever. Instead, it pops up very annoying ads. Popup blockers like Google's toolbar, will not block these popups as they are spawned from a program on your computer, not from a webpage you are visiting. The program is so secretive, that many people who have it installed do not realize it and think the popups are coming from the websites they are visiting!

Then, a web page reads,

"You have requested to uninstall 180search Assistant. Sorry you did not find 180search Assistant worth your while. Note: You must select 'yes' at the prompt to complete the uninstall."

Then, a web page reads,

"You have successfully uninstalled 180search Assistant. Sorry you did not find it worth your while. Please come again."

At this point you would have been done with the uninstall. But they have completely and utterly lied to you. This uninstall does not work. I went through this painful process and checked for the spyware and it still existed in all of its entirety.

Manually uninstall 180 Search Assistant

Close down the 180 Search Assistant process as described below:
"CTRL-ALT-DEL"

"Processes" tab
Click "msbb.exe" (If you do not have msbb.exe, there are two possibilities: 1) You may have an alternate variation or 2) it may be temporarily shut down. Check for it again and later and different times. It should be running when you receive one of its annoying ads.)
Click "End Process"

Check "Windows Task Manager" to make sure msbb.exe is no longer running. There is a chance you could invoke it again, such as running the uninstall under "Add or Remove Programs", which you should not do. If it is still there, close it down as previously explained.

Find 180 Search Assistant using Windows' Search:
"Start"
"Search"
"For Files or Folders..."
"All files and folders"
Enter "msbb" in "All or part of the file name:"
Click "Search"
Wait for full results
.
Before you delete anything... read the next two lines carefully:
Do not delete msbbs.ht. It is a Microsoft file.
Whenever you are in doubt about deleting a file, please research it in Google like this: http://www.google.com/search?q=msbbs.ht. You can see from the results that msbbs.ht is not spyware. To be extra cautious about a file, research it in Google. For example: http://www.google.com/search?q=msbb.exe shows that msbb.exe is spyware right off the bat (first result).
Back to the search results...

You may see the install files in "C: \ Program Files \ 180Solutions". Delete these files.
You may see the install files in "C: \ Program Files \ Search-Assistant". Delete these files.
You may see the install files in "C: \ WINDOWS \ 180Solutions". Delete these files.
You may see the install files in "C: \ Program Files \ ???". Delete these files. By the

way, ??? is a directory of another piece of software. If this is the case, then this piece of software is probably the host program. This is very important, as the host program, by definition of "host program", is the program that installed 180 Search Assistant. You must remove the host program. I don't care if you like the program, remove it. It will probably keep reinstalling 180 Search Assistant over and over again.) Delete these files.

You may see the install files in "C: \ Program Files" itself (not under another folder.) Delete these files.
Basically, delete them wherever you find them! You may see the install files in another directory which I do not know of. There exists many variations of this program.

Pops Buster Note: Mostly applies to XP System

You may see some prefetch files in "C: \ WINDOWS \ Prefetch".
Delete these files. All prefetch files can be deleted, even if they have nothing to do with 180 Search Assistant. If exists, delete "180Solutions" and/or "Search-Assistant".
Note: Deleting "180Solutions" and/or "Search-Assistant" directory/directories will also delete other programs from 180 Solutions, even if they are not 180 Search Assistant. "sais.exe" may be such a program. "Start"
"Search"
"For Files or Folders..."
"All files and folders"
Enter "180Solutions" in "All or part of the file name:"

"Startup" tab
See "msbb" in the startup? Ok, this was just to show you that it does exist there. This is not how you delete it. You can disable it from here, but let's just delete it completely instead. Close down "System Configuration Utility", here's how to remove it:
"Start"
"Run..."
Type "regedit" and press Enter
Go to "HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run"
Delete "msbb" entry (This removes 180 Search Assistant from the "System Configuration Utility" startup menu. Go see that it is gone.)
Go to "HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Uninstall"
Delete "msbb" directory (This removes the annoying and false "Uninstall 180search Assistant" entry in "Add or Remove Programs" now that we have already manually deleted the program's files and directories. Go see that it is gone if you wish.)
Go to "HKEY_CURRENT_USER \ Software"
Delete "180solutions" directory
Delete "msbb" directory
Go to "HKEY_LOCAL_MACHINE \ SOFTWARE"
Delete "180solutions" directory
Delete "msbb" directory
Please, if anyone knows of any other registry entries or anything else this annoying spyware program leaves on your sytesm, do not hesitate to contact me and let me know so that I can append this information to this uninstall tutorial.
DONE at LAST !!!
--------------------------------------------------------------------------------

Your Computer Has a Mind of Its Own

Spyware, trojans and other pests contact other computers, and each pest is program of its own, therefore they use system resources such as CPU cycles, memory and an Internet connection.

Slow Computer

There are several reasons your computer may be running slow, but if you use it on a regular basis, then you're familiar with its noises, hang-ups and how it reacts. Older computers tend to run slower. Some applications cause computers to run slower. Computers are machines, they do not have moods. A sudden change in how your computer is running could be a sign of spyware or adware. Fix this problem now.

Trojan Buster.com

FIRST RESPONSE: Not to put my Service out of Buisiness from the start....but I truly suggest loading in the Mozzila FireFox Browser.
I made the change for myself and I am now free again to surf the net again without two hours per night of Adaware and Virus scans. It seems that most of the Trojan and Browser Hi-Jacks were written to attack Microsoft IE.

For now, Firefox has some cool Interenet protections going on. This may not last for long....so I may end up researching RATS for FireFox. Ease of use is the same and you can IMPORT all your Favorites from Internet Explorer. For those who remain faithful to Bill Gates till the end, I will continue to try to provide a Service that is pertinent to the service that you are using.

+++++++++++++++++++++++++++++++++++++++++++++++++++++


This page has been visited times.

This page created using the webpage creation facilities of Webspawner.
Copyright © 2005 Douglas C. Killoran, Jr.. All Rights Reserved.