ABXZone Computer  Forums



Welcome to the ABXZone Computer Forums forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact us.

Reply
 
LinkBack Thread Tools Display Modes
Old 06-02-2008, 06:31 AM   #1
Registered User
 
Join Date: Jun 2008
Posts: 2
Baidu Bar.....BDGuard.sys again!

I see that more than a year ago a member had a lot of trouble getting rid of the BDGuard.SYS Trojan. Which has now been identified as a very dangerous beast. Dare not use Paypal, my bank or anything that needs passwords.
I have got it on my laptop, came from the PPStream which I have used to watch soccer games.
Whilst I am more than competant, I am no expert with computers. I don't think I could do all the registry edditing safely that the guy above did.
I would have thought that after 18 months there would now be a program that would clean it.
Truesword, amongst others, states it can clean it but it can't! Spybot, Zone Alarm Suite, Lavasoft and AVG V8 all find it and after "fix" say they have cleaned it. But as before, within seconds it's back. Nearly threw the laptop out the window yesterday.
Anyone have any latest info that might help.
(Offline)   Reply With Quote

 
Old 06-02-2008, 07:45 AM   #2
TQ
You gonna throw that?
 
TQ's Avatar
 
Join Date: Mar 2001
Location: Austin, TX
Posts: 8,442
Re: Baidu Bar.....BDGuard.sys again!

This thread may assist you...

I only glanced at the thread, but the fellow claims to have resolved the issue.
__________________
Create in me a pure heart, O God, and renew a steadfast spirit within me - Psalm 51:10

My goal in life is to be as good of a person as my dogs already think I am...

Daywalker Studio:
Software: Adobe Audition 3.0/Pro Tools LE 7.4/Acid Pro 6.0/Multiple VST, DirectX and RTAS plugins/Kontakt 3 Sampler/Windows XP Professional
PC Hardware: D975XBX2-504/E6600/4x2GB Mushkin XP2-6400/eVGA 800GTX/HP f1905 19" flat panel/Echo Audio Gina24 Sound Card/2 Maxtor 6B300SO's/1 Maxtor STM500AS/1 Western Digital WD2500JD/PleXwriter Premium/Plextor 716A/Samsung LightScribe DVD burner/Logitech Revolution MX/Antec P-180b/PPC&C Silencer 610/Zalman CNPS9500 HSF
Recording Hardware: Mbox 2 Factory Pro/Mackie SR24.4VLZ Pro Console/M-Audio Axiom 25 MIDI Controller/Audio-Technica 4033a microphone/Symetrix 528E/PreSonus Eureka/Mackie MR8 active monitors

Game Machine: Gigabyte GA-X48-DQ6/E8400/4x2GB Mushkin XP2-8500/BFG GTX280/HP f2105 21" flat panel/Creative Labs X-Fi Elite Pro/Maxtor 6H500F0/Maxtor STM3320/Western Digital WD4000KD/Plextor 760A/Toshiba DVD-ROM/Zalman CNPS9700/Antec P-180/PPC&C Silencer 610/Ideazon Merc Stealth keyboard/Vista Business64 SP1
(Offline)   Reply With Quote
Old 06-02-2008, 07:51 AM   #3
TQ
You gonna throw that?
 
TQ's Avatar
 
Join Date: Mar 2001
Location: Austin, TX
Posts: 8,442
Re: Baidu Bar.....BDGuard.sys again!

Here's another method that I located after searching. I found it here...


Removal of Badiu.Sobar is as simple as downloading and instaling Windows Defender ,(if not already installed) , rebooting in safe mode (not with networking) and running Defender. The files will be deleted and the system will ask to re-boot to complete removal.

Works on Windows XP Home SP2 and Pro SP2 as tested on my machines.

These are the files associated with it:

C:\Program Files\Baidu\bar
-baidubar.dat
-BaiDuBar.dll
-bdgdins.dll
C:\Program Files\Baidu\bar\img
-imglist.bmp
-logo.bmp

Registry Keys:

clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{FE14F22E-BE14-4F08-A80F-F27BC3A67B2D}

clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{B580CF65-E151-49C3-B73F-70B13FCA8E86}

clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{A7F05EE4-0426-454F-8013-C41E3596E9E9}

clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{7C76C055-ED6E-4535-A70F-CD476E727F67}

regkey:
HKLM\SYSTEM\CurrentControlSet\Services\BdGuard

regkey:
HKLM\Software\Classes\MimeFilter.AdFilter.1

regkey:
HKLM\Software\Classes\MimeFilter.AdFilter

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{FE14F22E-BE14-4F08-A80F-F27BC3A67B2D}

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{B580CF65-E151-49C3-B73F-70B13FCA8E86}

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{A7F05EE4-0426-454F-8013-C41E3596E9E9}

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{7C76C055-ED6E-4535-A70F-CD476E727F67}

regkey:
HKLM\Software\Classes\BaiduBarEx.DropTarget.1

regkey:
HKLM\Software\Classes\BaiduBarEx.DropTarget

regkey:
HKLM\Software\Classes\BaiduBarEx.BandIE.1

regkey:
HKLM\Software\Classes\BaiduBarEx.BandIE

regkey:
HKLM\Software\Classes\BaiduBar.Tool.1

regkey:
HKLM\Software\Classes\BaiduBar.Tool

regkey:
HKLM\Software\Classes\BaiduBar.Baidu.1

regkey:
HKLM\Software\Classes\BaiduBar.Baidu

regkey:
HKCU@S-1-5-21-1715567821-1482476501-725345543-1003\software\baidu

driver:
BdGuard

file:
C:\WINDOWS\system32\drivers\BDGuard.SYS
__________________
__________________
Create in me a pure heart, O God, and renew a steadfast spirit within me - Psalm 51:10

My goal in life is to be as good of a person as my dogs already think I am...

Daywalker Studio:
Software: Adobe Audition 3.0/Pro Tools LE 7.4/Acid Pro 6.0/Multiple VST, DirectX and RTAS plugins/Kontakt 3 Sampler/Windows XP Professional
PC Hardware: D975XBX2-504/E6600/4x2GB Mushkin XP2-6400/eVGA 800GTX/HP f1905 19" flat panel/Echo Audio Gina24 Sound Card/2 Maxtor 6B300SO's/1 Maxtor STM500AS/1 Western Digital WD2500JD/PleXwriter Premium/Plextor 716A/Samsung LightScribe DVD burner/Logitech Revolution MX/Antec P-180b/PPC&C Silencer 610/Zalman CNPS9500 HSF
Recording Hardware: Mbox 2 Factory Pro/Mackie SR24.4VLZ Pro Console/M-Audio Axiom 25 MIDI Controller/Audio-Technica 4033a microphone/Symetrix 528E/PreSonus Eureka/Mackie MR8 active monitors

Game Machine: Gigabyte GA-X48-DQ6/E8400/4x2GB Mushkin XP2-8500/BFG GTX280/HP f2105 21" flat panel/Creative Labs X-Fi Elite Pro/Maxtor 6H500F0/Maxtor STM3320/Western Digital WD4000KD/Plextor 760A/Toshiba DVD-ROM/Zalman CNPS9700/Antec P-180/PPC&C Silencer 610/Ideazon Merc Stealth keyboard/Vista Business64 SP1
(Offline)   Reply With Quote
Old 06-02-2008, 07:52 AM   #4
TQ
You gonna throw that?
 
TQ's Avatar
 
Join Date: Mar 2001
Location: Austin, TX
Posts: 8,442
Re: Baidu Bar.....BDGuard.sys again!

Good luck.
__________________
Create in me a pure heart, O God, and renew a steadfast spirit within me - Psalm 51:10

My goal in life is to be as good of a person as my dogs already think I am...

Daywalker Studio:
Software: Adobe Audition 3.0/Pro Tools LE 7.4/Acid Pro 6.0/Multiple VST, DirectX and RTAS plugins/Kontakt 3 Sampler/Windows XP Professional
PC Hardware: D975XBX2-504/E6600/4x2GB Mushkin XP2-6400/eVGA 800GTX/HP f1905 19" flat panel/Echo Audio Gina24 Sound Card/2 Maxtor 6B300SO's/1 Maxtor STM500AS/1 Western Digital WD2500JD/PleXwriter Premium/Plextor 716A/Samsung LightScribe DVD burner/Logitech Revolution MX/Antec P-180b/PPC&C Silencer 610/Zalman CNPS9500 HSF
Recording Hardware: Mbox 2 Factory Pro/Mackie SR24.4VLZ Pro Console/M-Audio Axiom 25 MIDI Controller/Audio-Technica 4033a microphone/Symetrix 528E/PreSonus Eureka/Mackie MR8 active monitors

Game Machine: Gigabyte GA-X48-DQ6/E8400/4x2GB Mushkin XP2-8500/BFG GTX280/HP f2105 21" flat panel/Creative Labs X-Fi Elite Pro/Maxtor 6H500F0/Maxtor STM3320/Western Digital WD4000KD/Plextor 760A/Toshiba DVD-ROM/Zalman CNPS9700/Antec P-180/PPC&C Silencer 610/Ideazon Merc Stealth keyboard/Vista Business64 SP1
(Offline)   Reply With Quote
Old 06-02-2008, 08:28 AM   #5
Registered User
 
Join Date: Jun 2008
Posts: 2
Re: Baidu Bar.....BDGuard.sys again!

Many thanks, will give it a go.
(Offline)   Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




Powered by vBulletin® Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.1
vBulletin Skin developed by: vBStyles.com

© 2006 - 2009 ABXZone Forums | About ABX Zone Forums | Advertising Opportunities | Legal | A member of the Crowdgather Forum Community