|
|
|||||||||
|
|||||||||
| |||||||||
|
|
|
| |||||||||
![]() |
|
|
«
Previous Thread
|
Next Thread
»
|
Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
#1
|
|||
|
|||
|
WHAT IN THE H - E - Double L!!!!!! C'mon admin or helpers!
Why is no one helping me? I don't mean to get testy, but I have been on this site numerous times and received wonderful, expedient help from kind folks.... NOW, I have been viewed 17 or some odd times, with NO response!!!! I really need some help. Every time I let someone use my PC, it seems to get screwed up. Apparently I did not have virus protection, which I do now.
PLEASE people! I have no idea what to do, and am a clueless novice. Please let me know what to fix to get rid of this nightmare, "Aboutblank". I cannot even retrieve my work e-mails thru Yahoo! It hijacks the page everytime I try to go Yahoo or Hotmail..... please help: Logfile of HijackThis v1.98.2 Scan saved at 12:46:37 AM, on 3/6/05 Platform: Windows 98 SE (Win9x 4.10.2222A) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\SYSTEM\KERNEL32.DLL C:\WINDOWS\SYSTEM\MSGSRV32.EXE C:\WINDOWS\SYSTEM\MPREXE.EXE C:\WINDOWS\SYSTEM\mmtask.tsk C:\WINDOWS\SYSTEM\MSTASK.EXE C:\WINDOWS\EXPLORER.EXE C:\WINDOWS\TASKMON.EXE C:\WINDOWS\SYSTEM\SYSTRAY.EXE C:\WINDOWS\SYSTEM\QTTASK.EXE C:\WINDOWS\LOADQM.EXE C:\PROGRAM FILES\ISP50\BIN\BARTSHEL.EXE C:\WINDOWS\SYSTEM\HPZTSB09.EXE C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE C:\WINDOWS\SYSTEM\SPOOL32.EXE C:\WINDOWS\SYSTEM\WMIEXE.EXE C:\WINDOWS\SYSTEM\RNAAPP.EXE C:\WINDOWS\SYSTEM\TAPISRV.EXE C:\PROGRAM FILES\YAHOO!\MESSENGER\YMSGR_TRAY.EXE C:\PROGRAM FILES\ISP50\BIN\PPSHARED.EXE C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\WINWORD.EXE C:\WINDOWS\SYSTEM\DDHELP.EXE C:\PROGRAM FILES\ISP50\BIN\BARTSHEL.EXE C:\PROGRAM FILES\ISP50\DIALER\DIALER.EXE C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE C:\WINDOWS\SYSTEM\PSTORES.EXE C:\PROGRAM FILES\PEOPLEPC ACCELERATED\PROPELAC.EXE H:\HIJACKTHIS1982.EXE R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.miami.com/mld/miamiherald/sports/football R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://c:\windows\TEMP\se.dll/sp.html R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.miami.com/mld/miamiherald/sports/football R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by AT&T Broadband Internet R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8080 O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINDOWS\EliteToolBar\EliteToolBar version 53.dll O2 - BHO: (no name) - {496A5785-88E3-11D9-80D4-000867EB0CBC} - C:\WINDOWS\SYSTEM\BDPLE.DLL O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINDOWS\EliteToolBar\EliteToolBar version 53.dll O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe O4 - HKLM\..\Run: [SystemTray] SysTray.Exe O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\SYSTEM\QTTASK.EXE O4 - HKLM\..\Run: [ATTRedUpate] C:\PROGRAM FILES\COMMON FILES\AT&T\REDCON\PROGRAMS\AutoUpdate.exe O4 - HKLM\..\Run: [LoadQM] loadqm.exe O4 - HKLM\..\Run: [Propel Accelerator] "C:\PROGRAM FILES\PEOPLEPC ACCELERATED\PROPELAC.EXE" O4 - HKLM\..\Run: [WinAuth] C:\WINDOWS\winlogon.exe O4 - HKLM\..\Run: [Bart Station] C:\Program Files\ISP50\hta\station.sbrt O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb09.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\AIM95\aim.exe -cnetwait.odl O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SPYSWEEPER.EXE" /0 O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRAM FILES\YAHOO!\MESSENGER\ypager.exe -quiet O4 - Startup: Microsoft Office.lnk = C:\Program Files\microsoft office\office\OSA9.EXE O8 - Extra context menu item: Refresh Pa&ge with Full Quality - C:\Program Files\PeoplePC Accelerated\pac-page.html O8 - Extra context menu item: Refresh Pi&cture with Full Quality - C:\Program Files\PeoplePC Accelerated\pac-image.html O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE O9 - Extra button: (no name) - {97C66720-F390-11D5-80D3-0008C74B081A} - (no file) (HKCU) O12 - Plugin for .adp: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll O18 - Protocol: icoo - {4A8DADD4-5A25-4D41-8599-CB7458766220} - C:\WINDOWS\MSOPT.DLL (file missing) O18 - Filter: text/html - {6CA0FCE6-8D20-11D9-80D4-0008645E7630} - C:\WINDOWS\SYSTEM\BDPLE.DLL O18 - Filter: text/plain - {6CA0FCE6-8D20-11D9-80D4-0008645E7630} - C:\WINDOWS\SYSTEM\BDPLE.DLL |
|
#2
|
|||
|
|||
|
about:blank? I believe that just opens up a blank browser window. Run a spyware scan with AdAware, Spybot S&D and then run Norton AntiVirus.
|
|
#3
|
||||
|
||||
|
alienalias please calm down, you'll only be answered if you are nice. also if someone doesn't answer it normally means they don't know the answer.
|
|
#4
|
|||
|
|||
|
Here you go... hope it helps!
Hi mate, I'm a brand new member here now,
I sympathise with you, not getting help from a site that's been set up to give help is frustrating. I've had a lot of experience with crap like what you're going though with the Web Page hijack, so this is what I suggest, given your HijackThis post. Of course, my disclaimer here: if you do happen to delete something you needed or wanted, it's entirely your responsibility. In your post are the lines: O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINDOWS\EliteToolBar\EliteToolBar version 53.dll O2 - BHO: (no name) - {496A5785-88E3-11D9-80D4-000867EB0CBC} - C:\WINDOWS\SYSTEM\BDPLE.DLL O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINDOWS\EliteToolBar\EliteToolBar version 53.dll Now, do you know what EliteBar is? Is there some sort of added toolbar in Internet Explorer that you like to use? If not, then you can pretty safely delete these three things. The BHOs are Browser Helper Objects downloaded and installed sometime along your internet browsing journeys... pretty much all of them are not needed and are most likely causing problems. Worst case scenario, if Yahoo! has put something in your browser that you use to get mail, etc, then this might disappear. Personally I find even the Googlesearch bar to be annoying... but everyone has their preferences. Also install Spybot Search and Destroy and navigate to the BHO List button... you may need to activate advanced settings or something like that once you know your way around. Here lists the BHO's on your computer, you may get a little more information from there... but HijackThis is pretty good for info as it is. Finally, if you can, run your Adware / Virus scanner while Windows is in SafeMode (reboot and hit F8 before the initial loading windows screen comes up) and if anything couldnt be removed while in normal mode, there is a good chance it will be removed in Safe Mode because they are no longer running. Post back if you have solved your problem... Cheers -DJ SpeCtre |
|
#5
|
|||
|
|||
|
I hate malware. There are forums dedicated to just this, and they even have subforums where you post HJT logs like you did, and they can provide "expert" help:
http://www.security-forums.com/forum/index.php http://castlecops.com/forum67.html have been helpful to me. Cheers, Ryan |
![]() |
| Viewing: Dev Shed Forums > System Administration > Antivirus Protection > WHAT IN THE H - E - Double L!!!!!! C'mon admin or helpers! |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|
|
|