Antivirus Protection
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationAntivirus Protection

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old March 6th, 2005, 10:31 PM
alienalias alienalias is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Feb 2005
Posts: 5 alienalias User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 59 m
Reputation Power: 0
WHAT IN THE H - E - Double L!!!!!! C'mon admin or helpers!

Why is no one helping me? I don't mean to get testy, but I have been on this site numerous times and received wonderful, expedient help from kind folks.... NOW, I have been viewed 17 or some odd times, with NO response!!!! I really need some help. Every time I let someone use my PC, it seems to get screwed up. Apparently I did not have virus protection, which I do now.
PLEASE people! I have no idea what to do, and am a clueless novice. Please let me know what to fix to get rid of this nightmare, "Aboutblank". I cannot even retrieve my work e-mails thru Yahoo! It hijacks the page everytime I try to go Yahoo or Hotmail..... please help:

Logfile of HijackThis v1.98.2
Scan saved at 12:46:37 AM, on 3/6/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\ISP50\BIN\BARTSHEL.EXE
C:\WINDOWS\SYSTEM\HPZTSB09.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\YAHOO!\MESSENGER\YMSGR_TRAY.EXE
C:\PROGRAM FILES\ISP50\BIN\PPSHARED.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\WINWORD.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\ISP50\BIN\BARTSHEL.EXE
C:\PROGRAM FILES\ISP50\DIALER\DIALER.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\PEOPLEPC ACCELERATED\PROPELAC.EXE
H:\HIJACKTHIS1982.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.miami.com/mld/miamiherald/sports/football
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://c:\windows\TEMP\se.dll/sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.miami.com/mld/miamiherald/sports/football
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by AT&T Broadband Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8080
O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINDOWS\EliteToolBar\EliteToolBar version 53.dll
O2 - BHO: (no name) - {496A5785-88E3-11D9-80D4-000867EB0CBC} - C:\WINDOWS\SYSTEM\BDPLE.DLL
O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINDOWS\EliteToolBar\EliteToolBar version 53.dll
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\SYSTEM\QTTASK.EXE
O4 - HKLM\..\Run: [ATTRedUpate] C:\PROGRAM FILES\COMMON FILES\AT&T\REDCON\PROGRAMS\AutoUpdate.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [Propel Accelerator] "C:\PROGRAM FILES\PEOPLEPC ACCELERATED\PROPELAC.EXE"
O4 - HKLM\..\Run: [WinAuth] C:\WINDOWS\winlogon.exe
O4 - HKLM\..\Run: [Bart Station] C:\Program Files\ISP50\hta\station.sbrt
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb09.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SPYSWEEPER.EXE" /0
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRAM FILES\YAHOO!\MESSENGER\ypager.exe -quiet
O4 - Startup: Microsoft Office.lnk = C:\Program Files\microsoft office\office\OSA9.EXE
O8 - Extra context menu item: Refresh Pa&ge with Full Quality - C:\Program Files\PeoplePC Accelerated\pac-page.html
O8 - Extra context menu item: Refresh Pi&cture with Full Quality - C:\Program Files\PeoplePC Accelerated\pac-image.html
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra button: (no name) - {97C66720-F390-11D5-80D3-0008C74B081A} - (no file) (HKCU)
O12 - Plugin for .adp: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O18 - Protocol: icoo - {4A8DADD4-5A25-4D41-8599-CB7458766220} - C:\WINDOWS\MSOPT.DLL (file missing)
O18 - Filter: text/html - {6CA0FCE6-8D20-11D9-80D4-0008645E7630} - C:\WINDOWS\SYSTEM\BDPLE.DLL
O18 - Filter: text/plain - {6CA0FCE6-8D20-11D9-80D4-0008645E7630} - C:\WINDOWS\SYSTEM\BDPLE.DLL
Comments on this post
Viper_SB disagrees: easy now

Reply With Quote
  #2  
Old March 9th, 2005, 04:43 PM
AsymptoticCoder AsymptoticCoder is offline
Information and Data Junkie
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2004
Location: Southern California, USA
Posts: 108 AsymptoticCoder User rank is Private First Class (20 - 50 Reputation Level)AsymptoticCoder User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 17 h 13 m 2 sec
Reputation Power: 5
Facebook
about:blank? I believe that just opens up a blank browser window. Run a spyware scan with AdAware, Spybot S&D and then run Norton AntiVirus.

Reply With Quote
  #3  
Old March 9th, 2005, 07:43 PM
Viper_SB's Avatar
Viper_SB Viper_SB is offline
Psycho Canadian
Dev Shed Demi-God (4500 - 4999 posts)
 
Join Date: Jan 2001
Location: Canada
Posts: 4,788 Viper_SB User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Viper_SB User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Viper_SB User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Viper_SB User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Viper_SB User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Viper_SB User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Viper_SB User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Viper_SB User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Viper_SB User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Viper_SB User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Viper_SB User rank is Lieutenant Colonel (40000 - 50000 Reputation Level) 
Time spent in forums: 4 Weeks 20 h 3 m 3 sec
Reputation Power: 437
alienalias please calm down, you'll only be answered if you are nice. also if someone doesn't answer it normally means they don't know the answer.

Reply With Quote
  #4  
Old March 14th, 2005, 12:50 AM
DJ SpeCtre DJ SpeCtre is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2005
Posts: 10 DJ SpeCtre User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 2 h 35 m 24 sec
Reputation Power: 0
Here you go... hope it helps!

Hi mate, I'm a brand new member here now,
I sympathise with you, not getting help from a site that's been set up to give help is frustrating. I've had a lot of experience with crap like what you're going though with the Web Page hijack, so this is what I suggest, given your HijackThis post. Of course, my disclaimer here: if you do happen to delete something you needed or wanted, it's entirely your responsibility.

In your post are the lines:

O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINDOWS\EliteToolBar\EliteToolBar version 53.dll
O2 - BHO: (no name) - {496A5785-88E3-11D9-80D4-000867EB0CBC} - C:\WINDOWS\SYSTEM\BDPLE.DLL
O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINDOWS\EliteToolBar\EliteToolBar version 53.dll

Now, do you know what EliteBar is? Is there some sort of added toolbar in Internet Explorer that you like to use? If not, then you can pretty safely delete these three things. The BHOs are Browser Helper Objects downloaded and installed sometime along your internet browsing journeys... pretty much all of them are not needed and are most likely causing problems. Worst case scenario, if Yahoo! has put something in your browser that you use to get mail, etc, then this might disappear. Personally I find even the Googlesearch bar to be annoying... but everyone has their preferences.

Also install Spybot Search and Destroy and navigate to the BHO List button... you may need to activate advanced settings or something like that once you know your way around. Here lists the BHO's on your computer, you may get a little more information from there... but HijackThis is pretty good for info as it is.

Finally, if you can, run your Adware / Virus scanner while Windows is in SafeMode (reboot and hit F8 before the initial loading windows screen comes up) and if anything couldnt be removed while in normal mode, there is a good chance it will be removed in Safe Mode because they are no longer running.

Post back if you have solved your problem... Cheers

-DJ SpeCtre

Reply With Quote
  #5  
Old March 14th, 2005, 01:20 AM
AsymptoticCoder AsymptoticCoder is offline
Information and Data Junkie
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2004
Location: Southern California, USA
Posts: 108 AsymptoticCoder User rank is Private First Class (20 - 50 Reputation Level)AsymptoticCoder User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 17 h 13 m 2 sec
Reputation Power: 5
Facebook
I hate malware. There are forums dedicated to just this, and they even have subforums where you post HJT logs like you did, and they can provide "expert" help:

http://www.security-forums.com/forum/index.php
http://castlecops.com/forum67.html

have been helpful to me.

Cheers,
Ryan

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationAntivirus Protection > WHAT IN THE H - E - Double L!!!!!! C'mon admin or helpers!


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 4 hosted by Hostway