A blue toolbar when I open IE. . .

Discussion in 'Malware Help (A Specialist Will Reply)' started by Sparda, Jun 17, 2005.

  1. Sparda

    Sparda Private E-2

    Please help me, everytime i open Internet Explorer a blue toolbar appeares on the bottom of my screen. I was used to just clicking it off with the little x to close it but it seems that it has been updated, which i have read that it can do automatically without letting you know. :eek: :mad:

    The URL of this toolbar seems to be: http://lop.com/passthrough/newpass2.html (didnt hyperlink so no-one would visit) if thats any help. . .
    EDIT: sorry i didnt realise that it hyperlinked automatically, please dont visit that site as you may get the same thing as i have!!!

    I have read other posts at topics related to this (as most forums advise you to do) but I am sorry but I cant find any help there. I have used all of the tools posted in the "Basic spyware and trojan removal" but they havent helped. I have downloaded the Hijack This tool as a last resort and am awaiting further instructions.

    Thanks to any help,

    -Nathan
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    http://www.majorgeeks.com/images/grenade.gif Download HijackThis 1.99.1

    http://www.majorgeeks.com/images/grenade.gif Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    http://www.majorgeeks.com/images/grenade.gif Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the ZIP file as your backups will not be safely stored.

    http://www.majorgeeks.com/images/grenade.gifBefore running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    http://www.majorgeeks.com/images/grenade.gifRun HijackThis and save your log file.

    http://www.majorgeeks.com/images/grenade.gif Post your log as an ATTACHMENT to your next post. (Do NOT copy/paste the log into your post as it will be removed).

    http://www.majorgeeks.com/images/grenade.gifNeed help with HJT? See this thread: NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting
     
  3. Sparda

    Sparda Private E-2

    My Hijack This log:

    I would greatly appreciate it if you can pick out other spyware/malware that the scanner may have missed aswell as the annoying blue toolbar enteries :)

    Many thanks,

    -Nathan
     

    Attached Files:

  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Warez P2P Client is not a good thing to have installed as most malware/virus infections now days comes from P2P programs. Its up to you whether you keep it, but let me remind you..as long as you are using P2P, you will have malware/virus problems.

    First, lets start by running the following online scans:

    Bitdefender online scan
    RavAntivirus online scan <-- select Auto Clean then click Scan My PC
    TrojanScan online scan

    After you have complete the above online scans, reboot and post a fresh HJT log.
     
  5. Sparda

    Sparda Private E-2

    Ok i'll run the checks now and uninstall the P2P program, although i started getting the blue toolbars long before i installed the P2P client
     
  6. Sparda

    Sparda Private E-2

    Should i also uninstall P2P IRC clients such as mIRC also?
     
  7. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Personally, anything relating to P2P needs to go. Buts like I said before its all up to you whether you keep it or not. If you dont use mIRC then yeah uninstall it.

    These infections may have started before you installed it but I can assure you that some of it came from P2P.
     
  8. Sparda

    Sparda Private E-2

    Wow i was going through my add/remove programs list uninstalling thing that i use rarely/never and i uninstalled MSN Messenger Plus! 3 and the blue toolbar disappeared along with another IE toolbar which i never used! Thanks for your help and i will take your advice into consideration, it it wasnt for you telling me to unistall the P2P software then i would never of realised, Thanks bjgarrick!
     
  9. Sparda

    Sparda Private E-2

    Now i'll look at the sticky that says about malware protection to make sure this NEVER happens again (or so I hope).
     
  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    I was about to get to there where we uninstalled that and some others, for now attach a current HJT log so we can confirm your clean.
     
  11. Sparda

    Sparda Private E-2

    Sorry this post is so late after the others, My new Hijack log:

    Thanks again for your continuing support :)
     

    Attached Files:

  12. Sparda

    Sparda Private E-2

    I ran a couple of anti-spyware programs which got rid of a few things, so I rebooted my PC and this is the new Hijack This log:
     

    Attached Files:

  13. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.

    R3 - Default URLSearchHook is missing

    O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

    O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

    Again, make sure All Browser Windows are Closed when you Click FIX.

    Are you having any further problems?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds