Over 1 million tech questions and answers.

Hijack log, tried suggested fix, still goes to about:blank

Q: Hijack log, tried suggested fix, still goes to about:blank

Help! My search browser keeps going to about:blank and I get a "Home search" page come up. I tried the recommended method in an earlier thread to run swsserviceremove, cwshredder Hijackthis and aboutbuster. It worked the first time I rebooted and opened IE, but then soon resorted to the initial problem. Here is the Hijack log:
Logfile of HijackThis v1.97.7
Scan saved at 6:06:02 PM, on 10/24/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\WINDOWS\system32\atlik32.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Documents and Settings\Kerry\Application Data\urpo.exe
C:\WINDOWS\System32\??chost.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\WINDOWS\System32\hpoipm07.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\REGLOCS.OLD:qotsz
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Kerry\Desktop\hijackthis.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\ekokp.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ekokp.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://education.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\ekokp.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\ekokp.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ekokp.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\ekokp.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\ekokp.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = sas.ce1.attbb.net:8000
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.ce1.attbb.net
O2 - BHO: (no name) - {05D1E7E3-6BEF-35A7-EA95-41C9AA0FD288} - C:\WINDOWS\system32\crjr32.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [atlik32.exe] C:\WINDOWS\system32\atlik32.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [sdkxn.exe] C:\WINDOWS\system32\sdkxn.exe
O4 - HKLM\..\Run: [SAUpdate] "C:\Program Files\Comcast\BBClient\Programs\SAUpdate.exe"
O4 - HKLM\..\Run: [sais] c:\program files\180solutions\sais.exe
O4 - HKLM\..\Run: [SAClient] "C:\Program Files\Comcast\BBClient\Programs\RegCon.exe" /admincheck
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [ietv32.exe] C:\WINDOWS\system32\ietv32.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [ComcastSUPPORT] C:\Program Files\Support.com\bin\tgkill.exe /cleaneahtioga /start
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [addgf32.exe] C:\WINDOWS\system32\addgf32.exe
O4 - HKLM\..\Run: [sysag32.exe] C:\WINDOWS\system32\sysag32.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Ncao] C:\Documents and Settings\Kerry\Application Data\urpo.exe
O4 - HKCU\..\Run: [Fqn] C:\WINDOWS\System32\??chost.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\ipsecdialer.exe
O4 - Global Startup: Forget Me Not.lnk = C:\Program Files\Broderbund\AG CreataCard\AGRemind.exe
O4 - Global Startup: HPAiODevice(hp psc 700 series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
O4 - Global Startup: HPAiODevice(hp psc 700 series) - 2.lnk = C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: SideFind (HKLM)
O9 - Extra button: Research (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: ComcastHSI (HKCU)
O9 - Extra button: Help (HKCU)
O9 - Extra button: Support (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O15 - Trusted Zone: *.blazefind.com
O15 - Trusted Zone: *.flingstone.com
O15 - Trusted Zone: *.searchbarcash.com
O15 - Trusted Zone: *.slotch.com
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {386A771C-E96A-421F-8BA7-32F1B706892F} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v4.0/0006_regular.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52...pple.com/mickey/us/win/QuickTimeInstaller.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1093488902718
O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - http://216.249.24.140/code/PWActiveXImgCtl.CAB
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {9184D21C-9835-42C5-A883-EA8BE7FC048D} (Downloader Class) - http://www.shop.intuit.com/commerce/account/downloads/executables/ie/IDA.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37914.5563078704
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) - http://216.249.24.60/code/iPIX-ImageWell-ipix.cab

Any suggestions?

RELEVANCY SCORE 200
Preferred Solution: Hijack log, tried suggested fix, still goes to about:blank

I recommend downloading and running DAP. It can help sort out any driver and firmware related issues on your system

It's worked out well for many of us in the past.

You can download it direct from this link http://downloaddap.org. (This link will open the download page of DAP so you can save a copy to your computer.)

A: Hijack log, tried suggested fix, still goes to about:blank

Read other 14 answers
RELEVANCY SCORE 55.2

I know this conflicts with advice posted here re computer slowness. I am going to follow those suggestions, but wanted to post this in case there is something glaring Thanks in advance and I'll be busy while waiting for an answer! Logfile of Trend Micro HijackThis v2.0.2Scan saved at 9:45:31 PM, on 3/30/2009Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v8.00 (8.00.6001.18702)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Lavasoft\Ad-Aware\AAWService.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Google\Update\GoogleUpdate.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Yahoo!\Search Protection\SearchProtection.exeC:\PROGRA~1\Yahoo!\browser\ybrwicon.exeC:\Program Files\Registry Mechanic\RegMech.exeC:\PROGRA~1\Yahoo!\browser\ycommon.exeC:\Program Files\McAfee.com\Agent\mcagent.exeC:\HP\KBD\KBD.EXEC:\Program Files\Spyware Doctor\pctsTray.exeC:\windows\system\hpsysdrv.exeC:\WINDOWS\system32\hphmon06.exeC:\WINDOWS\system32\hkcmd.exeC:\Pro... Read more

A:Updated Hijack This; they suggested this

Welcome to the BleepingComputer Forums. Since it has been a few days since you scanned your computer with HijackThis, we will need a new HijackThis log. If you have not already downloaded Random's System Information Tool (RSIT), please download Random's System Information Tool (RSIT) by random/random which includes a HijackThis log and save it to your desktop. If you have RSIT already on your computer, please run it again. Double click on RSIT.exe to run RSIT. Click Continue at the disclaimer screen. Please post the contents of log.txt. Thank you for your patience.Please see Preparation Guide for use before posting about your potential Malware problem. If you have already posted this log at another forum or if you decide to seek help at another forum, please let us know. There is a shortage of helpers and taking the time of two volunteer helpers means that someone else may not be helped. Please post your HijackThis log as a reply to this thread and not as an attachment. I am always leery of opening attachments so I always request that HijackThis logs are to be posted as a reply to the thread. I do not think that you are attaching anything scary but others may do so. While we are working on your HijackThis log, please: Reply to this thread; do not start another! Do not make any changes on your computer during the cleaning process or download/add programs on your computer unless instructed to do so. Do not run any other tool until ... Read more

Read other 5 answers
RELEVANCY SCORE 54.4

Hi everyone! I posted the following thread after experiencing major computer slowdown the last week or so:

http://forums.techguy.org/windows-n...roblems-may-hardware-windows.html#post5318750

And it was suggested to me that I post a log from hijackthis to this forum, in case I might be having malware issues ( I really hope that's all it is to be honest.)

Hoping someone could take a look!
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 3:03:37 PM, on 11/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\2\FreeRAM XP Pro.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Eastlink Internet Security\Anti-Virus\fsgk32st.exe
C:\Program Files\Eastlink Internet Security\Anti-Virus\FSGK32.EXE
C:\Program Files\Eastlink Internet Security\Common\FSMA32.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Eastlink Internet Security\Common\FSMB32.EXE
C:\WINDOWS\system32\PSIService.exe
C:\Program Files\Eastlink Internet Security\Common\FCH... Read more

A:Hijack This log, as suggested by my main thread

Run ActiveScan online virus scan:
http://www.pandasoftware.com/products/activescan.htm

Once you are on the Panda site click the Scan your PC button.
A new window will open...click the Check Now button.
Enter your Country.
Enter your State/Province.
Enter your e-mail address and click send.
Select either Home User or Company.
Click the big Scan Now button.
If it wants to install an ActiveX component allow it.
It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
When download is complete, click on My Computer to start the scan.
When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
Post the contents of the ActiveScan report.
 

Read other 1 answers
RELEVANCY SCORE 47.2

Well I refrained from throwing the computer off the roof so far but came really close. Here is my Hijack this log I hope that someone can give me a better understanding of what my problem is. Thanks for any help.

Logfile of HijackThis v1.99.1
Scan saved at 6:48:54 PM, on 7/17/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\System32\CTsvcCDA.exe
c:\progra~1\mcafee\MCAFEE~2\MssSrv.exe
C:\WINDOWS\system32\sistray.EXE
C:\PROGRA~1\LEXMAR~1\ACMonitor_X84-X85.exe
C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X84-X85.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\NETGEAR WG311v2 Adapter\wlancfg5.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
C:\WINDOWS\system32\srvany.e... Read more

A:RE: Blank, Blank, Blank &^%$ Good old Hijack this

Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should 'not' have any open browsers when you are following the procedures below.

Go to My Computer->Tools/View->Folder Options->View tab and make sure that 'Show hidden files and folders' (or 'Show all files') is enabled. Also make sure that 'Display the contents of system folders' is checked. If you have Windows XP, the search feature is a little different. When you click on 'All files and folders' on the left pane, click on the 'More advanced options' at the bottom. Make sure that 'Search system folders', 'Search hidden files and folders', and 'Search subfolders' are checked.

For the options that you checked/enabled earlier, you may uncheck them after your log is clean. If we ask you to fix a program that you use or want to keep, please post back saying that (we don't know every program that exists, so we may tell you to delete a program that we think is bad to keep).

Download CWShredder at http://www.greyknight17.com/spy/CWShredder.sfx.exe and run it. Uncompress the file and run it. Click on 'I Agree' button if you agree with it. Click on 'Fix' (it will automatically fix anything it finds for you) and OK. If it asks if you want to delete a certain random file, choose No and post that filename here. Let it finish th... Read more

Read other 5 answers
RELEVANCY SCORE 40.4

I have been plagued by a persistent about:blank hijacker. SpyBot is clean (aside from the usual DSO Exploit). CWShreader says the system is clean. LavaSoft AdAware also comes up clean.

I have History Kill and now just tried SpywareGuard, both of which catch the fact that the home page is being changed to about:blank.

I have run HijackThis and cleaned everything that I thought was suspicious, being overzealous rather than cautious. This did get rid a popup to 540.scmg.net, but not the about:blank hijack.

Here's the HijackThis log file. Any suggestions?

Logfile of HijackThis v1.99.0
Scan saved at 17:02:21, on 30/01/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\HistoryKill\histkill.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Mes... Read more

A:about:blank hijack

Read other 16 answers
RELEVANCY SCORE 40.4

Hi, Our homepage used to be yahoo and now it is About:Blank. I have read several posts here about the same problem. Please find my "Hijack this" log below. Please consider me a beginner.
Thanks for your time. Janiree
Logfile of HijackThis v1.99.0
Scan saved at 1:45:14 AM, on 2/1/05
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\MDM.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\STARTER.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\PROFILES\JANICE\DESKTOP\STUFF\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\sp.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\sp.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssis... Read more

A:About:Blank Hijack

Please check and remove these entries..
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\sp.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\sp.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {4401FDC3-7996-4774-8D2B-C1AE9CD6CC25} - (no file)
O2 - BHO: TChkBHO Class - {1D580880-25D5-11D8-B4C4-00A0AC00DFD3} - C:\WINDOWS\SYSTEM\UMSLRES.DLL
O18 - Filter: text/html - {9B439C41-7369-11D9-B4C4-000593A5C35D} - C:\WINDOWS\SYSTEM\ALCFGD.DLL
O18 - Filter: text/plain - {9B439C41-7369-11D9-B4C4-000593A5C35D} - C:\WINDOWS\SYSTEM\ALCFGD.DLL

Then download and run About:Buster http://www.majorgeeks.com/download4289.html

Then search for and delete ALCFGD.DLL, sp.dll, and UMSLRES.DLL.
 

Read other 3 answers
RELEVANCY SCORE 40.4

Is this clean?... my browser keeps changing to about:blank and I have used CWShredder a 100 times and it says it picks it up, but then doesn't delete anything.

Logfile of HijackThis v1.97.7
Scan saved at 6:17:53 PM, on 4/14/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AIM\aim.exe
C:\Documents and Settings\Evan\My Documents\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: TX4 - {00000000-0000-5DFC-5652-1705043F6518} - C:\WINDOWS\System32\audiosrv32.dll
O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - C:\WINDOWS\twaintec.dll
O2 - BHO: (no name) - {1C78AB3F-A857-482e-80C0-3A1E5238A565} - C:\WINDOWS\System32\toolbar.dll
O2 - BHO: (no name) - {2B782D72-0D9D-4797-B5F2-69407122A217} - C:\WINDOWS\System32\caiii.dll (file missing)
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINDOWS\2_0... Read more

A:About:Blank hijack

Read other 12 answers
RELEVANCY SCORE 40.4

Hi All,I'm hoping that somebody will be able to help me out with stopping my pc reverting to the about:blank homepage.Even though i have removed the about:blank sections in hijack this i'm obviously missing the source of it!Any help will be much appreciated.Logfile of HijackThis v1.99.0Scan saved at 7:23:55 PM, on 2/14/05Platform: Windows 98 SE (Win9x 4.10.2222A)MSIE: Internet Explorer v5.00 (5.00.2614.3500)Running processes:C:\WINDOWS\SYSTEM\KERNEL32.DLLC:\WINDOWS\SYSTEM\MSGSRV32.EXEC:\WINDOWS\SYSTEM\SPOOL32.EXEC:\WINDOWS\SYSTEM\MPREXE.EXEC:\WINDOWS\SYSTEM\mmtask.tskC:\WINDOWS\SYSTEM\MSTASK.EXEC:\WINDOWS\TASKMON.EXEC:\WINDOWS\SYSTEM\SYSTRAY.EXEC:\WINDOWS\SOUNDMAN.EXEC:\WINDOWS\SYSTEM\WMIEXE.EXEC:\WINDOWS\EXPLORER.EXEC:\MY DOCUMENTS\BEN\HIJACKTHIS.EXER1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailureR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailureR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailureR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailureR1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailureR0 - HKLM\Softwa... Read more

A:Hijack This and About:Blank

Hello Glammy and Welcome! Sorry you're having malware trouble.Download: "StartDreck", from hereUnzip it to its own folder, name the folder Startdreck and double-click on StartDreck.exe to start the program.Press ConfigPress Unmark AllCheck the following boxes only:Registry -> Run KeysSystem/drivers> Running processesPress OkPress Save and select the location to save the log file(default is the same folder as the application)Post the log in this thread for review.

Read other 9 answers
RELEVANCY SCORE 40.4

I'm a newbie, I have about:blank. I've run ad-aware, spybot, shredder etc. Restarted multiple times. Homepage finally returned until son's IM was logged on. I have 5 users on my windows xp system. Here is the latest log...ANY help would be greatly appreciated.Logfile of HijackThis v1.99.0
Scan saved at 9:15:06 PM, on 1/22/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\PROGRA~1\INCRED~1\bin\IncMail.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\System32\w... Read more

A:About:blank hijack log

Read other 16 answers
RELEVANCY SCORE 40.4

Another About:Blank Hijacking!

I have been trying to catch all the threads about this nasty hijack. I also, have been hijacked. Tried HJT, Adware, Spybot, CWShredder and manually editing the registry all to no avail.

I saw a few threads about Notepad and Windows Media Player being affected. both of mine were. However, I was able to determine within a couple of hours when the hijacking occured so I decided to do a file search by date so I could check all the files that changed on the date of hijacking within time frame I think it happened. I found that both my notepad.exe and windows media player exe files were changed, I now had two files one with a .bak extension. I deleted the exe file and renamed the .bak extension to exe and now both my notepad and media player are working again. Not sure if this had anything to do with the hijacking, but I think since others with the same about:blank hijack had the same problem, it must be related.

I downloaded a program (RegistryProt) to monitor any changes to my registry. What is interesting is that the spyware popups (related to the hijacking) are setting off the registry change, but the file in the registry its trying to change is the exe file of my popup blocker. Could this be trying to continue to disable my blockup popper?? Since I believe the popup is what causing the hijack to continue after getting rid of it with HJT, Adware and Spybot

Not posting my HJT right now because its clean for the moment, but it does keep coming... Read more

A:Any fix for the About: Blank Hijack yet?

Just to let you know, after trying all of the solutions to fix this hijack, it still kept coming back. Because the registryprot program I downloaded caught one of the popups that the hijack continually set off, and showed me the file in my registry it was trying to change (my ISP provided blockup popper) I decided to call my ISP, although they could not manually fix the hijack, they suggested to do a system restore back to a date I knew was good. Not having installed any new programs, the restore fixed everything! and all is back to normal without losing any data.
 

Read other 1 answers
RELEVANCY SCORE 40.4

I cannot use internet explorer, I have tried many removal tools inc spybot & spyware doctor & bitdefender

Please help!
Logfile of HijackThis v1.99.1
Scan saved at 10:43:55, on 29/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\Sony\WiseWan\NOVATE~1\NWAppService.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\PROGRA~1\Sony\WiseWan\NOVATE~1\NwAppLauncher.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Common File... Read more

Read other answers
RELEVANCY SCORE 40.4

I've just started having trouble with my homepage - it keeps changing to about:blank I've ran a virus scan, Adaware, Spybot,CWShredder.
Here is my hijack this log: Can someone please look at it for me and help?

Logfile of HijackThis v1.99.0
Scan saved at 8:51:36 PM, on 2/2/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\System32\mshelp32.exe
C:\WINDOWS\System32\cmd32.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\HijackThis.exe

R1 - HKCU\Software\... Read more

Read other answers
RELEVANCY SCORE 40.4

I've been trying to help my brother rid his computer of this problem. I read many other posting and did as many educated guesses about the Hihjack this log, but the problem came back within two days.

Logfile of HijackThis v1.99.0
Scan saved at 10:33:55 PM, on 1/27/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\GEARSec.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\Program Files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SymTray.exe
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe
C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
C:\WINNT\system32\wfxsnt40.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\ScanSoft\TEXTBR~1.0\Bin\INSTAN~1.EXE
C:\Program Files\AIM\aim.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ScanSoft\Pagis\Monitor.exe
C:\Document... Read more

A:need help - about blank hijack log

CWShredder http://www.intermute.com/spysubtract/cwshredder_download.html
Close all browser windows, Open cwshredder.exe then click "Fix" and let
it run.

Print this, boot to safe mode - fix

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Steve\LOCALS~1\Temp\sp.dll/sp.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Steve\LOCALS~1\Temp\sp.dll/sp.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

O2 - BHO: (no name) - {BA2C2192-94EE-45EF-8DFA-E93CEB9EBEA4} - C:\WINNT\system32\lpika.dll

O18 - Filter: text/html - {299F1E25-EA40-465D-BAA1-EF1ED6AE9E14} - C:\WINNT\system32\lpika.dll

O18 - Filter: text/plain - {299F1E25-EA40-465D-BAA1-EF1ED6AE9E14} - C:\WINNT\system32\lpika.dll

O23 - Service: Ati HotKey Poller - Unknown - C:\WINNT\System32\Ati2evxx.exe (file missing)

View Hidden Files
Open Windows Explorer. Go to Tools, Folder Options and click on the View tab.
Make sure that "Show hidden files and folders" is checked.
Also uncheck "Hide protected ... Read more

Read other 1 answers
RELEVANCY SCORE 40.4

Please take a look at my HJT log and let me know what I need to delete to finally rid my system of "QUICK Web Search" .....
Thanks, much appreciated:

Logfile of HijackThis v1.99.1
Scan saved at 2:13:38 AM, on 5/16/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Mobile Connection Manager\Diamond.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\sysvz.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Mobile Connection Manager\Wnex7DO.exe
C:\WINDOWS\system32\javafv32.exe
C:\WINDOWS\System32\atievxx.exe
C:\Program Files\StealthSurf Pro\Window Cleanser\wcservice.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\Tablet.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\PROGRA~1\MOBILE~1\apcomsrv.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\mqz... Read more

A:About:Blank Hijack (HJT log Help)

Read other 7 answers
RELEVANCY SCORE 40.4

A friend asked me for help with a hijack today. I advised running CWShredder which I sent and then manually reset her homepage. Then run SpywareBlaster which I also sent. (Since adding that to my system, I haven't been Hijacked.) I am attaching her Hijackthis log file. If there is anything further that should be done, please advise.

Much Thanks in advance !!
 

A:about:blank hijack

First we shall post that log out here for ease in the matter:

Logfile of HijackThis v1.97.7
Scan saved at 8:12:12 PM, on 8/2/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v5.50 (5.50.4134.0100)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\COMPAQ\CPQINET\CPQINET.EXE
C:\PROGRAM FILES\COMPAQ\DIGITAL DASHBOARD\DEVGULP.EXE
C:\CPQS\BWTOOLS\SCCENTER.EXE
C:\WINDOWS\TWAIN_32\PAPRPORT\3100B\FLATBED.EXE
C:\PROGRAM FILES\MOTIVE\MOTMON.EXE
C:\PROGRAM FILES\MICROSOFT HARDWARE\KEYBOARD\TYPE32.EXE
C:\PROGRAM FILES\VISIONEER\PAPERPORT\CONFIG\EREG\REMIND32.EXE
C:\COREL\SUITE8\PROGRAMS\DAD8.EXE
C:\WINDOWS\SYSTEM\HIDSERV.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\BTTNSERV.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\EAUSBKBD.EXE
C:\PROGRAM FILES\DIAL MODEM MADNESS\DIALER.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\TEMP\TD_0001.DIR\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\TEMP\sp.html
R1 - HKCU\Software\Microsoft\I... Read more

Read other 2 answers
RELEVANCY SCORE 40.4

Hi fellow friends,

I'm in serious need of help. Recently my computer has been hijack with some homepage. I have TRIED all that i can to remove this hijack but nevertheless a fruitless one. So I hope someone from this forum can help me in this problem. Thanks in advance.

*Note: scanned all these in safe mode*

This is my HijackThis log :
Logfile of HijackThis v1.99.0
Scan saved at 1:37:08 PM, on 12/19/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Documents and Settings\Administrator\Desktop\hijackthis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7D6BEC01-15E2-46F0-8ED3-D715DE09A8F9} - (no file)
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashG... Read more

A:about:blank Hijack! Need help!!

I dont no how to help with the HJ list, but it is one of the longest ones I have ever seen, your pc must be real slow.

You need to run anti spyware and virus programmes.

Get spybot here download, update then run it.

You could also try adaware here download and update it before you run it.

Make sure you run your AV software as well.
 

Read other 1 answers
RELEVANCY SCORE 40.4

hey i currently have the about:blank trojan, i have the latest spybot which i run regularly and it never seems to get rid of the DSO exploit, so i downloaded a DSO exploit fixer program and that is installed and running. I have also run the cwshredder to try and get rid of the about:blank virus but all to no avail. I know there are 2 files to the virus one is visable and the other is hidden and the latter regenerates the visable one when t is deleted. so i have dowloaded hijack this whether it will do any good i don't know. but can you look at my log and tell me if anything is there if it shouldn't be. thanks. regards ric
 

A:about:blank + hijack this

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Palm\HOTSYNC.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\USER\Desktop\banjo\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\USER\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\USER\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.btinternet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\USER\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\USER\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\USER\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\USER\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\In... Read more

Read other 1 answers
RELEVANCY SCORE 40.4

hello, I have been hijacked by cws about:blank for about 3-4 days now. I installed cwshredder and although it says it fixed it, it keeps coming back. I installed hjt and removed all line entries referring to cws (please see attached) and still it comes back, I used pest control deleted all reg entries, it keeps coming back, everytime it changes the dll name and pops back up changing my bho's and with the help of the bho monitor I can see the dll and delete it, but I need to get to the source file that keeps creating these random dlls. Any help will be much appreciated. Thank you very much.

Logfile of HijackThis v1.97.7
Scan saved at 10:09:52, on 09.04.2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\gearsec.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Toshiba\Toshiba Applet\tpwrsave.exe
C:\Program Files\Toshiba\Toshiba Applet\TMEPROP.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\TOSHIBA\DualPointUtility\TEDTray.e... Read more

A:Csw About: Blank Hijack!

Read other 16 answers
RELEVANCY SCORE 40.4

My PC has been hijacked by the about:blank hijacker. I have ran HiJack This and added the log below...Logfile of HijackThis v1.99.0Scan saved at 00:12:03, on 04/02/2005Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\SYSTEM32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Network Associates\VirusScan\Avsynmgr.exeC:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exeC:\Program Files\Network Associates\VirusScan\VsStat.exeC:\Program Files\Network Associates\VirusScan\Vshwin32.exeC:\Program Files\Network Associates\VirusScan\Avconsol.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Network Associates\VirusScan\Webscanx.exeC:\WINDOWS\system32\wscntfy.exeC:\Program Files\Common Files\Network Associates\McShield\Mcshield.exeC:\WINDOWS\ippx.exeC:\Program Files\PopUp Killer\popupkiller.EXEC:\WINDOWS\system32\n3monap23.exeC:\WINDOWS\netdm.exeC:\Program Files\Sony Corporation\Image Transfer\SonyTray.exeC:\PROG... Read more

A:About;blank hijack...please help

Hi tanyaw and welcome Please review the following instructions, Please download and check for updates where instructed, Please print out the instructions or save them to notepad, as you don't want to get back online until the following process is complete.First:Download AboutBusterThen Unzip it to your desktop.. ?Don?t run it yet?Check it for updates if any are found please download them then close out the programGo to process manger and end the following process, Don't be concerned if you don't see themippx.exen3monap23.exenetdm.exeapieo32.exeNext, reboot into 'SAFE MODE'. (By tapping the F8 key on start up)Please restart HJT put a check next to the following if they still exist, close all open windows and click ?fix.checked?R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\lkfqr.dll/sp.html#28129R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\lkfqr.dll/sp.html#28129R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.u.tv/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blankR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\lkfqr.dll/sp.html#28129R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOW... Read more

Read other 10 answers
RELEVANCY SCORE 40.4

my home page keep changing to this about:blank webportal..

heres my log from Hijack This 1.97.7

Logfile of HijackThis v1.97.7
Scan saved at 1:44:10 AM, on 6/27/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\RUNDLL32.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\ctfmon.exe
E:\logitech\MouseWare\system\em_exec.exe
E:\nist\nistime-32bit.exe
E:\VMware Workstation\vmware-authd.exe
C:\WINDOWS\System32\vmnat.exe
C:\WINDOWS\System32\vmnetdhcp.exe
G:\pq\pq.exe
E:\mIRC603\mirc.exe
E:\ventrilo220\Ventrilo.exe
E:\AIM\aim.exe
G:\SteamFinal\steam.exe
E:\HLSWv1\hlsw_1_0_0_11-beta.exe
E:\DLMage\DNLOAD~1.EXE
C:\Program Files\Internet Explorer\iexplore.exe
F:\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\holden\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\holden\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\holde... Read more

A:about:blank hijack :( help

Read other 10 answers
RELEVANCY SCORE 40.4

Hello,Thank you for taking the time to read this message. I'm a newbie to this forum who is seeking some expert advice re. ABOUT BLANK. Everytime I open IE I get a webpage titled about blank. I've done some internet searching looking for any clue on how to rid myself of this headache and this website came up. What a great community you have here!Based on suggestions from other members, I've used spybot with no success.Next step... Hijack This.I hope someone can help me get rid of this nasty little bugger. Thank You, in advance, for any suggestions / advice.Here is my Hijack This logfile...Logfile of HijackThis v1.99.1Scan saved at 6:05:16 PM, on 8/7/2005Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes:C:\WINNT\System32\smss.exeC:\WINNT\system32\csrss.exeC:\WINNT\system32\winlogon.exeC:\WINNT\system32\services.exeC:\WINNT\system32\lsass.exeC:\WINNT\system32\svchost.exeC:\WINNT\system32\svchost.exeC:\WINNT\System32\svchost.exeC:\WINNT\System32\svchost.exeC:\WINNT\System32\svchost.exeC:\Program Files\Common Files\Symantec Shared\ccProxy.exeC:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeC:\WINNT\Explorer.EXEC:\Program Files\Norton Internet Security\ISSVC.exeC:\Program Files\Com... Read more

A:Hijack This LOG. Plz help w/ about blank

Hello Freddog2 and welcome to the BC malare forum. After reviewing your log I see a few items that require our attention. Please print these directions and then proceed with the following steps in order.Step #1Download Cwshredder.exe and save it to a folder of its own. Start the program and click on the Check for Update button. If an update is available then download and install it. Close the program (do not run it yet).Download CCleaner and install it but do not run it yet.Now we need to remove a service. I'm not sure if this will work as planned but I'm going to use you for a guinea pid Open Notepad and Copy/Paste the contents of the quote box below into the new document:  Const title = "Service Removal Tool"Set oWS = CreateObject("Wscript.Shell")sService = inputbox("Removing Service:",title," 11F?#???`I")If sService = "" thenmsgbox "Script halted. No changes were made.", vbInformation, titlewscript.quitEnd IfstrComputer = "."Set objWMIService = GetObject("winmgmts:{impersonationLevel=impersonate}!\\" & strComputer & "\root\cimv2")Set colListOfServices = objWMIService.ExecQuery _("Select * from Win32_Service Where Name = '" & sService & "' or displayName = '" & sService & "'")If colListOfServices.count > 0 ThenFor Each objService In colListOfServicesobjService.StopService()wscript.Sleep 5000obj... Read more

Read other 1 answers
RELEVANCY SCORE 40.4

I keep getting the about:blank as my homepage, and I cant get rid of it. I've tried Norton,Ad-aware, and spysweeper and cant get rid of it. Will someone please help? Here's my HJT log.
Logfile of HijackThis v1.98.0
Scan saved at 3:11:51 PM, on 7/11/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\LXSUPMON.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\tjzsfou.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Mythic\Atlantis\game.dll
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Jay\My Documents\My Pictures\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME... Read more

A:Help, About:Blank Hijack

Hi and welcome to TSG,

Download this: http://freeatlast100.100free.com/index.html

FINDnFIX.exe

Run !LOG!.bat and copy and paste the log here.
 

Read other 1 answers
RELEVANCY SCORE 40.4

I am having a problem this site helped a friend of mine fix.

My home page is being changed to about:blank, some adult sites are
being added to my favorites list, my computer seems to lock up now and then too.

I tried Microsoft anti-spyware and two other programs. All of them
find and claim to remove the issue. It seems to regenerate itself.

they find

unspecified.spyware.65
CWS ( I think that right)
Trojanz

I followed the instructions I found on this site to create a log, the steps
I followed included using the hijack this analyzer. The instructions told me
to let you know this.

Thank you in advance for any help you can provide me, I am hopeful you can help.

Here is the log...

====================================================================
Log was analyzed using KRC HijackThis Analyzer - Updated on 4/1/05
Get updates at http://www.greyknight17.com/download.htm#programs

***Security Programs Detected***

C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec S... Read more

A:about:blank hijack

Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should 'not' have any open browsers when you are following the procedures below.

Go to My Computer->Tools->Folder Options->View tab and make sure that 'Show hidden files and folders' is enabled. Also make sure that 'Display the contents of system folders' is checked. If you have Windows XP, the search feature is a little different. When you click on 'All files and folders' on the left pane in the Search Window, click on the 'More advanced options' at the bottom. Make sure that 'Search system folders', 'Search hidden files and folders', and 'Search subfolders' are checked.

For the options that you checked/enabled earlier, you may uncheck them after your log is clean. If we ask you to fix a program that you use or want to keep, please post back saying that (we don't know every program that exists, so we may tell you to delete a program that we think is bad to keep).
===============

We'll need to download these program(s) to help us deal with the "About:Blank" infection:

-

Download, unzip to your desktop CWShredder and run it, then:

1. Click "Check For Update"

(If an update isn't available, skip to step #4.)

2. Click "Click here to Download the upate".
3. When the new version h... Read more

Read other 17 answers
RELEVANCY SCORE 40.4

Hi, Have read upteen threads on this problem and still have the about:blank problem.

Running XP professional. Can`t install service pack 2 as this pop up doesn`t let me run : %systemroot%\system32\oobe\msoobe.exe /a. It uses it to open a pop up.

Spyware Guard detects the home page change etc........ Disconnected from the internet yet popups still come. Everytime I reboot i have to force rundll32.exe to stop. Looked this up on google and this could be my problem aswell as about:this as it says its more than likely a trojan/virus. This process is always running in task manager. Even when i kill it - it returns itself.

Anyway i have all updated new versions of Adaware, CSW, SpyBot. Ran Spybot - rebooted. Ran CSW rebooted. Ran CSW rebooted, and as mentioned in many threads - here is the hijackthis result.

Logfile of HijackThis v1.99.0
Scan saved at 19:05:00, on 09/02/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ahead\InCD\InCD.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\System32\pctspk.exe
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\PROGRA~1\nt... Read more

A:Another about:blank hijack

I have managed to get rid of the pop ups for the time being by using

start spywareblaster
click tools
about:blank appears.
replace about:blank with the path of your prefered start page you have before:like for example http://www.microsoft...
Make the same thing (if they are other entries) with your prefered

from this thread http://www.faqfarm.com/Computer/Virus/19285 very handy - many suggested methods for deleting about:blank.

I also used adaware away and seems to have done the trick. However my main concern is "rundll.32"

RUNDLL.32 - checked google and no real answers on how to get rid of it. I get - your system has performed an illegal operation. I get this every time i reboot. I have to end task every time to get rid of it.

Anyone any suggestions? I will continue to search for solutions in this forum aswell as the internet but any response would be brialliant.

here is my current log

Logfile of HijackThis v1.99.0
Scan saved at 01:58:49, on 10/02/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe... Read more

Read other 3 answers
RELEVANCY SCORE 40.4

I've got a variant of the About:Blank/SmartSearch Hijack and I've done everything I can think of to rid myself of it. I've run Spybot S&D and got everything it picked up, run CWShredder and it comes back clean, I've run HijackThis and got everything I think is wrong. I'll attach a log just in case. I've done a virus scan with Norton which came back clean. I even found a program called About:Buster and ran that and it still didn't work. If it helps, the SmartSearch page is downloaded from the IP 206.161.207.99 I'm at wits end here...

Logfile of HijackThis v1.97.7
Scan saved at 10:47:51 PM, on 6/27/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SYMTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON UTILITIES\NPROTECT.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON CLEANSWEEP\CSINJECT.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\CPQEADM.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\COMPAQ\CPQINET\CPQINET.EXE
C:\PROGRAM FIL... Read more

A:About:Blank hijack

Read other 14 answers
RELEVANCY SCORE 40.4

undefined
My search page has been replace by about:blank. I try to remove but keeps coming back. Can somebody help?
Here is the Log file.

Logfile of HijackThis v1.97.7
Scan saved at 6:21:07 PM, on 4/8/2004
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP2 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\SYSTEM32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\WINNT\System32\internat.exe
C:\Program Files\GetRight\getright.exe
C:\Program Files\eDonkey2000\edonkey2000.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe
C:\Program Files\Spybot\SpybotSD.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Downloads\HijackThis.exe
C:\Program Files\AnalogX\DLLArchive\dllarch.exe
C:\Program Files\Microsoft Office\Office\OUTLOOK.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\System32\lofjeic.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\System32\lofjeic.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main... Read more

A:about:blank hijack

Read other 16 answers
RELEVANCY SCORE 40.4

I need help with about.blank hijiack.I cannot go to window update to download the security file when i scan for it,it alway bring me back to about.blank please take a look at my logfile.

Logfile of HijackThis v1.99.1
Scan saved at 4:16:05 PM, on 3/12/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\CPQEADM.EXE
C:\COMPAQ\CPQINET\CPQINET.EXE
C:\PROGRAM FILES\COMPAQ\DIGITAL DASHBOARD\DEVGULP.EXE
C:\PROGRAM FILES\ALCATEL\SPEEDTOUCH USB\DRAGDIAG.EXE
C:\PROGRAM FILES\IOMEGA CD-RW\DIRECTCD.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\HIDSERV.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\BTTNSERV.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\EAUSBKBD.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\COMPAQ\DIGITAL DASHBOARD\CPQMLCK.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\STEAM\STEAM.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\INTERN... Read more

A:Help With about.blank Hijack

Read other 8 answers
RELEVANCY SCORE 40.4

flrman1 said:

Right click on the desktop and choose "Properties" . Click on the "Desktop" tab then the "Customize Destop" button. Click on the "Web" tab. If there is anything there under "Web pages" select it and click "Delete"

I'm experiencing the same problem - when I go to web tab I see one entry my home page which when viewed shows about:blank. I cant delete it because it's greyed out...

Can anyone please help me!

CheersClick to expand...
 

A:about:blank hijack

Hi ecat

Welcome to TSG!

I have split your post off into your own thread. In the future if you have a Question/Problem please start a "New Thread". It get's too confusing trying to address two different people's problem in the same thread and you may get overlooked.

Please continue in this thread.
 

Read other 2 answers
RELEVANCY SCORE 40.4

Hi Forum Member,
I am trying to remove the about:blank virus. I have run Hijack This. This is the log.
Logfile of HijackThis v1.99.1
Scan saved at 1:42:43 AM, on 2/23/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\BCMDMMSG.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MDM.EXE
C:\WINDOWS\SYSTEM\DEVLDR16.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\ATIPTAXX.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE10\WINWORD.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\HPZSTATX.EXE
C:\WINDOWS\MSAGENT\AGENTSVR.EXE
C:\PROGRAM FILES\NETZERO\EXEC.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\NETZERO\EXEC.EXE
C:\PROGRAM FILES\NETZERO\QSACC\X1EXEC.EXE
C:\PROGRAM FILES\ADOBE\ACROBAT 4.0\READER\ACRORD32.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCAGENT.EXE
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCDASH.EXE
C:\PROGRAM FILES\MCAFEE.COM\SHARED\MGHTML.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://my.netzero.net/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s... Read more

A:Hijack This log and about:blank

First off, I take it you are running netzero correct?

You have tried just changing your homepage.

Also get:
Spybot Search and destroy and seacrch for updates.

Spyware Gaurd

Run Spybot fix the problems and post another HJT log.

Alan
 

Read other 2 answers
RELEVANCY SCORE 40.4

So it seems I've been infected with the now infamous about:blank homepage hijacker. I've done the standard procedure (run adaware, spybot, and cwshredder) and the hijack returns after about 12 hours each time I run those programs. I've noticed that spybot's tea timer shows maybe six changes to the registry when the homepage changes to about:blank. Here's the HJT log. Any help is appreciated. Thanks.-------Logfile of HijackThis v1.97.7Scan saved at 12:52:37 PM, on 6/22/2004Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\csrss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\brsvc01a.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\System32\brss01a.exeC:\WINDOWS\System32\nvsvc32.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\MsPMSPSv.exeC:\WINDOWS\system32\csrss.exeC:\WINDOWS\system32\winlogon.exeC:\Program Files\Winamp\winampa.exeC:\Program Files\McAfee\McAfee VirusScan\alogserv.exeC:\Prog... Read more

A:about:blank hijack (w/ HJT log)

Download and install APM from: http://www.diamondcs.com.au/index.php?page=apmClose all windows except HijackThis and fix the lines below.R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Tim\LOCALS~1\Temp\sp.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Tim\LOCALS~1\Temp\sp.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Tim\LOCALS~1\Temp\sp.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Tim\LOCALS~1\Temp\sp.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Tim\LOCALS~1\Temp\sp.htmlR0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Tim\LOCALS~1\Temp\sp.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blankO2 - BHO: (no name) - {6D1821F5-C991-4908-BC7D-27B31E2E5A94} - C:\WINDOWS\System32\emjhj.dllThen run APM that we had downloaded and in the upper window select explorer.exeIn the lower window find and right-click the file C:\WINDOWS\System32\emjhj.dll.Select Unload DLL and click OK on the prompts t... Read more

Read other 9 answers
RELEVANCY SCORE 40.4

I have an issue, my browser has been hijacked to about:blank, I have used Adaware, and Spybot but no go. I went through registry and deleted all applicable entries and that did not work. Can anyone help this thing is giving me a headache. Operating System Win2000K pro, Browser IE 6.0.2800.1106, all updates installed. Virus Symantec Anti-virus CE 8.0.1.429

Read some similar posts below is HJT log file:

Logfile of HijackThis v1.97.7
Scan saved at 11:54:18 AM, on 6/25/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\NavNT\DefWatch.exe
C:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe
C:\PROGRA~1\NavNT\rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\Promon.exe
C:\PROGRA~1\NavNT\vptray.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINNT\kdx\KHost.exe
C:\Program Files\Winamp\Winampa.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
C:\WINNT\system32\lskkue.exe
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\Program Files\TOSHIBA\NetDevSw\NetDevSW.exe
C:\Program Files\Rocket Software\RocketTime\RocketT... Read more

A:About:blank Hijack

(Please don't double post for the same problem)
Problem being addressed here:

http://forums.techguy.org/showthread.php?t=243101
 

Read other 2 answers
RELEVANCY SCORE 40.4

Hello. My homepage keeps resetting itself to about:blank, and I'm getting some serious pop-ups. I have run Norton Professional, AdAware SE, Spybot and Registrar Lite. I have fixed all the problems that these programs have presented, but to no avail.

Here is my Hijack This log. I would greatly appreciate any help.

Logfile of HijackThis v1.99.1
Scan saved at 3:08:52 PM, on 20/03/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\ipsu.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\sdkbm32.exe
C:\W... Read more

Read other answers
RELEVANCY SCORE 40.4

My start page is hijacked by about:blank. it opens this page every time i get on the internet even if i change my homepage to what i want it to be. can you please give me a step by step process on how to fix this problem.
 

A:about:blank hijack

Welcome to TSG
HIJACK THIS:

Download and copy hijackthis to its own folder , it makes backups so keeping them separate and available can be useful.

Note the Spyware tools websites are very often under attack and so I have provided more than 1 location to download from:

http://www.tomcoyote.org/hjt/
http://209.133.47.200/~merijn/downloads.html
http://www.thespykiller.co.uk/
http://www.sherrylynn.us/privacypolicy

Close all open windows and open Hijack This. Click “Scan”. When the scan is finished (it only takes a second), the scan button will change to “Save Log”.
Click on “Save Log” and then save it to NotePad.
Click on “Edit” – “Select all” – “copy” and then “paste” into the thread.
DO NOT FIX ANYTHING wait advice from one of the many security experts in this forum.
I currently do not have the skill/competence to advise and poor advice can be far more damaging to your PC with this software.

Please have patience and wait for an expert to provide further detailed advice
 

Read other 1 answers
RELEVANCY SCORE 40.4

Well i've fallen victim of the about blank hijack. I think anyways. I've tried several times both in safe mode and normal mode to get rid of it using ad-aware, cw shredder, sybot, and hijack this. this thing keeps coming back. Here is my HJT log, thanks for any help from you guys!
Logfile of HijackThis v1.97.7
Scan saved at 11:06:45 PM, on 6/22/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\WINDOWS\MMKeybd.exe
C:\documents and settings\olson's\local settings\temp\Fvq.exe
C:\documents and settings\olson's\local settings\temp\DMP.exe
C:\WINDOWS\System32\IEHost.exe
C:\WINDOWS\System32\wltbsmr.exe
C:\Program Files\Common files\WinTools\WToolsA.exe
C:\PROGRA~1\Itch ooze\Flaw heck.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Netropa\Traymon.exe
C:\Program Files\Netropa\OSD.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common files\WinTools\WToolsS.exe
C:\Program Files\... Read more

A:about blank hijack...ugh...Please help!

the thread wouldnt let me post the entire HJT log, too many characters i guess, so here is the rest. Thanks
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Olson's\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Olson's\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Olson's\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Olson's\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Olson's\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Olson's\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: (no name) - {339BB23F-A864-48C0-A59F-29EA915965EC} - (no file)
O3 - Toolbar: Defy soap one - {49B8058E-0DCC-D3A0-A658-728074B06400} - C:\PROGRA~1\DELETE~1\site save.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\... Read more

Read other 2 answers
RELEVANCY SCORE 40.4

Hi, i too have this problem. I dont believe Hijack This nor spybot can remove it. I followed your instructions, and this is what i got(i also attached it):

regf       Pugf hbin  ˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙Ø˙˙˙nk, €$*f[Ä ˙˙˙˙ ˙˙˙˙˙˙˙˙ 8 x ˙˙˙˙ 0 8 M a  Windows Čž˙˙sk˙˙x x    ”     ģ
     !
 €  !      #
 €  #  ?    
     ?   
    ?    
        ˙˙˙˙Ų˙˙˙vk 8 Ų   fłAppInit_DLLsÖ¨ęGĄ˙˙˙C : \ W I N D O W S \ S y s t e m 3 2 \ s q l . d l l  T ° Š˙˙˙vk  P   ĄUDeviceNotSelectedTimeoutš˙˙˙1 5  Ų(ĶWš˙˙˙9 0  ! Š˙˙˙vk  €'   zGDIProcessHandleQuota"žą˙˙˙vk  Ą   °ŗSpooler2š˙˙˙y e s Ą  °  p * č ą˙˙˙vk  €   =pswapdiskŠ˙˙˙vk  `   RæTransmissionRetryTimeoutą˙˙˙°  p * č  X Š˙˙˙vk  €'   C USERProcessHandleQuotao x ˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙˙... Read more

A:about:blank hijack

Read other 8 answers
RELEVANCY SCORE 40.4

Hi

Good day!
I'd using the hijack 1.97 to get rid of the "searchweb2.com". after Fix check, My IE url option become blank, and I can't set back to the url i wants. I had try to download the winsockXP fix to solve the problem but still my IE url is blank. How can i fix my IE back
pls help
thanks
 

Read other answers
RELEVANCY SCORE 40.4

I just want to make sure that I fix the right things in my Hijack this log to get rid of having about:blank as my homepage. I can see most of it but I always miss something. I have AdAware SE, spybot, & Panda alos once I do the fixes in Hijack. So once I go into safe mode can you guys tell me what you see that should be fixed with Hijack. Thanks a ton.

Logfile of HijackThis v1.99.1
Scan saved at 11:28:04 AM, on 4/27/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Software\Panda Platinum 2005 Internet Security\PavProt.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Panda Software\Panda Platinum 2005 Internet Security\PaSSrv.exe
C:\Program Files\Panda Software\Panda Platinum 2005 Internet Security\Firewall\PavFires.exe
C:\Program Files\Panda Software\Panda Platinum 2005 Internet Security\PavFnSvr.exe
C:\Program Files\Panda Software\Panda Platinum 2005 Internet Security\Pavkre.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Panda Software\Panda Platinum 2005 Internet Security\pavsrv51.exe
C:\Progra... Read more

A:help w/ hijack this log - about : blank

Fix:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\C77A4~1.AIN\LOCALS~1\Temp\se.dll/spage.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\C77A4~1.AIN\LOCALS~1\Temp\se.dll/spage.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {578BF54E-2DFE-4D1F-96FA-D155B2D62E8A} - C:\WINDOWS\system32\lhjk.dll
O4 - HKLM\..\Run: [qkequhuz] C:\WINDOWS\sdkduips.exe
O4 - HKLM\..\Run: [] c:\WINDOWS\System32\
O4 - HKLM\..\Run: [zzb] c:\WINDOWS\System32\zzb.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\C77A4~1.AIN\LOCALS~1\Temp\se.dll,DllInstall
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [] c:\WINDOWS\System32\
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/28475e17a90a8e...ip/RdxIE601.cab
O18 - Filter: text/html - {2FF75BAF-548C-416D-BAEE-ED87539F61A3} - C:\WINDOWS\system32\lhjk.dll
O18 - Filter: tex... Read more

Read other 2 answers
RELEVANCY SCORE 40.4

This forum has helped me out in the past. I'm hoping someone can work their magic again.Adware (about:blank, only the best, et al) have taken over my operating system Windows XP. On startup and logging on, my desktop remains empty, and I can only access programs/files through Windows Task Manager. There is no start up menu on the desktop.Thank you in advance for any help! I really appreciate your efforts.Here's the log:Logfile of HijackThis v1.97.7Scan saved at 5:33:52 PM, on 2/4/2005Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\System32\CTsvcCDA.exeC:\WINDOWS\System32\nvsvc32.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\MsPMSPSv.exeC:\WINDOWS\System32\taskmgr.exeC:\Program Files\Internet Explorer\iexplore.exeC:\WINDOWS\d3wa.exeC:\WINDOWS\iprn.exeC:\Documents and Settings\Mike\Desktop\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\qvogo.dll/sp.html#28129R1 - HKCU\Sof... Read more

A:Hijack This Log...about:blank etc

Your logfile is being analyzed now, and a response will be posted shortly.

Thanks
daveai

Read other 92 answers
RELEVANCY SCORE 40.4

hello everybody. I have a problem with a hijacker that wont go away. It changes the homepage to about:blank. I think it is the CWS hijacker but not sure. I have run all the ususal safeguards, but it still continues to come back after about 24 hours, so I am obviously not getting all of it.

I have run...

cws shredder
adaware
spybot
spy sweeper
aboutbuster

Here is my updated hijackthis log...
Logfile of HijackThis v1.97.7
Scan saved at 8:30:57 AM, on 6/29/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Joe\Desktop\Joe's Folder\New Installs\Roxio Easy CD Creater 5 Platinum\DirectCD\DirectCD.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LMPDPSRV.EXE
C:\Program Files\ABBYY FineReader 5.0 Sprint\CAgent.exe
C:\Documents and Settings\Joe\Desktop\Joe's Folder\New Installs\Logitech Mouse and Keyboard\iTouch\iTouch.exe
C:\DOCUME~1\Joe\Desktop\JOE'SF~1\NEWINS~1\LOGITE~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\documents and settings\joe\desktop\joe's folder\new installs\counterstrike\steam.exe
C:\Documents and Settings\Joe\Desktop\Joe's Folder\New Installs\AIM Instan... Read more

Read other answers
RELEVANCY SCORE 40.4

Hi my name is Zack and I just joined yesterday. You helped me get rid of the Jimbutts hijack. Thanks!!!!Now I have the about blank hijack. I either get a blank page or a generic search engine when I open explorer. It also hijacks at any point during internet use. In addition, when I open explorer my anti virus software goes crazy with alerts about trojans, etc. Please help!!!I have all of the anti-virus and anti-spyware you recommended to get rid of Jimbutts. I just deleted some files from Windows32 which seems to have helped, but I am worried the problem will come back. Here is my log. Thank you so much!!Y'all are the best.zackLogfile of HijackThis v1.98.2Scan saved at 6:35:32 PM, on 3/10/2005Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\csrss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\System32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Programme\Gemeinsame Dateien\Symantec Shared\ccProxy.exeC:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exeC:\Programme\Norton Perso... Read more

A:about blank hijack

you really are in a mess firstly download and run the free trial version of TDS3Then run two online virus scans from any of the following locations and post a summary of their findings in your next reply. http://www.ravantivirus.com/scan/ - RAVhttp://www.pandasoftware.com/activescan/ - Pandahttp://www.bitdefender.com/scan/licence.php - BitDefenderhttp://security.symantec.com/sscv6/default...id=ie&venid=sym - Symantecthen reboot and post a fresh Hijackthis log.

Read other 24 answers
RELEVANCY SCORE 40.4

My browser's about:blank page has been reset to a web portal page, and even when I configure my browser to open in the about:blank mode, the portal page still appears.

I tried removing all spyware on my computer with both Adaware and Spybot S&D, but to no avail. I then used Hijak This to create a log, and I was hoping someone could tell me what to remove. Thanks!

Logfile of HijackThis v1.97.7
Scan saved at 5:34:58 PM, on 5/3/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\ZoneLabs\minilog.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\LVCOMS.EXE
C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb01.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\FILTER~1\filtergate.exe
C:\Program Files\... Read more

A:Hijack This Log - HELP! ( about:blank )

Read other 8 answers
RELEVANCY SCORE 40.4

I ran Ad-aware and Spybot and no fix.
Here's my Hijack log.

Logfile of HijackThis v1.97.7
Scan saved at 9:21:36 AM, on 6/18/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\TEMP\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\WINDOWS\TEMP\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\WINDOWS\TEMP\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\TEMP\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\WINDOWS\TEMP\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\WINDOWS\TEMP\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {DCFFC381-C0C1-11D8-B8F9-002085361046} - C:\WINDOWS\SYSTEM\LJGFKA.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A... Read more

A:About:Blank Hijack. Can anyone help?

Read other 16 answers
RELEVANCY SCORE 40.4

i've been searching everywhere on the net to fix the about:blank hijacker spyware/virus.....it's been months! everytime i open IE and type a webaddress, it goes to "about:blank" search site. please please help. i need my computer back! thanks..here my hjt logLogfile of HijackThis v1.98.2Scan saved at 6:45:10 PM, on 3/27/2005Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\hkcmd.exeC:\Program Files\Java\j2re1.4.2_03\bin\jusched.exeC:\Program Files\Intel\Modem Event Monitor\IntelMEM.exeC:\Program Files\Dell\Media Experience\PCMService.exeC:\Program Files\Common Files\Dell\EUSW\Support.exeC:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXEC:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exeC:\Program Files\Logitech\ImageStudio\LogiTray.exeC:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exeC:\Program Files\Real\... Read more

A:Need help! about:blank hijack!

Download the following file and extract it:http://www.derbilk.de/SpSeHjfix110.zipRun the program and then post its resulting log and a new

Read other 1 answers
RELEVANCY SCORE 40.4

What can I do to get rid of this stupid About:Blank hijack?
Any help at all is so very welcome.

Thanks in Advance:
Jess
Here is my HijackThis log:

Logfile of HijackThis v1.97.7
Scan saved at 3:43:39 PM, on 6/26/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\System32\ups.exe
C:\WINDOWS\System32\BRMFRSMG.EXE
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\j2re1.4... Read more

A:About:Blank Hijack

Read other 14 answers
RELEVANCY SCORE 40.4

Hi,
I was really heartened to see such a forum as this. Last time my computer came down with something similar, I had to ask someone to entirely redo my hard disk.
I hope I don't have to do it again. I'm a total novice at this. Please consider this fact while suggesting a fix. Thanks in advance
Regards,
Anand S Panimaya



Logfile of HijackThis v1.99.0
Scan saved at 11:30:51 AM, on 1/25/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP1 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\MICROS~2\Office\OUTLOOK.EXE
C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe
C:\WINNT\system32\taskmgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\panimaya\My Documents\My Downloads\Software\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Ba... Read more

A:About:blank hijack? HJT Log

Welcome to TSF.

No need to post all those and attach it also. Next time just post the result.txt log.

Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should not have any open browsers when you are following the procedures below.

Go to My Computer->Tools/View->Folder Options->View tab and make sure that 'Show hidden files and folders' (or 'Show all files') is enabled. Also make sure that Display the contents of System Folders' is checked. Windows XP's search feature is a little different. When you click on 'All files and folders' on the left pane, click on the 'More advanced options' at the bottom. Make sure that Search system folders, Search hidden files and folders, and Search subfolders are checked.

For the options that you checked/enabled earlier, you may uncheck them after your log is clean. If we ask you to fix a program that you use or want to keep, please post back saying that (we don't know every program that exists, so we may tell you to delete a program that we think is bad to keep).

Turn off system restore by right clicking on My Computer and go to Properties->System Restore and check the box for Turn off System Restore. Click Apply and then OK. Restart your computer. After we are finished with your log file and verified that it's clean, you ma... Read more

Read other 3 answers
RELEVANCY SCORE 40.4

I have spoken via BC with tg1911 and he/she told me to post here after loading/running some freeware.I have the about blank issue (maybe different ones) and still am having problems with computer lag, random lock ups and slow internet traffic. THANKS FOR ANY HELP.Logfile of HijackThis v1.99.1Scan saved at 1:20:34 PM, on 2/11/2006Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Common Files\Symantec Shared\ccProxy.exeC:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeC:\Program Files\Norton Internet Security\ISSVC.exeC:\Program Files\Common Files\Symantec Shared\SNDSrvc.exeC:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exeC:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\sony\giga pocket\shwserv.exeC:\Program Files\iPod\Bin\iPodSrv.exeC:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exeC:\WINDOWS\System32\svchost.exeC:\Program ... Read more

A:About Blank Hijack This Log

Hello tailboard and welcome to the BC HijackThis forum. I do not see any problems in the HijackThis log. It is clean.What do you mean by I have the about blank issuePost back with some details of the problem and we'll see if we can't point you in the right direction.Cheers.OT

Read other 1 answers