Recent content by db533

  1. D

    about:blank hijack

    Logfile of HijackThis v1.99.0 Scan saved at 21:20:29, on 08/02/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe...
  2. D

    about:blank hijack

    Part 2 of 2 -------------------------------------------------- Enumerating Windows NT/2000/XP services Microsoft ACPI Driver: System32\DRIVERS\ACPI.sys (system) Microsoft Kernel Acoustic Echo Canceller: system32\drivers\aec.sys (manual start) AFD Networking Support Environment...
  3. D

    about:blank hijack

    Panda found 5, TrendMicro found one in a lost cluster that had been saved to disk. All these have been fixed. I also installed TrojanHunter which found Gator in quarantined files in XoftSpy. I deleted all quarantined files for XoftSpy, so this should be gone too, although in quarantine I suspect...
  4. D

    about:blank hijack

    For completeness, here's the HijackThis as it now looks. O17 look suspect to me?! Logfile of HijackThis v1.99.0 Scan saved at 21:00:16, on 07/02/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes...
  5. D

    about:blank hijack

    Mosaic1, here's the result of running hive.bat. It wasn't readable in Notepad. I hope it makes more sense to you than it did to me!
  6. D

    about:blank hijack

    Startuplist - part 2 of 2 -------------------------------------------------- Enumerating Windows NT/2000/XP services Microsoft ACPI Driver: System32\DRIVERS\ACPI.sys (system) Microsoft Kernel Acoustic Echo Canceller: system32\drivers\aec.sys (manual start) AFD Networking Support...
  7. D

    about:blank hijack

    Startuplist - part 1 of 2: StartupList report, 07/02/2005, 20:30:55 StartupList version: 1.52.2 Started from : C:\Install\HijackThis 1_99\HijackThis.EXE Detected: Windows XP SP2 (WinNT 5.01.2600) Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180) * Using default options * Including...
  8. D

    about:blank hijack

    I have applied the SpyBot fix and fixed the 2 O9 entries suggested above, but the homepage continues to switch to about:blank. Another feature is that my MRU list persistently retains (or has re-inserted into it) porn sites even though I continuously clean the MRU using History Kill.
  9. D

    about:blank hijack

    Thank you for pointing me to a fix for SpyBot. Any ideas on the about:blank trojan? I can live with SpyBot misbehaving, but the trojan is a real pain...
  10. D

    about:blank hijack

    I have been plagued by a persistent about:blank hijacker. SpyBot is clean (aside from the usual DSO Exploit). CWShreader says the system is clean. LavaSoft AdAware also comes up clean. I have History Kill and now just tried SpywareGuard, both of which catch the fact that the home page is...
Top