Solved: help! about:blank problem!

Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

pandora_6666

Thread Starter
Joined
Jul 11, 2005
Messages
31
I am ready to go insane! i have spent five days running several anti-spyware, add ware, and anti-virus programms to no avail. They geerally find the "problem", though some call it an Anarchy virus, while others say it is an adware lefeat. the problem is my homepage keeps reseting to about:blank, there are tons of pop ups, my pages are hijacked and taken to weird sites, and explorer is having a lot of problems - this last one may or may not be related. I have gone inot windows registry and manually changed things myself, and it will work for one opening of the homepage, but the second time, it goes back to about:blank, and the resets everything. There is a registry key that spyfighter keeps finding as a new entry, and when you decline, it will just keep doing it and doing it again andagian. i went in and manualy deleted this key, and it instantly put itself back. I am at my wits end! If someone could help me i would appreciate it - also any insite on where in the world this was picked up at would also be helpful! Thanks so much!
Jo
 

pandora_6666

Thread Starter
Joined
Jul 11, 2005
Messages
31
Logfile of HijackThis v1.99.1
Scan saved at 7:33:56 PM, on 7/11/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON CLEANSWEEP\CSINJECT.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SYMTRAY.EXE
C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON UTILITIES\NPROTECT.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\LEXPPS.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\PROGRAM FILES\MUSICMATCH\MUSICMATCH JUKEBOX\MM_TRAY.EXE
C:\PROGRAM FILES\ACCELERATION SOFTWARE\PHANTOMCD\BPLAYER.EXE
C:\WINDOWS\SYSTEM\USBMONIT.EXE
C:\PROGRAM FILES\NORTON SYSTEMWORKS\PASSWORD MANAGER\ACCTMGR.EXE
C:\WINDOWS\SYSTEM\WINIV.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\NTJN32.EXE
C:\WINDOWS\MSAR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\PROGRAM FILES\MICROCORE\DIALER.EXE
C:\WINDOWS\MSAR.EXE
C:\WINDOWS\MSAR.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\ADDQH32.EXE
C:\WINDOWS\SYSTEM\IEWS32.EXE
C:\WINDOWS\ADDQH32.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\NETGW.EXE
C:\WINDOWS\ADDQH32.EXE
C:\WINDOWS\ADDQR32.EXE
C:\WINDOWS\ADDQH32.EXE
C:\WINDOWS\ADDQH32.EXE
C:\WINDOWS\ADDQH32.EXE
C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\wacdq.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\wacdq.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system\wacdq.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\wacdq.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\wacdq.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\wacdq.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\wacdq.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Joey Loves Charles
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O2 - BHO: Class - {0B77DD19-4507-15E8-A38D-0DA38C44E22B} - C:\WINDOWS\SYSTEM\IPXJ.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [LexStart] lexstart.exe
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [LexmarkPrinTray] PrinTray.exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [NPROTECT] c:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.EXE /Consumer
O4 - HKLM\..\Run: [CTFMon] C:\WINDOWS\SYSTEM\CTF\CTFMON.EXE
O4 - HKLM\..\Run: [bplayer.exe] "C:\PROGRA~1\ACCELE~1\PHANTO~1\BPLAYER.EXE"
O4 - HKLM\..\Run: [Gene USB Monitor] c:\windows\SYSTEM\USBMonit.exe
O4 - HKLM\..\Run: [AcctMgr] C:\PROGRAM FILES\NORTON SYSTEMWORKS\PASSWORD MANAGER\ACCTMGR.EXE /startup
O4 - HKLM\..\Run: [SpyFighterMonitor] "D:\PROGRAM FILES\SPYFIGHTER.EXE" monitor
O4 - HKLM\..\Run: [WINIV.EXE] C:\WINDOWS\SYSTEM\WINIV.EXE
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ccEvtMgr] "c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [CSINJECT.EXE] c:\Program Files\Norton SystemWorks\Norton CleanSweep\csinject.exe
O4 - HKLM\..\RunServices: [SymTray - Norton SystemWorks] c:\Program Files\Common Files\Symantec Shared\SymTray.exe "Norton SystemWorks"
O4 - HKLM\..\RunServices: [NPROTECT] c:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O4 - HKLM\..\RunServices: [MSAR.EXE] C:\WINDOWS\MSAR.EXE /s
O4 - HKLM\..\RunServices: [APPNR.EXE] C:\WINDOWS\SYSTEM\APPNR.EXE /s
O4 - HKLM\..\RunServices: [ADDOW.EXE] C:\WINDOWS\SYSTEM\ADDOW.EXE /s
O4 - HKLM\..\RunServices: [CRQR32.EXE] C:\WINDOWS\SYSTEM\CRQR32.EXE /s
O4 - HKLM\..\RunServices: [ADDPB32.EXE] C:\WINDOWS\ADDPB32.EXE /s
O4 - HKLM\..\RunServices: [NTJN32.EXE] C:\WINDOWS\SYSTEM\NTJN32.EXE /s
O4 - HKLM\..\RunServices: [APIZS.EXE] C:\WINDOWS\SYSTEM\APIZS.EXE /s
O4 - HKLM\..\RunServices: [D3ZG32.EXE] C:\WINDOWS\SYSTEM\D3ZG32.EXE /s
O4 - HKLM\..\RunServices: [SYSZR.EXE] C:\WINDOWS\SYSZR.EXE /s
O4 - HKLM\..\RunServices: [D3HA.EXE] C:\WINDOWS\D3HA.EXE /s
O4 - HKLM\..\RunServices: [NETWW32.EXE] C:\WINDOWS\NETWW32.EXE /s
O4 - HKLM\..\RunServices: [MSBJ32.EXE] C:\WINDOWS\MSBJ32.EXE /s
O4 - HKLM\..\RunServices: [ADDEZ32.EXE] C:\WINDOWS\SYSTEM\ADDEZ32.EXE /s
O4 - HKLM\..\RunServices: [IPGX.EXE] C:\WINDOWS\IPGX.EXE /s
O4 - HKLM\..\RunServices: [SYSYH.EXE] C:\WINDOWS\SYSYH.EXE /s
O4 - HKLM\..\RunServices: [NTMC32.EXE] C:\WINDOWS\SYSTEM\NTMC32.EXE /s
O4 - HKLM\..\RunServices: [MSJE32.EXE] C:\WINDOWS\SYSTEM\MSJE32.EXE /s
O4 - HKLM\..\RunServices: [ATLNM.EXE] C:\WINDOWS\ATLNM.EXE /s
O4 - HKLM\..\RunServices: [ATLDP.EXE] C:\WINDOWS\SYSTEM\ATLDP.EXE /s
O4 - HKLM\..\RunServices: [NETCE.EXE] C:\WINDOWS\SYSTEM\NETCE.EXE /s
O4 - HKLM\..\RunServices: [IEOA.EXE] C:\WINDOWS\IEOA.EXE /s
O4 - HKLM\..\RunServices: [ADDQH32.EXE] C:\WINDOWS\ADDQH32.EXE /s
O4 - HKLM\..\RunServices: [IEWS32.EXE] C:\WINDOWS\SYSTEM\IEWS32.EXE /s
O4 - HKLM\..\RunServices: [NETGW.EXE] C:\WINDOWS\SYSTEM\NETGW.EXE /s
O4 - HKLM\..\RunServices: [ADDQR32.EXE] C:\WINDOWS\ADDQR32.EXE /s
O4 - HKCU\..\Run: [Weather] C:\PROGRAM FILES\AWS\WEATHERBUG\WEATHER.EXE 1
O4 - Startup: birthen.exe.lnk = C:\WINDOWS\Profiles\Pandora\Desktop\Tolkien stuff\elvish calendar dowloaded\birthen.exe
O4 - User Startup: birthen.exe.lnk = C:\WINDOWS\Profiles\Pandora\Desktop\Tolkien stuff\elvish calendar dowloaded\birthen.exe
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZNxdm414XXUS
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\PROGRAM FILES\ATI MULTIMEDIA\TV\EXPLBAR.DLL
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0521.DLL
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0521.DLL
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralInitialSetup1.0.0.8.cab
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/ClickYesToContinue/ie/bridge-c3.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?

Thank you very much! i saw that some people had a hijack this log, but was not sure what it was!
Jo
 
Joined
Sep 7, 2004
Messages
49,014
khazars is in bed I suspect, so to help you along

Get all of these you do not have and run them

SpywareBlaster 3.4 http://majorgeeks.com/download2859.html
SpyBot V1.4 http://www.majorgeeks.com/download2471.html
AdAware SE 1.06 http://www.majorgeeks.com/download506.html

DL them (they are free), install them, check each for their
definition updates
and then run AdAware and Spybot, fixing anything
they say.


Download the trial version of Ewido Security Suite http://www.ewido.net/en/download/
· Install ewido.
· During the installation, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
· Launch ewido
· It will prompt you to update click the OK button and it will go to the main screen
· On the left side of the main screen click update
· Click on Start and let it update.
· DO NOT run a scan yet. You will do that later in safe mode.

Restart your computer into safe mode now. Perform the following steps in safe mode:


Run Ewido:
· Click on scanner
· Click Complete System Scan and the scan will begin.
· During the scan it will prompt you to clean files, click OK
· When the scan is finished, look at the bottom of the screen and click the Save report button.
· Save the report to your desktop
This will take some time to run!
Post that log and a new HiJack log

Also Download CWShredder http://www.intermute.com/products/cwshredder.html - have it ready to run
 
Joined
Apr 25, 2005
Messages
239
Hi. Im having the same problem but i dont get any pop ups, its only my homepage is set to About:blank. I did a HJT log somewhere and someone told me to delete some folders and some files, but some of them are very important like installers for games which i need. My Ewido says it has errors in it everytime i run it but if i dont press anything the send report thing will go off and the scan will complete. Doesnt pick up anything though.
 

pandora_6666

Thread Starter
Joined
Jul 11, 2005
Messages
31
I have downloaded the programs but Ewido will not install as I only have windows 98 and it says i must have Xp to use it. is there another program i need instead? Thank you,
Jo
 
Joined
Sep 7, 2004
Messages
49,014
pandora_6666 said:
I have downloaded the programs but Ewido will not install as I only have windows 98 and it says i must have Xp to use it. is there another program i need instead? Thank you,
Jo
Ooops sorry about that
 

pandora_6666

Thread Starter
Joined
Jul 11, 2005
Messages
31
I ran the other two anyway, and here is thehijack log:


Logfile of HijackThis v1.99.1
Scan saved at 5:44:20 PM, on 7/13/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\LEXPPS.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\WINIV.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\MICROCORE\DIALER.EXE
C:\WINDOWS\SYSTEM\WINXB32.EXE
C:\WINDOWS\SYSTEM\WINXB32.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\NETZQ32.EXE
C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\cqeqj.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\cqeqj.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system\cqeqj.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\cqeqj.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\cqeqj.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\cqeqj.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\cqeqj.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Joey Loves Charles
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O2 - BHO: Class - {CDBCDF8D-F3C6-EE7D-C673-A31C7CDFB1F3} - C:\WINDOWS\APIEG32.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [WINIV.EXE] C:\WINDOWS\SYSTEM\WINIV.EXE
O4 - HKLM\..\RunServices: [CRNQ.EXE] C:\WINDOWS\CRNQ.EXE /s
O4 - HKLM\..\RunServices: [WINXB32.EXE] C:\WINDOWS\SYSTEM\WINXB32.EXE /s
O4 - HKLM\..\RunServices: [MSRH.EXE] C:\WINDOWS\SYSTEM\MSRH.EXE /s
O4 - HKLM\..\RunServices: [APPBQ32.EXE] C:\WINDOWS\SYSTEM\APPBQ32.EXE /s
O4 - HKLM\..\RunServices: [ATLWV.EXE] C:\WINDOWS\SYSTEM\ATLWV.EXE /s
O4 - HKLM\..\RunServices: [NTHJ32.EXE] C:\WINDOWS\SYSTEM\NTHJ32.EXE /s
O4 - HKLM\..\RunServices: [WINCI32.EXE] C:\WINDOWS\WINCI32.EXE /s
O4 - HKLM\..\RunServices: [APIRS32.EXE] C:\WINDOWS\APIRS32.EXE /s
O4 - HKLM\..\RunServices: [D3CJ.EXE] C:\WINDOWS\D3CJ.EXE /s
O4 - HKLM\..\RunServices: [IETX.EXE] C:\WINDOWS\SYSTEM\IETX.EXE /s
O4 - HKLM\..\RunServices: [IEAA32.EXE] C:\WINDOWS\IEAA32.EXE /s
O4 - HKLM\..\RunServices: [ATLIJ32.EXE] C:\WINDOWS\SYSTEM\ATLIJ32.EXE /s
O4 - HKLM\..\RunServices: [CRRN32.EXE] C:\WINDOWS\CRRN32.EXE /s
O4 - HKLM\..\RunServices: [NETZQ32.EXE] C:\WINDOWS\SYSTEM\NETZQ32.EXE /s
O4 - HKLM\..\RunServices: [ADDRR32.EXE] C:\WINDOWS\SYSTEM\ADDRR32.EXE /s
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZNxdm414XXUS
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\PROGRAM FILES\ATI MULTIMEDIA\TV\EXPLBAR.DLL
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0521.DLL
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0521.DLL
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
 
Joined
Jul 13, 2005
Messages
2
Look at the new thread called Connect to US.A1.YIMG.COM. I fixed this problem using that technique. Save your FAVORITES before you begin...
Johnscr
 
Joined
Sep 7, 2004
Messages
49,014
Download CWShredder http://www.intermute.com/products/cwshredder.html

Close all browser windows,
Open cwshredder.exe then click "Fix" and let it run.

Download About:Buster from:
http://www.majorgeeks.com/download4289.html
Double click aboutbuster.exe, click Update, click OK, click Start, then click OK.

Fix these with HJT – mark them, close IE, click fix checked

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\cqeqj.dll/sp.html#37049

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\cqeqj.dll/sp.html#37049

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system\cqeqj.dll/sp.html#37049

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\cqeqj.dll/sp.html#37049

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\cqeqj.dll/sp.html#37049

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\cqeqj.dll/sp.html#37049

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\cqeqj.dll/sp.html#37049

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

O2 - BHO: Class - {CDBCDF8D-F3C6-EE7D-C673-A31C7CDFB1F3} - C:\WINDOWS\APIEG32.DLL

O4 - HKLM\..\Run: [WINIV.EXE] C:\WINDOWS\SYSTEM\WINIV.EXE

O4 - HKLM\..\RunServices: [CRNQ.EXE] C:\WINDOWS\CRNQ.EXE /s

O4 - HKLM\..\RunServices: [WINXB32.EXE] C:\WINDOWS\SYSTEM\WINXB32.EXE /s

O4 - HKLM\..\RunServices: [MSRH.EXE] C:\WINDOWS\SYSTEM\MSRH.EXE /s

O4 - HKLM\..\RunServices: [APPBQ32.EXE] C:\WINDOWS\SYSTEM\APPBQ32.EXE /s

O4 - HKLM\..\RunServices: [ATLWV.EXE] C:\WINDOWS\SYSTEM\ATLWV.EXE /s

O4 - HKLM\..\RunServices: [NTHJ32.EXE] C:\WINDOWS\SYSTEM\NTHJ32.EXE /s

O4 - HKLM\..\RunServices: [WINCI32.EXE] C:\WINDOWS\WINCI32.EXE /s

O4 - HKLM\..\RunServices: [APIRS32.EXE] C:\WINDOWS\APIRS32.EXE /s

O4 - HKLM\..\RunServices: [D3CJ.EXE] C:\WINDOWS\D3CJ.EXE /s

O4 - HKLM\..\RunServices: [IETX.EXE] C:\WINDOWS\SYSTEM\IETX.EXE /s

O4 - HKLM\..\RunServices: [IEAA32.EXE] C:\WINDOWS\IEAA32.EXE /s

O4 - HKLM\..\RunServices: [ATLIJ32.EXE] C:\WINDOWS\SYSTEM\ATLIJ32.EXE /s

O4 - HKLM\..\RunServices: [CRRN32.EXE] C:\WINDOWS\CRRN32.EXE /s

O4 - HKLM\..\RunServices: [NETZQ32.EXE] C:\WINDOWS\SYSTEM\NETZQ32.EXE /s

O4 - HKLM\..\RunServices: [ADDRR32.EXE] C:\WINDOWS\SYSTEM\ADDRR32.EXE /s

O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusear...?p=ZNxdm414XXUS

O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)

O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab

O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/min...ransporter.cab?


DL http://www.downloads.subratam.org/KillBox.zip

Restart your computer into safe mode now. (Tapping F8 at the first black screen) Perform the following steps in safe mode:

Double-click on Killbox.exe to run it. Now put a tick by Standard File Kill. In the "Full Path of File to Delete" box, copy and paste each of the following lines one at a time then click on the button that has the red circle with the X in the middle after you enter each file. It will ask for confimation to delete the file. Click Yes. Continue with that same procedure until you have copied and pasted all of these in the "Paste Full Path of File to Delete" box.

c:\counter.cab

C:\WINDOWS\system\cqeqj.dll

C:\WINDOWS\APIEG32.DLL

C:\WINDOWS\SYSTEM\WINIV.EXE

C:\WINDOWS\CRNQ.EXE /s

C:\WINDOWS\SYSTEM\WINXB32.EXE /s

C:\WINDOWS\SYSTEM\MSRH.EXE /s

C:\WINDOWS\SYSTEM\APPBQ32.EXE /s

C:\WINDOWS\SYSTEM\ATLWV.EXE /s

C:\WINDOWS\SYSTEM\NTHJ32.EXE /s

C:\WINDOWS\WINCI32.EXE /s

C:\WINDOWS\APIRS32.EXE /s

C:\WINDOWS\D3CJ.EXE /s

C:\WINDOWS\SYSTEM\IETX.EXE /s

C:\WINDOWS\IEAA32.EXE /s

C:\WINDOWS\SYSTEM\ATLIJ32.EXE /s

C:\WINDOWS\CRRN32.EXE /s

C:\WINDOWS\SYSTEM\NETZQ32.EXE /s

C:\WINDOWS\SYSTEM\ADDRR32.EXE /s

Note: It is possible that Killbox will tell you that one or more files do not exist. If that happens, just continue on with all the files. Be sure you don't miss any.

Exit the Killbox.

Open Windows Explorer. Go to Tools, Folder Options and click on the View tab.
Make sure that "Show hidden files and folders" is checked.
Now click "Apply to all folders", Click "Apply" then "OK"

Delete these folders



START – RUN – type in %temp% OK - Edit – Select all – File – Delete
Delete everything in the C:\Windows\Temp folder or C:\WINNT\temp
Empty the recycle bin

Run CWS and About:buster again
Boot and post a new log

Please give feedback on what worked/didn’t work and the current status of your system
 

pandora_6666

Thread Starter
Joined
Jul 11, 2005
Messages
31
Well, I did as you suggested. Kill Box could not find any of the files that had the /s after them. i restarted, reset the homepage...... and still had about:blank :( Also, still have the pop ups. here is the new hijack log:

Logfile of HijackThis v1.99.1
Scan saved at 12:20:04 AM, on 7/14/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\MFCRF.EXE
C:\WINDOWS\MSZK32.EXE
C:\WINDOWS\SYSTEM\ADDSR32.EXE
C:\WINDOWS\SYSUJ.EXE
C:\WINDOWS\SYSTEM\WINXB32.EXE
C:\WINDOWS\IPQK32.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\LEXPPS.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\JAVAMG32.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\MICROCORE\DIALER.EXE
C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\hkfhs.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\hkfhs.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system\hkfhs.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\hkfhs.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\hkfhs.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\hkfhs.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\hkfhs.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Joey Loves Charles
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O2 - BHO: Class - {75B6C7E6-9911-FE7D-F3E4-78BCBDB3681A} - C:\WINDOWS\SYSTEM\IPSU32.DLL
O2 - BHO: Class - {3DCC181A-7DEF-24B0-6C35-70B9122CAEAB} - C:\WINDOWS\SYSFN32.DLL
O2 - BHO: Class - {1267B80D-1183-D8F5-834A-13C4038C9320} - C:\WINDOWS\IPCY32.DLL
O2 - BHO: Class - {E5CE2C16-61AF-05AF-A2FE-3BCC78E1789C} - C:\WINDOWS\SYSTEM\D3WD32.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [D3LQ32.EXE] C:\WINDOWS\D3LQ32.EXE
O4 - HKLM\..\Run: [JAVAMG32.EXE] C:\WINDOWS\SYSTEM\JAVAMG32.EXE
O4 - HKLM\..\RunServices: [MFCRF.EXE] C:\WINDOWS\MFCRF.EXE /s
O4 - HKLM\..\RunServices: [MSZK32.EXE] C:\WINDOWS\MSZK32.EXE /s
O4 - HKLM\..\RunServices: [ADDSR32.EXE] C:\WINDOWS\SYSTEM\ADDSR32.EXE /s
O4 - HKLM\..\RunServices: [SYSUJ.EXE] C:\WINDOWS\SYSUJ.EXE /s
O4 - HKLM\..\RunServices: [WINXB32.EXE] C:\WINDOWS\SYSTEM\WINXB32.EXE /s
O4 - HKLM\..\RunServices: [IPQK32.EXE] C:\WINDOWS\IPQK32.EXE /s
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\PROGRAM FILES\ATI MULTIMEDIA\TV\EXPLBAR.DLL
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0521.DLL
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0521.DLL
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab

Thanks,
Jo
 
Joined
Sep 7, 2004
Messages
49,014
Run CWS again

Fix these with HJT – mark them, close IE, click fix checked

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\hkfhs.dll/sp.html#37049

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\hkfhs.dll/sp.html#37049

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system\hkfhs.dll/sp.html#37049

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\hkfhs.dll/sp.html#37049

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\hkfhs.dll/sp.html#37049

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\hkfhs.dll/sp.html#37049

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\hkfhs.dll/sp.html#37049

O2 - BHO: Class - {75B6C7E6-9911-FE7D-F3E4-78BCBDB3681A} - C:\WINDOWS\SYSTEM\IPSU32.DLL

O2 - BHO: Class - {3DCC181A-7DEF-24B0-6C35-70B9122CAEAB} - C:\WINDOWS\SYSFN32.DLL

O2 - BHO: Class - {1267B80D-1183-D8F5-834A-13C4038C9320} - C:\WINDOWS\IPCY32.DLL

O2 - BHO: Class - {E5CE2C16-61AF-05AF-A2FE-3BCC78E1789C} - C:\WINDOWS\SYSTEM\D3WD32.DLL

O4 - HKLM\..\Run: [D3LQ32.EXE] C:\WINDOWS\D3LQ32.EXE

O4 - HKLM\..\Run: [JAVAMG32.EXE] C:\WINDOWS\SYSTEM\JAVAMG32.EXE

O4 - HKLM\..\RunServices: [MFCRF.EXE] C:\WINDOWS\MFCRF.EXE /s

O4 - HKLM\..\RunServices: [MSZK32.EXE] C:\WINDOWS\MSZK32.EXE /s

O4 - HKLM\..\RunServices: [ADDSR32.EXE] C:\WINDOWS\SYSTEM\ADDSR32.EXE /s

O4 - HKLM\..\RunServices: [SYSUJ.EXE] C:\WINDOWS\SYSUJ.EXE /s

O4 - HKLM\..\RunServices: [WINXB32.EXE] C:\WINDOWS\SYSTEM\WINXB32.EXE /s

O4 - HKLM\..\RunServices: [IPQK32.EXE] C:\WINDOWS\IPQK32.EXE /s

Restart your computer into safe mode now. (Tapping F8 at the first black screen) Perform the following steps in safe mode:

Double-click on Killbox.exe to run it. Now put a tick by Standard File Kill. In the "Full Path of File to Delete" box, copy and paste each of the following lines one at a time then click on the button that has the red circle with the X in the middle after you enter each file. It will ask for confimation to delete the file. Click Yes. Continue with that same procedure until you have copied and pasted all of these in the "Paste Full Path of File to Delete" box.

C:\WINDOWS\system\hkfhs.dll
C:\WINDOWS\SYSTEM\IPSU32.DLL
C:\WINDOWS\SYSFN32.DLL
C:\WINDOWS\IPCY32.DLL
C:\WINDOWS\SYSTEM\D3WD32.DLL
C:\WINDOWS\D3LQ32.EXE
C:\WINDOWS\SYSTEM\JAVAMG32.EXE
C:\WINDOWS\MFCRF.EXE
C:\WINDOWS\MSZK32.EXE
C:\WINDOWS\SYSTEM\ADDSR32.EXE
C:\WINDOWS\SYSUJ.EXE
C:\WINDOWS\SYSTEM\WINXB32.EXE
C:\WINDOWS\IPQK32.EXE

Note: It is possible that Killbox will tell you that one or more files do not exist. If that happens, just continue on with all the files. Be sure you don't miss any.

Exit the Killbox.


START – RUN – type in %temp% OK - Edit – Select all – File – Delete
Delete everything in the C:\Windows\Temp folder or C:\WINNT\temp
Empty the recycle bin
Boot

Run ActiveScan online virus scan

http://www.pandasoftware.com/activescan/

When the scan is finished, anything that it cannot clean have it delete it. Make a note of the file location of anything that cannot be deleted so you can delete it yourself.
- Save the results from the scan!

Post a new HiJackThis log along with the results from ActiveScan


Please give feedback on what worked/didn’t work and the current status of your system
 
Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

Users Who Are Viewing This Thread (Users: 0, Guests: 1)

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 807,865 other people just like you!

Latest posts

Staff online

Members online

Top