Honest, I tried.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by WorkHelp, Jun 9, 2004.

  1. WorkHelp

    WorkHelp Private E-2

    One of our computers here seems to be infected with whatever produces the homepage about:blank search engine and will not go away. I've run ad aware, spybot, spydoctor and attempted to download Spywareblaster, but I was told the program had an error and I couldn't reinstall it so that the error went away. Below is the HijackThis log for the computer. I've read through some of the threads here and also did a google search on about:blank. I don't know enough to fix anything further and was hoping someone could help, please. :) Also to note, every time I run Spybot it seems to find the same problems, I tell it to fix the problems, but every new scan they pop up again. Thank you in advance for any help! And I apologize for the length of it, I didn't want to remove anything that I wasn't sure was important.

    Logfile of HijackThis v1.97.7
    Scan saved at 2:11:57 PM, on 6/9/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\hkcmd.exe
    C:\Program Files\Dell\Media Experience\PCMService.exe
    C:\Program Files\Common Files\Dell\EUSW\Support.exe
    C:\Program Files\CasinoOnline\CsRemnd.exe
    C:\Documents and Settings\PDaddy\My Documents\PRINTKEY.EXE
    C:\Documents and Settings\PDaddy\Desktop\HijackThis.exe
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\cknfpfa.dll/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\cknfpfa.dll/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\cknfpfa.dll/sp.html (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\cknfpfa.dll/sp.html (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\cknfpfa.dll/sp.html (obfuscated)
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\cknfpfa.dll/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {76E719F6-1F9A-4244-97BF-29C1AFDB1CE1} - C:\WINDOWS\System32\cknfpfa.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
    O4 - HKLM\..\Run: [Remndr] "C:\Program Files\CasinoOnline\CsRemnd.exe"
    O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\spydoctor.exe" /Q
    O4 - HKLM\..\RunOnce: [Index Washer] C:\Program Files\Webroot\Washer\WashIdx.exe "PDaddy"
    O4 - HKCU\..\RunOnce: [Index Washer] C:\Program Files\Webroot\Washer\WashIdx.exe "PDaddy"
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: PRINTKEY.lnk = C:\Documents and Settings\PDaddy\My Documents\PRINTKEY.EXE
    O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
    O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Messenger (HKLM)
    O13 - DefaultPrefix:
    O13 - WWW Prefix:
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/148119a2571ca3/housecall.antivirus.com/housecall/xscan53.cab
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to MG's WorkHelp,

    Are your versions of Ad-aware and SpyBot up to date. They have made changes recently and Ad-aware is trying to deal with the about:blank problem.
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\cknfpfa.dll/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\cknfpfa.dll/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\cknfpfa.dll/sp.html (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\cknfpfa.dll/sp.html (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\cknfpfa.dll/sp.html (obfuscated)
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\cknfpfa.dll/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {76E719F6-1F9A-4244-97BF-29C1AFDB1CE1} - C:\WINDOWS\System32\cknfpfa.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

    O4 - HKLM\..\Run: [Remndr] "C:\Program Files\CasinoOnline\CsRemnd.exe"

    If you do not know how to boot in safe mode go here: http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406
    Then reboot into safe mode and search for and delete these files. They should be in c:\windows\system32 according to the HijaakThis log.
    cknfpfa.dll
    sp.html

    And also delete this folder:
    C:\Program Files\CasinoOnline

    Now reset your web settings. If you do not know how to do this, go here:
    http://www.pestpatrol.com/Support/H...ar_a_Hijack.asp
    and under the Search Hijacks section see the info on "Reset Web Settings".
    Now reboot in normal mode and let us know the results.
     
  3. WorkHelp

    WorkHelp Private E-2

    Hello and thank you. It's getting late here so I will attempt what you suggest tomorrow morning. Ad Aware and SpyBot should be up to date as I just d/l'd them today and have them set to search for updates, but I will be sure to double check. Thank you again, I will post after attempting this tomorrow morning.
     
  4. WorkHelp

    WorkHelp Private E-2

    I did as suggested and explorer is so far no longer popping up with about:blank. It currently has msn as the homepage rebooting in normal mode. I was able to locate and delete the casino program file and the cknfpfa.dll files in safe mode, but did not find the sp.html file, instead a search showed a few other files which I left alone. I also reran ad aware and spybot before attempting to open IE explorer, they both found new problems which I had them fix and then rebooted again. Below is the new hijack this log, I still see the casino online program and the cknfpfa.dll. Should I ask HijackThis to fix anything, even though I'm not getting the about:blank homepage anymore?


    Logfile of HijackThis v1.97.7
    Scan saved at 10:54:07 AM, on 6/10/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\hkcmd.exe
    C:\Program Files\Dell\Media Experience\PCMService.exe
    C:\Program Files\Common Files\Dell\EUSW\Support.exe
    C:\Documents and Settings\PDaddy\My Documents\PRINTKEY.EXE
    C:\Documents and Settings\PDaddy\Desktop\Spyware Blockers\HijackThis.exe
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\cknfpfa.dll/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\cknfpfa.dll/sp.html (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\cknfpfa.dll/sp.html (obfuscated)
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {76E719F6-1F9A-4244-97BF-29C1AFDB1CE1} - C:\WINDOWS\System32\cknfpfa.dll (file missing)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
    O4 - HKLM\..\Run: [Remndr] "C:\Program Files\CasinoOnline\CsRemnd.exe"
    O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\spydoctor.exe" /Q
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: PRINTKEY.lnk = C:\Documents and Settings\PDaddy\My Documents\PRINTKEY.EXE
    O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
    O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Messenger (HKLM)
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/148119a2571ca3/housecall.antivirus.com/housecall/xscan53.cab


    Again, thanks for the help, was nice to see that damn about:blank homepage go away. :)
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looking better but we need to find out why this cknfpfa.dll stuff and CasinoOnline came back.
    Download and run CrapCleaner and let it clean up all stuff it has selected by default on the Windows Tab. Download it here: http://www.majorgeeks.com/download4191.html

    Now download and run CWShredder from here: http://www.majorgeeks.com/download4086.html
    Let it fix anything it finds.

    Also download and run CoolWWWSearch.SmartKiller from here: http://www.majorgeeks.com/download4113.html

    Now shutdown all applications (especially broswers) run HijaakThis and have it fix the following lines:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\cknfpfa.dll/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\cknfpfa.dll/sp.html (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\cknfpfa.dll/sp.html (obfuscated)
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {76E719F6-1F9A-4244-97BF-29C1AFDB1CE1} - C:\WINDOWS\System32\cknfpfa.dll (file missing)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O4 - HKLM\..\Run: [Remndr] "C:\Program Files\CasinoOnline\CsRemnd.exe"

    Now boot in safe mode again and double check that the stuff we removed the last time is gone:
    This file:
    C:\WINDOWS\System32\cknfpfa.dll

    And also delete this folder:
    C:\Program Files\CasinoOnline

    While in safe mode run Ad-aware and SpyBot again and let them clean what they find.

    Reboot normal and before accessing the internet get a Hijaak This log. Then access the internet again and close down all browsers and run Hijaak This again and see if anything has changed in the log.
     
  6. WorkHelp

    WorkHelp Private E-2

    Ok it got worse. I wasn't about to get to the steps in the last post till today, as it was a very busy week. This time I was walking by my coworker's desk and it looked like the spyware was breeding. I ran adaware again, crap cleaner, CWShredder and SpyBot. Adaware found about 159 things. There was a power search toolbar installed into the browser and a few other programs I've already deleted. I ran HijackThis, after following the steps in the above post as instructed, both before and after opening IE. The only difference I spotted was that IE was now listed as being used. Here is the resulting log:

    Logfile of HijackThis v1.97.7
    Scan saved at 10:29:35 AM, on 6/21/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\hkcmd.exe
    C:\Program Files\Dell\Media Experience\PCMService.exe
    C:\Program Files\Common Files\Dell\EUSW\Support.exe
    C:\documents and settings\pdaddy\local settings\temp\XJbg0D.exe
    C:\WINDOWS\System32\dx72c.exe
    C:\Program Files\MProcessor\mprocessor.exe
    C:\WINDOWS\System32\eqnocx.exe
    C:\Documents and Settings\PDaddy\My Documents\PRINTKEY.EXE
    C:\WINDOWS\System32\Fnx374f8.exe
    C:\WINDOWS\System32\KgnJ8U3.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\PDaddy\Desktop\Spyware Blockers\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\PDaddy\LOCALS~1\Temp\sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\PDaddy\LOCALS~1\Temp\sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\PDaddy\LOCALS~1\Temp\sp.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\PDaddy\LOCALS~1\Temp\sp.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\PDaddy\LOCALS~1\Temp\sp.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\PDaddy\LOCALS~1\Temp\sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {25CD09A7-513B-4586-94BC-56D451FDCEB2} - C:\WINDOWS\System32\lebfhia.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\Program Files\SEP\sep.dll
    O3 - Toolbar: PowerSearch - {4E7BD74F-2B8D-469E-D6F5-F66EA787AD2D} - C:\PROGRA~1\POWERS~1\Toolbar\pwrsbikd.dll (file missing)
    O3 - Toolbar: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\Program Files\SEP\sep.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
    O4 - HKLM\..\Run: [XJbg0D] C:\documents and settings\pdaddy\local settings\temp\XJbg0D.exe
    O4 - HKLM\..\Run: [Dsi] C:\WINDOWS\System32\dp-him.exe
    O4 - HKLM\..\Run: [2LRX2W83X2T3MQ] C:\WINDOWS\System32\Ahm8.exe
    O4 - HKLM\..\Run: [v73k37S] dx72c.exe
    O4 - HKCU\..\Run: [MProcessor] "C:\Program Files\\MProcessor\mprocessor.exe"
    O4 - HKCU\..\Run: [ewsqRXe9R] eqnocx.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: PRINTKEY.lnk = C:\Documents and Settings\PDaddy\My Documents\PRINTKEY.EXE
    O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
    O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
    O9 - Extra 'Tools' menuitem: MaxSpeed (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Messenger (HKLM)
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/148119a2571ca3/housecall.antivirus.com/housecall/xscan53.cab



    Again thanks for the help and advice on this, it's greatly appreciated. I'm curious though, is this stuff likely to be propagating itself or is it likely someone's surfing or clicking to get this stuff added on?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Until you get the proper protection on your systems this will keep happening. You need:
    1. a firewall. Check out http://www.majorgeeks.com/download3356.html or http://www.majorgeeks.com/download738.html
    2. a full virus scan/protection program. For home use see: http://www.majorgeeks.com/download1968.html For work use see: http://www.majorgeeks.com/download3314.html
    3. a spyware blocker program: http://www.majorgeeks.com/download2859.html
    You log is getting worse again. We have more work to do again. I'll have to get back to you later.
     
  8. WorkHelp

    WorkHelp Private E-2

    Yes, it's gotten much worse. Now there are multiple programs seemingly installing themselves. WhenUSearch/Powersearch tool bar, clock sync. Thanks for your help...do you get paid to do this? You should. :p I'll work on the options you just posted.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Paid! LOL! If I could find a job doing this, I think I would! There would be plenty of full time work. That's for sure. It could get crazy after awhile but that's what my current job has become too.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  11. WorkHelp

    WorkHelp Private E-2

    lol, yeah, you'd never run out of work there. So does any of this relate to your current job or were you mistreated by Spyware as a child and are now on a crusade? (Just curious as to how you may have gotten into this and learned so much about it, if you don't mind me asking of course)
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    LOL! No it does not relate at all to my current job. I do use lots of PC and Sun Workstations in my job (research & development). I guess you could consider it a crusade (lol). Just trying to help as much as possible. I like helping and enjoy playing around with PC's and programming. The kind of work that I do is very technical and my actual job function requires me to dig in and find the root causes of problems so we can get them fixed. So I guess I'm just applying that methodology here.
     
  13. WorkHelp

    WorkHelp Private E-2

    I'm working on this right now, but I'm running into a problem with Spyware Blaster 3.1, when I try to run it I get this error message:

    The program has been damaged, possibly by a bad sector of the hard drive or a virus, please reinstall it.

    Any suggestions?
     
  14. WorkHelp

    WorkHelp Private E-2

    Okey doke. Tried running the sygate scan and even though I turned off the firewall the second time around, it still gave me the message that you've blocked all our ports. Also tried doing the second scan link at Trend Micro and IE gave me an error and shut down. I also ran the peper trojan cleaner which I'm assuming worked, but I didn't get any messages other than watching it install. Let me know if I might have done anything wrong, thank you for your help.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is this the same error wth Spy Blaster you were talking about in your first message?
    If so do you mean the error occurs, when you are downloading the file, or when you try to install Spy Blaster, or when you try to run it. You have said different things in each message.

    Run an error check on you hard disk to see if there are any problems with it.
    Also delete whatever downloaded installation file you have for Spy Blaster 3.1 and download a copy from here: http://www.majorgeeks.com/download2859.html

    If it is already installed, uninstall it. And then reboot and install the version downloaded from MG's.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have the Win XP firewall turned on or do you have an external hardware firewall in a router?

    What was the IE error message?

    To see if the Peper Trojan cleaner had any effect, you will have to give me another Hijaak This log.

    Are you still having about blank problems?
     
  17. charco

    charco Private E-2

    Chaslang - I guess this is a pretty stupid question but how do I start a new thread?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click the Icon/Button near the top left side of the page that says New Thread. It shows when you have entered any forum but have not entered a thread. Once in a thread, this button becomes Post Reply.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds