*C:\WINDOWS\system32\msblank.html* need help fixing

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by nv178177, Aug 31, 2005.

  1. nv178177

    nv178177 Private E-2

    My internet explorer homepage is set to this link "C:\WINDOWS\system32\msblank.html"

    I can't reset my homepage to where it was.

    Also, I have this toolbar that just popped up and I can't remove it. I ran spybot s&d and removed all the existing spyware, but that toolbar is still there and my homepage is still at that location.

    Could someone please help me fix this problem?

    Thank you.
     
  2. nv178177

    nv178177 Private E-2

    Thank you for responding. I've ran all the spyware detections and it is still on my toolbar, and I still get the same homepage. I have attached my HJT log file.

    Thank you again for your help.
     

    Attached Files:

  3. nv178177

    nv178177 Private E-2

    I think that took care of it. The toolbar is gone and my homepage is reset back to the default. If there's anything else I need to get rid of or clean, please let me know.

    Thank you so much for your help.
     

    Attached Files:

  4. nv178177

    nv178177 Private E-2

    I think I still have a problem. My AV keeps detecting a virus named "hclean32.exe." Is there something I need to do to remove it permanently?
     
  5. nv178177

    nv178177 Private E-2

    Yes I did disable system restore. It's detecting it in C:\Windows\System32. I did uninstall Wareout. Or at least I thought I did. I don't see it in the add/remove programs.
     
  6. nv178177

    nv178177 Private E-2

    Ok. Here you go.
     

    Attached Files:

  7. nv178177

    nv178177 Private E-2

    I didn't mention this earlier, but I also deleted these three files: winctrl16.exe, winctrl32.exe, and winctrl64.exe.

    Do i need these files?
     
  8. nv178177

    nv178177 Private E-2

    I just ran Spybot and it found "Smitfraud", but it can't fix it. I tried to restart and then run spybot like it asked, but it was still unable to fix the problems.
     
  9. nv178177

    nv178177 Private E-2

    D3? R u still there?
     
  10. nv178177

    nv178177 Private E-2

    Thanks for responding. I still do appreciate your help. I

    I have installed and ran the program you suggested. It cleaned 79 problems. I haven't encountered any problems in about 10 minutes, but I'll be certain to tell you if something comes up.

    Here's the report.

    Thank you again.
     

    Attached Files:

  11. nv178177

    nv178177 Private E-2

    My AV just spotted again the hclean.exe at 8:12 CDT. The ewid also came up and I cleaned the infected files.
    I was getting some pop-ups that stated something about my spyware detection was bad, and if I wanted to learn how to get rid of it. One came on my desktop/screen, and one was in my taskbar (bottom right). I haven't seen those yet since the ewid scan, but I'll keep you updated.

    Thanks
     
  12. nv178177

    nv178177 Private E-2

    This isn't the popups, but my AV now detected a Trojan Horse "A0088507.exe" in the "C:\System Volume Information\restore{5B942C52-3EC6-4393-ADAF-2DA421A20CCE}\RP339\"

    Ewid did not see it, I guess, because I didn't get the option to remove it with ewid.
     
  13. nv178177

    nv178177 Private E-2

    I can't find the system restore tab. I right clicked on My Computer,but there is no system restore tab.
     
  14. nv178177

    nv178177 Private E-2

    It says computer administrator next to my name.
     
  15. nv178177

    nv178177 Private E-2

    Okay, I've tried booting in safe mode, and it still does not appear. Is there another way to get there?
     
  16. nv178177

    nv178177 Private E-2

    I tried to copy and paste, but I got an error when I tried to double click and merge it. It said the specified file is not a registry script.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Add a line at the top of the file that says:

    REGEDIT4

    Then you should be able to merge it into the registry!
     
  18. nv178177

    nv178177 Private E-2

    Ok that worked. Now what should I do?
     
  19. nv178177

    nv178177 Private E-2

    Here's the new HJT log. It hasn't been going to the about:blank. The problem has been my AV has been finding a Trojan virus "hclean.exe" in my system restore everytime I open mozilla browser, and I can't disable system restore, even though I have admin rights.

    I entered the reg file, but I still don't see the option to disable system restore.

    Thanks for the help.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not attach your log!

    Trying to keep you moving along so you have a log here for D3 when he returns.
     
  21. nv178177

    nv178177 Private E-2

    DOH!
    Thanks,
     

    Attached Files:

  22. nv178177

    nv178177 Private E-2

    d3? Should I post another hjt log?
     
  23. nv178177

    nv178177 Private E-2

    No. I don't see a system restore tab at all.
     
  24. nv178177

    nv178177 Private E-2

    I went to HKEY_LOCAL_MACHINE/SOFTWARE/POLICIES/MICROSOFT/WINDOWSNT... but there's no systemrestore. And that's the only place that has the SOFTWARE/...WINDOWSNT.
     
  25. nv178177

    nv178177 Private E-2

    Any other suggestions?
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds