About:blank homepage & Trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by Cheryl1980, Jun 11, 2006.

  1. Cheryl1980

    Cheryl1980 Private E-2

    New to the site, kind of, used to get on a few years ago and got such useful help that I had to come back again. I am basically needing to get rid of a trojan and this about:blank that keeps setting my home page. I have downloaded and ran:

    1) AVG Free
    2) Spybot - Search and Destroy
    3) CC Cleaner
    4) Remove It Pro ST-XE

    Some things have been removed, but not all and that is why I am posting for help.

    Now, I know there are several other things that I should probably download and do but I have been through so many of the exact same things being said over and over again in the FAQs that my mind is going numb. I know when I was on the site before, someone had me download a hijack this thing and then post what turned up but I can't find a link for hijack this on this site. Any help at all would be appreciated.

    Thanks,
    Cheryl
     
  2. Cheryl1980

    Cheryl1980 Private E-2

    I should make it clear that some things simply won't download and work on my computer, such as hijack this won't unzip, spybot search and destroy automatically closes when trying to scan, defender won't work because my computer won't let me verify my Windows through the site because it says that something is blocking it, etc. I have done as much as I can do in READ ME.
     
  3. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    This is the exe for HijackThis; Save it to C:\Program Files\HJT.

    HijackThis
     
  4. Cheryl1980

    Cheryl1980 Private E-2

    Tried to run your link and it popped up saying I couldn't proceed cause it was infected with "W32\generic.worm!p2p"..........now what?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your McAfee antivirus definitions are way out of date and they are wrong. The file is not infected. Either update McAfee or disable it.
     
  6. Cheryl1980

    Cheryl1980 Private E-2

    ok, how do I disable McAfee?
     
  7. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Update your definitions or right-click on the McAfee icon in the System Tray and disable it.
     
  8. Cheryl1980

    Cheryl1980 Private E-2

    Ok, here goes.....(see attachment)
     

    Attached Files:

  9. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    You did not save HijackThis to the location I specified. If you can not download stuff with your computer, then download from another computer and save the files to a CD or Thumb drive. Then transfer the files to your computer. I is very important to get HijackThis saved where I specified. Your HijackThis log shows some infections we need to deal with.
     
  10. Cheryl1980

    Cheryl1980 Private E-2

    okay, hope this is right
     

    Attached Files:

  11. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    The installed version of Java on this compter is out-dated. Install version 1.5.0_07 available from http://www.java.com/en/download/manual.jsp. Make sure you uninstall all older versions that are on your computer before installing the latest version of Java.

    You are running 2 Resident Antvirus applications. You only need 1. Having more that 1 resident Antivirus application on your computer will cause problems. They will interfer with each of and create conflicts, causing system performance to suffer. Pick one uninstall the other

    HijackThis is still not in the location I specified. Right-click on the underlined text and Save Link as to your Desktop. Move_HijackThis.vbs

    Double-click Move_HijackThis.vbs on your Desktop. This script will move HijackThis to the proper location. DO THIS before you continue with my instructions.

    Running processes:
    C:\WINDOWS\SYSTEM32\SOL.EXE <<=== This is the Microsoft Solitaire Game. This should not be open while running HijackThis.
    C:\Program Files\Internet Explorer\iexplore.exe <<=== Internet Explorer should not be open while running HijackThis.

    Make sure you have closed all browser windows, all sessions of Windows Explorer and any other programs you may have open before running HijackThis.

    Download
    - Pocket Killbox

    Now Run HijackThis. Click the 'Do a system scan only' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click the RED X.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open Windows Explorer navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Post a fresh HijackThis log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds