about:blank --> http://www.securityuptodate.net/

Discussion in 'Malware Help (A Specialist Will Reply)' started by PM15071, May 27, 2006.

  1. PM15071

    PM15071 Private E-2

    Got something on the system that prevents me from changing the Home Page from 'about:blank'. It always goes to 'http://www.securityuptodate.net/'.

    I booted to Safe Mode and then ran AdAware, SpyBot and the McAfee AntiVirus. This removed some things but the problem was still there when I booted normally.

    Any assistance as to how to get this crap off this machine will be most appreciated.

    Win XP SP2 on a Dell 4550.

    On a side note, after installeing SP2 I can no longer use the 'Switch User' function - any help with this would be great too!!!

    Thanks in advance.......
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  3. PM15071

    PM15071 Private E-2

    Ok - ran the steps in this Sticky thread READ & RUN ME FIRST.

    Some problems were detected and deleted by BitDefender.
    PandaScan found some issues but did nothing with them.
    Logs from these two and from HiJackThis are attached.

    I still have the about:blank problem.

    Thanks for your assistance.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay what you need to do now is run the below because that is part of what you have:

    SpywareQuake & SpyFalcon Removal Procedure

    Afterwards, attach the requested smitfiles.txt log and also attach a new HJT log.
     
  5. PM15071

    PM15071 Private E-2

    Hi chaslang,

    It looks like that did the trick.
    I found and deleted only -dxole32.exe- from the list of files in your instructions.
    I do not see the Browser HiJack or the about:blank after that last procedure.

    Here are the logs.

    Thanks again for your assistance!!!
     

    Attached Files:

    Last edited: May 29, 2006
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We have a little more cleanup to do.

    First please install HijackThis properly as per step 7 of the READ ME. You installed it exactly where step 7 specifies not to install it (that is on you Desktop and in C:\Documents and Settings).

    Also the READ ME does specify not to use Spybot's Teatimer (at least not while doing cleanup since it gets in the way). However you have some other reasons not to use Teatimer. You have SpywareGuard, TrendMicro Antispyware, and Teatimer all running. This will cause a significant drain on system resources which slows your PC down and can cause conflicts.

    Is your copy of Trend Micro a paid version?

    Disable/shutdown Teatimer and Trend Micro Antispyware and then run HijackThis and select the below lines and then exit ALL browsers before click Fix Checked:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost;
    O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
    O9 - Extra button: (no name) - {9239E4EC-C9A6-11D2-A844-00C04F68D538} - (no file)
    O16 - DPF: {8E28B3A9-FE83-45D1-B657-D5426B81A121} - http://cs5b.instantservice.com/jars/customerxsigned35.cab
    O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/1435/ftp.coupons.com/v3122/cpbrkpie.cab
    O16 - DPF: {C6B086D2-146B-47A4-A218-B82DCAF2D872} (cpbrxpie Control) - http://a19.g.akamai.net/7/19/7125/4007/ftp.coupons.com/r3120/cpbrxpie.cab
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://innovativesystems.webex.com/client/v_mywebex/webex/ieatgpc.cab

    Now exit HijackThis. Reboot and then attach a new HJT log.
     
  7. PM15071

    PM15071 Private E-2

    Hi chaslang,

    HiJackThis is running from c:\SpyWare.

    Teatimer and TrendMicro Antispyware have been disabled.

    Trend Micro is the free 30 day version.

    The lines you specified from HiJackThis were selected and then Fix Checked was clicked on.

    Rebooted and a new HiJackThis is attached as requested.

    Thanks.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    One of the lines did not get fixed:

    O9 - Extra button: (no name) - {9239E4EC-C9A6-11D2-A844-00C04F68D538} - (no file)


    Try again and make sure it gets fixed. If it does not fix, temporarily disable Windows Defender's active (realtime) protection and the fix the line. Windows Defender may be blocking the fix.

    Just let me know if you get that line fixed.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds