about:blank new case

Discussion in 'Malware Help (A Specialist Will Reply)' started by ben-g, Jan 7, 2005.

  1. ben-g

    ben-g Private E-2

    Hi there,
    I have some infection/hijacking problems lately. My home page is hijacked with "about:blank trusted trusted start page". And I know that more people have had this problem, but with there messages I was not able to get rid of it!

    First I tried to do what is explained on: Read this first: http://forums.majorgeeks.com/showthread.php?t=35407
    But all the online and free scans didn't work. Well as a matter of fact, it became worst after running the online checks in the safe mode (there's no firewall in my safe mode!!!). I found a lot of virusses with the scans, but my home page stays hijacked. After the scans I got the elitumElitebar as well, which is found by spybot S&D, but can't be deleted.

    Is there any one who would like to help me get rid of my infections and hijacks? I can post a hijackThis log. I hope so, please let me know!

    See ya, Ben-G
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well I would not say the online scans did not work, they did find a lot of viruses which is one of the reasons we want you to run them. All of recommended steps/scans may not always fix the exact problem you have. However, they do typically find additional problems (like in your case) that require fixing which will max the additional cleanup steps .go smoother.

    If you have performed all the steps of the READ ME FIRST and you still have a problem, follow the guidelines below and post your HJT log.

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. ben-g

    ben-g Private E-2

    Yeah, I did run Hijack this, see attachment. I hope you guys can see what's wrong with my computer, becoz I dont understand much of the log file... :rolleyes:

    OK, thanks in advance for watching the log file, and I hope to find out how to get rid of this brutal hijack. Is this Hijacking legal any ways? Cant I sue someone for this???

    See ya!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have two antivirus applications installed and running. You must choose one and uninstall the other. They will conflict with each other and will eat up valuable system resources.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).


    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    D:\WINDOWS\System32\evosys.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    Did you want your start page to be set to about:blank? If so, skip the next two lines. Otherwise fix them and set your home page manually in Windows Explorer.
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    O4 - HKLM\..\Run: [blah service] evosys.exe
    O4 - HKLM\..\RunServices: [Microsoft Windows W32 Services] mssw32.exe
    O4 - HKLM\..\RunServices: [Windows Media Player] msams.exe
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [blah service] evosys.exe
    O23 - Service: Win32 USB2.0 Driver - Unknown - D:\WINDOWS\System32\w32usb2.exe (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    D:\WINDOWS\System32\evosys.exe
    D:\WINDOWS\System32\mssw32.exe
    D:\WINDOWS\System32\msams.exe

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  5. ben-g

    ben-g Private E-2

    OK, I tried to follow your instructions, but not everything worked. Maybe, first I'll have to give a little background info on the situation: I have Windows XP, and my problems is that my home page is hijacked. Every time I change my home page settings, it switch back to about:blank. It means that some kind of startpage is started. Next to this problem (or maybe it is the same) my Spybot S&D finds ElitumElite, but can't fix it.

    Right, I 've followed your instructions and in Hijackthis I killed

    D:\WINDOWS\System32\evosys.exe

    Then I fixed in HJT the following

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    O4 - HKLM\..\Run: [blah service] evosys.exe
    O4 - HKLM\..\RunServices: [Microsoft Windows W32 Services] mssw32.exe
    O4 - HKLM\..\RunServices: [Windows Media Player] msams.exe
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [blah service] evosys.exe
    O23 - Service: Win32 USB2.0 Driver - Unknown - D:\WINDOWS\System32\w32usb2.exe (file missing)

    Then, in the safemode I deleted

    D:\WINDOWS\System32\evosys.exe

    but I couldn't find

    D:\WINDOWS\System32\mssw32.exe
    D:\WINDOWS\System32\msams.exe

    So I couldn't delete those. I attachted a new log file. I hope you can find something in there? Thanks in advance!

    Ben-G
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I want you to do something to check you Virus application out:

    Start Norton AntiVirus from “Start \ Programs \ Norton AntiVirus”. If Norton AntiVirus comes up without problems, then you are probably okay and the BootWarn.exe entry in your HJT can be fixed.
    It was left behind by mistake and is no longer needed now that Norton AntiVirus is fully installed and opens without error messages (you don't get any error messages do you)?

    Do you have SpywareBlaster or any other programs installed that may be blocking your home page from being changed?

    Try this:

    Right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to www.majorgeeks.com (leave it at that for the time being we can change it to what you may want later). Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now post a new HJT log.
     
    Last edited: Jan 9, 2005
  7. ben-g

    ben-g Private E-2

    Hi,
    The problems are not over yet! My norton, didnt find any infected files! My Spybot, still finds ElitumElite files, but still can't fix them.

    I also tried to change my homepage again, including the reset and deletion of cookies and all that, but after I open Iexplorer, the settings change back to the about:blank page.

    Do you have any suggestions what it can be? I can't imagine that this can't be fixed! Hope to hear some ideas!

    Ben-G
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your home page is set to www.majorgeeks.com as I had you change it.

    Just have HJT fix the below entry:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank


    Check out message #14 in this thread:
    http://forums.majorgeeks.com/showthread.php?t=51474

    You may have the same issue.
     
    Last edited: Jan 10, 2005
  9. ben-g

    ben-g Private E-2

    HI, Thanks. I got rid of the Elitum.Elite infection, by following your advice in thread 14 (MS antispy, and your fixvx2.reg file (without internet connection)). Thanks for that! That one worked!

    My hijacking problem is still not solved though! Every time I change it in the internet options, or even in MS antispy I got the chance to change it, but every time I open Iexplorer and I check my internet options again, my homepage is changed to about:blank again.

    I've created a new HJT log file, maybe you can see if there's still something wrong?
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to uninstall all of your antispyware programs and popup blockers and then reboot. Do not reinstall them yet. I would be careful with using Microsoft Antispyware anyway. It has problems with false positives and some items it will clean up will were put into your system to protect you from malware.

    Now use the method I gave at the end of message # 6 to Reset Web Settings. Now get a new HJT log and post it here.
     
  11. ben-g

    ben-g Private E-2

    Remove all my antispyware? R U serious? I have a lot of them installed since I got all this Hijacking problems...

    I have:

    Spybot S&D
    Ad-aware SA
    Pop-up Away
    Microsoft AntiSpyware
    AboutBuster
    LSPFix.exe
    CWShredder.exe
    HijackThis.exe
    Stinger.exe

    Do u really want me to uninstall/remove them all, or can I keep a few of them?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Spybot S&D <--- uninstall
    Ad-aware SA <--- you can leave this as long as it is not the purchased version
    Pop-up Away <--- uninstall
    Microsoft AntiSpyware <--- uninstall, has too many false positives anyway
    AboutBuster <--- not an antispyware scanner program and is not installed
    LSPFix.exe <--- not an antispyware scanner program and is not installed
    CWShredder.exe <--- not an antispyware scanner program and is not installed
    HijackThis.exe <--- not an antispyware scanner program and is not installed
    Stinger.exe <--- not an antispyware scanner program and is not installed


    Are you sure you do not have SpywareBlaster installed? If you do, uninstall it too.
     
  13. ben-g

    ben-g Private E-2

    Okay, I've uninstalled:

    Spybot S&D
    Ad-aware SA (just in case)
    Pop-up Away
    Microsoft AntiSpyware

    Then I rebooted, did a virus check with Norton (who did not found anything), and then I changed my home page as you explained in #6.

    After this I did run HJT, see my file. I tried to fix the following line:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

    Then I rebooted again, and opened Iexplorer. It opened with www.majorgeeks.com for once and if I check the tools-> internet options, it is changed back to about:blank... Just like before!

    Do you have any other ideas?
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! As long as everything is still uninstalled, do the below!

    Right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now open and close a couple of IE sessions! Then get a new HJT log and post it.

    By the way you did not answer the below question before:

    Are you sure you do not have SpywareBlaster installed? If you do, uninstall it too.
     
  15. ben-g

    ben-g Private E-2

    Alright, Ive changed it again in the IE properties and you can see in the first hijackthis.log file that the first line has been changed to majorgeeks.com, but the second stays: about:blank.

    Then I opended IE two times, and about:blank has returned, as also can be seen in hijackthis2.log.

    By the way I don't have SpywareBlaster installed, I dont know to be honest if I ever had it, but that doesnt matter does it?

    Ok, thanks for your effort man!
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixhome.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.)


    Double-click on the fixhome.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to merge say yes.

    Now get another HJT scan. Then run IE a couple time and see what happens.
     
  17. ben-g

    ben-g Private E-2

    Oh, man! How persistend can this hijacker be??

    I used your fixhome.reg and I ran a Hijackthis see in attachment hijackthis5.log. Then I opened IE, which opens with Majorgeeks.com, but changes as usual directly back to about:blank. In hijackthis6.log you can see how it looks like after opening IE!

    Do you think I have to take drastic measures, like re-installing Windows again? I hope not!
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are there other user accounts on this PC?

    If so, have you checked each of them out?

    Please get a copy of the below file into a ZIP file and post it here as an attachment:

    D:\Windows\Inf\IERESET.INF

    The I want you to do the steps of message #16 again except at the end DO NOT run HJT or run any browsers. In fact make sure when you run the steps, every application especially browsers are closed. The as soon as you finish merge into the registry. Do the following (yes you are reading it corretly):

    pull the power plug to your computer!!! The object is to not have a graceful Windows shut down. Malware can respawn during a shut down. Wait a minute and then power back up.

    Now see what happens.
     
    Last edited: Jan 12, 2005
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  20. ben-g

    ben-g Private E-2

    OK, I did #16 again and then I killed the power for a minute. When I started first a diskscan came (did I had to skip it?). Nothing was changed, my IE is still not good.

    I dont have other users, only my own (called: ben) and ofcourse as an admin.

    Then I downloaded the three files (zips and exe) and I ran the find.bat file (output.txt as attachment)). I also zipped a iereset file for u, as u asked. I hope u can understand it.

    One last detail, since I have this problem with my homepage, my IE shows a:"-" after the title of the page. So for example this page is titled: MajorGeeks Support Forums - Reply to Topics - (normally it would be: MajorGeeks Support Forums - Reply to Topics) without "-" at the end. Maybe it is not import, but that's just what I noticed.

    OK, hopefully it will make things clearer??
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you use or did you ever use a program call ReGet ( see http://deluxe.reget.com/en/)?

    I see something in the output.log that I'm wondering about. This is what I'm referring too:

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
    "iebar"=""

    I'm not sure if iebar is valid or not. A search brings up the above link and also:
    http://computercops.biz/clsid-694.html
     
  22. ben-g

    ben-g Private E-2

    Ah, interessing...

    To answer your question, no I never used software called Reget. It seems on their page that it is some kind of speeding-up download thing and u have to pay for it, but I dont never pay for software!

    It might be the iebar thing, but I think u know a lot of more about these things, what do u think should I try to get rid of this iebar? (You probably know how to get rid of it, dont u?)

    Do I have to do smthing wit the killbox and VX2Finder(126).exe?
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We don't need to use VX2finder or Killbox for anything yet.

    Copy the contents of the bold print in the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fix.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.)

    Double-click on the fix.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to merge say yes.

    Then get another find.bat log and post it. Also check if you still get the extra -
     
  24. ben-g

    ben-g Private E-2

    I did the fix.reg, then another find.bat, see attachment.

    IE didnt change the extra -

    The webpage is still changed back to about:blank whenever I try to change it. I dont really understand the find.bat output file, but I saw that the iebar was not present anymore in the Hkey's. OK, but probably u do understand it.
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I'm not sure what is causing this. Are you sure you have no other programs loaded/installed that try to protect your home page?

    Do you have system restore disabled?


    Download ProcessExplorer: http://www.sysinternals.com/files/procexpnt.zip
    Now leave one Internet Explorer session running (like this one).

    Unzip ProcessExplorer and now run it and lets configure some options first:
    Click View and select Show Lower Pane. And where it says "Lower Pane View" make sure DLL's is checked. Now click on iexplorer.exe. Now also under the View menu choose "Select columns" and put a check mark on "Image Path".
    Now click on File and then Save As. And save the process list. Post it back here as an attachment. Also, from now on if I say to kill a process, use ProcessExplorer instead of Task Manager. Sometimes ProcessExplorer can kill things that Task Manager and HijackThis's process manager cannot.

    After that create a StartUp List Log using HijackThis.
    Run HJT and on the first screen, click the button that says "Open the Misc Tools section". In the next window first select "List also minor sections (full)" and then click the button that says "Generate StartupList log". CLick Yes to the Do you want to continue prompt. Now a notepad window will come up with the Startuplist.txt file. It is already saved in the the directory HJT is running from. So just come back here and upload the file as an attachment to your next message.

    Also download one more item AppRead:
    http://www10.brinkster.com/expl0iter/freeatlast/FNF/AppRead.zip

    Unzip AppRead.zip to a folder. Double click on the regread.exe file. Don't run the other program call runread.exe. regread.exe will create a file in the same directory it was run from called regread.log Upload regread.log here too. That will require an additional message because you can only have two attachments in a message.
     
    Last edited: Jan 13, 2005
  26. ben-g

    ben-g Private E-2

    My system restore is (and was) turned off. I dont think I have any programs running that will protect my homepage, at least not that I m aware of.

    I did the ProcessExplorer steps to told me to do, and the attachment is called: iexplore.exe.txt.

    Then I did the HJT start up list, I didnt know if I had to close all IE windows, so I didnt close them.

    I couldnt download AppRead http://www10.brinkster.com/expl0ite...FNF/AppRead.zip, I was not allowed on that page --> I was not authorized for this page...
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Go to here first:

    http://www10.brinkster.com/expl0iter/freeatlast/FNF/

    then scroll down the page until you see:

    >>AppRead.zip-AppInit_Viewer made by IMM(2K/XP only!)<<

    Click on it to download AppRead.zip. The follow my previous instructions.

    I also see a DLL file attaching to Iexplore.exe that I don't like the looks of. Please do the following:

    Click Start, Search and the Select "All files and folders"
    In the "All or part of the file name:" box, enter ppc.dll
    Now select "More advanced options"
    Make sure the following check boxes are checked:
    - Search system folders
    - Search hidden files and folders
    - Search subfolders
    Then click the Search button.

    Tell me exactly what matches you get. It could be:
    C:\WINDOWS\SYSTEM\ppc.dll
    or
    c:\Program Files\PPC Advertor\ppc.dll << I'm guessing this one.

    I need the results of the above before continuing on the about:blank problem but there is another entry I just noticed in your HJT log that should be fixed.

    Run HJT and fix the below entry:
    O16 - DPF: {91433D86-9F27-402C-B5E3-DEBDD122C339} - http://www.netvenda.com/sites/games-nl/nl/games6.cab
     
  28. ben-g

    ben-g Private E-2

    I attached the REGREAD.LOG file.

    I also searched for ppc.dll and it was located on

    D:\Program Files\PPC Advertor\ppc.dll, like u was thinking. (D:\ is my Windows disk).

    then I fixed in HJT:

    O16 - DPF: {91433D86-9F27-402C-B5E3-DEBDD122C339} - http://www.netvenda.com/sites/games-nl/nl/games6.cab
     

    Attached Files:

  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


    Okay. Thats what I suspected! Follow the steps below.

    Click Start, and then click Run. (The Run dialog box appears.)
    Type, or copy and paste, the following text:
    regsvr32 /u D:\Program Files\PPC Advertor\ppc.dll
    then click OK. If a dialog box confirming this action appears, click OK.

    Then reboot in safe mode and make sure no browsers or other applications ar running.
    Run Windows Explorer and navigate to and delete:
    D:\Program Files\PPC Advertor <---- the whole folder

    Let me know if you run into any problems doing this.

    If that all worked, then reboot in normal mode and Reset Your Web Settings as we tried before. Let me know how things look now.
     
  30. ben-g

    ben-g Private E-2

    When I run your line (regsvr32 /u D:\Program Files\PPC Advertor\ppc.dll), I get the message that something failed. I made a jpg of that message and attached it.

    I dont know if that is right? Before I continue with the rest in the safemode I would like to hear from u if that message is OK?
     

    Attached Files:

  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's okay just continue and let me know what happens.
     
  32. ben-g

    ben-g Private E-2

    Yes!!! You did it, man. finally the homepage doesnt change anymore. So I deleted the folder D:\Program Files\PPC Advertor in safemode.

    And then I resetted the IE setting like u showed before.

    There is still that extra - where we talked about, but probably it has nothing to do with this, it doesnt bother!

    Thanks for your help chaslang! Im gonna reinstall my Spybot and adaware, before I get more of these problems.
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds