about:blank problem that won't go away

Discussion in 'Malware Help (A Specialist Will Reply)' started by nifferj, Jul 28, 2006.

  1. nifferj

    nifferj Private E-2

    I have tried everything I know to get this problem to go away.
    I have done the steps on your website and tried everything. I bought Spyware Doctor and that found a Look2Me and a CWS problem but, the about blank problem won't show up or go away.
    Everytime I close a website, it comes up, About:Blank and then shows a IE error and it must close.
    CAN ANYONE HELP ME PLEASE!!
    Here is my JHJT LOG

    Edit by bjgarrick: Inline log attached!
     

    Attached Files:

    Last edited by a moderator: Jul 28, 2006
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download LSP-Fix

    This process may be different now that the version has been updated. If it is different please let me know so I can make changes.

    After download is complete, Run LSP-Fix

    Check the Box labeled "I know what I'm doing" and then click on the inetcntrl.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move inetcntrl.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.

    (Note: If the file inetcntrl.dll is already in the remove section, then just click FINISH.)

    Once you have completed the above I need you to go back to step 6 in the READ ME and run the online scans and attach your logs as requested per the READ ME. Once you have completed this step, read thru the HJT article to relocate your HJT and rename it so we can get started on you a fix.
     
  3. nifferj

    nifferj Private E-2

    Okay I ran the program and have these logs for you to look at...
     

    Attached Files:

  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    I will be check your two logs, while I'm doing so I need you to do two things before we start a fix.

    Navigate to C:\Program Files\hijackthis and rename HijackThis.exe to "anaylze.exe" without the quotations.
    Before running HJT you must close ALL browsers.
    Once you have completed these two steps, attach a fresh HJT log.
     
  5. nifferj

    nifferj Private E-2

    I just did what you asked me to do....hope this works better
     

    Attached Files:

  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Let's address this first...

    The below is part of Sony's garabage that adds a Rootkit to your PC.
    O23 - Service: Plug and Play Device Manager ($sys$DRMServer) - First 4 Internet Ltd - C:\WINDOWS\system32\$sys$filesystem\$sys$DRMServer.exe
    O23 - Service: XCP CD Proxy (CD_Proxy) - Unknown owner - C:\WINDOWS\CDProxyServ.exe

    You should see this link and remove the rootkit:
    http://www.bleepingcomputer.com/startups/$sys$DRMServer.exe-13347.html

    http://www.bleepingcomputer.com/forums/topic34904.html

    Once you have completed this post, then I would like you to follow the steps below...

    Using ShowNet...

    Once your done, attach the log from ShowNet along with a fresh HJT log.
     
  7. nifferj

    nifferj Private E-2

    ShowNew only gives a notepad version and then says there is a problem in the DOS box.
     

    Attached Files:

  8. nifferj

    nifferj Private E-2

    I appreciate all the help in helping me get rid of my problems.
    I can't figure out how to do this step though

    --Delete C:\%WinDir%\system32\$sys$filesystem\aries.sys (Replace %WinDir% with the directory that Windows is installed on your computer)

    Other than that I have to ask what software can I get to run my DVD Player that will not install garbage.
     
  9. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Windows Media Player will play your DVD's, you may have to install a codec but the guys in Software can assist you with that. As for the malware, let's start by working up a fix.
     
  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download LSP-Fix

    After download is complete, Run LSP-Fix

    Check the Box labeled "I know what I'm doing" and then click on the inetcntrl.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move inetcntrl.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.

    (Note: If the file inetcntrl.dll is already in the remove section, then just click FINISH.)

    Next, scan with HijackThis and check the boxes for the following entries:
    ( Make sure ALL browser windows are closed when you click FIX )

    O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    Again, make sure ALL browser windows are closed when you click FIX.

    Next, run CCleaner to clean up cookies and temp files.


    Run full scans with Ad-Aware SE & Spybot S&D and have both programs fix what they find.

    Note: Remember to get all updates before doing the scans.


    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    • Temporary Files
    • Temporary Internet Files
    • Recycle Bin
    And Click OK.


    After you complete the above, REBOOT and proceed with the rest of this fix...

    Finally, I would like you to flush your System Restore points. Please follow the instructions in the below:


    • Disable and Re-enable System Restore

    • Turn OFF System Restore to flush any bad Restore Points.

    • Then, follow the instructions at the bottom of the linked page to Re-enable the Restore Utility which will create a fresh restore point.
    After you complete the above reboot once more and then scan with HijackThis and attach the new log.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  11. nifferj

    nifferj Private E-2

    Here is the most recent Hijack this log
     

    Attached Files:

  12. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your log looks good, are you having any further problems?
     
  13. nifferj

    nifferj Private E-2

    Haven't seen any yet, again thanks for the help.
    I will update you sometime in the next 24-48 to let you know of any problems if there are any.
     
  14. nifferj

    nifferj Private E-2

    Can I remove all the stuff from these steps such as CCLeaner, Ad-Se, and the rest
     
  15. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Good Deal! Also to stay clean I recommend following the steps in the thread below.

    How to Protect yourself from malware!
     
  16. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Yes, you can remove whatever you downloaded and installed if you like.
     
  17. nifferj

    nifferj Private E-2

    I have Norton Anti-Virus and Spyware Doctor. Should I disable norton and get AVG?
     
  18. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    I recommend AVG over Norton, actually I recommend anything over Norton but that's me. If you do install AVG you need to uninstall Norton. Do not install more than one antivirus or firewall. I have never used Spyware Doctor so I can't say anything about it, I use Spy Sweeper and it does a great job.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds