about:blank solution!?!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by aledrinker, Sep 15, 2004.

  1. aledrinker

    aledrinker Private E-2

    Greetings one and all. I've had numerous run-ins with the now infamous about:blank irritant and have the following possible solution. Firstly, Adaware6, Spybot and AVG will not remove it. AdawareSE 1.04 got rid of it for about 24hrs - then it popped up again. I have now tried this: http://s12ds2.ewizard.cc/uninstall.exe This came from the hacker himself and has (so far) removed the problem. Save it, run it, reset homepage and start MSIE. About:blank will probably come back - but with no text on the page. Repeat the process and (well, in my case) voila - it's gone! No HJT logs, no registry jiggery pokery. What do you guys think? It seems all too simple - but it also seems to be legitimate. Best of luck - Ale. :)
     
  2. melomano

    melomano Private E-2

    Are you saying us to download a *.exe from a hackers page?
    Sounds a little bit crazy and risky to me!
     
    Last edited: Sep 15, 2004
  3. aledrinker

    aledrinker Private E-2

    I agree, it sounds crazy - but hell, if it works....! This thing has been attacking us for ages and nothing else has worked. Others have tried it and found that it has cleared the problem - and you have to give some creit to the hacker if they have provided a solution. I guess the question is - can anyone actually find anything wrong with the exe. to suggest that it shouldn't be used??
     
  4. melomano

    melomano Private E-2

    Aledrinker,

    OK, I trust you...But other guys go first!
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I personally would not trust it to begin with. Unless I had a test PC I could evaluate it on, I would be careful. See the links below which dicuss the uninstall.exe. Some success, some failures, some short term success. But who knows who is doing the posting.

    http://www.computing.net/security/wwwboard/forum/12814.html
    http://miataru.computing.net/cgi-bin/printer.pl?12874|security
    http://www.computing.net/windows95/wwwboard/forum/158464.html

    It's up to you if you would like to be the beta tester! Otherwise you will need to work thru this the long way.
     
  6. aledrinker

    aledrinker Private E-2

    Thanks Chaslang - well, I guess I'm the beta tester then! Just to update - I've booted the PC today - and all seems to be still ok. I'm going to do some registry checking tonight and see if I can identify any of the stuff thats mentioned in other threads / forums. Will also get a shredder download. I'll keep you posted - unless the PC crashes completely!
    Take care guys. Ale.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Let me understand this. You had about:blank problems and you downloaded the program from that link and ran it and problems appear to be gone?

    How about posting a HijackThis log as an attachment so I can see what it looks like?

    Melomano,
    The decision is yours. But if you are going to try it, please save a HijackThis log from before and after running it. And post them here as text attachments.
     
  8. aledrinker

    aledrinker Private E-2

    Ok chaslang - I'm defeated now - it's back and I'm fed up!
    The exe. came from the computing.net forum that you posted links to earlier. Thought it would be worth a try - obviously I was wrong! As requested, I attach the HJT log for you to look at. At this stage, I am completely in your hands - and a little scared at the prospect of fiddling with registry stuff! But, if you can help - I would be eternally grateful!
    Ale.
     

    Attached Files:

    • hjt.txt
      File size:
      6.7 KB
      Views:
      2
    Last edited by a moderator: Sep 16, 2004
  9. melomano

    melomano Private E-2

    Aledrinker,

    Well, as my mom says "don't drink water from strangers". And, by the way, thank you for being my beta tester. :)

    Seriously, aledrinker, I hope we find something to cure our PCs from that devil HSA, (aka About:Blank) problem. If I find something useful in the web I will post it to you.

    Peace pal.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Aledrinker,

    Okay I expected that. And do not post inline HJT logs. Only text file attachments. Note your HJT is way out of date.

    Please follow all the steps in this Sticky thread < READ ME FIRST: Basic Spyware, Trojan And Virus Removal >

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.


    NOTE: You should read the tutorial in this Sticky thread < Hijack This Tutorial And How To Post Your Log File > Do not post a HijackThis log until we ask you to and when we do it must be text document attachment to your message.

    Update! Due to Hijack This logs destroying search engine and web site searches, we now ask you do not post your Hijack This log file unless requested by us. It is for advanced users, so if you do not understand how to use it, you do not need it....yet. Instead, please tell us in your post what symptoms you are experiencing so we can try and resolve it that way. When, and if, we ask you to post your log file, please attach it as a file. To do this save the log file and select manage attachments in a new thread to upload it. All running programs should be closed, including your web browser, e-mail, items in the tray, anything you can close... Close before running Hijack This!


    Do NOT run Hijack This from the Desktop, a temp folder or choose run from the download. Place it in its own folder, for example C:\Program Files\HJT


    Start by giving the results of all the above.
     
    Last edited: Sep 16, 2004
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The cure is here on MG's! I have fixed literally 100's of these. The problem is that they keep mutating or coming out with newer and more insidious types all the time. And they impact each OS type a little different. Makes it difficult, but not impossible yet, to cure. It requires some detailed steps and quite often repetition. If it were easy, all of the virus and spyware protection software companies would already have a fix. So as you can see, it is almost impossible to predict the exact solution. That is why all of these companies with all the people working for them have not been able to find a true solution for this problem.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have a problem you need to work, please start a new thread for your issue. And follow the guidelines I just posted for Ale.

    Hmmm! Aren't we already working that with you somewhere?
     
  13. melomano

    melomano Private E-2

    Sorry Chaslang, didn't mean that. I was trying to help everybody in this forum (especially you) because I think is the best I've ever step on on my journey to discover a cure for my PC. As a matter of fact I invest my time reading your document called "Generic Solution to HSA..." to come with some suggestions & feedback that can improve it and post a thread of it.


    As a matter of fact I started a new thread yesterday about my problem and no, Chaslang, no one is working with me somewhere (as 18:49 my mexican hour time).

    Cheers

    Peace
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I search for your other thread. I found it. And now I see you just bumped it by adding some more info. I'll be there shortly. Very busy day today.
     
  15. aledrinker

    aledrinker Private E-2

    Ok guys - thanks for staying with me on this!! I'm about to embark on the instructions as suggested below. I'll let you know what I find and get back - see you later! Ale.
     
  16. aledrinker

    aledrinker Private E-2

    Right - phew!!
    ADAware removed:
    possible browser hijack x 2 data miner HKEY_local_machine_software\microsoft\IE\main "start page"(about:blank)
    HKEY_users:S-1-5-21-18-

    CCleaner removed an enormous list of stuff

    Spybot removed:
    DSO Exploit x 3
    HKEY_users\s-1-5-18\software\microsoft\windows\current users\internet settings\zones\0\1004!=w=3
    HKEY_users\s-1-5-21-1858025970-426469163-3499916212-1005\software
    HKEY_users\.default

    CWshredder removed:
    CWS.loadbat
    CWS.searchx
    (7 infected registry values for the above)
    restored 7 items - internet pages

    Kill2me says no signs of infection

    About buster log attached as is HJT (updated version!)

    I hope this is all ok!! look faorward to your reply.
    Take care, Ale
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are running HijackThis from the ZIP file. My instructions specifically said not to do that. Please install it into its own directory as I indicated in message # 10.

    What about McAfee Stinger and the online scans? You did not run them.

    Do you still have Panicware - Pop-Up Stopper installed? It appear that at lease one file is missing and also BHO Demon has disabled it. Do you still want to use it?

    What is your expect home page?
    www.majorgeeks.com or http://uk.yahoo.com

    Before continuing, I need you to get HijackThis in its own directory and I need answers to my questions. Right now you do not show True about:blank hijack problems.
     
  18. aledrinker

    aledrinker Private E-2

    I put HijackThis in a folder on the c drive C:\HijackThis - but when I open it to run the program, it says it appears to have been started from a temp folder. I haven't a clue what is going on with it. I'll have a search through and see if I can find it somewhere else. Sorry, missed those steps - I'll do the other scans and so on. pop up stopper I'm not bothered about - so I'll remove it anyway. Yesterday, after all the scans, the home page set itself to Google.com. I had previously had Majorgeeks.com set up as homepage - but it has come back with about:blank today anyway!
    I'll do some more scanning and come back. Ale.
     
  19. aledrinker

    aledrinker Private E-2

    I'm getting really cheesed off with this now! I've just deleted HijackThis and downloaded it again - straight into it's folder on the C drive - but it still tells me it is coming from a temp folder somewhere. I have not had to unzip it either - it goes straight into the folder and runs from there. What the heck have I done that's wrong???? Also, I cannot do online scans in safe mode as I can't connect to the internet - so I'll have to do those in normal mode. Nothing ever works as it's supposed to for me!!!!
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The file you are donwloading is a compressed ZIP file. You need to extract the hijackthis.exe file out of the ZIP file into its own directory. What you are missing is the fact that you are not extracting it from the ZIP file. You are running it from the ZIP file.

    If you cannot figure out how to do that with WinXP's built-in ZIP viewer, download and install WinZip from here: http://www.majorgeeks.com/download525.html
    Now when you double click on a ZIP file WinZIP will come up and you can tell it what to do. Tell to extract and then browse to the directory where you want to extract it. You can even create a directory (folder) if it does not exist already.

    Your home page changed from majorgeeks to google due to running About:Buster (I assume you must have run it.)
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes, you can do the scans in safe mode. You just have to choose Safe Mode with Networking Support as the tutorial indicates.
     
  22. aledrinker

    aledrinker Private E-2

    Thanks Chaslang - finally got the zip file thing sorted! I attach the (hopefully) correct HijackThis log - done today. Re the scans in safe mode issue, when I try and connect to the internet in safe mode with networking support - nothing happens - the PC simply does not connect - doesn't dial out or anything. As soon as I boot in normal mode - everything works as normal! I did the scans in normal mode (hope the information might be of some use anyway?!) Any suggestions as to what else I can try to get online in safe mode???
    Trend Micro found:
    Troj strtpg.IX
    Troj Muss.A
    HTML strt pg IX (2 off)
    Java Bytever.A (2 off)

    Symantec security scan showed:
    Hacker exposure = safe
    Windows vulnerability = safe
    Anti Virus product check = vulnerable (it does not recognise AVG which I use)

    Hope some of this will provide more useful info. About:blank continues to affect Yahoo and Hotmail accounts and constantly re-asserts itself as my homepage. A lot of pop ups telling me that I am infected with spyware keep appearing - probably attached to the source of the problem itself?!
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You never answered my questions from message # 17

    "Do you still have Panicware - Pop-Up Stopper installed? It appear that at lease one file is missing and also BHO Demon has disabled it. Do you still want to use it?
    "

    I see some problems to clear up in your log but first we have to hunt for some possible hidden problems.

    1) go here and download Registrar lite and install it: http://www.majorgeeks.com/download469.html
    2) Run it, copy and paste this line to reglite's address bar:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
    3) Click the "go" tab
    4) Find: "AppInit_Dlls" value on the right side panel.
    5) DoubleClick on AppInit_Dlls and tell me exactly what you see in the Value field:

    By the way the below is not a bad file. You just do not need it to be run at startup cluttering the System Tray and wasting resources. So have HijackThis fix this line. Alternately you can most likely do it by running WinZip and selecting Options and Configuration.
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    Also fix this line with HJT since the file is missing:
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    We will get to the rest of the problem lines later. I'm noting those lines below. Do not do anything with them yet. I need the above info from Registrar Lite first. I just want to save what I'm looking at thus far.

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {A8020BB6-8B6B-4D8A-86C6-7C3CB0A75A1C} - C:\WINDOWS\System32\bbpahaa.dll
    O18 - Filter: text/html - {158E9F40-1C34-4C55-A95B-1F5516FB7394} - C:\WINDOWS\System32\bbpahaa.dll
    O18 - Filter: text/plain - {158E9F40-1C34-4C55-A95B-1F5516FB7394} - C:\WINDOWS\System32\bbpahaa.dll
     
  24. aledrinker

    aledrinker Private E-2

    Hi,
    The result of the registrar lite scan (Applnit_dlls value) is:
    C:\windows\system32\logejkh.dll

    Answer re. panic ware pop up stopper - I have deleted it as I wasnt really using it.

    Re. the O2 and O18 registry entries below, bbpahaa keeps showing up on BHO and I keep disabling it.

    cheers and thanks for your help so far!
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You mean you keep using HJT to fix the line but it comes back? Disabling is something else (which BHO Demon can do). We need to work on the AppInit_DLLs line.

    I want you to Run Registrar lite again but this time do the following:
    - copy the following into the address bar or expand the same key by hand:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs

    - Rename the Folder Windows to NotWindows (in the left hand pane of reglite)
    - Double Click "AppInit_DLLs" again and clear the data value:
    C:\windows\system32\logejkh.dll < delete this line , 'Apply' and 'ok' to set.
    - Rename the NotWindows folder back to its original name Windows
    - Double check the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs entry to make sure the logejkh.dll file has not returned. If it has change the folder name to NotWindows again, delete the data value again, but do not change the folder name back to Windows. Just continue with the next step.
    - Restart computer in safe mode
    - This should make the file visible if we could not find it before. So run use Windows Explorer and go to C:\windows\system32 and locate the file logejkh.dll and delete it.
    - Also while in safe mode. Run HijackThis again and have it fix all of these lines from before (if still there):
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {A8020BB6-8B6B-4D8A-86C6-7C3CB0A75A1C} - C:\WINDOWS\System32\bbpahaa.dll
    O18 - Filter: text/html - {158E9F40-1C34-4C55-A95B-1F5516FB7394} - C:\WINDOWS\System32\bbpahaa.dll
    O18 - Filter: text/plain - {158E9F40-1C34-4C55-A95B-1F5516FB7394} -
    C:\WINDOWS\System32\bbpahaa.dll

    Now delete C:\WINDOWS\System32\bbpahaa.dll

    Now reboot in normal mode and let's see a new HJT log.
     
  26. aledrinker

    aledrinker Private E-2

    Quote:
    You mean you keep using HJT to fix the line but it comes back? Disabling is something else (which BHO Demon can do). We need to work on the AppInit_DLLs line.

    I haven't been using HJT to fix it - I've been disabling it with BHO Demon - as you mentioned.

    Ok - done all the other instructions and there were a couple of interesting points. When it came to deleting c:\windows\system32\logejkh.dll - it wasn't there!
    The same thing applied when I went to delete c:\windows\system32\bbpahaa.dll - it also wasn't there.

    Several of the registry entries that you listed to be fixed had changed. All the R1 lines and the R0 line ending in =about:navigation failure were not there.
    Now, as you can see from the log - they are back! Should I look for the logejkh.dll and bbpahaa.dll files in normal mode? or have HJT fix the registry in normal mode?
     
  27. aledrinker

    aledrinker Private E-2

    Ooops - sorry - forgot this bit!

    Cheers,
    Ale.
     

    Attached Files:

  28. aledrinker

    aledrinker Private E-2

    about:blank continues to plague me

    Hi chaslang / anyone, I have another thread "about:blank - solution??"- but there has been no relpy to my last post two days ago! Not sure what is happening - but I am still being ruled by about:blank. Can someone help me or at least let me know what's happening with my thread??
    Thanks,
    Ale
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: about:blank continues to plague me

    Sorry about that. You slipped down so far on he pages that I missed seeing your message. It's been exceptionally busy here. It's getting tuff to keep up. And the problems are becoming more and more difficult to remove thus make the open thread count increase while there are still dozens of new threads coming in daily.

    I merged your post back into your previous thread (which is now what you are reading). It is better to always keep all correspondence on this problem in one thread. We need to be able to see the history.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: about:blank continues to plague me

    You need to post a another HJT log and do not shutdown or reboot your PC until I can get back to you with some things to try. You problem may change filenames upon reboot and that may be the reason you did not see the files I asked you to delete.

    So get me that HJT this log and do these steps again (do not do any editing or mods on your own)

    1) Run Registrar lite & click on the word Registry in the top of the left Window
    2) Copy and paste this line to reglite's address bar:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
    3) Click the "go" tab
    4) Find: "AppInit_Dlls" value on the right side panel.
    5) DoubleClick on AppInit_Dlls and tell me exactly what you see in the Value field:


    Don't forget DO NOT reboot or reset. You can disconnect from the internet by what ever means necessary (unplug cables etc) but no reboots.
     
  31. aledrinker

    aledrinker Private E-2

    Ok, thanks chaslang - I'd noticed it was getting pretty busy in here!
    HJT log attached as requested. The Applnit_Dlls value is c:\windows\system32\logejkh.dll which is weird as it definitely wasn't ther when I tried to find it last time!

    I have noticed that BHO demon has started bringing up pfcanga.dll which seems to have replaced the bbpahaa.dll that was there previously.
    I hope there's a solution to this somewhere / somehow - it's driving me and my wife nuts! Incidentally, she tends to get a problem with IE shutting down on her - which I have not experienced. We have separate accounts on the PC so I don't know if that has anything to do with it?!
    Hope to hear from you soon. ale.
     

    Attached Files:

  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay this is part of the reason the problem keeps coming back. In message # 24 you told me you found the logejkh.dll but in message #26 where you were supposed to be deleting the line from AppInit_DLLs you said it was not there. Now it is back again. You have to make sure you find it and fix it this time.

    Print the below instructions or save them locally and disconnect from the Internet (unplug you analog phone line or ethernet cable to your PC) and DO NOT RUN ANY BROWSERS again until told to.

    I want you to Run Registrar lite again and do the following:
    - start by click on the word Registry in the top of the left Window pane to make sure you are at the beginning of the registry.
    - copy the following into the address bar or expand the same key by hand:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
    - Rename the Folder Windows to NotWindows (in the left hand pane of reglite)
    - Double Click "AppInit_DLLs" again and clear the data value:
    C:\windows\system32\logejkh.dll < delete this line , 'Apply' and 'ok' to set.
    (YOU HAVE TO MAKE SURE THIS WORKS. IF IT DOES NOT THE WHOLE PROCEDURE WILL NOT WORK.)
    - Rename the NotWindows folder back to its original name Windows
    - Double check the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs entry to make sure the logejkh.dll file has not returned. If it has, change the folder name to NotWindows again, delete the data value again, but do not change the folder name back to Windows. Just continue with the next step.
    - Restart computer in safe mode
    - This should make the file visible if we could not find it before. So run use Windows Explorer and go to C:\windows\system32 and locate the file logejkh.dll and delete it. (THIS TOO MUST BE COMPLETED CORRECTLY. THE FILE MUST BE DELETED).
    - Also while in safe mode. Run HijackThis again and have it fix all of these lines (if still there):
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    O2 - BHO: (no name) - {7031E96F-0F5E-4D12-8A01-BF91C20BCA58} - C:\WINDOWS\System32\pfcanga.dll
    O18 - Filter: text/html - {9F431CDC-A73C-4C46-9799-DE8943AD11C6} - C:\WINDOWS\System32\pfcanga.dll
    O18 - Filter: text/plain - {9F431CDC-A73C-4C46-9799-DE8943AD11C6} - C:\WINDOWS\System32\pfcanga.dll

    Use Windows Explorer to locate and delete C:\WINDOWS\System32\pfcanga.dll

    Reset Web Settings by clicking Start, Control Panel (for some systems it may be Start, Settings, Control Panel) and select Internet Options. Then click Programs and click the Reset Web Settings button. Then go back to the General tab and set your home page back to what you like (i.e., www.majorgeeks.com).

    Empty your recycle bin and also empty your c:\windows\Prefetch folder.

    You should run similar procedures on all user login accounts on this PC. In fact, if you have not done so the whole READ ME FIRST tutorial steps should be run for each user account.

    Now reboot in normal mode with you internet connection hooked back up. Post a new HJT log and tell me how all the steps went and how things look.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds