About:Blank

Discussion in 'Malware Help (A Specialist Will Reply)' started by drjimref, Feb 22, 2005.

  1. drjimref

    drjimref Private E-2

    My office has About:blank stuck on my main computer.
    I did find network ss and disabled it/ it reinstalls.
    trend micro scan finds about 21 bugs when it runs.

    I have read MA's post "read me first" I have tried this two different times to clear About:Blank as described thru step 4.

    Not sure to do optional steps 5 chaslang or 6 hijack this as a next resort.

    Thanks,

    Jim

    I am running Windows 2000 Professional with current service packs.
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Make sure you have HijackThis 1.99.1 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT


    We are very busy here at MajorGeeks.Com PhilliePhan, Chaslang or myself with check back when time permits.!
     
  3. drjimref

    drjimref Private E-2

    below is hjtlog file.

    lots of junk on a lot of lines :(

    Thanks for the help.
     

    Attached Files:

  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First:

    Download and run About:Buster & HSRemove


    After you run these programs, reboot and post me a new HJT log.
     
  5. drjimref

    drjimref Private E-2

    Will do. Have them from MA's post.

    Run is safe or regular mode?
     
  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Run in regular mode first. If you have any problems running them in normal mode then reboot in safe mode and run them.
     
  7. drjimref

    drjimref Private E-2

    Here is the run.

    Thanks,

    Jim
     

    Attached Files:

  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please print out these instructions so that you can operate with All Browser Windows CLOSED.
    Please make sure the Viewing of Hidden Files is Enabled as per the tutorial.

    Now, look in Task Manager (Ctrl-Alt-Del) for the following running processes and, if you see any of them, try to END them:

    winls32.exe

    javasw32.exe



    Now scan with HijackThis and Check the Boxes for the following:

    Again, make sure All Browser Windows are Closed when you Click FIX.


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\lpvek.dll/sp.html#28129

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\lpvek.dll/sp.html#28129

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm

    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\lpvek.dll/sp.html#28129

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\lpvek.dll/sp.html#28129

    R3 - Default URLSearchHook is missing

    O2 - BHO: (no name) - {A75B8263-EFB9-58A0-021F-963C6A7122D9} - C:\WINNT\msbp32.dll

    O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)

    O4 - HKLM\..\Run: [tibs5] C:\WINNT\system32\tibs5.exe

    O4 - HKLM\..\Run: [javasw32.exe] C:\WINNT\javasw32.exe

    O4 - HKLM\..\RunServices: [MusIRC (irc.musirc.com) client] musirc4.72.exe

    O4 - HKLM\..\RunServices: [WinConf] MSIEx.exe

    O4 - Global Startup: Microsoft Office.lnk.disabled

    O15 - Trusted Zone: *.awmdabest.com

    O15 - Trusted Zone: *.frame.crazywinnings.com

    O15 - Trusted Zone: *.awmdabest.com (HKLM)

    O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)

    O15 - Trusted IP range: 206.161.125.149

    O23 - Service: Network Security Service (NSS) (?%AF夶À¨) - Unknown owner - C:\WINNT\system32\winls32.exe



    NOW:
    Please boot into Safe Mode with the Viewing of Hidden Files Enabled and navigate to and DELETE the following if they should remain:

    C:\WINNT\msbp32.dll

    C:\WINNT\system32\winls32.exe

    C:\WINNT\system32\tibs5.exe

    C:\WINNT\javasw32.exe

    musirc4.72.exe <-- Search For This One!

    MSIEx.exe <-- Search For This One!
    NOT TO BE CONFUSED WITH (Msiexec.exe) AS THIS IS A CRITICAL SYSTEM FILE!


    NEXT:
    Run CCleaner and Spybot S&D and have Spybot fix what it finds.


    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.


    Reboot to Normal Windows and Scan with HijackThis and attach the new log.
    Let me know of any problems you may have encountered with the above instructions and how your computer is running now.

    Good Luck!:)
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just a note! Normally you will find files like:
    in the c:\winnt\system32 folder.

    Another note: you should have stopped and disabled the below service per the READ ME FIRST:
    O23 - Service: Network Security Service (NSS) (?%AF夶À¨) - Unknown owner - C:\WINNT\system32\winls32.exe

    Without stopping this, you processes will come right back along with all the R0&R1 lines and the BHO. And they will most likely renamed themselves. So unless HSremove or About:Buster stopped that service, you could be starting this all over again.
     
  10. drjimref

    drjimref Private E-2

    You are right. That came back with the 015 trusted zone frame.crazywinning.com. bot stayed with the lin23 nns.

    I tried the hjt several times and these lines stayed put.
    File attached but will go in and stop this and try again. :)
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Refer to step to in the READ ME FIRST and stop and then disable the service.

    Then do the below:

    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file move.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.)

    Double-click on the move.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to merge say yes.

    After doing that, reboot and then post a new HJT log and do not power down or reboot again afterwards. Wait for the next instructions.
     
  12. drjimref

    drjimref Private E-2

    Cl,

    that seemed to piss about:blank off. I now have about 20 trusted zones pluse the multide of ro and r1 references to 28129.

    Let me know Good Sir and Thanks,
    jim
     

    Attached Files:

  13. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please download DelDomains and unzip it to your desktop. Do not run it yet.

    Find the files from deldomains.zip on your Desktop and RightClick on the deldomains.inf file and select Install.


    Please note that your about:blank has returned as a different name. PLEASE DO NOT REBOOT!

    After you do this above go thru this thread again:

    READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    After this is complete, then post new HJT log.
     
  14. drjimref

    drjimref Private E-2

    Let me know. It is growing. :)
    jim
     

    Attached Files:

  15. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    FOLLOW THIS STEP BY STEP! DO NOT SKIP ANYTHING LISTED IN HERE!


    First:

    Please look in Add or Remove Programs for the following and Uninstall them if found:

    Web Rebates

    AutoUpdate

    ISTsvc

    180solutions

    Internet Optimizer


    Second:

    Please print out these instructions so that you can operate with All Browser Windows CLOSED.
    Please make sure the Viewing of Hidden Files is Enabled as per the tutorial.

    Now, look in Task Manager (Ctrl-Alt-Del) for the following running processes and, if you see any of them, try to END them:


    istsvc.exe

    tapavi32.exe

    AutoUpdate.exe

    WebRebates0.exe

    synma12n.exe

    WebRebates1.exe

    winls32.exe

    javavy.exe



    Third:

    Now scan with HijackThis and Check the Boxes for the following:

    Again, make sure All Browser Windows are Closed when you Click FIX.


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\wmhpv.dll/sp.html#28129

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\wmhpv.dll/sp.html#28129

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\wmhpv.dll/sp.html#28129

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\wmhpv.dll/sp.html#28129

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\wmhpv.dll/sp.html#28129

    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\wmhpv.dll/sp.html#28129

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\wmhpv.dll/sp.html#28129

    R3 - Default URLSearchHook is missing

    O2 - BHO: (no name) - {B8392868-66F4-2587-FD0D-0AC72FFCD1EA} - C:\WINNT\atlko32.dll

    O3 - Toolbar: YourSiteBar - {86227D9C-0EFE-4f8a-AA55-30386A3F5686} - C:\PROGRA~1\YOURSI~1\ysb.dll

    O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe

    O4 - HKLM\..\Run: [sais] c:\program files\180solutions\sais.exe

    O4 - HKLM\..\Run: [AutoLoaderAproposClient] "C:\DOCUME~1\KAY\LOCALS~1\Temp\cxtpls_loader.exe" /PC=CP.IST /ForSupportedBrowsers /ShowLegalNote=nonbranded

    O4 - HKLM\..\Run: [v7nW3qV] tapavi32.exe

    O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"

    O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"

    O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"

    O4 - HKLM\..\Run: [javavy.exe] C:\WINNT\system32\javavy.exe

    O4 - HKCU\..\Run: [ew46RkZ3j] synma12n.exe

    O4 - Global Startup: Iomega Backup Scheduler.lnk.disabled

    O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm

    O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} (Installer Class) - http://www.ysbweb.com/ist/softwares/v4.0/ysb_regular.cab

    O23 - Service: Network Security Service (NSS) (?%AF夶À¨) - Unknown owner - C:\WINNT\system32\winls32.exe



    Fourth:

    NOW:
    Please boot into Safe Mode with the Viewing of Hidden Files Enabled and navigate to and DELETE the following if they should remain:


    C:\Program Files\ISTsvc <--- Delete Whole Folder!

    C:\Program Files\AutoUpdate <--- Delete Whole Folder!

    C:\Program Files\Web_Rebates <--- Delete Whole Folder!

    c:\program files\180solutions <--- Delete Whole Folder!

    C:\Program Files\Internet Optimizer <--- Delete Whole Folder!

    C:\WINNT\system32\tapavi32.exe

    C:\WINNT\system32\synma12n.exe

    C:\WINNT\system32\winls32.exe

    C:\WINNT\system32\javavy.exe

    C:\WINNT\wmhpv.dll

    C:\WINNT\atlko32.dll

    ysb.dll <-- Search For This File & Delete It!

    cxtpls_loader.exe <-- Search For This File & Delete It!

    tapavi32.exe <-- Search For This File & Delete It!

    synma12n.exe <-- Search For This File & Delete It!


    Fifth:

    NOW:
    Run CCleaner and Spybot S&D and have Spybot fix what it finds.


    Sixth:

    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.


    Reboot to Normal Windows and Scan with HijackThis and attach the new log.
    Let me know of any problems you may have encountered with the above instructions and how your computer is running now.

    Good Luck!:)
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    BJ,

    I believe his explorer.exe may be infected. We have been seeing some of these lately. I think the below steps should be followed.

    Download Kaspersky Anti-Virus Personal 5.0
    as it cleans this thoroughly + much of the crap that comes with it!! This version is a 30 day trial.


    drjimref, You should print this out for reference!

    You must disable any resident AV programs you have and install KAV 5.0.

    When Installing, do the following as you come to them:

    Uncheck the Operate According to Recommended Settings Box

    Uncheck the Use Real-time Protection against Network Attacks Box

    Uncheck the Use The iStreams Technology Box


    Now, allow KAV 5.0 to download and install Updates. Then, look under Settings > Configure Updater and select Extended Database > OK > Check for Updates and allow those to install.

    Then, Click Settings > Configure On-Demand Scan Settings and Set Scan Level to Maximum > Perform Recommended Action > OK

    NOW, Close ALL Programs (including KAV 5.0) and Browsers!

    Physically Disconnect from the Internet - Pull the Cable!!

    Boot to SAFE MODE

    OPEN KAV 5.0 BUT DO NOT RUN IT YET!!!

    Open Task Manager (Ctrl-Alt-Del) and RightClick explorer.exe and END IT! Don't be alarmed when all of your desktop items disappear. That is normal.

    Everything will go blank except for KAV 5.0 and Task Manager. DO NOT CLOSE THEM!!

    Now : Start a FULL SYSTEM SCAN. Click the Protection Tab and select Scan My Computer .

    This process may take HOURS . . . . LET IT RUN!

    When the Scan and Cleanup are done, go to Task Manager and select File / New Task and type explorer.

    Close KAV 5.0 and TaskManager and reboot to Normal Windows and get a fresh HijackThis Log and let us know how things look!
     
  17. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Thanks Chas! This infection is kinda nasty, and this one came back with 3 times as many infections.
     
  18. drjimref

    drjimref Private E-2

    Question:

    BJ - Should I not disable the Nss to start with? Cl pointed out that was needed on the first run before I start your steps.

    CL - Do I do the KAV 5 first or wait till I do BJ's clean then either run it or reboot and run?

    Thanks for all the help.

    JIm
     
  19. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Go ahead and do post 15, dont post the new log just yet. After you complete post 15 move to post 16 by Chas!

    After you complete Chaslangs steps then attach a new log.

    DONT POST THE NEW LOG UNTIL BOTH POST ARE COMPLETE!
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do what BJ just said but you should first stop and disable the NSS immediately. You should have done that when you first ran the READ ME FIRST. It still must be done.
     
  21. drjimref

    drjimref Private E-2

    Got the ka5 down loaded and it reboted and got it installed.

    Went to go into cp and to "Add and remove" - ran into a block. The Add and remove pops up for about 1/2 a second and closes back to the main cp screen in classic view.
    Suggestions to get it up so I can uninstall some fo the crud?
    Thanks,

    Jim
     
  22. drjimref

    drjimref Private E-2

    Help.

    Tried to attack this problem several ways and keep getting my butt kicked.
    I can not get into the add and delete programs.
    I can not get on line and run trend micro to see if I can get the virus block to clear on several programs.

    Is it the kav 5 program which did not ask the installing questions mentioned it just installed and rebooted by itself and I never got a chance to unckeck the three boxes mentioned?

    or is it the bugs are getting pissed?

    What to do and where to start past services.msc and stop the nss?
    Thanks,

    Jim
     
  23. drjimref

    drjimref Private E-2

    about: blank (2)

    Re: about:Blank This was continuation from a post on yesterday but I am hung up and cannot proceed to do the next step from posts from CL and BJG.

    I keep getting my butt kicked from when we tried to fix this yesterday. The bugs multiplied by 3 times yesterday on the attempted fix. I can not get into the add and delete programs in CP. The Add and remove window pops up for about 1/2 a second and then closes back to the main cp screen in classic view.
    Suggestions to get it up so I can uninstall some of the crud to be able to work the suggested programs from BJG.

    CL Is it the kav 5 program which did not ask the installing questions mentioned it just installed and rebooted by itself and I never got a chance to unckeck the three boxes mentioned?

    or is it the bugs are getting pissed?

    What to do and where to start past services.msc and stop the nss? NSS starts up every time you reboot.

    Below are the last two posts from CL and BJG to be up to date on previous posts.

    Thanks,

    JIM - I feel like Custer right now. :) Where did they all come from?


    Edit by chaslang: deleted unnecessary quotes of BJ's and chaslang's steps to avoid the clutter.
     
    Last edited by a moderator: Feb 23, 2005
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: about: blank (2)

    Why did you start a new thread?

    I'll be merging you back to the other thread and deleting the unnecessary quotes to avoid clutter.
     
  25. drjimref

    drjimref Private E-2

    Re: about: blank (2)

    Just down in the water and trying to get up.

    This bug is on my main computer with my business information on it.

    Delete the thread and lets start over.

    Thanks for the reply.

    Jim
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: about: blank (2)

    Answer some questions:

    1) did you do what every steps you did while disconnected (unplugged cable) from the internet?

    2) did you stop and disable the NSS yet?

    3) can you still run HijackThis?
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: about: blank (2)

    Are you using a different PC to correspond with us or is it the infected one?

    What type of access to the internet do you have? Dial-up, cable, DSL ?
     
  28. drjimref

    drjimref Private E-2

    no did not unplug.

    kav 5 was installed and program rebooted itself before settings questions answered and applied. Norton was off but possible conflict??

    Nss is disabled each time.

    Probably can still run a log from hjt. I have not tried. I have been trying to fig out why the freezes for some of the programs and how to work around to be able to do BJG's outline before running your kav5.

    Do you want a log?

    I am on another computer at this time but will post one asap if possible.
    Thanks,

    Jim
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't know your setup and how much you know about computers but is it possible for you to do stuff we request witht the other PC disconnected (unplugged) from the internet. And communicate via your second PC. Do you have the ability to copy any downloads we may need to the infected computer and get logs from it back to the uninfected one for posting here?
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes, post a current log. Also answer message # 27 and #29
     
  31. drjimref

    drjimref Private E-2

    Yes- I can get into explorer but the mgeeks site causes ie to close.

    As you posted I had already put the hjt log on floppy and was posting as attached when you posted.

    Sorry- I know a little about computers but this program is a monster if it blocks out ie and add/remove programs.

    Jim
     

    Attached Files:

  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What is this in reference too? explorer.exe and IE are not the same thing! Unplug the infected computer from the internet.

    Please answer my previous questions.
     
  33. drjimref

    drjimref Private E-2

    sorry window's explorer works. Internet explorer will open with all the about but if you want to go to the Majorgeeks site internet explorer closes after trying. Same if you want to see trend micro's scan site. My error on ie and explorer being the same thing in my poor mind now.

    ) did you do what every steps you did while disconnected (unplugged cable) from the internet? No I am afraid that kav5 might have hung up with norton turned off when I down loaded. After the kav 5's self reboot the computer has run slow. After the down load I tried to get into Cp Add and delete and program pops open the closes in 1/2 second. Nss was turned off first.

    2) did you stop and disable the NSS yet? Yes each time

    3) can you still run HijackThis? Yes file sent from this computer.

    I have DSL.
    I am on my computer to talk. and will unplug the other computer before any thing else done.

    Thanks, JIm
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Do not open any browsers (IE) in the infected computer unless requested. Do not run anything on it at all unless requested? If you think you need to do something we did not mention, ask first.

    One question that you did not answer: do you have the ability to copy files we ask you to download from the uninfected computer to the infected one. Either via a CD burner, a flashdrive, a floppy (but many things may not fit on floppy).

    Okay! I'm going to take a look at the last log you posted.
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    OKAY! First step on infected computer!

    I want to get rid of the O23 line related to the Network Security Service.

    Please run HijackThis click on the "Open the Misc Tools Section" button on the open page. Then select "Delete an NT service" on the left-hand side.
    A "Delete a Windows NT Service" window will pop up. Try entering the following into the box and then click OK:
    Network Security Service (NSS)

    Then run another scan. Is the O23 line gone? If not, do the below:

    If that does not work try entering the short name: ?%AF夶À¨
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Next step on infected computer:

    Please run HijackThis click on the "Open the Misc Tools Section" button on the open page. Then select "Open Uninstall Manager" on the left-hand side.

    First click the Save list.. button. This will save a list of programs in your uninstall list. A log file will pop up names uninstall_list.txt. Copy that to you other PC and upload here at MG's in a message.

    Then for the heck of it try clicking the "Open Add/Remove Software list" button. Does that work? Does it stay open?

    If so, look in the Add/Remove programs list for anything like the below and uninstall them:

    ISTsvc
    180solutions or SAIS
    AutoUpdate
    Internet Optimizer
    WebRebates0 or WebRabtes or Web Rebates

    Tell me the results of the above.
     
    Last edited: Feb 23, 2005
  37. drjimref

    drjimref Private E-2

    Yes I have cd burner and cd floppy.

    I will go to the other machine and start step one.

    I will try. How do you do some of the odd letter listed?
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just copy and paste them from the log file you saved. With these strange chars, leave off the surrounding ( ).

    But that comes second. Try the Network Security Service (NSS) first.

    Remember to only do steps I request. If I do not say to reboot, don't!
     
  39. drjimref

    drjimref Private E-2

    CL,

    HJT deleted the line 023 when hjt but it froze the system. Upon reboot the services.msc showed nss there in auto and I stopped it again.

    Ran HJT and there is no 023 nss line listed.

    Open uninstall mananger opened ok.

    Add/remove opens and stays open.

    Question is uninstall the same as delete for this program. Uninstall not seen.

    jim
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Follow the rest of my directions. You are uninstalling using Add/Remove programs not deleting with HJT. You need to post the uninstall_list.log I asked for too. Do that first!!!
     
  41. drjimref

    drjimref Private E-2

    enclosed list.

    add/remove programs blinks but does not open.

    023 nss gone. Disabled on services.msc
     

    Attached Files:

  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How did you get Ad-Aware SE install without uninstalling Ad-Aware 6 Personal?

    What is MOGO?
     
  43. drjimref

    drjimref Private E-2

    How did you get Ad-Aware SE install without uninstalling Ad-Aware 6 Personal? BEATS ME.

    What is MOGO? DENTAL PACKAGE FOR THE OFFICE
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! See if you can use the Uninstall routine from Add/Remove programs (bring up thru HJT method) and uninstall the below. Some may not uninstall, tell me which ones:

    Ad-aware 6 Personal
    Home Search Assistent
    Internet Optimizer
    ISTsvc
    Search Extender
    Shopping Wizard
    Uninstall 180searchAssistant
    WebRebates (by TopRebates.com)
     
  45. drjimref

    drjimref Private E-2

    "Okay! See if you can use the Uninstall routine from Add/Remove programs (bring up thru HJT method) and uninstall the below."

    Add/Remove programs will not open. Blinks on and computer makes a quick whine and window closes back to the scree that lists programs from hjt.
     
  46. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Use the quote button if you want to quote messages.
    I message # 39 you said it stayed open?????
     
  47. drjimref

    drjimref Private E-2

    My error. (again)
    Opened the Misc Tools Section" button on the open page. Then select "Open Uninstall Manager" on the left-hand side. This screen is open but the
    Open "Add/Remove Software list" button just blinks and stays on the uninstall manager page when button is hit. I thought this was the correct page when it opened the first time.
     
  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Use HijackThis and on the Uninstall window have it Delete each of the following (I'm skipping Ad-Aware 6):

    Home Search Assistent
    Internet Optimizer
    ISTsvc
    Search Extender
    Shopping Wizard
    Uninstall 180searchAssistant
    WebRebates (by TopRebates.com)

    Tell me the results!
     
  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hello Jim.... you there? Where did you go? .... To pull some teeth. I think that is less painful then this! ;)
     
  50. drjimref

    drjimref Private E-2

    They all appear to be deleted after doing a refresh of the list

    fwiw
    Add/remove would still not open more than 1/2 second after deletions.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds