About:Blank

Discussion in 'Malware Help (A Specialist Will Reply)' started by drjimref, Feb 22, 2005.

  1. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    OK!

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINNT\system32\ipin32.exe
    C:\Program Files\Web_Rebates\WebRebates0.exe
    C:\WINNT\system32\ipec32.exe
    C:\Program Files\Web_Rebates\WebRebates1.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\wmhpv.dll/sp.html#28129
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\wmhpv.dll/sp.html#28129
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\wmhpv.dll/sp.html#28129
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\wmhpv.dll/sp.html#28129
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\wmhpv.dll/sp.html#28129
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\wmhpv.dll/sp.html#28129
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\wmhpv.dll/sp.html#28129
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {B8392868-66F4-2587-FD0D-0AC72FFCD1EA} - C:\WINNT\atlko32.dll
    O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
    O4 - HKLM\..\Run: [sais] c:\program files\180solutions\sais.exe
    O4 - HKLM\..\Run: [v7nW3qV] tapavi32.exe
    O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
    O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
    O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"
    O4 - HKLM\..\Run: [javavy.exe] C:\WINNT\system32\javavy.exe
    O4 - HKLM\..\Run: [ipec32.exe] C:\WINNT\system32\ipec32.exe
    O4 - HKCU\..\Run: [ew46RkZ3j] synma12n.exe
    O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm

    After clicking Fix, exit HJT.

    Tell me when you finish this while I work on the next steps! Let me know if you have any problems with any of those steps.
     
  2. drjimref

    drjimref Private E-2

    Done as requested. Log file posted to check.
    Had to go back in c:\programs\webrebates 0 and 1 and re kill both- hard to get off.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download this ExplorerXP and get it installed on the infected computer. Let me know when finished.

    DO NOT RUN Windows Explorer or IE anymore. They are spreading your infection!
     
  4. drjimref

    drjimref Private E-2

    installed
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Fix this line again with HJT:
    O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"

    Do not open any Windows Explorer sessions to delete anything? DO NOT RUN ANYTHING UNLESS I REQUEST IT. Some of your problems are spreading each time you run IE or Windows Explorer?


    - NOW PULL THE POWER PLUG TO YOUR PC! I do not want you to power down the normal way.

    - After that wait a minute or two and then power up into safe mode (still with no internet connection available and do not open any browsers). Only run what I request.

    - Run ExplorerXP that I had you download. It is pretty straight forward using it and navigating around. I want you to use it to delete the below (if you can find them):
    C:\Program Files\ISTsvc <--- the whole folder
    C:\Program Files\AutoUpdate <--- the whole folder
    C:\Program Files\Internet Optimizer <--- the whole folder
    C:\program files\180solutions <--- the whole folder
    C:\Program Files\Web_Rebates <--- the whole folder
    C:\WINNT\wmhpv.dll
    C:\WINNT\atlko32.dll
    C:\WINNT\system32\tapavi32.exe or C:\WINNT\tapavi32.exe
    C:\WINNT\system32\javavy.exe
    C:\WINNT\system32\ipec32.exe
    C:\WINNT\system32\synma12n.exe or C:\WINNT\synma12n.exe

    - Empty your Recycle Bin. In fact as an additional measure do the following:
    Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin
    And Click OK.
     
    Last edited: Feb 23, 2005
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let me know when you finish those steps! Stay in safe more when completed. And get a HijackThis log from safe mode and post it here. Don't forget to tell me the results of those steps.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't have a c:\windows\Prefetch folder to delete files in because you are running Win2K. That was in my original instructions before I edited it to remove that step.
     
  8. drjimref

    drjimref Private E-2

    Did not find
    internet optimizer
    180solutions
    atlko32.dll ??sp
    tapavi32.exe
    synmal12n.32
    javavy.exe
    ipec32.exe

    did not find c:\windows\prefetch folder but running 2000 pro
    did the clean program.

    In the programs I noticed in addition
    yoursite bar
    complus applications
    the grideon software
    scooby doo home viedo dat and other files


    NSS still shows up as disabled on the services.msc program
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have viewing of hidden file enabled? Those items should have been there.

    I added a message below awhile ago when I noticed that I still had the prefetch instruction in there and had deleted it.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can you bring up Add/Remove programs now while in safe mode?

    Do you have the software to reinstall your Symantec stuff? The reason I ask is because I want to uninstall it while in safe mode because I think it may be conflicting with Kaspersky which we need to run.
     
  11. drjimref

    drjimref Private E-2

    I will check. It was checked this morning to see all files.

    Back in a minute.

    Question can I get to it with the sub explorer program to check Yes I have
    show hidden files checked on the program.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Never mind! ExploreXP shows all by default.

    Just give me an answer to the Symantec question below!
     
  13. drjimref

    drjimref Private E-2

    I looked again but did not see the programs we were looking for. Some empty dat files that have 0 dat but look funny.

    Add/remove will not work from hjt or main program. Flicks on a second and then is gone again.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Third time I'm asking this:

    Just give me an answer to the Symantec question below!

    Also what are the names of the dat files?
     
  15. drjimref

    drjimref Private E-2

    from 63 Add/remove will not work from hjt or main program. Flicks on a second and then is gone again.

    I will go back and check the other. Just some blank data files sitting in the folders where I was looking to delete what you requested.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's not what I'm referring to! Read message # 60 again.

    What are the filenames that end in .dat what are the file dates too. You may want to click on the column labled Date Modified and see what else you find for the same date. There could be more of those bad .exe files from the HSA infection.
     
  17. drjimref

    drjimref Private E-2

    all with 0 size
    atlxw.exe
    evyel.txt
    jvafl.txt
    kfrcw.dat
    ofzrm.dat
    qgzpu.dat
    sfxsw.dat
    skpog.txt
    xzzuy.dat
    klkh.dat
    last entry in winit is one of the large number files like you show in hjt with starting 677....for about 20 characters and .dat ending and 1kb size

    yes I have the pcanywhere software. but not able to get to add/remove
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Delete all of the below:
    atlxw.exe
    evyel.txt
    jvafl.txt
    kfrcw.dat
    ofzrm.dat
    qgzpu.dat
    sfxsw.dat
    skpog.txt
    xzzuy.dat
    klkh.dat

    I don't follow the below:
    Not PC Anywhere. Do you have the Symantec Antivirus disks to reinstall? I know we cannot uninstall. I would just use HJT to remove the registry entries to stop some of it from loading. We may need to reinstall later to fix (if the HJT backups do not work out for us).
     
  19. drjimref

    drjimref Private E-2

    I will go back and look at dates. Is there a problem deleting these with 0 data or 0 txt?

    Apreciate the help. Wife just called to check on me. Must have fig that I had gotten lost.

    Sorry about the fog but a long day.

    Thanks for all the help.

    What else are we looking for?
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you see my previous message? You have to alway remember to look for more messages in between posting your own.
     
  21. drjimref

    drjimref Private E-2

    Strange stuff in the dates from the last two weeks.
    folder.httzzk in programs

    in winit
    syszh32.exe
    xzzvy.dat 2.12.05

    In the last two weeks there are bunch of new exe and dat files and strange dat files that show listed. Tried to copy names but did not work. Of course I have down loaded about a dozen help clean programs too in the last few days.

    I have to go. the screen is running together and I have to be back here at 7:30 am.

    The file I am talking about uses the {677....} characters similar to some of the hjt lines that use this to define a file.

    Will delete in the am. Thanks again.



    JIm
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What is winit do you mean winnt?

    Delete these: syszh32.exe and xzzvy.dat

    Do not reboot this PC. Will talk with you later when you and I are both back.
    Did you delete the other list of files I told you to delete?

    You must always remember to look back for new unanswered messages each time you post. You could miss important info. Also always answer questions ASAP.

    I don't remember seeing and lines in your HJT log with {677....}
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you mean you see filenames like the CLSIDs from the O2 BHO lines. CLSIDs look something like:
    {B8392868-66F4-2587-FD0D-0AC72FFCD1EA}

    with the braces included.
     
  24. drjimref

    drjimref Private E-2

    Yes {674b661b-d323-4792-b8da-91af350b0234}.dat 9.08.04

    Back in August of I had a crash and had the policy go only to the ins companies because of problems.

    Lady went to look up a med she was given by md and got the about:blank problem.

    Thanks for the help. I will go in and delete the noted data files.

    Nss still shows up as disabled so far. but shows up.

    I await your comand.

    Would it be easier to try to reconnect and transfer the dental package to the backup machine so that I can set this one to the side to fix or format and reinstall? Dell 4600 2.4 gig with 256.
    The only problem is it came with xp home and I had a tech that has since moved set it up to win 2000 pro. He spent more time looking for drivers than anything. Sad that dell will only put xp and you can not get 2000 pro on regular machines afaik with out getting over into their servers and other systems.

    Let me know.

    Jim
     
  25. drjimref

    drjimref Private E-2

    deleted the files.

    other odd ones if I do not mispell them too badly. Hard to tell what is a bug and what we downloaded the last few days.

    n_yeudto.txt 101k
    n_xzzvyc.dat 101k there are 7 of these files in txt or dat all starting with n_ ??

    ucypk.dat 8k
    wrzen.dat 8
    d3an32.exe 0
    civyi. at 8k
    ncyun.txt 12k
    usatl.exe. 8 k

    are some more but there are still other dat/txt and exe/dll in the list by date most current

    Let me know if I can reboot in safe and nw and try to copy dental program to other computer so I can work. I do not want to lose 5 hrs worth of work but sure need to get dental package up to work.

    Jim

    per your msg I was using the hjt to point out the type of line it is not there but just a .dat file and the only one in winit folder
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By all means if you need to get stuff off this computer for business, do what you need to do. Just avoid, if possible, connecting it to the internet. Do not run anything you do not need to run. If you need to boot in normal mode to do this then go ahead. Just let me know what you had to do.

    Yes, it can be easier sometimes to reformat a PC. However that would mean you must have the ability to backup all necessary data and programs first. And you must have the knowledge to reinstall everything and setup everything to get you back to where you were. Sounds like you may have problems getting a Win 2000 install to work for you again since it will not have all the drivers you may need.

    Let me know what you decide to do.

    If you decide to keep working on this PC, please post a current HijackThis log back here after you complete doing whatever you need to do to get your Dental package transferred.
     
  27. drjimref

    drjimref Private E-2

    Ready to go this pm.

    I did a nero burn and got the package up on a old dell so I can leave this one off. line.

    When I did the upgrade several years ago. The dental people did not suport Xp and were not sure of xp pro at the time so I have win pro 2000. Now the people support the xp pro so my next will be a dell with xp pro as the small network hub and it will run with xp or win 200 pro on the other computers.

    I have two win 2000 pro here and one xp and two xp at the house and three old 98 sec ed around. I am really lost since I can not do one program much less three operating systems.

    Let me know. Worst case it to burn some more files and put the win xp family back on if I have to.
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's see a current HJT log on this baby.
     
  29. drjimref

    drjimref Private E-2

    Posted.
    still in safe mode.
    Tried to get into add/remove programs no luck. A?R stay on about a second now is the only difference.
     

    Attached Files:

  30. drjimref

    drjimref Private E-2

    CL, What do you think?

    Try a few more times before learning how to install windows xp?

    Thanks again for all the help.

    Jim
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Here are a few things I want you to try:

    Do you have your Win 2000 Pro CD?
    Is the CD already at SP4 level?

    Run ExplorerXP and navigate to c:\winnt and locate explorer.exe. Right click on it and select Properties. What is the Size of the file? I don't care about Size on disk. Just the line that says Size: It will show two numbers. One in KB and the other in bytes. I want the one in bytes.
    Also now click on the Version tab and give me the file version.

    Also look on your harddisk for a folder named i386 . It may be c:\i386 or c:\winnt\i386
    Look for explorer.exe in there two. It may appear as explorer.ex_
    Let me know if you find the i386 folder and an explorer.exe or an explorer.ex_ in the folder. If you find both, tell me that too.
     
  32. drjimref

    drjimref Private E-2

    Do you have your Win 2000 Pro CD? YES
    Is the CD already at SP4 level? PROB NOT SP 2?

    I want the one in bytes.
    243,472
    Also now click on the Version tab and give me the file version.
    5.0.3700.6690
    Also look on your harddisk for a folder named i386 . It may be c:\i386 or c:\winnt\SERVICEPACKFILES\i386 IS WHERE IT IS LOCATED
    EXPLORER.EXE 243,712
    NO OTHERS
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What is the version number of the one in c:\winnt\SERVICEPACKFILES\i386

    You should also look for explorer.exe in c:\winnt\system32\dllcache

    And go back and get the Created and Modified dates and time for:
    c:\winnt\explorer.exe
    c:\winnt\SERVICEPACKFILES\i386\explorer.exe

    You should also look for explorer.exe in c:\winnt\system32\dllcache
    and get me size, version, and Created & Modified dates for it too.
     
  34. drjimref

    drjimref Private E-2

    What is the version number of the one in c:\winnt\SERVICEPACKFILES\i386
    5.0.3700.6690

    I SEE ZIPPED FILES FOR SP4.CAB

    You should also look for explorer.exe in c:\winnt\system32\dllcache NONE

    And go back and get the Created and Modified dates and time for:
    c:\winnt\explorer.exe
    WED 7.23.03 02:03:21PM
    THUR 6.19.2003 1:05:04 PM
    c:\winnt\SERVICEPACKFILES\i386\explorer.exe
    WED 7.23.2003 2:03:24 PM
    WED 08. 08:2004 10:54:19 AM

    You should also look for explorer.exe in c:\winnt\system32\dllcache NOT SEE IT
    and get me size, version, and Created & Modified dates for it too.
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I cannot find anything really wrong with those files. That does not mean that they are clean though. Malware could make changes and maintain sizes and dates just to throw you off. See if you can get the Kaspersky Anti-Virus to run right now in safe mode.
     
  36. drjimref

    drjimref Private E-2

    Let me know what you think. Is it worth it or is it time to say uncle and move on? We have looked at th is several times and got some progress but still no add/remove. Let me know what you think?


    When we had the August crash the tech did not rebuild but cleaned and it has been working well till we got this. I have never done a format/ load xp but did several for 98 se. I will copy the needed files to disk if needed only a few document files and such and save them.

    Would it do any good to save the drivers for the win pro 2000 or would there be too many bugs lurking there if I wanted to format/reload pro 2000?

    Thanks,

    Wife said come home now if I want to get in the h ouse tonight.

    Jim
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See my previous message and also download and run this:

    http://securityresponse.symantec.com/avcenter/FxIstbar.exe


    Then boot into normal mode and post a new HJT log.

    Drivers you may need could be scattered all around. It would more than likely be much easier to go to XP rather than try to get Win 2000 running again. Let's see what normal boot shows. If clean we will connect to the internet. That will be the deciding point. If the infections come right back, you would get your PC back faster by formatting and load XP.
     
  38. drjimref

    drjimref Private E-2

    SCANNING now and will let it run.
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    OK! See my below message for what's next. Go home! That's where I have to go now too. And it is snowing very hard. May take awhile to get there (35 miles).

    Talk with you later.
     
  40. drjimref

    drjimref Private E-2

    I will stay another 20 minutes to see what happens. It has found 1 bug so far. Then run program and boot and post log.

    Thanks,
    Be safe going home. I am close to Houston- no snow but plenty of rain today.
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please note exactly what is found by name (virus name) and also the file and path if given.

    Path is something like: c:\winnt\system32 just an example
    File is: explorer.exe just an example

    I'm outta here!
     
  42. drjimref

    drjimref Private E-2

    CL, I lied and went home. The Kav5 program ran quickly to 40% completete then hit the NOrton quaratine file and slowed up. Not sure it was looking at the definitions or that the man last summer never cleaned the q file when he fixed it. It had found 4 or 5 virus then when it hit the above Norton it was at say 150 when I left and continuing to add as it ran thru the q file.

    We will see today.

    Hope you made it home ok in the snow. It was 50 here last night and still draining the 2 -3 inches of rain we had from the am.

    Poeple in the Houston area can not drive on dry roads much less rain. Most have never seen snow/ice the last few years much less try to drive in it.

    The trend online site found many that norton didnot when it was run. My script for Norton on some and McAfee on other machines area about up. You rec several. Which is best for wife and family? I plan to put your recomenatons sheet to work today on their machines.

    I had told people do not get online and surf on the main machine. Just go and down load dental benefits from our set companies. Office mgr went to check a drug she was given and mispelled it and was asked "Is this what you mean" and bang about:blank.

    I would love to see the guys that wrote this stuck up in the Huntsville Texas state pen with some of these big old country boys from East Texas as cell mates.
     
  43. drjimref

    drjimref Private E-2

    Looks better and I can get into the add/remove.

    Log attached.

    02 has an about:blank statement.

    NNS still shows up as disabled in the services.msc

    properties shows c:winnit\system32\winls32.exe /s

    did not see it in the explorer program. Not sure how to see all inc system files will check.

    JIm
     
  44. drjimref

    drjimref Private E-2

    CL,

    Rebooted and ran spybot, cc hs, about buster
    ab found
    in sys32 folder mpqwo.dat and rmqbw.dat and cleaned
    HS removed 13 items
    spybot got 13
    did a fix and took the R0 line out.

    reran a hjt log and attached.

    We are looking better. Let me know what you think.
    I took the extra ad-aware off and it deleted both that showed the same amt of mem in add/reomve.
    Still concerned about the NSS being there and not deleted.

    Talk with you later.
    Jim

    They moved the younger daughter's soccer game to 5 so taking off to go.
     

    Attached Files:

  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That log is clean. Is that from normal boot mode?

    Since you can get into Add/Remove programs now, have you looked for all those things we were trying to uninstall? If still there, uninstall.

    For recommendations on which software to use see: How to Protect yourself from malware!
    AVG and Avast are preferred over Norton or McAfee. You can use them for free but they have pay versions with more advanced features too.

    When you boot into safe mode make sure viewing of hidden files is enabled. Can you find:
    c:winnit\system32\winls32.exe

    Go to the below link and run ONLY steps 13l (that's a lower case L) thru 17.
    When all else fails - Generic Solution to HSA (Only the Best) & About:Blank hijack

    Make sure the HJT log from step 17 is for normal boot mode.

    After that see if that NSS service is still around.
     
  46. drjimref

    drjimref Private E-2

    That log is clean. Is that from normal boot mode? YES

    Since you can get into Add/Remove programs now, have you looked for all those things we were trying to uninstall? If still there, uninstall. NOT YET

    For recommendations on which software to use see: How to Protect yourself from malware! HAVE A COPY GOING TO PUT THEM ON MY HOME COMPUTER WHICH AFAIK IS CLEAN AND THEN THE WIFE'S THAT HASJUST SOME HOPEFULLY MINOR MESS ON IT.

    AVG and Avast are preferred over Norton or McAfee. You can use them for free but they have pay versions with more advanced features too.

    WHICH IS BETTER? YOU HAVE TO PAY FOR THE OTHERS ANYWAY. THE TREN MICRO IS NOT AS GOOD? IT HAD FOUND THE 21 BUGS WITH THIS PROBLEM THAT NORTON DID NOT SEE. I HATE MACAFEE AND ALL THE ADD ONS.

    When you boot into safe mode make sure viewing of hidden files is enabled.

    WILL TRY ON MONDAY AT THE OFFICE. I WAS STILL USING THE EXPLORER DOWNLOAD AND NOT WIN EXPLORER

    FOXFIRE INSTEAD OF INTERNET EXP? WHAT ALL IS IT LACK? I USE GOOGLE, KEEP MY FEW BOARD I STAY ON IN FAVORITES AND THAT IS ABOUT IT.

    Can you find:
    c:winnit\system32\winls32.exe

    Go to the below link and run ONLY steps 13l (that's a lower case L) thru 17.
    When all else fails - Generic Solution to HSA (Only the Best) & about:Blank hijack WILL DO ON MONDAY FIRST THING

    Make sure the HJT log from step 17 is for normal boot mode. THANKS WILL TALK ON MONDAY.
    THANKS,
    JIM
    After that see if that NSS service is still arou
     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Jim,

    Notice how I used the quote boxes above to distinguish your text from mine! You should try to use them. It makes it easier to read messages that way. You can interlace more as you can see in this message.

    Are you asking me which is better? TrendMicro is very good too. If you don't mind paying for the software, any of the three versions (AVG, Avast, or PC Cillin from Trend) are good. If you want to sample one for awhile to see how you like it. Try the free versions of either Avast or AVG . I have given the free version of Avast to several people who are bad about doing updates. Once you install it and set it up, it updates automatically (set it and forget it). This is great for many users.

    I'm looking forward to seeing the results.
     
  48. drjimref

    drjimref Private E-2

    CL About:Blank

    Checked everything listed and found nothing.

    Went into exp and set the switch to see all inc system files and still cannot find c:winnit\system32\winls32.exe did reset the switches and tried again and tried search of c:\ and for different set ups like winls*.* and still nothing.

    services.msc still shows it to the above address and displays as disabled.

    I will go on and run the other items from your handout but fig we have to find the NSS file to be safe.

    Thanks,

    Jim
     
  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: CL About:Blank

    Has this PC been connected to the Internet yet?

    Please download GetService.zip from here: Getservice.zip

    Extract the file to a folder where you can find it, then go to the folder and double-click on the getservices.bat file. A notepad will open up. Please paste the contents of that notepad file as an attachment too. Call it service.txt.
     
  50. drjimref

    drjimref Private E-2

    NO it has not.

    Just came in and rebooted in safe to look for problems.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds