About:Blank

Discussion in 'Malware Help (A Specialist Will Reply)' started by drjimref, Feb 22, 2005.

  1. drjimref

    drjimref Private E-2

    Here is file. Still in safe mode from before. Never did 13.l yet.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run HijackThis click on the "Open the Misc Tools Section" button on the open page. Then select "Delete an NT service" on the left-hand side. A "Delete a Windows NT Service" window will pop up. Try entering the following into the box and then click OK:

    Network Security Service (NSS)

    If that does not work try entering the short name: ?%AF夶À¨

    Then reboot and let's see if the service is truly gone.
     
  3. drjimref

    drjimref Private E-2

    ?%AF夶À¨ flolder
    was the first thing found in the registry edit when I got to the area that you wanted me to look. None of the other stuff was found. Deleted then ran adaware and spybot and both found items.


    Just rebotted and NSS was gone.

    HJT log attached.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's time to reboot in normal mode and get a HijackThis log.

    It that looks okay, the next step would be to reconnect to the internet and open one browser session, let it connect, and then close the browser and get another HJT log.
     
  5. drjimref

    drjimref Private E-2

    I did that then rebooted and looked at the log and did not see anything. Connected to net then off checked then down loaded the first listed free virus protection package and installed it since I had taken Norton off during the time we have worked on it. Updated the virus package and left the computer running the scan. I had also updated Ad-aware too.

    What does the interface with foxfire look like? Would it work with this office computer where the most they should be doing is looking at clients insurance benefit information and nightly connecting and sending out the dental claims?
    Work= similar enough for the staff to find what they need with out problems.

    I will post the log first thing this morning so if it looks clean I can get the main computer back up and running.

    Thanks- Jim
     
  6. drjimref

    drjimref Private E-2

    Here is the log. After a full reboot. Hope that I can get on line with this computer. I can not see anything but do not know much either.
    Scan was neg other than some norton leftovers.
    Please let me know.

    Jim
     

    Attached Files:

  7. drjimref

    drjimref Private E-2

    Reboot after running all scans still clean afaict.

    Let me know what you think.

    Jim
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks clean Jim! But there are a few things to do.

    First we should remove the Kasperksy AV package you install since you now installed AVG.
    It looks like something remove one of your files for PC Anywhere (see the O23 - Service)


    Have HJT fix the below two lines. These are left over after running HSremove.
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm

    Then reset your home page to what you would like.


    FireFox looks a lot like IE and you can import your Favorites right into it. You will have to
    check to see if it works on the sites you will be going to. Some websites do require IE inorder
    to work properly.

    You need to install a firewall (Sygate or ZoneAlarmFree) and after that it will be time to connect this baby to the web and see what happens. See the following thread which includes info on the firewall links: How to Protect yourself from malware!
     
  9. drjimref

    drjimref Private E-2

    I tried Zonealarm but we seemed to have problems with the other computers seeing the main dental computer. I will play with the setting to see if I can get it attached and working. Any suggestions on how to keep the 3 computers seeing each other and keeping the fw up?

    Thanks,
    Jim
     
  10. drjimref

    drjimref Private E-2

    Thanks,



    I hate PC anywhere. Guess that I will worry about PC anywhere when the dental people need to remote access the program. You know how sensitive it is.

    Thanks,

    Jim
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to define your PC Network in ZoneAlarm. You must put in info on your allowable IP address range, your DNS server, etc. Do you know what I'm referring to?

    But first you could just install it on the problem PC and connect to the internet and see if the PC remains clean. Some of the problems you had could do this.

    It is not safe to run your network without a firewall!!!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just incase you do not understand the idea with ZoneAlarm.

    Ignore the .... below. I'm using them to space the fields out. The message editors do not allow you to space exactly.
    Name...............................Ip address/Site...............Entry Type..........Zone
    Doman Name Server..........your DNS IP address.........IP Address .........Trusted
    DHCP Server.....................DHCP server IP address.....IP Address.........Trusted
    Dental Network..................your network definition.......Network..............Trusted
    Dental Network IP Range....Range of IP addresses......IP Range.............Trusted

    Your DHCP & DNS IP address can be found by running ipconfig /all from the command prompt. It will also show your IP address and Subnet Mask and Default Gateway

    Dental Network (I chose this name) needs to have an IP address and Subnet mask. A typical one may be:
    192.168.1.0/255.255.255.0

    Dental Network IP Range would then allow a range of address to be used for the PCs on your network. Let's assume you want to allow for 10 PCs. You would set the range to 192.168.1.1 - 192.168.1.11 Yes that counts to 11 but you need to leave one address like 192.168.1.1 for your Default Gateway.
     
  13. drjimref

    drjimref Private E-2

    CL, Not sure how to install the addresses. Have them but not sure how to install them in Zone alarm.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Under the Firewall selection look for the Zones tab. Then you will see what you already have configured. You can use the Add button at the bottom to add to your configuration. Pressing F1 while on the Zones screen will bring up some help for you too.
     
  15. drjimref

    drjimref Private E-2

    Glad to see you working today.

    Computer still apears to be clean.

    Internet is working but I cannot get into any of my insurance programs where I have to sign in.

    Also on the in help on about ie I have no information listed where it should show several types of info for version, id ect. All are blank.

    Think it is a loss of i explorer informaiton that is causing the problem or the active x and other changes that I put in?

    Thanks,

    Jim
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Jim,

    Sounds like we made a lot of progress. Perhaps you should post another HJT log now that you have the PC back on line.

    I'm not sure why you are having a problem with your insurance programs. What exactly happens? Can you connect but login is not accepted? Are there any error messages?
    Check your active X settings on this PC with those of another PC where login works.
    Do these programs require IE? Are you sure FireFox cannot be used?

    When you click on Help in internet explorer and select About Internet Explorer, doesn't a window popup? If so, is this where you mean there is not info?
     
  17. drjimref

    drjimref Private E-2

    On the help window-about-on this computer I can see the version/ ciphor strength/update inf and product id. and the stats for each field.

    On the computer that had about:blank you see the above fields but all these fields are blank. There is no information listed at all.

    I had changed all the activeX fields to what was recomended but they are the same on this machine except for one item.
    Mircosoft VM
    Java permissions
    set to high high

    While on the main machine this whole listing for java permissions is missing
    It goes from microsoft vm
    then straight to access data sourses.
    We did put sun micro on the main machine.

    One of the logon scripts is in java for the dental logon. When you click on it nothing happens other that the java statement show up on the line at the bottom of the page. All statements are returning false for any link.

    Other than that the you can surf like regular on the internet.
    Thanks,

    Jim
     
  18. drjimref

    drjimref Private E-2

    CL,

    Pushed an internet explorer 6 download and the program started to work and see the dental insurance program and I can access the screens.

    Thanks,

    Jim
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    OK! Sounding good. But I would still like to see a current HJT log!
     
  20. drjimref

    drjimref Private E-2

    log attached.

    after reload only problem is pc anywhere and lost file.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have HJT fix the below two Alexa related lines:
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm


    As far as the below
    O23 - Service: pcAnywhere Host Service (awhost32) - Unknown owner - (no file)


    It should look something like this:
    O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe

    So look to see if the C:\Program Files\Symantec\pcAnywhere\awhost32.exe files is actually on your PC. If not, copy it from one the other PC to this PC and put it into the proper folder.
     
  22. drjimref

    drjimref Private E-2

    Re: About:Blank fixed

    Hey CL, Great job. Still free except for the minor crud. Will fix it Monday.

    Just downloaded firefox to try as a browser. Looks about the same as ie6. What am I missing other that a bug problem with ie6 othere than learning a few minor differences? Any of the standard settings need to be changed?

    How does the Sun micro java plug into the system? Does it take the regular mS java out or just replace it with Sun to be used in exactly the same way?

    Sure am Glad that I killed Norton on one and McAfee on another computer. The free one looks a lot nicer. Still thinking about tetting the Tren Micro paid program.

    Zone alarm works well for trusted sites inside the office system after your suggestion..

    Thanks again for all the help.

    JimD
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: About:Blank fixed

    Explain minor crud!

    Firefox is very easy to use. I think you will like it. It is safer since it has no active x to worry about and fewer malware creators attack it than IE. You should be able to use it as installed. Just import your Favorites from IE into it.

    Following the steps at the end of the READ ME FIRST having to do with uninstalling MS Java and then installing Sun Java.
     
  24. drjimref

    drjimref Private E-2

    CL, Posting on the other thread was there. Just curious about how many versions there are of about blank. Most have a number in the ro r1 lines and hers had about:blank at the end.

    Installed FireFox and it looks the same. About the only thing I see is I liked to drop to favorites on the line and now have to drag to the fav drop to the side bar.


    Have a great day up there. Daughter in from Baylor and we are off to church then I have to come home and mow the yard. Spring is in down here.

    Minor crud is the ro alexandra line that needs to be removed.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are saying you want your Favorites to appear as a sidebar in FireFox, click View, Sidebar, and select Bookmarks.
     
  26. drjimref

    drjimref Private E-2

    CL,

    Ilie the FF. The only thing I need to fig out is where to increase the font size for the favorites in the side bar.

    You had said with PC anywhere do the following. The file is there but I am not sure why it is not being seen. I can start pcanywhere from the run menu.

    As far as the below
    O23 - Service: pcAnywhere Host Service (awhost32) - Unknown owner - (no file)


    " From you earlier post -It should look something like this:
    O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe

    So look to see if the C:\Program Files\Symantec\pcAnywhere\awhost32.exe files is actually on your PC. If not, copy it from one the other PC to this PC and put it into the proper folder. "
    Do not have it on any other computer. But will work on it some more. IE6 started up but still had quirks from About:blank and worked but lost its id info. Wonder it that happened to this file nad it is not being seen?

    Jim
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You could try running this: IEFix to see if it repairs anything with IE.

    As far as PC Anywhere, you could try uninstalling, rebooting, and then reinstalling.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds