Browser Hijacked about blank?? / Still no Internet connection

Discussion in 'Malware Help (A Specialist Will Reply)' started by mjdak, Jan 29, 2005.

  1. mjdak

    mjdak Private E-2

    Browser Hijacked about blank??

    Help please...My internet connection worked fine earlier tonight. Now I cannot connect with either IE or Firefox. I have followed the basic instructions for removing spyware as instructed here, but still about blank is showing up and no connection or browsers working. I am able to connect in safe mode. OS is Windows XP Pro, Dell 8250 2 yrs old. It seems like I will need specific instructions to clean this up and I would appreciate any help anyone can give. Thanks.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Browser Hijacked about blank??

    First, please run as much of the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal as you can and run them in the order indicated. If you still have a problem, after that, follow the guidelines below and post your HJT log.

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. mjdak

    mjdak Private E-2

    Still no Internet connection

    Here is my Hijack This Log. About Blank appears to be gone after a few more tweaks, namely having HJT fix it. Nothing appears in Spybot or any of the virus scans. Still can't connect except in safe mode. Attached is the log I hope.
     
  4. PhilliePhan

    PhilliePhan Guest

    Re: Still no Internet connection

    Your log didn't attach. I'll merge you back into original thread so Chas not confused :)

    PP
     
  5. mjdak

    mjdak Private E-2

    I think I attached the HJT text this time.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nope! Not yet. Are you clicking upload? What file name did you use? Watch for error messages in the Manage Attachments window.
     
  7. mjdak

    mjdak Private E-2

    Upload errors. Attachment in progress but nothing happens. I'll try again. Thanks for your patience.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That log looks like it is from a safe mode boot. HJT logs must be from normal boot mode.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also note: You must only run one software firewall. You are running at leasts two and possibly three. You have Sgate and Norton's. Did you disable the WinXP SP2 firewall?

    You must pick which one you want from Norton and Sgate and uninstall the other. Do not use the one from Windows. It is not good enough.
     
  10. mjdak

    mjdak Private E-2

    I'll reboot in normal mode and then get it and come back in safe mode to post.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you see my message about the firewalls? That could be your problems with not being able to connect.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're moving a little too slow!

    I have to get some sleep now! It's 3:42 am here! We'll have to continue later.

    Make sure you read my message about the firewalls and take care of that.
     
  13. mjdak

    mjdak Private E-2

    Sorry for the delay. I have to reboot into safe mode to connect. The firewall does not seem to be the problem. Here is the HJT in normal mode.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have both firewalls installed! I repeat you MUST remove one!
    And did you disable the WinXP SP2 built-in firewall?
     
  15. mjdak

    mjdak Private E-2

    I'll remove spygate and check on WinXp2 Firewall. Will get back with you tomorrow. Thanks for your patience.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay after Sygate is removed and WinXP SP2 firewall is disabled. Reboot and let me know where things stand.
     
  17. mjdak

    mjdak Private E-2

    Problem fixed. Internet connection okay. I gues sygate doesn't play with Symantec too well. Thanks for the help. Now I can sleep! BTW....did the HJT look ok for anything else? Peace.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have HJT fix the O9 line with (no file)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)


    This next line I would bet is not needed and is a waste of system resources:
    O4 - HKLM\..\Run: [sr1exe] "C:\Documents and Settings\All Users\Application Data\Dell\Alert\252\updtSup3.exe"


    Questions:

    Do you know What the below are for?
    O4 - HKLM\..\Run: [SAClient] "C:\Program Files\Insight\BBClient\Programs\QicSetup.exe" /AfterReboot
    O16 - DPF: {0335A685-ED24-4F7B-A08E-3BD15D84E668} - http://dl.filekicker.com/send/file/128985-NZIL/PhPSetup.cab
    O16 - DPF: {56281C46-2A92-45F1-863D-E214733EB2D6} - http://www.cursorzone.com/cursors/cross_setup_td035.cab
    O16 - DPF: {FB48C7B0-EB66-4BE6-A1C5-9DDF3C37249A} (MCSendMessageHandler Class) - http://xtraz.icq.com/xtraz/activex/MISBH.cab
     
  19. mjdak

    mjdak Private E-2

    Thanks, I will have HJT fix the 09 and 04 line. The InsightBB is my internet provider and the QIC setup is a configuration/troubleshooting utility that begins at startup. The ICQ has something to do with the ICQ instant message program. Not sure about the others. Thanks for your great help.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. I would recommend running HJT again and fixing any of those O16 lines that you do not recognize. If they really are valid and required but a website you use, they will redownload the next time you connect to them anyway.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds