help with about:blank

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by flyers, Dec 9, 2004.

  1. flyers

    flyers Private E-2

    i am running windows xp and i have the nasty about:blank. i followed all of the instructions in the sticky. adaware removed 21 objects, spybot fixed 6 problems. for some reason i couldn't run aboutbuster. hsremove removed 10 items, but it didn't reset my homepage. about:blank is still there. here is my hjt list. please help me. thanks
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your version of Win XP is seriously out of date. You need to get updated after we get you fixed up (it is not always a good idea to update, especially to XP SP2 with malware problems present). When we finish you should read: How to Protect yourself from malware!

    It would be a lot more help if you explained why About:Buster would not run. For example did you get an error message? State the exact error message. You may just be missing some files. If you receive an error message about a missing MSCOMCTL.OCX file when you run about:Buster, download the file in the link below and run it. It will give you the necessary file.

    http://www.javacoolsoftware.net/downloads/missingfilesetup.exe

    Next time please wait for someone to ask you to upload you HijackThis log. Before going any further please put it in the proper type directory as we requested in the tutorial. You have it here:
    C:\Documents and Settings\Keith\Local Settings\Temp\HijackThis.exe

    We request that not be in any temp folder nor be in any subdirectory of c:\Documents and Settings. Please move it to c:\Program Files\HJT or c:\Program Files\HijackThis or even C:\Program Files\SpywareTools.

    Make sure you have done the following 3 items before continuing:
    - HijackThis installed in the proper directory
    - you have system restore disabled
    - you have viewing of hidden files enabled (per the tutorial).

    1) Go here and download Registrar lite and install it: http://www.majorgeeks.com/download469.html
    2) Run it, copy and paste this line to reglite's address bar:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
    3) Click the "go" tab
    4) Find: "AppInit_Dlls" value on the right side panel.
    5) DoubleClick on AppInit_Dlls and tell me exactly what you see in the Value field:

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Keith\LOCALS~1\Temp\sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Keith\LOCALS~1\Temp\sp.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Keith\LOCALS~1\Temp\sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    O21 - SSODL: Sysctl Desktop Handler - {23456789-0000-0020-0900-00AAFF6D2EA4} - C:\WINDOWS\System32\ntosv.dll
    O21 - SSODL: eplrr - {41C8BFDC-F9EE-4688-86BA-6B871B97510C} - C:\WINDOWS\System32\eplrr3.dll
    Noramlly I would reboot to safe mode here and delete bad files. However the two files from your log that I mention below are not clearly declared to be a problem. I believe they are but to be safe I will ask you to rename that rather than delete them.
    So boot into safe mode and use Windows Explorer to rename the files below as specified:
    C:\WINDOWS\System32\ntosv.dll to C:\WINDOWS\System32\ntosvdll.bad
    C:\WINDOWS\System32\eplrr3.dll to C:\WINDOWS\System32\eplrr3dll.bad

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  3. flyers

    flyers Private E-2

    sorry about the hijack this log. for some reason when i ran about buster, it said missing or corrupted file, but i tried it again this morning, and it worked. there was nothing found with the scan. i moved hijack this to C/program files. system restore is disabled. hidden files are enabled. i did registrar lite, copied and pasted. the value had nothing in it. i am going to do the hijack this instructions now, and i will report back to you soon. thanks for all your help.
     
  4. flyers

    flyers Private E-2

    here is my new hjt log.
     

    Attached Files:

  5. flyers

    flyers Private E-2

    sorry i forgot about rename the last 2 files. here is the newest hjt log. thanks again. i still get the white desktop with the color changing to grey. i tried to cahnge my desktop, but it didn't work. any suggestions.
     
  6. flyers

    flyers Private E-2

    here is the lastest hjt log uggh!
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not put HijackThis in the proper directory yet.
    And why do you keep having WinZip running?

    C:\PROGRA~1\WINZIP\winzip32.exe
    C:\Documents and Settings\Keith\Local Settings\Temp\HijackThis.exe

    You could have lost all of your HJT backups now. Especially if any disk cleaners like CCleaner have been run. You were suppose to fix that before continuing.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have HJT fix the following two lines:
    O21 - SSODL: Sysctl Desktop Handler - {23456789-0000-0020-0900-00AAFF6D2EA4} - C:\WINDOWS\System32\ntosv.dll (file missing)
    O21 - SSODL: eplrr - {41C8BFDC-F9EE-4688-86BA-6B871B97510C} - C:\WINDOWS\System32\eplrr3.dll (file missing)


    Exit HJT.

    Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot! And then get a new HJT log and post it back here.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds