Is the about blank virus in here somewhere

Discussion in 'Malware Help (A Specialist Will Reply)' started by GAZ W, Jan 30, 2005.

  1. GAZ W

    GAZ W Private E-2

    The log from hijack this...is the about blank virus in there somewhere ? if so what do i have to delete to get rid?

    Logfile of HijackThis v1.99.0
    Scan saved at 16:25:15, on 30/01/05
    Platform: Windows 98 SE (Win9x 4.10.2222A)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Edit by chaslang: Unrequested inline log deleted

    thanks
     
    Last edited by a moderator: Jan 30, 2005
  2. jarcher

    jarcher I can't handle a title

    Have you already gone through this sticky if not please do so. . .
    READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal:
    if you have double check everything and make sure you did do everything
    and all software is up to date

    Run through this before attaching a log
    NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting:
    *Note that your HijackThis should be up-to-date (v1.99) and MUST be extracted to its own safe folder - C:\Program Files\HijackThis! Please do this!!!*
     
  3. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    NOTE: You are infected by the about:blank hijacker and need to complete all steps listed above is the stickies. The more you co-operate and the more information you provide us, the better we can assist you.

    NOTE: When posting HJT or any other log for assistance please attach it to your post, NEVER post an inline log. This will be removed by a mod. Please remember to always post your log as an attachment.

    Thanks, Bj:)
     
    Last edited by a moderator: Jan 30, 2005
  4. GAZ W

    GAZ W Private E-2

    ok ive done all the above and gone through eveything there , downloaded all the progs and run them in that order

    This is my HJT log now

    Edit by chaslang: Inline log deleted. Please follow directions!
     
    Last edited by a moderator: Jan 30, 2005
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you keep skipping steps of the READ ME FIRST and ignoring the fact that we asked you multiple times not to post inline logs, you are not going to get anywhere.

    ALL steps of the READ ME FIRST must be run. The online scans are not optional steps and you did not run them.

    Note when finished resolving your current problems you must go to Windows Update and get you system updated. At a minimum I can see your Internet Explorer is out of date and represents a security risk.

    Also answer a question. Do you know what the next line is for?
    O4 - Startup: Startup.exe

    Are you using some kind of startup manager?
    Or is this related to an incorrectly installed Linksys Wireless-G utility?

    If not, it may be malare!
     
    Last edited: Jan 30, 2005
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's try to keep you moving along!

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://c:\windows\TEMP\sp.dll/sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://c:\windows\TEMP\sp.dll/sp.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    O2 - BHO: (no name) - {4F70BDC1-DB0C-4B38-BB8B-38EE51C22FF0} - C:\WINDOWS\SYSTEM\DNJE.DLL

    As I asked before, what do you know about the below Startup.exe line? If you don't know what it is, fix it too.
    O4 - Startup: Startup.exe

    O16 - DPF: {11111111-1111-1111-1111-111111113458} - file://C:\WINDOWS\Tempor~1\Content.IE5\OHYZ09M3\explorer38[1].cab
    O16 - DPF: {45231111-1111-1111-1111-111111113458} - file://C:\WINDOWS\Tempor~1\Content.IE5\KXMNCD23\epl28[1].cab
    O18 - Filter: text/html - {DA70AD68-B53A-43CA-8D51-EFA6129CA528} - C:\WINDOWS\SYSTEM\DNJE.DLL
    O18 - Filter: text/plain - {DA70AD68-B53A-43CA-8D51-EFA6129CA528} - C:\WINDOWS\SYSTEM\DNJE.DLL

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\SYSTEM\DNJE.DLL

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again.

    Now empty your Recycle Bin.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log (as an attachment). And tell us how things are working.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds