MyTechSupport.ca :: Your Computer Technical Resource Headquarters! MyTechSupport.ca :: Your Computer Technical Resource Headquarters!
HOME FORUMS RESOURCES & TOOLS ARTICLES ONLINE STORE ABOUT US
Computer Support Forums arrow Internet & Network Support arrow Security & Viruses arrow Topic: about blank
June 05, 2020, 06:16:57 PM
 

Home Forum Rules Help Search Mobile Version Login Register

Welcome, Guest. Please login or register.
Did you miss your activation email?
June 05, 2020, 06:16:57 PM

Login with username, password and session length
 Featured Sites:
News
New  Check out our improved Download section for tons of software....
  0 Members and 1 Guest are viewing this topic.
Pages: [1] Go Down Print
Author Topic: about blank  (Read 4828 times)
delboy
Newbie
*

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 5


Bookmark and Share

View Profile
« on: June 30, 2004, 04:46:56 PM »

PLEASE SUPPLY RELEVANT INFORMATION:
Operating System Version:xp professional
Problem Application Name & Version:ie v6 sp1
Problem Hardware Make & Model:
Error Messages:



Hi can someone please help me get rid of this about blank problem.I have run various spyware programmes but the problem remains.I,m attaching a hijackthis log file.Many thanks in advance.

Download Attachment: logfile.txt 5.81 KB
Right click and select Save Target As... then rename the file as shown here and save.
Logged

 
Cactus
Security & Virus Specialist
Global Moderator
Hero Member
*****

Karma: +2/-0
Offline Offline

Gender: Male
Posts: 4327


Bookmark and Share

View Profile
« Reply #1 on: June 30, 2004, 04:53:39 PM »


Delboy's HJT Logfile

Logfile of HijackThis v1.97.7
Scan saved at 17:19:06, on 30/06/2004
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\System32\E_SSRP03.EXE
C:\Program Files\Norton Internet Security Professional\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\NVATray.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Norton Internet Security Professional\Norton AntiVirus\SAVScan.exe
C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\Program Files\Common Files\EPSON\EBAPI\SAgentNT.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\EPSON\EBAPI\EBRR.EXE
C:\Users\SENDER\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\derek\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\derek\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\derek\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\derek\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\derek\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\derek\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.usefulware.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E94DA5D-D09B-4AD7-8239-F207F1E73FE5} - C:\WINDOWS\System32\dppj.dll
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security Professional\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security Professional\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NVIDIA nForce APU1 Utilities] NVATray.exe
O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe /startup
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security Professional\UrlLstCk.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
O4 - Startup: Norton Disk Doctor.LNK = C:\Program Files\Norton SystemWorks\Norton Utilities\NDD32.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV03.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{81A971E7-05FF-4FF8-9E3B-0408B7FC5D3E}: NameServer = 213.120.62.103
O17 - HKLM\System\CCS\Services\Tcpip\..\{CEA7E1E8-88A6-434F-AC52-25C342A518FB}: NameServer = 213.120.62.103,213.120.62.105


« Last Edit: June 30, 2004, 04:54:36 PM by Cactus » Logged

**PLEASE**.....do not post your hijack log in someone else's thread. Start a separate thread HERE! Thank you.

cactus@mytechsupport.ca

My System Specs

Avg Antivirus::Ad-Aware::Spybot::Windows Update::Recuva
Malwarebytes::SUPERAntiSpywareFREE
benditup
Hero Member
*****

Karma: +2/-0
Offline Offline

Gender: Male
Posts: 2105


Bookmark and Share

View Profile
« Reply #2 on: June 30, 2004, 08:15:15 PM »

HI Delboy, could you please download and Install
FindnFix.exe

from that link

Run the "!LOG!.bat" file, wait for the final output (log.txt)
post the results....

I also noticed that you have SpyKiller---If it's the free version
please use your Add/Remove Programs to uninstall it----- We'll get you
free spyware removers later
I also Notice that you are controlling programs on Startup via MSCONFIG
Not that there's anything wrong with that but you may be hiding other
Malicious activity
We'll deal with that later, could you post that FindnFix log first,
thanx....
Logged

 
delboy
Newbie
*

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 5


Bookmark and Share

View Profile
« Reply #3 on: July 01, 2004, 06:46:52 AM »

Hi benditup, I,ve done what you said and I have attached the log file  below hope you can help.
Thanks

Download Attachment: log.txt 8.12 KB
Right click and select Save Target As... then rename the file as shown here and save.
Logged

 
benditup
Hero Member
*****

Karma: +2/-0
Offline Offline

Gender: Male
Posts: 2105


Bookmark and Share

View Profile
« Reply #4 on: July 01, 2004, 07:14:22 AM »

Open the FINDnFIX folder and then open the keys1 folder. Right-click on the MOVEit.bat file and select 'edit'.
 That will open the file as an empty text file - copy and paste this line into the blank file:

move %WinDir%\System32\WINMF.DLL %SystemDrive%\junkxxx\WINMF.DLL

Save the file and close.
This Next Step will cause your computer to Restart
Still in the keys1 folder, double click on FIX.bat. You will get an alert of about 15 seconds before reboot - allow it to reboot.

On restart, open the FINDnFIX folder again and double-click on RESTORE.bat. When it is finished, in FINDnFIX folder, there will be a file called Log1.txt - post it's contents in your next reply.

==============================================================
==============================================================
Important Note:
Occasionally when trying to edit the MOVEit.bat file the following error occurs: "Windows cannot find "C:FINDnFIX\keys1\MOVEit.bat. Make sure you typed the name correctly then try again."

If that happens, skip that step and proceed this way instead. In the keys1 folder, double click on FIX.bat. You will get an alert of about 15 seconds before reboot - allow it to reboot. On restart, open Explorer and navigate to C:\Windows\System32 folder, find the WINMF.DLL file (it should be visible now). Highlight the file and using top menu, click Edit>Move to folder...

Select C:\junkxxx as destination. Move the file.

Open the FINDnFIX folder again and double-click on RESTORE.bat. When it is finished, in FINDnFIX folder, there will be a file called Log1.txt - post it's contents in your next reply.
Logged

 
delboy
Newbie
*

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 5


Bookmark and Share

View Profile
« Reply #5 on: July 01, 2004, 08:08:51 AM »

Ok Benditup have done what you said and am attaching log1.txt.Hope i,m doing this right.

Thanks
D

Download Attachment: log1.txt 8.34 KB
Right click and select Save Target As... then rename the file as shown here and save.
Logged

 
benditup
Hero Member
*****

Karma: +2/-0
Offline Offline

Gender: Male
Posts: 2105


Bookmark and Share

View Profile
« Reply #6 on: July 01, 2004, 06:52:44 PM »

Good Work Delboy,
A couple more steps and you hopefully should be completely clear of this

Open the FINDnFIX folder again and open the Files2 folder. Double-click on the ZIPZAP.bat.
It will quickly clean the rest and will make a copy of the bad file(s) in the same folder (junkxxx.zip)
It will open your email client with instructions. Simply drag and drop the junkxxx.zip file from the folder into the mail message and submit to the specified addresses.
If you decide to email you will have to link to this thread

RESTART your computer and delete the whole FINDnFIX folder and files

Do another Scan with Hijackthis and post it for some final cleaning
Logged

 
delboy
Newbie
*

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 5


Bookmark and Share

View Profile
« Reply #7 on: July 02, 2004, 09:39:40 AM »

Ok benditup I have done what you said and when I opened my browser thankfully the about blank was gone.I am attaching the new hijackthis log hopefully it is ok. Many thanks for your help I would never have been able to get rid of that myself.D

Download Attachment: hijackthis2.txt 5.03 KB
Right click and select Save Target As... then rename the file as shown here and save.
Logged

 
benditup
Hero Member
*****

Karma: +2/-0
Offline Offline

Gender: Male
Posts: 2105


Bookmark and Share

View Profile
« Reply #8 on: July 02, 2004, 06:47:17 PM »

Did you uninstall Spykiller? I would if it's the free version...
Let's do some final cleaning
If you haven't done so already,
Download CWShredder and save to Desktop---the usual link is down, try
this one
http://www.soft32.com/download_19014.html

Assuming you have already uninstalled spykiller
Do another Scan with Hijackthis and put a check next to these entries and then FIX CHECKED when ALL other windows are closed

O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup

Next would you open up CWShredder and let it FIX all problems

RESTART your computer
Find and delete this folder if it exists
C:\Program Files\SpyKiller <---this folder

Don't open a browser yet, instead access Internet Options via Control
Panel
Under the Programs tab "Reset Web Settings"
Under the General tab---Delete files + offline content---Also Reset home page
additionallly---Do a Disk Cleanup

If you haven't done so already
Download and Install Ad-Aware

CHECK FOR UPDATES
Do a custom scan
click the gear wheel at the top and check these options:

General> activate these: "Automatically save log-file" and "Automatically quarantine objects prior to removal"

Scanning > activate these: "Scan within archives", "Scan active processes", "Scan registry", "Deep scan registry", "Scan my IE Favorites for banned sites" and "Scan my Hosts file"

Tweaks > Scanning Engine> activate this: "Unload recognized processes during scanning."

Tweaks > Cleaning Engine: activate these: "Automatically try to unregister objects prior to deletion" and "Let Windows remove files in use after reboot."

Click "Proceed" to save your settings, then click "Start", make sure "Activate in-depth scan" is ticked green then scan your system. When the scan is finished, the screen will tell you if anything has been found, click "Next". The bad files will be listed, right click the pane and click "Select all objects" - this will put a check mark in the box at the side, click "Next" again and click "OK" at the prompt "# objects will be removed. Continue?".

RESTART your computer one more time and post a final log
Let me know how your doing

You should also try some preventive measure
Download and install SpywareBlaster
Check for updates---enable all protection
SpywareGuard, Spybot and IE-Spyad are also widely recommended
READ THIS
How did I get Infected
« Last Edit: July 02, 2004, 06:56:53 PM by benditup » Logged

 
angel_eater
Newbie
*

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 2


Bookmark and Share

View Profile
« Reply #9 on: July 05, 2004, 12:01:37 AM »

THIS IS IT!!! Here is how you fix this damn problem. I scratched my head for weeks trying to fix my friend's computer and I finally figured it out...GO ME.
Follow these instructions, then I'll explain how I dumbfoundedly stumbled into the solution.

1) Forget all of your spyware/adware detectors and registry programs.
2) Go here: http://www.oz.msie.tv
3) Click on the uninstall software link and save the uninstaller to your desktop
4) Run the uninstaller.
5) Go to your internet options and reset the home page to whatever you want.
6) Launch your internet explorer!!! You're done, it's as easy as that!!!

Here's how I stumbled onto the fix...I tried my 3 favorite internet fixer programs (ad-aware, spy sweeper, and hijackthis). I ran and updated them time after time and removed things manually and automatically from the registry and other locations on the hard drive to no avail. I then launched Internet Explorer and let it take me to the ****py search page which conveniently would show the URL as about:blank. I was looking for an uninstaller listed on the main page and did not see anything. I then wanted to try to figure out just what in the hell the URL for this search page was. Using some common sense and keeping my fingers crossed, I just went ahead and entered in a search for "legos" in the search bar. BOOM! Up came my results preceded with www.oz.msie.tv/. I then just deleted all of the search result info from the URL bar so that the URL simply read http://www.oz.msie.tv/. I hit enter and BAM! There was the link to uninstall that piece of ****. I downloaded and scanned with antivirus program. It was good to go so I ran it. Rebootted, then changed my home page back in internet options and launched internet explorer.

PLEASE POST THIS EVERYWHERE YOU USE FORUMS!!!

I struggled and researched this a million times and every time, after every removal process, I would reboot and get this damn about:blank search site even after all my scanning showed no threats/hijackers and task manager did not indicate any suspicious processes running either.

I hope this helps EVERYONE with this stupid about:blank problem!
Logged

 
delboy
Newbie
*

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 5


Bookmark and Share

View Profile
« Reply #10 on: July 05, 2004, 08:47:51 AM »

Hi benditup I have done everything you said and I am still free of about blank so thanks a lot.I have downloaded and installed spyware blaster as you said.
Many thanks again for all your help and my computer is actually running much faster now. I am attaching the log file as you asked hopefully it is clean.
Regards
D

angel-eater  benditup has fixed the problem for me but thanks for the advice.

Download Attachment: log3.txt 4.85 KB
Right click and select Save Target As... then rename the file as shown here and save.
Logged

 
angel_eater
Newbie
*

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 2


Bookmark and Share

View Profile
« Reply #11 on: July 05, 2004, 07:44:56 PM »

No problem.  I just posted this here in case anyone else stumbled into this thread.  I used hijack this also and removed all the registry entries that it reported and looked strange to me and it didn't work.  So the uninstaller hopefully will work for others.  Hope microsoft does something to stop hijackers and adware and all the other fun stuff with their products soon.
Logged

 
joseph
Newbie
*

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 9


Bookmark and Share

View Profile
« Reply #12 on: July 05, 2004, 08:15:59 PM »

Hello Guys,

I've tried angel_eater's instructions and unfortunately they didn't work for me.  I saved the uninstaller to my desktop and tried to run it, but it didn't work.  More than this, it installed a file onto my desktop by the name: fpijaeda.tmp.  My problems again, are the about blank and spykiller.  Really, any help will be greatly appreciated.  

Thanks,
Joseph
Logged

 
benditup
Hero Member
*****

Karma: +2/-0
Offline Offline

Gender: Male
Posts: 2105


Bookmark and Share

View Profile
« Reply #13 on: July 05, 2004, 08:33:36 PM »

Hi Joseph, Could you start your own topic please
Simply click on New Topic at the top of this forum

But First-----Would you please download Hijackthis---Important---Create a permanent folder hijackthis
EG---- Open MyDocuments----Right click an empty spot and select NEW---Folder----Name the new folder HJT ---this is where you will want to save Hijackthis too, also, backups will be stored there.
Download from here
http://www.spywareinfo.com/~merijn/files/HijackThis.exe
or here:
http://aumha.org/downloads/hijackthis.exe

Do a SCAN----Scan will change to SAVE LOG----copy and paste the WHOLE contents of the log here... Don't try and fix anything yet----It is all important
Logged

 
benditup
Hero Member
*****

Karma: +2/-0
Offline Offline

Gender: Male
Posts: 2105


Bookmark and Share

View Profile
« Reply #14 on: July 05, 2004, 08:46:02 PM »

Hi Delboy, optionally you can fix the R1 entry in your log
if it is not used as your default search engine

Besides that you look clean

If you don't mind I will lock this topic as everything seems well
If you need it reopened just PM(private message) Myself or Admin
Supply a link to this thread as well as username and problem, thanx
Logged

 
Pages: [1] Go Up Print 
 
Jump to:  

Powered by MySQL Powered by PHP

Powered by SMF 1.1.21 | SMF © 2015, Simple Machines

Valid XHTML 1.0! Valid CSS!

Disclaimer
This site is NOT responsible for any damage that the information on this site may cause to your system. Everything you try, whether inspired by the response given from this site or not, is entirely at your own risk. All product names and company names used herein are for identification purpose only and may be trademarks or registered trademarks of their respective owners. We are in no way affiliated or representing any of the companies on this site unless specified.
Back to Top
Stop Spam Harvesters, Join Project Honey Pot Fight Back Against Spammers! Get Firefox! Get Thunderbird! View Sylvain Amyots profile on LinkedIn
Back to Top
Google visited last this page September 20, 2018, 12:29:04 AM