About:Blank Hijack/Trojan/Virus/Something

edited September 2005 in Spyware & Virus Removal
Recently I was plagued by my homepage resetting to about:blank.
Every couple of minutes, my IE6 settings would reset and about:blank page would be my homepage.
Also running full-screen programs, after a couple of minutes windows would try to pop-up. Almost like alt+tab.
After running CWS Shredder, Adware 6, Hijackthis, AVG Virus and startuplist (to see what is starting up), I noticed this: see attachment
Apparently none of the following could detect this file.
I started up in safe-mode, and moved the file to another folder. Originally it was placed under Windows/System.
When i restarted the file had moved back into Windows/System
The filename seems random, but I don't know.
I hope this helps anyone else who has had this problem.

I have it zipped if anyone wants me to email it to them... :O

Comments

  • primesuspectprimesuspect Beepin n' Boopin Detroit, MI Icrontian
    edited April 2004
    Post your hijackthis log here, please :)

    And, welcome to short-media
  • KwitkoKwitko Sheriff of Banning (Retired) By the thing near the stuff Icrontian
    edited April 2004
    You might have missed an entry in HiJackThis. Repost your log. Perhaps we can find something you missed the first time.

    There's probably a registry entry in there somewhere causing it to respawn.
  • edited April 2004
    I think its gone now.
    Here is another attachment
    This is the log of zonealarm

    Logfile of HijackThis v1.97.7
    Scan saved at 10:06:23 PM, on 4/22/04
    Platform: Windows 98 SE (Win9x 4.10.2222A)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\WINDOWS\SYSTEM\ATI2EVXX.EXE
    C:\WINDOWS\SYSTEM\ATI2EVXX.EXE
    C:\PROGRAM FILES\GRISOFT\AVG6\AVGSERV9.EXE
    C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE
    C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
    C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
    C:\PROGRAM FILES\FINEPIXVIEWER\QUICKDCF.EXE
    C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPOTDD01.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\PROGRAM FILES\YAHOO!\MESSENGER\YMSGR_TRAY.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\PROGRAM FILES\WINDOWS MEDIA PLAYER\WMPLAYER.EXE
    C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
    C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
    O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
    O4 - HKLM\..\Run: [HydarVisionDesktopManager] desk98.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\GRISOFT\AVG6\avgcc32.exe /STARTUP
    O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [ATIPOLL] ati2evxx.exe
    O4 - HKLM\..\RunServices: [ATIPOLAB] ati2evxx.exe
    O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe
    O4 - HKLM\..\RunServices: [ATISmart] C:\WINDOWS\SYSTEM\ati2s9ag.exe
    O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
    O4 - Startup: Exif Launcher.lnk = C:\WINDOWS\Application Data\Microsoft\Installer\{24ED4D80-8294-11D5-96CD-0040266301AD}\ExifLauncher.exe
    O4 - Startup: hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    O4 - Startup: hp instant support.lnk = C:\Program Files\Hewlett-Packard\hpis\bin\matcli.exe
    O4 - Startup: Scanner Detector.lnk = C:\Program Files\ScanSuite\SDetect.exe
    O9 - Extra button: AIM (HKLM)
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37967.5658449074
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab
  • KwitkoKwitko Sheriff of Banning (Retired) By the thing near the stuff Icrontian
    edited April 2004
    Hmmm... nothing in there looks like it's a trojan horse or IRC bot. I suggest downloading a 30-day trial of TrojanHunter and running a scan just to make sure.

    At least you've got ZoneAlarm blocking its attempts to "call home".
  • primesuspectprimesuspect Beepin n' Boopin Detroit, MI Icrontian
    edited April 2004
    This looks suspicious because it normally wouldn't be in that location:

    O4 - Startup: Exif Launcher.lnk = C:\WINDOWS\Application Data\Microsoft\Installer\{24ED4D80-8294-11D5-96CD-0040266301AD}\ExifLauncher.exe

    I'd kill it.
  • edited April 2004
    ... i have the same problem... but unlike the person who started this thread i have no idea what is what on my computer. i dont know what to delete and what to delete

    this is my hijackthis log
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Mixer.exe
    C:\Program Files\D-Tools\daemon.exe
    C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
    C:\WINDOWS\System32\RUNDLL32.EXE
    C:\Program Files\Winamp\winampa.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\TrojanHunter 3.8\TrojanHunter.exe
    C:\Documents and Settings\Paul Minion\Desktop\hijackthis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\lfccmea.dll/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\lfccmea.dll/sp.html (obfuscated)
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\lfccmea.dll/sp.html (obfuscated)
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\lfccmea.dll/sp.html (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\lfccmea.dll/sp.html (obfuscated)
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\lfccmea.dll/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {A6321B49-52EC-4D59-A69B-DE28ABF73695} - C:\WINDOWS\System32\lfccmea.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
    O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM32\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [THGuard] C:\Program Files\TrojanHunter 3.8\THGuard.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
    O4 - Startup: PowerReg Scheduler V3.exe
    O4 - Global Startup: SketchBook Snapshot.lnk = G:\Games\UT2004\Alias SketchBook Pro 1.0\AliasSketchSnap.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Research (HKLM)
    O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 (HKLM)
    O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 (HKLM)
    O16 - DPF: Win32 Classes -
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    O16 - DPF: {23B7A816-3647-49D2-9756-6F41CE8F9201} (ddm_download.ddm_control) - http://bins.dynamicdesktopmedia.com/cab/ddm_control.CAB
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
    O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://files.ea.com/downloads/rtpatch/v2/EARTPX.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37882.0365162037
    O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} (MaxisSimCity4PatcherX Control) - http://simcity.ea.com/update/MaxisSimCity4PatcherX.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{8092F469-0E2D-43DC-984B-39B28501256F}: NameServer = 192.168.0.1

    help plz
  • TheBaronTheBaron Austin, TX
    edited April 2004
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\lfccmea.dll/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\lfccmea.dll/sp.html (obfuscated)
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about_:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\lfccmea.dll/sp.html (obfuscated)
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about_:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\lfccmea.dll/sp.html (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\lfccmea.dll/sp.html (obfuscated)
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\lfccmea.dll/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about_:blank
    O2 - BHO: (no name) - {A6321B49-52EC-4D59-A69B-DE28ABF73695} - C:\WINDOWS\System32\lfccmea.dll
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O16 - DPF: {23B7A816-3647-49D2-9756-6F41CE8F9201} (ddm_download.ddm_control) - http://bins.dynamicdesktopmedia.com/cab/ddm_control.CAB
    O17 - HKLM\System\CCS\Services\Tcpip\..\{8092F469-0E2D-43DC-984B-39B28501256F}: NameServer = 192.168.0.1

    I'd go ahead and get rid of these as well, im not entirely positive what they are
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
  • edited April 2004
    TheBaron wrote:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\lfccmea.dll/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\lfccmea.dll/sp.html (obfuscated)
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about_:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\lfccmea.dll/sp.html (obfuscated)
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about_:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\lfccmea.dll/sp.html (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\lfccmea.dll/sp.html (obfuscated)
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\lfccmea.dll/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about_:blank
    O2 - BHO: (no name) - {A6321B49-52EC-4D59-A69B-DE28ABF73695} - C:\WINDOWS\System32\lfccmea.dll
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O16 - DPF: {23B7A816-3647-49D2-9756-6F41CE8F9201} (ddm_download.ddm_control) - http://bins.dynamicdesktopmedia.com/cab/ddm_control.CAB
    O17 - HKLM\System\CCS\Services\Tcpip\..\{8092F469-0E2D-43DC-984B-39B28501256F}: NameServer = 192.168.0.1

    I'd go ahead and get rid of these as well, im not entirely positive what they are
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    didnt fix it... still there
  • shwaipshwaip bluffin' with my muffin Icrontian
    edited April 2004
    could you run hijackthis again and post the new log?
  • edited April 2004
    i did it again. its seems to work... its reset my DNS sever ip thingy tho...

    thanks guy ... if it happens again i will tell u. THAnks again
  • Straight_ManStraight_Man Geeky, in my own way Naples, FL Icrontian
    edited April 2004
    Pminion wrote:
    i did it again. its seems to work... its reset my DNS sever ip thingy tho...

    thanks guy ... if it happens again i will tell u. THAnks again

    Um, it redirected DNS to a site that pushed the IE settings, then. Fixing DNS will let you surf right again. Have you security packed your IE lately, and XP??? There are some new ones out that are taking advantage of the things that the new packs fix-- MS04-11 through MS04-014.

    Oh, one other thing for the readers here, there is a new trojan out, it comes in an email that offers a picture of a captured Osama Bin Laden.

    Two problems with this:
    1. Osama has not been captured yet.
    2. Instead of a pic, you get a new trojan instead. This one hit the wild in the last three-four days.

    Anything about Osama being captured, trash on sight please, in email. Until AFTER you see it on the news on TV, and even then news media does not email pics like that, they SHOW them to you on their corporate sites-- they want the copyuright kept, if and when it happens.

    John D.
  • edited April 2004
    TheBaron wrote:

    I'd go ahead and get rid of these as well, im not entirely positive what they are
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    i didnt delete these. but i was wondering if anyone else thinks i should
  • DexterDexter Vancouver, BC Canada
    edited April 2004
    There is a very thorough fix for this on another site called Computer Cops. I have not done this so I cannot verify the procedure, but the site is well noted, and the methodology is very sound. I recomend giving it a try.

    From:

    http://computercops.biz/modules.php?name=Forums&file=viewtopic&p=133970
    Follow these directions step by step in the order written.


    First Please download TheKillbox from this link: http://download.broadbandmedic.com/VbStuff/KillBox.zip

    Download the newest CWShredder from this page:

    http://www.computercops.biz/downloads-cat-14.html

    Do not run either yet.

    Sign off the Internet and close all IE Windows.
    Run CWShredder.

    Then copy the contents of the quote box to Notepad. Name the file fix.reg
    SAve all type All Files. Double click on fix.reg to remove certain other possible registry entries.

    Quote:

    Windows Registry Editor Version 5.00

    [-HKEY_CLASSES_ROOT\PROTOCOLS\Filter\text/html]
    [-HKEY_CLASSES_ROOT\PROTOCOLS\Filter\text/plain]



    To uninstall the secret reinstaller do this:
    Go to start>Run and type regedit. Press enter.

    Navigate to:
    Open the registry and navigate here:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
    Highlight Windows in the left pane.

    Look in the right pane for this value:
    AppInit_Dlls

    You won't see any data there.

    But if you right click on that and choose Modify Binary Data you will.

    If nothing is there it should just show a few 0's.

    But if they are hiding a dll they load to resintall, it will show a path to it.


    This is now one looks when there is only one file loading.
    0000 00 00 3A 00 5C 00 77 00 ..:.\.w.
    0008 69 00 6E 00 64 00 6F 00 i.n.d.o.
    0010 77 00 73 00 5C 00 73 00 w.s.\.s.
    0018 79 00 73 00 74 00 65 00 y.s.t.e.
    0020 6D 00 33 00 32 00 5C 00 m.3.2.\.
    0028 6D 00 73 00 6B 00 6B 00 m.s.k.k.
    0030 67 00 2E 00 64 00 6C 00 g...d.l.
    0038 6C 00 00 00 l...

    Notice on the far right. You want to look there. It looks funny because all of the periods.

    Look closely and you'll see the path and file name here was:
    Windows\system32\mskkg.dll

    This was the example. Yours will have its own file name. This is not the same file as you are seeing in your HijackThis log. Get its name the same as I just described.

    Once you have the filename unzip TheKillBox and run it.

    Unzip the files to a folder, then double-click on Killbox.exe to run it. In the "Paste Full Path of File to Delete" box, copy and paste the following:

    c:\windows\system32\filename Where filename is what you found as the filename in the appinit_dlls key in the registry.

    Don't click any of the buttons though, instead please click on the Action menu and choose "Delete on Reboot". On the next screen, click on the File menu and choose "Add File". The c:\Windows\system32\filename listing should show up in the window. If that's successful, choose the Action menu and select "Process and Reboot". You'll be prompted to reboot. Restart the Computer.

    When you get back into Windows reset your Search and Home pages.

    Look in the registry and remove the entry which should now be clearly visible and no longer hidden.


    This last part and removing the AppInit_Dlls entry and its corresponding file is removing the reinstaller. So you do not get reinfected. Do not go on the internet until you have performed all of the steps.

    Dexter...
  • edited May 2004
    Go to this link:
    http://www.spywareinfo.com/~merijn/cwschronicles.html and download CWShredder free of charge. It is updated frequently and specifically targets Cool Web Search, of which about:blank is a variant. It worked for me, following no luck from Adaware or Spybot S&D
  • edited September 2005
    I would like the zipped file to fix this please. bsanderos@aol.com
    Recently I was plagued by my homepage resetting to about:blank.
    Every couple of minutes, my IE6 settings would reset and about:blank page would be my homepage.
    Also running full-screen programs, after a couple of minutes windows would try to pop-up. Almost like alt+tab.
    After running CWS Shredder, Adware 6, Hijackthis, AVG Virus and startuplist (to see what is starting up), I noticed this: see attachment
    Apparently none of the following could detect this file.
    I started up in safe-mode, and moved the file to another folder. Originally it was placed under Windows/System.
    When i restarted the file had moved back into Windows/System
    The filename seems random, but I don't know.
    I hope this helps anyone else who has had this problem.

    I have it zipped if anyone wants me to email it to them... :O
This discussion has been closed.