Options

homepage redirects to about:blank

Hi my name is Andrew Mitchell and I would like to start off by saying thank you for creating a place to run to for help like this, i truly appreciate it. I have run all of the security programs offered on the site including spybot S&D and ad-aware. Hijackthis finds files I believe are my problem but after deleting them the problem comes back. i am redirected to a search engine (www.find-it-easy.org) when i try to go to my homepage (www.yahoo.com) and my homepage is hijacked to go to about:blank. Also, every website that requires me to use a user ID and password redirects back to this engine for example, yahoo mail, myspace. Below is the log file from hijackthis I will wait to make my next move until I hear from you guys. Thank you again... :)

Logfile of HijackThis v1.99.1
Scan saved at 1:05:28 PM, on 8/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\McAfee\McAfee AntiSpyware\Msssrv.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe
C:\Program Files\iRiver\iHP100\iHPDetect.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\iRiver\Service\MLService.exe
C:\Program Files\iRiver\Service\Updater.exe
C:\Program Files\Lexmark 5200 series\lxbtbmon.exe
C:\Program Files\McAfee\McAfee AntiSpyware\MssCli.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSComp.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\System32\svchost.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O1 - Hosts: 127.0.0.41 active-max.com
O1 - Hosts: 127.0.0.238 www.active-max.com
O1 - Hosts: 127.0.0.84 allaboutsearching.com
O1 - Hosts: 127.0.0.230 amazingautossearch.com
O1 - Hosts: 127.0.0.48 www.amazingautossearch.com
O1 - Hosts: 127.0.0.38 www.contexualsearch.com
O1 - Hosts: 127.0.0.80 crap2.com
O1 - Hosts: 127.0.0.205 www.dialup2.com
O1 - Hosts: 127.0.0.63 www.ecpm.com
O1 - Hosts: 127.0.0.55 find-quick.com
O1 - Hosts: 127.0.0.237 www.find-quick.com
O1 - Hosts: 127.0.0.201 lop.com
O1 - Hosts: 127.0.0.4 ao.lop.com
O1 - Hosts: 127.0.0.92 srch.lop.com
O1 - Hosts: 127.0.0.38 www.lop2.com
O1 - Hosts: 127.0.0.83 search200.com
O1 - Hosts: 127.0.0.39 www.mysearchnow.com
O1 - Hosts: 127.0.0.91 www.netsearchsoft.com
O1 - Hosts: 127.0.0.242 www.rub.to
O1 - Hosts: 127.0.0.80 searchexe.com
O1 - Hosts: 127.0.0.92 www.searchweb2.com
O1 - Hosts: 127.0.0.91 www.spawnet.com
O1 - Hosts: 127.0.0.59 tdmy.com
O1 - Hosts: 127.0.0.212 www.tfil.com
O1 - Hosts: 127.0.0.245 www.tdko.com
O1 - Hosts: 127.0.0.225 wrn.net
O1 - Hosts: 127.0.0.87 www.wrn.net
O1 - Hosts: 127.0.0.89 www.mp3search.com
O1 - Hosts: 127.0.0.97 www.lyricsdomain.com
O1 - Hosts: 127.0.0.241 omega-search.com
O1 - Hosts: 127.0.0.92 www.omega-search.com
O1 - Hosts: 127.0.0.72 trinityacquisitions.com
O1 - Hosts: 127.0.0.36 www.trinityacquisitions.com
O1 - Hosts: 127.0.0.253 wethere.com
O1 - Hosts: 127.0.0.88 asearchforyou.org
O1 - Hosts: 127.0.0.37 www.asearchforyou.org
O1 - Hosts: 127.0.0.24 intelesearch.com
O1 - Hosts: 127.0.0.205 www.intelesearch.com
O1 - Hosts: 127.0.0.83 www.isearchhere.com
O1 - Hosts: 127.0.0.80 www.iwantosearch.com
O1 - Hosts: 127.0.0.236 opensearch.org
O1 - Hosts: 127.0.0.7 searchbee.net
O1 - Hosts: 127.0.0.227 searchhotsex.com
O1 - Hosts: 127.0.0.50 www.searchhotsex.com
O1 - Hosts: 127.0.0.221 ifsearch.com
O1 - Hosts: 127.0.0.35 www.ifsearch.com
O1 - Hosts: 127.0.0.203 mastersearcher.com
O1 - Hosts: 127.0.0.40 look-today.com
O1 - Hosts: 127.0.0.250 aavc.com
O1 - Hosts: 127.0.0.247 www.aavc.com
O1 - Hosts: 127.0.0.56 acjp.com
O1 - Hosts: 127.0.0.86 www.acjp.com
O1 - Hosts: 127.0.0.225 www.ecmh.com
O1 - Hosts: 127.0.0.34 wabu.com
O1 - Hosts: 127.0.0.59 wabq.com
O1 - Hosts: 127.0.0.97 maximumexperience.com
O1 - Hosts: 127.0.0.27 www.maximumexperience.com
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [Lexmark 5200 series] "C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe"
O4 - HKLM\..\Run: [LXBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBTtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [iHP-100] C:\Program Files\iRiver\iHP100\iHPDetect.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [iRiver AutoDB] C:\Program Files\iRiver\Service\MLService.exe
O4 - HKLM\..\Run: [iRiver Updater] C:\Program Files\iRiver\Service\Updater.exe
O4 - HKLM\..\Run: [_AntiSpyware] C:\Program Files\McAfee\McAfee AntiSpyware\MssCli.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PopUpStopperCompanion] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSComp.exe"
O4 - Startup: RollerCoaster Tycoon 3 Registration.lnk = C:\Documents and Settings\Andrew Mitchell\Local Settings\Temp\{85B087FF-FCC8-491B-B159-4BB9E1F8B4AA}\{907B4640-266B-4A21-92FB-CD1A86CD0F63}\ATR1.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .qcp: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,23/mcgdmgr.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: lxbt_device - Lexmark International, Inc. - C:\WINDOWS\System32\lxbtcoms.exe
O23 - Service: McAfee AntiSpyware Real-Time Scanner (McAfeeAntiSpyware) - Network Associates, Inc. - C:\Program Files\McAfee\McAfee AntiSpyware\Msssrv.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

Comments

  • jaredjared College Station, TX Icrontian
    edited August 2005
    Alrighty

    Make sure you have a copy of HJT on the desktop or some place easy to get to. Go ahead and reboot your computer into safe mode. To do this start tapping F8 as yoru computer boots up.

    Once in safemode, fire up HJT and delete these:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    O1 - Hosts: 127.0.0.41 active-max.com
    O1 - Hosts: 127.0.0.238 www.active-max.com
    O1 - Hosts: 127.0.0.84 allaboutsearching.com
    O1 - Hosts: 127.0.0.230 amazingautossearch.com
    O1 - Hosts: 127.0.0.48 www.amazingautossearch.com
    O1 - Hosts: 127.0.0.38 www.contexualsearch.com
    O1 - Hosts: 127.0.0.80 crap2.com
    O1 - Hosts: 127.0.0.205 www.dialup2.com
    O1 - Hosts: 127.0.0.63 www.ecpm.com
    O1 - Hosts: 127.0.0.55 find-quick.com
    O1 - Hosts: 127.0.0.237 www.find-quick.com
    O1 - Hosts: 127.0.0.201 lop.com
    O1 - Hosts: 127.0.0.4 ao.lop.com
    O1 - Hosts: 127.0.0.92 srch.lop.com
    O1 - Hosts: 127.0.0.38 www.lop2.com
    O1 - Hosts: 127.0.0.83 search200.com
    O1 - Hosts: 127.0.0.39 www.mysearchnow.com
    O1 - Hosts: 127.0.0.91 www.netsearchsoft.com
    O1 - Hosts: 127.0.0.242 www.rub.to
    O1 - Hosts: 127.0.0.80 searchexe.com
    O1 - Hosts: 127.0.0.92 www.searchweb2.com
    O1 - Hosts: 127.0.0.91 www.spawnet.com
    O1 - Hosts: 127.0.0.59 tdmy.com
    O1 - Hosts: 127.0.0.212 www.tfil.com
    O1 - Hosts: 127.0.0.245 www.tdko.com
    O1 - Hosts: 127.0.0.225 wrn.net
    O1 - Hosts: 127.0.0.87 www.wrn.net
    O1 - Hosts: 127.0.0.89 www.mp3search.com
    O1 - Hosts: 127.0.0.97 www.lyricsdomain.com
    O1 - Hosts: 127.0.0.241 omega-search.com
    O1 - Hosts: 127.0.0.92 www.omega-search.com
    O1 - Hosts: 127.0.0.72 trinityacquisitions.com
    O1 - Hosts: 127.0.0.36 www.trinityacquisitions.com
    O1 - Hosts: 127.0.0.253 wethere.com
    O1 - Hosts: 127.0.0.88 asearchforyou.org
    O1 - Hosts: 127.0.0.37 www.asearchforyou.org
    O1 - Hosts: 127.0.0.24 intelesearch.com
    O1 - Hosts: 127.0.0.205 www.intelesearch.com
    O1 - Hosts: 127.0.0.83 www.isearchhere.com
    O1 - Hosts: 127.0.0.80 www.iwantosearch.com
    O1 - Hosts: 127.0.0.236 opensearch.org
    O1 - Hosts: 127.0.0.7 searchbee.net
    O1 - Hosts: 127.0.0.227 searchhotsex.com
    O1 - Hosts: 127.0.0.50 www.searchhotsex.com
    O1 - Hosts: 127.0.0.221 ifsearch.com
    O1 - Hosts: 127.0.0.35 www.ifsearch.com
    O1 - Hosts: 127.0.0.203 mastersearcher.com
    O1 - Hosts: 127.0.0.40 look-today.com
    O1 - Hosts: 127.0.0.250 aavc.com
    O1 - Hosts: 127.0.0.247 www.aavc.com
    O1 - Hosts: 127.0.0.56 acjp.com
    O1 - Hosts: 127.0.0.86 www.acjp.com
    O1 - Hosts: 127.0.0.225 www.ecmh.com
    O1 - Hosts: 127.0.0.34 wabu.com
    O1 - Hosts: 127.0.0.59 wabq.com
    O1 - Hosts: 127.0.0.97 maximumexperience.com
    O1 - Hosts: 127.0.0.27 www.maximumexperience.com
    O4 - HKCU\..\Run: [PopUpStopperCompanion] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSComp.exe"
    O4 - Startup: RollerCoaster Tycoon 3 Registration.lnk = C:\Documents and Settings\Andrew Mitchell\Local Settings\Temp\{85B087FF-FCC8-491B-B159-4BB9E1F8B4AA}\{907B4640-266B-4A21-92FB-CD1A86CD0F63}\ATR1.exe
    O12 - Plugin for .qcp: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll

    After you have deleted those, reboot and download about:buster (link in signature). Run that. Then update adaware and run a full system scan.

    Post here if you have any problems :)
Sign In or Register to comment.