This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Home Page Stuck On About:blank

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, I've just joined this forum and hope I'm following all the rules correctly. I think I have spyware, because of the following symptoms.

popups on sites that didn't used to give me popups.
Frequent see an icon in my lower right corner telling me I'm low on virtual memory
My Internet Explorer browser has its home page set to about:blank with my permission, and all attempts to change it don't work.

I've tried scanning with spybot search and destroy, adaware, and BHO demon. They find stuff and fix it, but my symptoms remain.

I've just downloaded and run hijack this, and saved the log. The log is as follows:

Logfile of HijackThis v1.97.7
Scan saved at 1:49:00 PM, on 7/29/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\wuauclt.exe
E:\Data\Tim's Utilities\General\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {1D1BEDD0-507F-525A-E711-6D282F4AE07F} - C:\WINDOWS\System32\cardovne.dll
O2 - BHO: (no name) - {3F881727-E71C-73E7-8901-155579A52A1D} - C:\WINDOWS\System32\muieungv.dll
O2 - BHO: (no name) - {6A2FAE54-3A80-4B49-994A-1E1C3AE738D8} - C:\WINDOWS\System32\gnembaa.dll
O2 - BHO: (no name) - {C053A1E9-3A74-F4C4-A55F-3EFE5F42737F} - (no file)
O3 - Toolbar: Windows Search Bar - {A1DD937D-71E1-4BB5-BD5D-1B01B9CB1C2F} - C:\PROGRA~1\WINDOW~4\WinSB.DLL
O4 - HKLM\..\Run: [intdctrr] C:\WINDOWS\System32\idctup20.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: BHODemon 2.0.lnk = E:\Data\Tim's Utilities\General\bhodemon\BHODemon.exe
O4 - Global Startup: Microsoft Office.lnk = E:\Apps\MSOffice\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\Apps\OfficeXP\Office10\EXCEL.EXE/3000
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa…director/sw.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = aus.madisonlife.com
O17 - HKLM\Software\..\Telephony: DomainName = aus.madisonlife.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = aus.madisonlife.com


I've been advised to post the above log to this forum and seek advice before taking further action with hijack this. Can anybody give me some advice? Thank you.
By the way, sometimes when running my other spyware killing software, I'm able to finally successfully change my home page. But inevitably, after awhile, it returns to about:blank, and stays there unchangable until I rerun my software.
Click here to download FindnFix.exe (2K/XP only!) by freeatlast. Double-click on the FINDnFIX.exe and it will install a folder called FINDnFIX on your system. Go to that folder and double-click on !LOG!.bat. The program takes a few minutes to collect the necessary information. When done post the contents of Log.txt in this thread.
Thank you for helping me out with this. I've run FINDnFIX. At first I got an error message because I wasn't logged on with administrator authority, so I relogged on as an administrator and rerand FINDnFIX. Here's the log file: »»»»»»»»»*** www10.brinkster.com/expl0iter/freeatlast/FNF/ ***»»»»»»»»» »»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»» Microsoft Windows XP [Version 5.1.2600] »»»IE build and last SP(s) 6.0.2800.1106 SP1-Q832894-Q330994-Q837009-Q831167 The type of the file system is NTFS. C: is not dirty. Thu 29 Jul 04 14:42:37 2:42pm up 0 days, 0:56 »»»»»»»»»»»»»»»»»»*** Note! ***»»»»»»»»»»»»»»»» The list will produce a small database of files that will match certain criteria. You must know how to ID the file based on the filters provided in the scan, as not all the files flagged are bad. Ex: read only files, s/h files, last modified date. size, etc. The filters provided should help narrow down the list, and hopefully pinpoint the culprit. Along with that,registry scan logged at the end should match the corresponding file(s) listed. »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Unless the file match the entire criteria, it should not be pointed to remove without attempting to confirm it's nature! »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» At times there could be several (legit) files flagged, and/or duplicate culprit file(s)! If in doubt, always search the file(s) and properties according to criteria! The file(s) found should be moved to \FINDnFIX\"junkxxx" Subfolder »»»»»»»»»»»»»»»»»»***LOG!***(*updated 7/29)»»»»»»»»»»»»»»»» »»»*»»»*Use at your own risk!»»»*»»»* Scanning for file(s)… »»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»» »»»»» (*1*) »»»»» ……… »»Locked or 'Suspect' file(s) found… C:\WINDOWS\System32\KBDLEK.DLL +++ File read error \\?\C:\WINDOWS\System32\KBDLEK.DLL +++ File read error »»»»» (*2*) »»»»»…….. KBDLEK.DLL Can't Open! »»»»» (*3*) »»»»»…….. C:\WINDOWS\SYSTEM32\ kbdlek.dll Fri Jun 18 2004 4:29:02p A…R 57,344 56.00 K 1 item found: 1 file, 0 directories. Total of file sizes: 57,344 bytes 56.00 K unknown/hidden files… No matches found. »»»»» (*4*) »»»»»……… Sniffing………. Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. Sniffed -> C:\WINDOWS\SYSTEM32\KBDLEK.DLL SNiF 1.34 statistics Matching files : 1 Amount in bytes : 57344 Directories searched : 1 Commands executed : 0 Masks sniffed for: *.DLL »»»»»(*5*)»»»»» ¯ Access denied ® ………………… KBDLEK.DLL …..57344 18.06.2004 »»»»»(*6*)»»»»» fgrep: can't open input C:\WINDOWS\SYSTEM32\KBDLEK.DLL »»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»» »»»»»Search by size… C:\WINDOWS\SYSTEM32\ kbdlek.dll Fri Jun 18 2004 4:29:02p A…R 57,344 56.00 K 1 item found: 1 file, 0 directories. Total of file sizes: 57,344 bytes 56.00 K No matches found. No matches found. Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. Sniffed -> C:\WINDOWS\SYSTEM32\KBDLEK.DLL SNiF 1.34 statistics Matching files : 1 Amount in bytes : 57344 Directories searched : 1 Commands executed : 0 Masks sniffed for: *.DLL Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. SNiF 1.34 statistics Matching files : 0 Amount in bytes : 0 Directories searched : 1 Commands executed : 0 Masks sniffed for: *.DLL Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. SNiF 1.34 statistics Matching files : 0 Amount in bytes : 0 Directories searched : 1 Commands executed : 0 Masks sniffed for: *.DLL »»Size of Windows key: (*Default-450 *No AppInit-398 *fake(infected)-448,504,512…) Size of HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Windows: 448 »»Dumping Values…….. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs SZ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DeviceNotSelectedTimeout SZ 15 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\GDIProcessHandleQuota DWORD 00002710 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Spooler SZ yes HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\swapdisk SZ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\TransmissionRetryTimeout SZ 90 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\USERProcessHandleQuota DWORD 00002710 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows AppInit_DLLs = (*** MISSING TRAILING NULL CHARACTER ***) DeviceNotSelectedTimeout = 15 GDIProcessHandleQuota = REG_DWORD 0x00002710 Spooler = yes swapdisk = TransmissionRetryTimeout = 90 USERProcessHandleQuota = REG_DWORD 0x00002710 »»Security settings for 'Windows' key: RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de) This program is Freeware, use it on your own risk! Access Control List for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: (NI) ALLOW Read BUILTIN\Users (IO) ALLOW Read BUILTIN\Users (NI) ALLOW Read BUILTIN\Power Users (IO) ALLOW Read BUILTIN\Power Users (NI) ALLOW Full access BUILTIN\Administrators (IO) ALLOW Full access BUILTIN\Administrators (NI) ALLOW Full access NT AUTHORITY\SYSTEM (IO) ALLOW Full access NT AUTHORITY\SYSTEM (NI) ALLOW Full access BUILTIN\Administrators (IO) ALLOW Full access CREATOR OWNER Effective permissions for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: no access BUILTIN\Users no access BUILTIN\Power Users no access BUILTIN\Administrators no access NT AUTHORITY\SYSTEM »»Member of…: (Admin logon required!) User is a member of group TIM\None. User is a member of group \Everyone. User is a member of group BUILTIN\Administrators. User is a member of group BUILTIN\Users. User is a member of group \LOCAL. User is a member of group NT AUTHORITY\INTERACTIVE. User is a member of group NT AUTHORITY\Authenticated Users. »»»»»»Backups created…»»»»»» 2:43pm up 0 days, 0:57 Thu 29 Jul 04 14:43:53 A C:\FINDnFIX\keyback.hiv –a– - - - - - 0 07-29-2004 keyback.hiv A C:\FINDnFIX\keys1\winkey.reg –a– - - - - - 287 07-29-2004 winkey.reg *Temp backups… . .. keyback2.hi_ winkey2.re_ C:\FINDNFIX\ JUNKXXX Thu Jul 29 2004 2:38:20p .D… 1 item found: 0 files, 1 directory. »»Performing string scan…. ———- WIN.TXT ————– ————– ————– ————– No strings found. ————– ————– REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" "DeviceNotSelectedTimeout"="15" "GDIProcessHandleQuota"=dword:00002710 "Spooler"="yes" "swapdisk"="" "TransmissionRetryTimeout"="90" "USERProcessHandleQuota"=dword:00002710 A handle was successfully obtained for the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows key. This key has 0 subkeys. The AppInitDLLs value exists and reports as 62 bytes, including the 2 for string termination. [AppInitDLLs] Ansi string : "C:\WINDOWS\System32\kbdlek.dll" 0000 43 00 3a 00 5c 00 57 00 49 00 4e 00 44 00 4f 00 | C.:.\.W.I.N.D.O. 0010 57 00 53 00 5c 00 53 00 79 00 73 00 74 00 65 00 | W.S.\.S.y.s.t.e. 0020 6d 00 33 00 32 00 5c 00 6b 00 62 00 64 00 6c 00 | m.3.2.\.k.b.d.l. 0030 65 00 6b 00 2e 00 64 00 6c 00 6c 00 00 00 | e.k…d.l.l… 
In the keys1 folder, double click on FIX.bat. You will get an alert of about 15 seconds before reboot - allow it to reboot. On restart, open Explorer and navigate to C:\Windows\System32 folder, find the KBDLEK.DLL file (it should be visible now). Highlight the file and using top menu, click Edit>Move to folder…

Select C:\Findnfix\junkxxx as destination. Move the file.

Open the FINDnFIX folder again and double-click on RESTORE.bat. When it is finished, in FINDnFIX folder, there will be a file called Log2.txt - post it's contents in your next reply.
Thank for your mastery of what appears to be rocket science. I followed your instructions, but when I got to the part where I look for KBDLEK.DLL, it doesn't exist. Here's a directory search of all files in C:\WINDOWS\system32 that start with KBDL: Volume in drive C has no label. Volume Serial Number is BCF2-90CF Directory of C:\WINDOWS\system32 08/23/2001 07:00 AM 6,656 kbdla.dll 08/23/2001 07:00 AM 5,632 kbdlt.dll 08/23/2001 07:00 AM 5,632 kbdlt1.dll 08/23/2001 07:00 AM 6,144 kbdlv.dll 08/23/2001 07:00 AM 6,144 kbdlv1.dll 5 File(s) 30,208 bytes 0 Dir(s) 393,340,928 bytes free What should I do at this point if I can't find KBDLEK.DLL?
Let's check. Click here to download and install Registrar Lite. Install, run, copy and paste this line to reglite's address bar:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs

and hit the "go" tab. Find: "Appinit_Dlls" value on the right side panel, DoubleClick, copy and post here the information in the 'Value' field.

Run the restore file and post the log.
Okay, I installed it and did what you said. In the value field I saw the following: C:\WINDOWS\System32\kbdlek.dll Next you ask that I run the restore file and post the log. What restore file? I don't see any.

Open the FINDnFIX folder again and double-click on RESTORE.bat. When it is finished, in FINDnFIX folder, there will be a file called Log2.txt - post it's contents in your next reply.

here
Sorry about that. I ran it, and here's the log (but I noticed an access is denied message while it ran… I hope it worked okay): »»»»»»»»*** www10.brinkster.com/expl0iter/freeatlast/FNF/ ***»»»»»»» Fri 30 Jul 04 17:33:50 5:33pm up 0 days, 2:10 Microsoft Windows XP [Version 5.1.2600] »»»IE build and last SP(s) 6.0.2800.1106 SP1-Q832894-Q330994-Q837009-Q831167 The type of the file system is NTFS. C: is not dirty. »»»»»»»»»»»»»»»»»»***LOG2!(*updated 7/29)***»»»»»»»»»»»»»»»» This log will confirm if the file was successfully moved, and/or the right file was selected… Scanning for file(s) in System32… »»»»»»» (1) »»»»»»» \\?\C:\WINDOWS\System32\KBDLEK.DLL +++ File read error C:\WINDOWS\System32\KBDLEK.DLL +++ File read error »»»»»»» (2) »»»»»»» KBDLEK.DLL Can't Open! »»»»»»» (3) »»»»»»» C:\WINDOWS\SYSTEM32\ kbdlek.dll Fri Jun 18 2004 4:29:02p A…R 57,344 56.00 K 1 item found: 1 file, 0 directories. Total of file sizes: 57,344 bytes 56.00 K Unknown/hidden files… No matches found. »»»»»»» (4) »»»»»»» Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. Sniffed -> C:\WINDOWS\SYSTEM32\KBDLEK.DLL SNiF 1.34 statistics Matching files : 1 Amount in bytes : 57344 Directories searched : 1 Commands executed : 0 Masks sniffed for: *.DLL »»»»»(5)»»»»» ¯ Access denied ® ………………… KBDLEK.DLL …..57344 18.06.2004 »»»»»(6)»»»»» fgrep: can't open input C:\WINDOWS\SYSTEM32\KBDLEK.DLL »»»»»»» Search by size… C:\WINDOWS\SYSTEM32\ kbdlek.dll Fri Jun 18 2004 4:29:02p A…R 57,344 56.00 K 1 item found: 1 file, 0 directories. Total of file sizes: 57,344 bytes 56.00 K No matches found. No matches found. Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. Sniffed -> C:\WINDOWS\SYSTEM32\KBDLEK.DLL SNiF 1.34 statistics Matching files : 1 Amount in bytes : 57344 Directories searched : 1 Commands executed : 0 Masks sniffed for: *.DLL Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. SNiF 1.34 statistics Matching files : 0 Amount in bytes : 0 Directories searched : 1 Commands executed : 0 Masks sniffed for: *.DLL Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. SNiF 1.34 statistics Matching files : 0 Amount in bytes : 0 Directories searched : 1 Commands executed : 0 Masks sniffed for: *.DLL »»»*»»» Scanning for moved file… »»»*»»» No matches found. Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. SNiF 1.34 statistics Matching files : 0 Amount in bytes : 0 Directories searched : 1 Commands executed : 0 Masks sniffed for: *.* fgrep: no files found for C:\FINDNFIX\JUNKXXX\*.* File not found - C:\FINDnFIX\junkxxx\*.* CHK-SAFE.EXE Ver 2.51 by Bill Lambdin Don Peters and Robert Bullock. MD5 Message Digest Algorithm by RSA Data Security, Inc. File name Size Date Time MD5 Hash ________________________________________________________________________ CRC-Cyclic Redundancy Checker, Version 1.20, 08-Feb-92, rtk C:\FINDNFIX\JUNKXXX No files found ####################################################### *Known files are… ——————– File: ((56k; (57,344 bytes) (CRC16 : 3138) CRC-32 : D5C9FB2E MD5 : C185B36F 9969D3A6 D2122BA7 CBC02249 ——————– File: ((35k; (35,840 bytes) (CRC16 : EEB1) CRC-32 : 33081C8B MD5 : 1DE9A8E2 4C826006 7A479B09 577D9CAE ——————– File: ((21k; (21,504 bytes) (CRC16 : 90A5) CRC-32 : 2258F59E MD5 : EFEE2CB3 B342A351 51802356 9637F8E6 ####################################################### »»Permissions: ERROR: There are no more files. Directory "C:\FINDnFIX\junkxxx\." Permissions: Type Flags Inh. Mask Gen. Std. File Group or User ======= ======== ==== ======== ==== ==== ==== ================ Allow 00000003 tco- 001F01FF —- DSPO rw+x BUILTIN\Administrators Allow 00000002 tc– 001F01FF —- DSPO rw+x NT AUTHORITY\SYSTEM Allow 00000009 –o- 001F01FF —- DSPO rw+x NT AUTHORITY\SYSTEM Allow 00000002 tc– 001F01FF —- DSPO rw+x BUILTIN\Administrators Allow 00000009 –o- 001F01FF —- DSPO rw+x BUILTIN\Administrators Allow 00000013 tco- 001F01FF —- DSPO rw+x BUILTIN\Administrators Allow 00000013 tco- 001F01FF —- DSPO rw+x NT AUTHORITY\SYSTEM Allow 00000010 t— 001F01FF —- DSPO rw+x AUS\TCK Allow 0000001B -co- 10000000 —A —- —- \CREATOR OWNER Allow 00000013 tco- 001200A9 —- -S– r–x BUILTIN\Users Allow 00000012 tc– 00000004 —- —- –+- BUILTIN\Users Allow 00000012 tc– 00000002 —- —- -w– BUILTIN\Users Owner: AUS\TCK Primary Group: AUS\Domain Users Directory "C:\FINDnFIX\junkxxx\.." Permissions: Type Flags Inh. Mask Gen. Std. File Group or User ======= ======== ==== ======== ==== ==== ==== ================ Allow 00000003 tco- 001F01FF —- DSPO rw+x BUILTIN\Administrators Allow 00000003 tco- 001F01FF —- DSPO rw+x NT AUTHORITY\SYSTEM Allow 00000000 t— 001F01FF —- DSPO rw+x AUS\TCK Allow 0000000B -co- 10000000 —A —- —- \CREATOR OWNER Allow 00000003 tco- 001200A9 —- -S– r–x BUILTIN\Users Allow 00000002 tc– 00000004 —- —- –+- BUILTIN\Users Allow 00000002 tc– 00000002 —- —- -w– BUILTIN\Users Owner: AUS\TCK Primary Group: AUS\Domain Users »»Size of Windows key: (*Default-450 *No AppInit-398 *fake(infected)-448,504,512…) Size of HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Windows: 448 »»Dumping Values: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DeviceNotSelectedTimeout SZ 15 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\GDIProcessHandleQuota DWORD 00002710 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Spooler SZ yes HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\swapdisk SZ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\TransmissionRetryTimeout SZ 90 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\USERProcessHandleQuota DWORD 00002710 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs SZ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows DeviceNotSelectedTimeout = 15 GDIProcessHandleQuota = REG_DWORD 0x00002710 Spooler = yes swapdisk = TransmissionRetryTimeout = 90 USERProcessHandleQuota = REG_DWORD 0x00002710 AppInit_DLLs = (*** MISSING TRAILING NULL CHARACTER ***) »»Security settings for 'Windows' key: RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de) This program is Freeware, use it on your own risk! Access Control List for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: (ID-NI) ALLOW Read BUILTIN\Users (ID-IO) ALLOW Read BUILTIN\Users (ID-NI) ALLOW QWCEN-DS– BUILTIN\Power Users (ID-IO) ALLOW QWCEN-DS– BUILTIN\Power Users (ID-NI) ALLOW Full access BUILTIN\Administrators (ID-IO) ALLOW Full access BUILTIN\Administrators (ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM (ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM (ID-NI) ALLOW Full access TIM\Administrator (ID-IO) ALLOW Full access CREATOR OWNER Effective permissions for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: no access BUILTIN\Users no access BUILTIN\Power Users no access BUILTIN\Administrators no access NT AUTHORITY\SYSTEM no access TIM\Administrator 00001150: $ ? x. QId 2? 00001190: x. QId 2? x. QId 2? 000011D0: vk x DeviceNotSelectedTimeout 1 5 00001210: ERProc vk ' GDIProcessHandleQuotak 00001250: 9 0 Handle vk t_SpoolerG y e s ta0 00001290: vk | swapdisk ` vk 000012D0: P utTransmissionRetryTimeout vk ' S 00001310:USERProcessHandleQuotab ` H vk 00001350:> p | AppInit_DLLs ' C : \ W I N D O W S \ S y s 00001390:t e m 3 2 \ k b d l e k . d l l H 000013D0: 00001410: 00001450: 00001490: 000014D0: 00001510: 00001550: ———- NEWWIN.TXT AppInit_DLLs' ————– ————– $011F0: DeviceNotSelectedTimeout $01238: GDIProcessHandleQuotak $012DE: utTransmissionRetryTimeout $01310: USERProcessHandleQuotab $01360: AppInit_DLLs ————– ————– C:\WINDOWS\System32\kbdlek.dll d…. 0 Jul 29 14:38 . d…. 0 Jul 29 14:38 .. 2 files found occupying -65536 bytes =============================================================================== 0 bytes 0 cps Files: 0 Records: 0 Matches: 0 Elapsed Time: 00:00:00.01 VDIR v1.00 Path: C:\FINDNFIX\JUNKXXX\*.* —————————————+————————————— . 07-29-:4 14:38|.. 07-29-:4 14:38 —————————————+————————————— 2 files totaling 0 bytes consuming 0 bytes of disk space. 20774912 bytes available on Drive C: No volume label …File dump… junkxxx\*.* The system cannot find the file specified. 0 file(s) copied. Detecting… C:\FINDnFIX\junkxxx Finished Detecting… 
For whatever reason, Fix.bat hasn't made the file visible but it's still there. Let's try a different approach.

Using Windows Explorer, go to your root drive: C:\ and create a new folder called 'Hijack' and within that folder, create two new folders, one called 'Backups' and one called 'Junk'.

Use the Registrar Lite program. Copy and paste the key below into reglite's address bar and hit 'Go':

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\

Click on the Windows key to highlight it, and use the top menu File>Export and save as (in the C:\Hijack\Backups folder):

1.) Winkey.reg (Save as type: regedit4 .reg type)
2.) Winkey.hiv (Save as type: Scroll to select-regetd32/WinAPI *hiv *dat files)

Navigate to C:\Hijack\Backups and confirm both files have been successfully saved.

Use the Registrar Lite program again. Copy and paste the key below into reglite's address bar and hit 'Go':

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows

Right-click on the Windows key in the left pane and rename it to something else - for example:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NotWindows

DoubleClick "Appinit_Dlls" value on right pane and erase the data in the 'Value' box at the the bottom of the new pane. The data to remove will be:

"C:\WINDOWS\System32\KBDLEK.DLL", hit 'Apply' and 'Ok' to set.

Rename 'NotWindows' back to 'Windows' in the left pane, close Registrar Lite and reboot the computer. If all goes well the hidden process will not run at startup and you should now be able to find and *see* the KBDLEK.DLL in C:\WINDOWS\System32.

Unzip and run Winfile from here. Open it up, click File>Move…

Copy and paste this into the 'From' box: C:\WINDOWS\System32\KBDLEK.DLL
Copy and paste this into the 'To' box: C:\Hijack\Junk\KBDLEK.DLL

Hit OK. Close Winfile and check in C:\Hijack\Junk for that file - let me know what's there.

Navigate to C:\Hijack\Backups and double-click on the winkey.reg file. Answer yes to the prompt. Run reglite again, copy and paste the key below into reglite's address bar and hit 'Go':

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\

Click on the Windows key to highlight it, and use the top menu File>Import browse to and select the "winkey.hiv" you saved earlier. Hit 'open', merge and 'ok' it.

Click here to download CWShredder by Merijn Bellekom and run it, hit 'fix' as opposed to 'scan only'. Reboot when done. Run HJT and post a new log.
When I try to download winfile, I get this message from internet: HTTP1.1 STATUS 403 Remote Access to this object forbidden This file cannot be directly accessed from a remote site, but must be linked through the Brinkster Member's site. I haven't done the rest of your instructions yet, as I wanted to await the answer to the above problem before I do it. Thank you.
Okay, I followed your instructions. I did everything in Registrar Lite like you said, and then rebooted. Upon reboot, though, I still couldn't see C:\WINDOWS\System32\KBDLEK.DLL. I then ran Winfile, and attempted to move KBDLEK.DLL like you said. When I hit , I got the following message: File Manager cannot move C:\WINDOWS\System32\KBDLEK.DLL: There are no more files. At this point, I'm assuming things aren't working, so I didn't continue with your instructions. What should I do at this point?
This again:

run, copy and paste this line to reglite's address bar:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs

and hit the "go" tab. Find: "Appinit_Dlls" value on the right side panel, DoubleClick, copy and post here the information in the 'Value' field

.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI