This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

About:blank Is Drivin Me Crazy....

40 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

So far so good! I was gone all weekend or I would have replied sooner.I would like to say thank you again. It is a great thing you people do here!
I recently had the about:blank infection. Dgosling helped me get it cleared up…..thanks again if you see this! Anway to my question. I recently downloaded TrojanHunter and in its scan it came up with this: Registry key exists: HKEY_LOCAL_MACHINE\SOFTWARE\Windows SyncroAd (matches Adware.WindUpdates.SyncroAd.100) Is this something I should be concerned with? I'm sorry if I should have had my post reopened, my machine is runnin better than ever with no sign of the hijacker so I didnt feel like I needed to.
Here is my newest log:
Logfile of HijackThis v1.98.2
Scan saved at 4:18:44 PM, on 10/23/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\F-Secure Anti-Virus\Anti-Virus\fsgk32st.exe
C:\Program Files\F-Secure Anti-Virus\backweb\4476822\program\fsbwsys.exe
C:\Program Files\F-Secure Anti-Virus\Anti-Virus\FSGK32.EXE
C:\Program Files\F-Secure Anti-Virus\Anti-Virus\fssm32.exe
C:\Program Files\F-Secure Anti-Virus\Common\FSMA32.EXE
C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
C:\Program Files\F-Secure Anti-Virus\Common\FSMB32.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\F-Secure Anti-Virus\Common\FCH32.EXE
C:\Program Files\F-Secure Anti-Virus\Common\FAMEH32.EXE
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\Program Files\F-Secure Anti-Virus\Anti-Virus\fsav32.exe
C:\Program Files\F-Secure Anti-Virus\FWES\Program\fsdfwd.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe
C:\PROGRA~1\LEXMAR~1\LXBRKsk.exe
C:\Program Files\F-Secure Anti-Virus\backweb\4476822\Program\fspex.exe
C:\WINDOWS\System32\atiptaxx.exe
C:\Program Files\Lexmark 3100 Series\lxbrbmon.exe
C:\Program Files\F-Secure Anti-Virus\Common\FSM32.EXE
C:\Program Files\Lexmark 3100 Series\lxbrcmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\F-Secure Anti-Virus\FSGUI\fsguiexe.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\HJT\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Lexmark 3100 Series] "C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe"
O4 - HKLM\..\Run: [LXBRKsk] C:\PROGRA~1\LEXMAR~1\LXBRKsk.exe
O4 - HKLM\..\Run: [ATIPTA] atiptaxx.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.0\THGuard.exe"
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Anti-Virus\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Anti-Virus\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\F-Secure Anti-Virus\FSGUI\FSSW.EXE" /reboot
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: Joint Operations Typhoon Rising Registration.lnk = C:\Documents and Settings\Tommy.ENGLISH\Local Settings\Temp\{4A10C207-2264-4C3B-B40A-85CE8E81A178}\{0325F1C1-883A-41AB-8981-B27359ABDFAF}\NOVG.EXE
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\TV\EXPLBAR.DLL
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O12 - Plugin for .au: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O16 - DPF: Yahoo! Pyramids - http://download.games.yahoo.com/games/clients/y/pyt1_x.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1097320249515
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/popc…aploader_v5.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A637D88C-46FB-4EC3-8A05-D336512DABDC}: NameServer = 209.206.199.16 209.142.136.85



I'm probably just being paranoid
Hello tommyw
After the infection you had I would be paranoid about an entry like that too.

I am not certain that the entry is actually in the location TH reported so I suggest that you open Registrar Lite and enter this in the address bar. However in my copy of XP there is no such entry in the Registry.

HKEY_LOCAL_MACHINE\SOFTWARE\Windows

If you do not find the entry there, then go to Search > Search Registry and enter: SyncroAd in the Text To Search For box. In the Search In box, select Registry. The button below right of the 'search in' box will bring up a window to select where you want the search to be done.

When the results are returned and if you find SynchroAd, I recommend you delete the value but it would be best unless you are very knowledgeable about the Registry I would post back the actual location of the entry and I will give you specific instructions for removing the entry. If you decide to remove it without posting back, please remember to back up that section of the Registry as we did earlier in your thread to make sure there is a copy of the registry in case there is a problem.

I also notice that you have a file running that may indicate that you have more than one Firewall active. They will conflict. I notice that you have Kerio Firewall running and you may also have the Windows Firewall in XP set to run. I would get rid of the Windows Firewall. Go to Start>Control Panel>Network Connections. Right click on your Ethernet connection or Dial up Networking icon (whichever you use to connect to the internet) and choose properties. On the Advanced tab of properties you will find the button to setup the Windows Firewall. Disable it and reboot. Then you will have Kerio running alone.

Another think you may want to do is to remove the link for registration of Typhoon Rising. Go to C:\Documents and Settings\Tommy.ENGLISH\LocalSettings\Temp\{4A10C207-2264-4C3B-B40A-85CE8E81A178}\{0325F1C1-883A-41AB-8981-B27359ABDFAF}\NOVG.EXE
and deleted what is in bold text. You do not need any files that are in your Temp directory - they are files that will run every time you play the game or use the program and will reinsert themselves if they are needed during a game/use of a program.

Good Luck!
Your right seeing that entry made me very nervous! I ran reglite and it dose exist here are the paths: HKEY_LOCAL_MACHINE\SOFTWARE\Windows SyncroAd I ran the search in reglite and this is what I found: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\\C:\WINDOWS\Downloaded Program Files\SyncroAdX.dll HKEY_LOCAL_MACHINE\SOFTWARE\Windows SyncroAd\\(default) HKEY_LOCAL_MACHINE\SOFTWARE\Windows SyncroAd\\param I've done the other things you sugested…but I'm not confortable messing around w/ my reg!
Hi tommyw,

I can imagine that you are concerned about entering your Registry and making changes but these changes should not create problems. It appears that these entries are not active because they are not showing in your HJT log file.

I will instruct you in the use of Registrar Lite as it is the easiest Registry editor that I know of. I will also have you make backups of the areas we are changing in the Registry so that if something does go wrong the backups can be restored for use.


Step#1

First of all there is a possibility that there is still an Active X for Synchrod on your computer. Please navigate to C:\WINDOWS\Downloaded Program Files and check the entries in that folder for one labeled SynchroAd. What I see in that folder from your HJT log are 2 Yahoo games downloaders, one Panda AV Actuve X and one Active X for Windows Update. Those are the only ones that should be there now. If there are any others, deleted them but make sure you keep a record to post of the names of the ones you delete.



Step#2

Now we will backup the areas of the Registry that we are going to be working on:

1. Open Registrar Lite and run it.

2. Copy and paste the bold text below into the address bar of Registrar Lite:(this is making a Registry backup for safety in case of error)

HKEY_LOCAL_MACHINE\SOFTWARE

3. Go to File> Export and and save as (in the C:\Program Files\Registrar Lite (Reglite) folder:

1.) Winkey.reg (Save as type: regedit4 .reg type)
2.) Winkey.hiv (Save as type: Scroll to select-regetd32/WinAPI *hiv *dat files)


4. You now have a backup of the section of the Registry that we will be working on. I am going to do this one step at a time so you understand what is being done.


Step#3

1. Copy and Paste the following bold text into Reglite's Address Bar:

HKEY_LOCAL_MACHINE\SOFTWARE\Windows SynchroAd\\

2. 6. Click Go

3. Look in the Left Hand pane to find Windows SyncroAd then in the right hand pane look for param

4. Highlight param in the right hand pane, right click on it and then choose Delete


Step#4

1. Copy and Paste the following bold text into Reglite's Address Bar:

HKEY_LOCAL_MACHINE\SOFTWARE\Windows SynchroAd\\

2. Click Go

3. Look in the Left Hand pane to find Windows SyncroAd then in the right hand pane look for (default)

4. Highlight (default) in the right hand pane, right click on it and then choose Delete



Step#5

1. Copy and Paste the following bold text into Reglite's Address Bar:

HKEY_LOCAL_MACHINE\SOFTWARE

2. 6. Click Go

3. Look in the Left Hand pane to find Software then in the right hand pane look for:

HKEY_LOCAL_MACHINE\SOFTWARE\Windows SyncroAd

4. Highlight Windows SynchroAd in the right hand pane, right click on it and then choose Delete



Step#6

1. Copy and Paste the following bold text into the Address Bar in Reg Lite

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs

2. Click Go

3. Look in the Left Hand pane to find SharedDLLs then in the right hand pane under SharedDLLs look for:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\\C:\WINDOWS\Downloaded Program Files\SyncroAdX.dll

4. Highlight C:\WINDOWS\Downloaded Program Files\SyncroAdX.dll in the right hand pane, right click on it and then choose Delete




Step#7

If you have had to change the permissions on the keys in Registrar Lite then they will have to be returned to the way they were . To do this please navigate to C:\ProgramFiles\Registrar Lite (Reglite) and double-click on Winkey.reg. It will ask if you want to merge this file with the registry, say Yes. Then double-click on Winkey.hiv and merge this file with the Registry. You have now returned the permissions to the way they were.




Step#8

Scan again with TH and see if it shows anything once you have complete removal from the Registry.


Step#9

Do an online AV scan from Housecall. Trend Micro from the link at the bottom of this post in my signature and fix anything it finds.


Step#10

Please scan again with HijackThis and

Post a new log file here in this thread with information on how your computer is functioning.
Hi Dgosling,

Everything went well! I found nothin in step 1, the rest went fine. TrojanHunter came up clean this time. For some reason I can't get house call to run? I ran panda again and it found:
Virus:W32/Mitglieder.V.worm Disinfected C:\WINDOWS\ShowMeMessageBox.exe.tcf

My machine has been runnin fine since the first fix…..just didnt want anything left lurkin around.

My latest log:

Logfile of HijackThis v1.98.2
Scan saved at 5:14:33 PM, on 10/25/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\F-Secure Anti-Virus\Anti-Virus\fsgk32st.exe
C:\Program Files\F-Secure Anti-Virus\backweb\4476822\program\fsbwsys.exe
C:\Program Files\F-Secure Anti-Virus\Anti-Virus\FSGK32.EXE
C:\Program Files\F-Secure Anti-Virus\Common\FSMA32.EXE
C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
C:\Program Files\F-Secure Anti-Virus\Anti-Virus\fssm32.exe
C:\Program Files\F-Secure Anti-Virus\Common\FSMB32.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\F-Secure Anti-Virus\Common\FCH32.EXE
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\Program Files\F-Secure Anti-Virus\Common\FAMEH32.EXE
C:\Program Files\F-Secure Anti-Virus\Anti-Virus\fsav32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\Program Files\F-Secure Anti-Virus\FWES\Program\fsdfwd.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\F-Secure Anti-Virus\backweb\4476822\Program\fspex.exe
C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe
C:\PROGRA~1\LEXMAR~1\LXBRKsk.exe
C:\WINDOWS\System32\atiptaxx.exe
C:\Program Files\Lexmark 3100 Series\lxbrbmon.exe
C:\Program Files\F-Secure Anti-Virus\Common\FSM32.EXE
C:\Program Files\Lexmark 3100 Series\lxbrcmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\F-Secure Anti-Virus\FSGUI\fsguiexe.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\HJT\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Lexmark 3100 Series] "C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe"
O4 - HKLM\..\Run: [LXBRKsk] C:\PROGRA~1\LEXMAR~1\LXBRKsk.exe
O4 - HKLM\..\Run: [ATIPTA] atiptaxx.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.0\THGuard.exe"
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Anti-Virus\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Anti-Virus\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\F-Secure Anti-Virus\FSGUI\FSSW.EXE" /reboot
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\TV\EXPLBAR.DLL
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O12 - Plugin for .au: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O16 - DPF: Yahoo! Pyramids - http://download.games.yahoo.com/games/clients/y/pyt1_x.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1097320249515
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/popc…aploader_v5.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A637D88C-46FB-4EC3-8A05-D336512DABDC}: NameServer = 209.206.199.16 209.142.136.85

Thank you AGAIN!
I am sorry Tommyw I must have missed the email telling me you had posted. The log looks great Congratulations! Is your computer working fine? If so I will close this thread and if you have problems within a short period of time we can reopen it. Please let me know how your PC is now? good luck!
I am glad that we were able to help! I am closing this topic now, but if you need it reopened, please send an email to the following link(Click for address) with the Subject line of the email "Reopen".
To receive a response, please include in your email: the user name used in the post, details of why you need it reopened, and a valid link to the post.

Emails with bad links to the post, emails that are not from the original poster, and emails that do not have "ReOpen" as the subject line, will be deleted without being opening.

Please start a New Topic if this is not your thread. Thank-you for your co-operation.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI