This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

I Am Being Hijacked To About Blank

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am having trouble geting rid of a hijack program, i have ran uptodate addaware, hijack this , spybot, and crshreder, and nothing helps . hijackthis finds and removes what i think is the poblem but when i reboot it comes back, i have enclosed a current hijack this log . Logfile of HijackThis v1.98.2 Scan saved at 9:17:16 PM, on 10/20/04 Platform: Windows 98 SE (Win9x 4.10.2222A) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\SYSTEM\KERNEL32.DLL C:\WINDOWS\SYSTEM\MSGSRV32.EXE C:\WINDOWS\SYSTEM\MPREXE.EXE C:\WINDOWS\SYSTEM\mmtask.tsk C:\WINDOWS\EXPLORER.EXE C:\WINDOWS\SYSTEM\RNAAPP.EXE C:\WINDOWS\SYSTEM\TAPISRV.EXE C:\WINDOWS\ptsnoop.exe C:\MY DOCUMENTS\HIJACKTHIS.EXE R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank O2 - BHO: (no name) - {2E5A7229-22D8-11D9-A1ED-00102712EE7D} - C:\WINDOWS\SYSTEM\BIIM.DLL O4 - HKLM\..\Run: [CountrySelection] pctptt.exe O4 - HKLM\..\Run: [PTSNOOP] ptsnoop.exe O18 - Filter: text/html - {2E5A7228-22D8-11D9-A1ED-0010485E4BE6} - C:\WINDOWS\SYSTEM\BIIM.DLL O18 - Filter: text/plain - {2E5A7228-22D8-11D9-A1ED-0010485E4BE6} - C:\WINDOWS\SYSTEM\BIIM.DLL
After reading some of the other posts that have a similar problem that i have i have doun loaded dllcompare and here is a log from that program. * DLLCompare Log version(1.0.0.125) Files Found that Windows does not See or cannot Access *Not everything listed here means you are infected! ________________________________________________ C:\WINDOWS\SYSTEM\hlpgh.dll Sun Aug 1 2004 10:39:44p A…. 57,344 56.00 K ________________________________________________ 711 items found: 711 files, 0 directories. Total of file sizes: 119,634,109 bytes 114.09 M ——————–End log———————
Download FxAgentB.exe from here and save it to your desktop. After downloading, double-click the FxAgentB file to run it and the program will scan your entire hard drive - this may take a while. When it is done, it will generate a log file called FxAgentB.log - save that information as you will need to paste it here later. Reboot when done.

Next click here to download CWShredder by Merijn Bellekom and run it, hit 'fix' as opposed to 'scan only'. If you already have CWShredder, click 'Check for update' and make sure you are running version 1.59.1. Reboot when done.

Then click here to download Ad-Aware SE and install. Before scanning click on "check for updates now" to make sure you have the latest reference file. Click "Start", select "Perform Full System scan" and "Next" to start the scan. When the scan is finished, the screen will tell you if anything has been found, click "Next". The bad files will be listed, right click the pane and click "Select all objects" - this will put a check mark in the box at the side, click "Next" again and click "OK" at the prompt "# objects will be removed. Continue?".

Reboot when done, rescan with HijackThis and post a new log here, together with the FxAgentB log and a new DllCompare log.
Logfile of HijackThis v1.98.2 Scan saved at 4:37:37 PM, on 10/21/04 Platform: Windows 98 SE (Win9x 4.10.2222A) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\SYSTEM\KERNEL32.DLL C:\WINDOWS\SYSTEM\MSGSRV32.EXE C:\WINDOWS\SYSTEM\MPREXE.EXE C:\WINDOWS\SYSTEM\mmtask.tsk C:\WINDOWS\EXPLORER.EXE C:\WINDOWS\SYSTEM\RNAAPP.EXE C:\WINDOWS\SYSTEM\TAPISRV.EXE C:\MY DOCUMENTS\HIJACKTHIS.EXE O4 - HKLM\..\Run: [CountrySelection] pctptt.exe O4 - HKLM\..\Run: [PTSNOOP] ptsnoop.exe Symantec Backdoor.Agent.B Removal Tool 1.0.1.2 hidden viral process: fffe0511 (terminated) process: EXPLORER.EXE, thread: FFFEA19D (terminated) process: RNAAPP.EXE, thread: FFFDDE1D (terminated) process: TAPISRV.EXE, thread: FFFCFD2D (terminated) process: DDHELP.EXE, thread: FFFAC6C9 (terminated) process: IEXPLORE.EXE, thread: FFFB8E2D (terminated) process: FXAGENTB.EXE, thread: FFFABF35 (terminated) registry: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce: *jqo (restored) c:\WINDOWS\SYSTEM\HLPGH.DLL: (will be deleted on next reboot) The Backdoor.Agent.B removal was successful. The system will delete 1 Backdoor.Agent.B files from your PC on next reboot. Here is the report: 1 file(s) could not be deleted. They will be deleted on next reboot. The total number of the scanned files: 21120 The number of deleted files: 0 The number of viral processes terminated: 1 The number of viral threads terminated: 6 The number of registry entries fixed: 1 The tool initiated a system reboot. * DLLCompare Log version(1.0.0.125) Files Found that Windows does not See or cannot Access *Not everything listed here means you are infected! ________________________________________________ O^E says: "There were no files found :)" ________________________________________________ 710 items found: 710 files, 0 directories. Total of file sizes: 119,576,765 bytes 114.04 M ——————–End log———————
You're welcome - glad to help :D

To help keep you clean follow the recommendations in Tony's article here:

So how did I get infected in the first place?



As this problem has been resolved the topic will be closed. If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)

The subject of the email must be "Reopen". Include your post username and details about why you need it reopened, with a valid link to your post.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI