This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Adware Does Not Correct Problem

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Here is my Hijack This log

I do have two different drives so I can use the unaffected drive for now


Logfile of HijackThis v1.99.0
Scan saved at 1:30:07 AM, on 1/30/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\SYGATE\SPF\SMC.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\STARTER.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\WMEDIA16.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPOTDD01.EXE
C:\PROGRAM FILES\COREL\WORDPERFECT OFFICE 2000\PROGRAMS\ALARM.EXE
C:\PROGRAM FILES\COREL\WORDPERFECT OFFICE 2000\PROGRAMS\DAD9.EXE
C:\APACHE2\BIN\APACHEMONITOR.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPOHMR08.EXE
C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPOEVM08.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPOSTS08.EXE
C:\HARD DRIVE D\SOFTWARE\HIJACK\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\sp.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\sp.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.google.ca"); (C:\Program Files\Netscape\Users\default\prefs.js)
O2 - BHO: (no name) - {B98CAB80-7259-11D9-8C38-0080E6E50985} - C:\WINDOWS\SYSTEM\MCPEGH.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\SYGATE\SPF\SMC.EXE -startgui
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [Shell] C:\WINDOWS\wmedia16.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SmcService] C:\PROGRAM FILES\SYGATE\SPF\SMC.EXE
O4 - HKCU\..\Run: [Autoupdate Service] C:\WINDOWS\msxmidi.exe
O4 - Startup: hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - Startup: CorelCENTRAL Alarms.LNK = C:\Program Files\Corel\WordPerfect Office 2000\programs\alarm.exe
O4 - Startup: Desktop Application Director 9.LNK = C:\Program Files\Corel\WordPerfect Office 2000\programs\dad9.exe
O4 - Startup: Monitor Apache Servers.lnk = C:\Apache2\bin\ApacheMonitor.exe
O4 - Startup: hp instant support.lnk = C:\Program Files\Hewlett-Packard\hpis\bin\matcli.exe
O4 - Startup: hp psc 1000 series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O12 - Plugin for .mpg: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll
O12 - Plugin for .mpeg: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll
O16 - DPF: {40289096-9F72-4A04-BCB3-E434ECDCEE33} (AppDLCtrl Class) - http://download.howudodat.com/chatterbox/download/appdl.cab
O16 - DPF: {11010101-1001-1111-1000-110263637096} - ms-its:mhtml:file://c:\nosuch.mht!http://dev.eurodnsservices.com/fwni/kill.chm::/d_Main.exe
O16 - DPF: {E93A6FCA-C052-45DF-AC9B-B729066092F8} (Util Class) - https://isupport4.hp.com/motivedocs/linklauncher/MotUtil.cab
O18 - Filter: text/html - {D3C77B80-6F46-11D9-8C38-0080B924D386} - C:\WINDOWS\SYSTEM\MCPEGH.DLL
O18 - Filter: text/plain - {D3C77B80-6F46-11D9-8C38-0080B924D386} - C:\WINDOWS\SYSTEM\MCPEGH.DLL
This self-help guide will allow you to remove the About:Blank Hijacker in Windows 95/98/ME
(Also known as Hidden_DLL, Appinit_DLLs, About:NavigationFailure, \temp\sp.html)



What this program does:

When you open Internet Explorer your browser will be redirected to a page called About:Blank or About:NavigationFailure.


Tools Needed for this fix:

HijackThis

CWShredder

Ad-Aware

StartDreck

Related Tutorials:

How to use HijackThis to remove Browser Hijackers & Spyware

How to remove CoolWebSearch with CWShredder

Using Ad-Aware SE to remove Spyware & Hijackers from Your Computer


Symptoms in a HijackThis Log:


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\Windows\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

If you have any of the types of symptoms then you most likely have this type of infection and should continue reading.


——————————————————————————–


Removal Instructions: - Note this fix is only for Windows 95, 98, or ME. For XP/2000 Instructions click here.


Please make sure that you can view all hidden files. Instructions on how to do this can be found here:
How to see hidden files in Windows


Download StartDreck from the link provided above.


Once it is downloaded, extract the file into c:\startdreck.


Navigate to c:\startdreck and double-click on Startdreck.exe


When the program opens click on the Config button.


Then click on the unmark all button.


Then put checkmarks in the following checkboxes:
Under Registry put a checkmark in the Run Keys checkbox.

Under System/Drivers put a check in the Running Proccess checkbox.


Press the OK button.


You will now see a lot of text appear on your screen. Scroll through this text until you see the RunServicesOnce section. Under that we are looking for an entry that contains a DLL in the \system directory followed by a ,StreamingDeviceSetup. An example of a entry like that is below:

»RunServicesOnce
**t=rundll32 C:\WINDOWS\SYSTEM\MSC.DLL,StreamingDeviceSetup

If this file does not exist skip to step 15.


Write down the file name from that entry. In the above example the filename is c:\windows\system\msc.dll


Now download Win98Fix.zip from http://www10.brinkster.com/expl0iter/freeatlast/pvtool.htm and extract it to c:\win98fix.


Navigate to the c:\win98fix folder and double-click on the RunFix.reg. If it prompts whether or not you want to merge the information, click the Yes button.


When that is done reboot your computer.


Now find the file found in step 9, which should now be visible, and delete it.


Now download Cwshredder from the link above.


After you download the program, unzip it into the directory c:\cwshredder. Make sure all browser windows are closed and double-click on the cwshredder.exe to start the program.


Next click on the FIX button, not the Scan Only button, and let it scan your computer. When it is done, exit the program.


Next, using Internet Explorer, run both of these two online virus scans:
http://housecall.antivirus.com/

http://www.pandasoftware.com/activescan


Please download and install the latest version of Ad-Aware from the link above.


When you run the program make sure you update it and then scan with it and fix any problems it finds.


Exit the program when you have fixed it everything it finds.


Now your computer should no longer be infected with the About:Blank hijacker. If you are still having problems and none of these steps worked, then please post a HijackThis log in our HijackThis Logs and Analysis forum




——————————————————————————–


This is a self-help guide. Use at your own risk.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI