This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

About:blank Problem

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am new to this forum and hope I am doing this correctly. My home page keeps getting reset to about:blank and my computer is extremely slow. Have run various programs including cwshredder ;but, nothing seems to fix the problem.

Any help would be appreciated. Below is my log from HijackThis.

Logfile of HijackThis v1.99.0
Scan saved at 5:00:28 PM, on 2/7/05
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v5.50 SP1 (5.50.4522.1800)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\BROADJUMP\CLIENT FOUNDATION\CFD.EXE
C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\HJT\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = home.bellsouth.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\sp.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = home.bellsouth.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\sp.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BellSouth
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar.dll
O2 - BHO: (no name) - {71FBDA41-73A1-11D9-98DA-000076807274} - C:\WINDOWS\SYSTEM\KAFJ.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - Startup: TextBridge Instant Access OCR.lnk = C:\Program Files\TextBridge Classic\Bin\TBMenu.exe
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmsearch.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmsimilar.html
O8 - Extra context menu item: Backward &Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmtrans.html
O8 - Extra context menu item: &AIM Search - res://C:\PROGRA~1\AIMTOO~1\AIMBAR.DLL/aimsearch.htm
O14 - IERESET.INF: START_PAGE_URL=http://www.bellsouth.net
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409
O18 - Filter: text/html - {2A6FDDC0-7888-11D9-98DA-0000C56C527A} - C:\WINDOWS\SYSTEM\KAFJ.DLL
O18 - Filter: text/plain - {2A6FDDC0-7888-11D9-98DA-0000C56C527A} - C:\WINDOWS\SYSTEM\KAFJ.DLL
I was able to save the startdreck.zip file to my desktop ;however, when I clicked on the link for w98fix.zip the page that came up stated that " This Account Has Been Suspended". The startdeck log is as follows: StartDreck (build 2.1.7 public stable) - 2005-02-08 @ 19:52:30 (GMT -05:00) Platform: Windows 98 (Win 4.10.1998 ) Internet Explorer: 5.50.4522.1800 Logged in as The Crowders at THECROWD »Registry »Run Keys »Current User »Run »RunOnce »Default User »Run »RunOnce »Local Machine »Run *ScanRegistry=C:\WINDOWS\scanregw.exe /autorun *TaskMonitor=C:\WINDOWS\taskmon.exe *SystemTray=SysTray.Exe *LoadPowerProfile=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme *BJCFD=C:\Program Files\BroadJump\Client Foundation\CFD.exe »RunOnce »RunServices *LoadPowerProfile=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme *SchedulingAgent=mstask.exe »RunServicesOnce **u=rundll32 C:\WINDOWS\SYSTEM\SQLEGGP.DLL,StreamingDeviceSetup »RunOnceEx »RunServicesOnceEx »Files »System/Drivers »Running Processes +FFCFF0A9=C:\WINDOWS\SYSTEM\KERNEL32.DLL +FFFF8415=C:\WINDOWS\SYSTEM\MSGSRV32.EXE +FFFFB385=C:\WINDOWS\SYSTEM\MPREXE.EXE +FFFFA94D=C:\WINDOWS\SYSTEM\mmtask.tsk +FFFE0755=C:\WINDOWS\SYSTEM\MSTASK.EXE +FFFE3469=C:\WINDOWS\RUNDLL32.EXE +FFFE9AF5=C:\WINDOWS\EXPLORER.EXE +FFFD381D=C:\WINDOWS\TASKMON.EXE +FFFD20A5=C:\WINDOWS\SYSTEM\SYSTRAY.EXE +FFFDE019=C:\PROGRAM FILES\BROADJUMP\CLIENT FOUNDATION\CFD.EXE +FFFC1E7D=C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE +FFFC0815=C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE +FFC3A38D=C:\WINDOWS\SYSTEM\SPOOL32.EXE +FFC3D921=C:\WINDOWS\DESKTOP\STARTDRECK.EXE »Application specific
Okay don't worry I have a copy, but on another computer. Give me some time to log into that computer and I will upload the file in my next post.
Go Ahead and download the following.

https://beta.activeupdate.trendmicro.com/fi…gentv1.0007.zip

Also Download the following CWshredder, Ad-aware, & Spy-Bot.
  • Updating Ad-aware:
    Double-Click the Desktop Icon > Click 'Check For Updates Now' > Click 'Connect'
  • Updating Spybot:
    Double-Click the Desktop Icon > Click Update > Drop-Down Box UniDo(Europe) > Select Pure-Elite(USA) or EON (AU) > Click 'Search for Updates' > Click 'Download Updates'
Please copy my notes in to notepad and save to your dekstop. You need to be offline and in safe mode to remove the About:Blank Bug

Now rebooot into safe mode (press f8 during reboot, select safe mode) and DON'T reconnect to the net.
  • Unzip the uninstall utlility you saved to your desktop
  • Allow the program to finish and exit out the program once complete
  • Double-Click CWShredder and click 'Fix'
  • Close CWShredder
  • Open Ad-aware and make the following changes to the settings in Ad-aware.
  • Under Ad-aware 6 > Settings (Gear at the top) > Tweak > Scanning Engine:
    check: "Unload recognized processes during scanning."
  • Under Ad-aware 6 > Settings (Gear at the top) > Tweak > Cleaning Engine:
    Check: "Let Windows remove files in use at next reboot."
Press 'Proceed'

Click 'Start'
  • Select option 'Use Custom scanning options'
  • Click 'Activate in-depth scan'
  • Click 'Select drives\folders to scan' Select the active partition which is usually C:
Click 'Customize'
  • Make sure the following are all are Checked:
  • 'Scan Within Archives'
  • 'Scan Active Processes'
  • 'Scan Registry'
  • 'Deep Scan Registry'
  • 'Scan My IE Favorites For Banned URL'S
  • 'Scan My Hosts File'
Click 'Proceed'
  • Now click "Next" to let Ad-aware scan your drives.
  • Once Ad-aware has completed its scan click 'Next' > Now Click 'Scan Summary' > Click All the Boxes with a Green Check Mark
  • Now Click 'Next' and Finally Click 'OK'
Close Out Ad-Aware

Open Spybot.
  • Click 'Search & Destroy'
  • Click 'Check for problems' (the program will now search your HDD)
  • Make sure all findings are checked and click 'Fix Selected Problems'
Close SpyBot and Reboot!

Once complete post a fresh log in your thread.
Did as you requested. Ran fixagent, CWShreder, Ad-aware, & SpyBot. Please note that all the programs did find problems. One question: CWShreder found no sign of CoolWeb ;however, it did find two register changes. Ad-aware did list CoolWeb as being found. Why the difference in results? When you said to enter a new log in this thread I assume that you were refering to StartDreck. I re-ran and here is new log. StartDreck (build 2.1.7 public stable) - 2005-02-09 @ 21:15:12 (GMT -05:00) Platform: Windows 98 (Win 4.10.1998 ) Internet Explorer: 5.50.4522.1800 Logged in as The Crowders at THECROWD »Registry »Run Keys »Current User »Run »RunOnce »Default User »Run »RunOnce »Local Machine »Run *ScanRegistry=C:\WINDOWS\scanregw.exe /autorun *TaskMonitor=C:\WINDOWS\taskmon.exe *SystemTray=SysTray.Exe *LoadPowerProfile=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme *BJCFD=C:\Program Files\BroadJump\Client Foundation\CFD.exe »RunOnce »RunServices *LoadPowerProfile=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme *SchedulingAgent=mstask.exe »RunServicesOnce »RunOnceEx »RunServicesOnceEx »Files »System/Drivers »Running Processes +FFCFF0B9=C:\WINDOWS\SYSTEM\KERNEL32.DLL +FFFF8405=C:\WINDOWS\SYSTEM\MSGSRV32.EXE +FFFFB395=C:\WINDOWS\SYSTEM\MPREXE.EXE +FFFE19D5=C:\WINDOWS\SYSTEM\mmtask.tsk +FFFE1C45=C:\WINDOWS\SYSTEM\MSTASK.EXE +FFFE5261=C:\WINDOWS\EXPLORER.EXE +FFFEE69D=C:\WINDOWS\TASKMON.EXE +FFFE9121=C:\WINDOWS\SYSTEM\SYSTRAY.EXE +FFFD5F79=C:\PROGRAM FILES\BROADJUMP\CLIENT FOUNDATION\CFD.EXE +FFFD6EB9=C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE +FFFC16D1=C:\WINDOWS\DESKTOP\STARTDRECK.EXE »Application specific Please note that when I went back on line to add this log that about:blank came up ;but, that my speed in changing web pages did increase greatly.
RunServicesOnce **u=rundll32 C:\WINDOWS\SYSTEM\SQLEGGP.DLL,StreamingDeviceSetup »RunServicesOnce Your startdreck log looks good. The programs removed the file that reinfects your system. If you could please post a fresh Hijackthis log so we can clean out what remains, I would appreciate it.
Ok. Here is my new HijackThis Log:

Logfile of HijackThis v1.99.0
Scan saved at 5:55:15 PM, on 2/10/05
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v5.50 SP1 (5.50.4522.1800)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\BROADJUMP\CLIENT FOUNDATION\CFD.EXE
C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\HJT\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = home.bellsouth.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\sp.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = home.bellsouth.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\sp.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BellSouth
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar.dll
O2 - BHO: (no name) - {71FBDA41-73A1-11D9-98DA-000076807274} - C:\WINDOWS\SYSTEM\KAFJ.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - Startup: TextBridge Instant Access OCR.lnk = C:\Program Files\TextBridge Classic\Bin\TBMenu.exe
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmsearch.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmsimilar.html
O8 - Extra context menu item: Backward &Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmtrans.html
O8 - Extra context menu item: &AIM Search - res://C:\PROGRA~1\AIMTOO~1\AIMBAR.DLL/aimsearch.htm
O14 - IERESET.INF: START_PAGE_URL=http://www.bellsouth.net
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O18 - Filter: text/html - {C2F6F340-7ADF-11D9-98DA-0000D2CC53BA} - C:\WINDOWS\SYSTEM\KAFJ.DLL
O18 - Filter: text/plain - {C2F6F340-7ADF-11D9-98DA-0000D2CC53BA} - C:\WINDOWS\SYSTEM\KAFJ.DLL
Close all your Internet Browsers and any running programs, run Hijackthis and place a check next to the following

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = home.bellsouth.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\sp.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = home.bellsouth.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\sp.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {71FBDA41-73A1-11D9-98DA-000076807274} - C:\WINDOWS\SYSTEM\KAFJ.DLL
O18 - Filter: text/html - {C2F6F340-7ADF-11D9-98DA-0000D2CC53BA} - C:\WINDOWS\SYSTEM\KAFJ.DLL
O18 - Filter: text/plain - {C2F6F340-7ADF-11D9-98DA-0000D2CC53BA} - C:\WINDOWS\SYSTEM\KAFJ.DLL

and click fix. Now search for the following file and delete it. If you receive an error message > Right-Click on the File > Properties > and Make sure Read-Only is NOT checked > If it's checked uncheck and try to delete > if you receive an error message again > Boot into safe mode and delete from safe mode.

File:
C:\WINDOWS\SYSTEM\KAFJ.DLL

Now run a full Ad-aware scan and please post a fresh Log.
Did as you said and here is my new hijackthis log:

Logfile of HijackThis v1.99.0
Scan saved at 7:12:06 PM, on 2/11/05
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v5.50 SP1 (5.50.4522.1800)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\BROADJUMP\CLIENT FOUNDATION\CFD.EXE
C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\HJT\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bellsouth.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BellSouth
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - Startup: TextBridge Instant Access OCR.lnk = C:\Program Files\TextBridge Classic\Bin\TBMenu.exe
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmsearch.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmsimilar.html
O8 - Extra context menu item: Backward &Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmtrans.html
O8 - Extra context menu item: &AIM Search - res://C:\PROGRA~1\AIMTOO~1\AIMBAR.DLL/aimsearch.htm
O14 - IERESET.INF: START_PAGE_URL=http://www.bellsouth.net
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab


ALSO I HAVE A COUPLE OF QUESTIONS / REMARKS:

(1) WHEN I DID AD-AWARE IT CAME UP WITH SEVERAL CRITICAL ITEMS AND
ALL OF THEM WERE TRACKING COOKIES. I DELETED THEM AND RE-RAN
THE PROGRAM. IT FOUND NO CRITICAL ITEMS.

(2) UNDER INTERNET OPTIONS I PUT IN MY PREFERED HOME PAGE (BELLSOUTH)
AND I NOTICED THAT UNDER THE USE BLANK OPTION ABOUT:BLANK IS
STILL LISTED. THIS APPEARS TO BE THE ONLY REFERENCE OF ABOUT:BLANK
ON MY COMPUTER. HOW CAN I GET THIS REMOVED.

THANKS
Does it still say that after changing the home page to bellsouth? You must manually change your homepage back to it's original after removing all the garbage.
YES. I WENT TO BELLSOUTH WHICH I USE AS MY HOME PAGE AND THEN CLICKED THE BOX THAT SAYS "USE CURRENT" AND THEN CLICKED APPLY. WHENEVER I GO ONLINE I GOES TO BELLSOUTH AS I WANTED. IF I CLICK ON THE OTHER BOXES THEY SHOW THE FOLLOWING: DEFAULT - SHOWS A BUNCH OF JUNK. _????X USE BLANK - SHOWS ABOUT:BLANK AS I TOLD THE COMPUTER TO USE THE CURRENT PAGE (WWW.HOME.BELLSOUTH.NET) AND IT DOES SO I BELIEVE EVERYTHING IS FINE. IS MY ASSUMPTION A GOOD ONE? WILL ABOUT:BLANK BEING LISTED UNDER USE BLANK PRESENT A PROBLEM ? ALSO TO PREVENT THE ABOUT:BLANK PROBLEM FROM OCCURING AGAIN, DO YOU HAVE ANY SUGGESTIONS THAT I NEED TO DO? THANKS
(1) I manually went to www.home.bellsouth.net and clicked on use current page as how page because I could enter it into default page. Couldn't figure out how. (2) When I click the default button it shows garbage. (3) When I click the use blank button it shows about:blank. After clicking use current page and rebooting the results are as follows: (1) When I go online bellsouth comes up as I wanted. (2) When I am online and at whatever webpage and click on home page it returns to bellsouth. My home page stays at bellsouth and no longer changes unless I do it manually. Thank goodness !!!!!
That sounds good to me. Based on your last log and the information you've provided, you're clean. Well Done Mate

To prevent the hijackers from taking over your system, increase the level of security on your system. Don't allow the hijackers to take you over!! Review these articles to increase the level of security.

http://www.computercops.biz/postt7736.html
http://www.markusjansson.net/eienbid.html

In addition, retain the spyware removal tools I had you download, update them weekly and perform full scans after updating. Good Way to keep spyware off your system.


I am going to lock this thread. If you have any problems please pm a moderator with a link to this thread and they will re-open this thread.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI