wgf743
Topic Starter
about:blank is entrenched on my system and scoffs at my attempts to root it out.
CoolWWWSearch may still be lurking but "blank" is the main issue.
Today 3/9/05 I did the following:
- turned off the DSL modem
- ran CWShredder v.1.59.1
- ran FXAgentB.exe, no finds
- ran Spybot S&D 1.3,
- ran AboutBuster, ref list 25, obtained 3/8/05
- checked IE home page, it was set to http://www.google.com, made it http://www.msn.com
- ran HiJackThis, log follows
(more steps after log)
Logfile of HijackThis v1.97.7
Scan saved at 11:52:49 AM, on 3/10/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\crir.exe
C:\Program Files\TimeSink\AdGateway\TsAdBot.exe
C:\quic2002\QWDLLS.EXE
C:\hijack\HijackThis.exe
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\acrobat\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {9283B90B-6824-9F8C-CDEE-A26195750B35} - C:\WINDOWS\system32\wings.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [TimeSink Ad Client] "C:\Program Files\TimeSink\AdGateway\TsAdBot.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Quicken Startup.lnk = C:\quic2002\QWDLLS.EXE
O4 - Global Startup: Billminder.lnk = C:\quic2002\BILLMIND.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.frame.crazywinnings.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1106782197740
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab
——— end log
(more steps)
- waited a few hours, checked IE home page, still set to msn.com OK
- did NOT turn on modem
- clicked on IE, naturally got message "cannot find page/server………."
- checked IE home page, now set to about:blank
- ran HiJackThis again, log follows
Logfile of HijackThis v1.97.7
Scan saved at 4:08:49 PM, on 3/10/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\crir.exe
C:\Program Files\TimeSink\AdGateway\TsAdBot.exe
C:\quic2002\QWDLLS.EXE
C:\hijack\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\acrobat\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {9283B90B-6824-9F8C-CDEE-A26195750B35} - C:\WINDOWS\system32\wings.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [TimeSink Ad Client] "C:\Program Files\TimeSink\AdGateway\TsAdBot.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Quicken Startup.lnk = C:\quic2002\QWDLLS.EXE
O4 - Global Startup: Billminder.lnk = C:\quic2002\BILLMIND.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.frame.crazywinnings.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1106782197740
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab
——— end log
The "28129" and "about:blank" entries have been on the system before and I have got rid of them but here they are again. I don't need"Crazywinnings.com" also. In the earlier log, I don't know what c:\windows\crir.exe is for. It's gone in the second log.
I've tried running the purgers in "safe mode" earlier but no good results.
I have been reading some of the other topics concerning the "about:blank" problem, and borrowed some of the recommendations given there, as far as which purgers to run and when, but it looks as if I need a procedure for my own particular situation.
Could you please recommend one?
I also have a couple of Spybot issues (should I start another topic on this?) that may be related.
In the "Immunize" screen, it tells me that "Browser Helper to block bad downloads is NOT installed," and I can't click the checkbox for "Enable permanent blocking of bad addresses in Internet Explorer." If I do the Immunize, and afterwards check the Sites list for the Restricted Sites in the Security tab of IE Properties, it looks as if Spybot has placed its list there. When the IE home page gets set to "about:blank," the Sites that Spybot set up are gone. On another system I have (running Windows 9x) when I bring up the Immunize screen, it tells me that "Browser Helper to block bad downloads" is installed, and I can click the "…permanent blocking…" checkbox. I thought I made identical default installs on both systems but must have missed something. Any ideas on this?
Thanks very much for any help you can give me on these problems.
CoolWWWSearch may still be lurking but "blank" is the main issue.
Today 3/9/05 I did the following:
- turned off the DSL modem
- ran CWShredder v.1.59.1
- ran FXAgentB.exe, no finds
- ran Spybot S&D 1.3,
- ran AboutBuster, ref list 25, obtained 3/8/05
- checked IE home page, it was set to http://www.google.com, made it http://www.msn.com
- ran HiJackThis, log follows
(more steps after log)
Logfile of HijackThis v1.97.7
Scan saved at 11:52:49 AM, on 3/10/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\crir.exe
C:\Program Files\TimeSink\AdGateway\TsAdBot.exe
C:\quic2002\QWDLLS.EXE
C:\hijack\HijackThis.exe
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\acrobat\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {9283B90B-6824-9F8C-CDEE-A26195750B35} - C:\WINDOWS\system32\wings.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [TimeSink Ad Client] "C:\Program Files\TimeSink\AdGateway\TsAdBot.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Quicken Startup.lnk = C:\quic2002\QWDLLS.EXE
O4 - Global Startup: Billminder.lnk = C:\quic2002\BILLMIND.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.frame.crazywinnings.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1106782197740
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab
——— end log
(more steps)
- waited a few hours, checked IE home page, still set to msn.com OK
- did NOT turn on modem
- clicked on IE, naturally got message "cannot find page/server………."
- checked IE home page, now set to about:blank
- ran HiJackThis again, log follows
Logfile of HijackThis v1.97.7
Scan saved at 4:08:49 PM, on 3/10/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\crir.exe
C:\Program Files\TimeSink\AdGateway\TsAdBot.exe
C:\quic2002\QWDLLS.EXE
C:\hijack\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\acrobat\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {9283B90B-6824-9F8C-CDEE-A26195750B35} - C:\WINDOWS\system32\wings.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [TimeSink Ad Client] "C:\Program Files\TimeSink\AdGateway\TsAdBot.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Quicken Startup.lnk = C:\quic2002\QWDLLS.EXE
O4 - Global Startup: Billminder.lnk = C:\quic2002\BILLMIND.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.frame.crazywinnings.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1106782197740
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab
——— end log
The "28129" and "about:blank" entries have been on the system before and I have got rid of them but here they are again. I don't need"Crazywinnings.com" also. In the earlier log, I don't know what c:\windows\crir.exe is for. It's gone in the second log.
I've tried running the purgers in "safe mode" earlier but no good results.
I have been reading some of the other topics concerning the "about:blank" problem, and borrowed some of the recommendations given there, as far as which purgers to run and when, but it looks as if I need a procedure for my own particular situation.
Could you please recommend one?
I also have a couple of Spybot issues (should I start another topic on this?) that may be related.
In the "Immunize" screen, it tells me that "Browser Helper to block bad downloads is NOT installed," and I can't click the checkbox for "Enable permanent blocking of bad addresses in Internet Explorer." If I do the Immunize, and afterwards check the Sites list for the Restricted Sites in the Security tab of IE Properties, it looks as if Spybot has placed its list there. When the IE home page gets set to "about:blank," the Sites that Spybot set up are gone. On another system I have (running Windows 9x) when I bring up the Immunize screen, it tells me that "Browser Helper to block bad downloads" is installed, and I can click the "…permanent blocking…" checkbox. I thought I made identical default installs on both systems but must have missed something. Any ideas on this?
Thanks very much for any help you can give me on these problems.