This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

About:blank Entrenched

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

about:blank is entrenched on my system and scoffs at my attempts to root it out.
CoolWWWSearch may still be lurking but "blank" is the main issue.

Today 3/9/05 I did the following:

- turned off the DSL modem
- ran CWShredder v.1.59.1
- ran FXAgentB.exe, no finds
- ran Spybot S&D 1.3,
- ran AboutBuster, ref list 25, obtained 3/8/05
- checked IE home page, it was set to http://www.google.com, made it http://www.msn.com
- ran HiJackThis, log follows
(more steps after log)

Logfile of HijackThis v1.97.7
Scan saved at 11:52:49 AM, on 3/10/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\crir.exe
C:\Program Files\TimeSink\AdGateway\TsAdBot.exe
C:\quic2002\QWDLLS.EXE
C:\hijack\HijackThis.exe

O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\acrobat\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {9283B90B-6824-9F8C-CDEE-A26195750B35} - C:\WINDOWS\system32\wings.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [TimeSink Ad Client] "C:\Program Files\TimeSink\AdGateway\TsAdBot.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Quicken Startup.lnk = C:\quic2002\QWDLLS.EXE
O4 - Global Startup: Billminder.lnk = C:\quic2002\BILLMIND.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.frame.crazywinnings.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1106782197740
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab

——— end log

(more steps)
- waited a few hours, checked IE home page, still set to msn.com OK
- did NOT turn on modem
- clicked on IE, naturally got message "cannot find page/server………."
- checked IE home page, now set to about:blank
- ran HiJackThis again, log follows

Logfile of HijackThis v1.97.7
Scan saved at 4:08:49 PM, on 3/10/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\crir.exe
C:\Program Files\TimeSink\AdGateway\TsAdBot.exe
C:\quic2002\QWDLLS.EXE
C:\hijack\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\acrobat\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {9283B90B-6824-9F8C-CDEE-A26195750B35} - C:\WINDOWS\system32\wings.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [TimeSink Ad Client] "C:\Program Files\TimeSink\AdGateway\TsAdBot.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Quicken Startup.lnk = C:\quic2002\QWDLLS.EXE
O4 - Global Startup: Billminder.lnk = C:\quic2002\BILLMIND.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.frame.crazywinnings.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1106782197740
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab

——— end log

The "28129" and "about:blank" entries have been on the system before and I have got rid of them but here they are again. I don't need"Crazywinnings.com" also. In the earlier log, I don't know what c:\windows\crir.exe is for. It's gone in the second log.

I've tried running the purgers in "safe mode" earlier but no good results.

I have been reading some of the other topics concerning the "about:blank" problem, and borrowed some of the recommendations given there, as far as which purgers to run and when, but it looks as if I need a procedure for my own particular situation.
Could you please recommend one?

I also have a couple of Spybot issues (should I start another topic on this?) that may be related.
In the "Immunize" screen, it tells me that "Browser Helper to block bad downloads is NOT installed," and I can't click the checkbox for "Enable permanent blocking of bad addresses in Internet Explorer." If I do the Immunize, and afterwards check the Sites list for the Restricted Sites in the Security tab of IE Properties, it looks as if Spybot has placed its list there. When the IE home page gets set to "about:blank," the Sites that Spybot set up are gone. On another system I have (running Windows 9x) when I bring up the Immunize screen, it tells me that "Browser Helper to block bad downloads" is installed, and I can click the "…permanent blocking…" checkbox. I thought I made identical default installs on both systems but must have missed something. Any ideas on this?

Thanks very much for any help you can give me on these problems.
Welcome to the forum.
You are using an old version of HJT, could you please delete it and rescan the system with the new version and post that log.
When you do, please download HJT into its own folder so backups can be made.

example: C:\MyHJT\HJT.exe or C:\MyDocuments\MyHJT\HJT.exe

http://tools.radiosplace.com/HijackThis.exe

Thanks, MrC
Thank you for your reply.
Here is a new log from the version of HijackThisI that I just downloaded. I see a couple of new entries from the last log. All we have run since the last log is Quicken, TurboTax, and MSWord. The computer is a laptop, standalone at home - no networks.

Logfile of HijackThis v1.99.1
Scan saved at 10:36:59 AM, on 3/17/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\crir.exe
C:\Program Files\TimeSink\AdGateway\TsAdBot.exe
C:\WINDOWS\sdkuc.exe
C:\quic2002\QWDLLS.EXE
C:\WINDOWS\system32\cmd.exe
C:\hijack\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\acrobat\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {095AE972-3DD7-8BEE-89A9-42A741DF2F69} - C:\WINDOWS\winhk32.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [TimeSink Ad Client] "C:\Program Files\TimeSink\AdGateway\TsAdBot.exe"
O4 - HKLM\..\Run: [sdkuc.exe] C:\WINDOWS\sdkuc.exe
O4 - HKLM\..\RunOnce: [crir.exe] C:\WINDOWS\crir.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Quicken Startup.lnk = C:\quic2002\QWDLLS.EXE
O4 - Global Startup: Billminder.lnk = C:\quic2002\BILLMIND.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O15 - Trusted IP range: 206.161.125.149
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1106782197740
O23 - Service: Workstation NetLogon Service ( 6QÔõ'ª´ÆÐ8) - Unknown owner - C:\WINDOWS\system32\mszr.exe (file missing)

End log ——-
Please read through and understand these instructions before you start (you may want to print this out).

Please download and install these programs - don't run them yet!!

Please download and unzip
AboutBuster to a folder. Inside the folder is a readme file that has instructions on the use of the program.
AboutBuster MUST be updated before you use it.
Start AboutBuster, click the update button, check for update, drag the box to the side and hit download updates, close the box . Don't run it yet.

Download and unzip cwsserviceremove to your desktop. use link below:
http://lineofire.geekstogo.com/cwsserviceremove.zip

Download CW-Shredder at the link below:
http://cwshredder.net/bin/CWShredder.exe

Open Windows Explorer & Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked.
Also uncheck "Hide protected operating system files" and untick "hide extensions for known file types" . Now click "Apply to all folders"
Click "Apply" then "OK"

Reboot into SafeMode. <—MAKE SURE YOU KNOW HOW TO DO THIS!!

+++++++++++++++++++++++++++++++++++++++++++++++++

Here's the fix:

Important Step
1. Go to Start->Run and type "Services.msc" (without quotes) then hit Ok
Scroll down and find the service called:
Workstation NetLogon Service

When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close any open windows. If you don´t find this service listed go ahead with the next steps.

2. Reboot into Safe Mode

3. Press Ctrl+Alt+Delete once => Click Task Manager => Click the Processes tab => Double-click the Image Name column header to alphabetically sort the processes => Scroll through the list and look for:

crir.exe
sdkuc.exe

If you find the files, click on them, and then click End Process => Exit the Task Manager, if not continue on.

4. CLOSE ALL WINDOWS AND BROWSERS Scan with Hijack This and put checks next to all the following, then click "Fix Checked"

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\mvxnn.dll/sp.html#28129
O2 - BHO: (no name) - {095AE972-3DD7-8BEE-89A9-42A741DF2F69} - C:\WINDOWS\winhk32.dll
O4 - HKLM\..\Run: [TimeSink Ad Client] "C:\Program Files\TimeSink\AdGateway\TsAdBot.exe"
O4 - HKLM\..\Run: [sdkuc.exe] C:\WINDOWS\sdkuc.exe
O4 - HKLM\..\RunOnce: [crir.exe] C:\WINDOWS\crir.exe
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O15 - Trusted IP range: 206.161.125.149
O23 - Service: Workstation NetLogon Service ( 6QÔõ'ª´ÆÐ8) - Unknown owner - C:\WINDOWS\system32\mszr.exe (file missing)

Click on Fix Checked and exit HijackThis.

5. Run AboutBuster . This will scan your computer for the bad files and delete them. It will ask to scan the system again, let it. Save the report (copy and paste into notepad or wordpad and save as a .txt file) and post a copy back here when you are done with all the steps.

6. Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure these 3 are checked and then press *ok* to remove:

Temporary Files
Temporary Internet Files
Recycle Bin

7. Double click on the cwsserviceremove and when asked to merge say yes.

8. Run CW-Shredder - Hit the FIX button - let it run and fix what it finds.

9. Reboot into normal mode.

10. Download and run this online virus scan:
http://housecall.trendmicro.com/housecall/start_corp.asp
Make sure you check "AutoClean"

11. Reboot and post a fresh HJT log back here by using the add reply button below, and lets see how we did, MrC

NOTE: You have TimeSink installed on your computer:
C:\Program Files\TimeSink\AdGateway\TsAdBot.exe
Here's a link to what it is.
http://cexx.org/tsadbot.htm
You may be able to uninstall it from your control panels add/remove programs, look for TimeSink.
Let me know.
Hello MrC

Looks as if we might be nearly there.

I have run the "fix" steps.
Misc comments on steps:
Ran in Safe mode thru step 8.
3. crir.exe and sdkuc.exe were not running
5. AboutBuster scanned 1452 items using Ref list 25. Log follows these comments.
8. CW-Shredder V.2.12, no finds, probably due to scans done on earlier dates. It had "finds" a couple of weeks ago.
10. Ran the TrendMicro virus scan. 53 finds. mostly for
chopenoz.b agent.kg… searchaid.a hideproc.b,
did not note them all, deleted them.
11. Hijack log below. Trusted zone entries are persisting.
In Control Panel/Add-Remove Programs, TSA was in program list, I checked it to remove, already removed.

After turning on the DSL modem and running the TrendMicro virus scan, I checked IE Internet Properties/General tab. Home page is still set to google.com. That's encouraging.


* About:Buster Log

Scanned at: 11:41:12 AM on: 3/21/2005


– Scan 1 —————————
About:Buster Version 4.0
Reference List : 25


ADS not scanned System(FAT)
Removed 2 Random Key Entries
Removed! : C:\WINDOWS\sdkuc.exe
Removed! : C:\WINDOWS\tcbyje.dat
Removed! : C:\WINDOWS\mzemku.dat
Attempted Clean Of Temp folder.
Removed Uninstall Key (HSA)
Removed Uninstall Key (SE)
Removed Uninstall Key (SW)
Pages Reset… Done!

– Scan 2 —————————
About:Buster Version 4.0
Reference List : 25


ADS not scanned System(FAT)
Attempted Clean Of Temp folder.
Pages Reset… Done!

* End AboutBuster 3/21/05

———————————————

Logfile of HijackThis v1.99.1
Scan saved at 12:41:41 PM, on 3/21/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\quic2002\QWDLLS.EXE
C:\hijack\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\acrobat\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Quicken Startup.lnk = C:\quic2002\QWDLLS.EXE
O4 - Global Startup: Billminder.lnk = C:\quic2002\BILLMIND.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O15 - Trusted IP range: 206.161.125.149
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1106782197740
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab

* End Log 3/21/05 12:41

———————————————

The "crazywinnings" entries don't stay gone yet.

Other than that, looking pretty good!! Thank you very much.

Looks as if I should surely get the TrendMicro PC-cillin product or an equivalent and keep that running after we're done. I hate to admit I've been operating in "naive" mode.

Concerning SpyBotS&D - once "Immunize" has been run, SpyBot doesn't need to be kept running, does it? I would assume that the browser should now be keeping out SpyBot's list of restricted sites, not SpyBot itself.

End post.

Concerning SpyBotS&D - once "Immunize" has been run, SpyBot doesn't need to be kept running, does it? I would assume that the browser should now be keeping out SpyBot's list of restricted sites, not SpyBot itself.


No it runs in the back round.

————————————————————————-

To get those 015s:
Download this file to your desktop:
http://www.mvps.org/winhelp2002/DelDomains.inf

Right-click on the deldomains.inf file and select 'Install'

Once it is finished your Zones should be reset.

——————————————————————————

Here's my recommendations for a secure system, if you have any questions, let me know.


Some preventive maintenance:

Must have or do.

Now that you're clean: <—-Important Step!!!!
Delete your system restore files and create a new restore point:
(ME and XP users only)

XP system restore

ME system restore


Visit Windows Update and install all the lastest critical updates.

Install these two free programs, they sit in the backround and protect your system from spy and adware being installed on your system, also from your browser being hijacked. Check for updates weekly.

SpywareBlaster

SpywareGuard


IE-SPYAD
Puts over 5000 sites in your restricted zone, so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
IE-SPYAD

SpyBot has some protection benefits - use them.

Need a free anti virus?
AVG*free
(check for updates - daily)

How about a firewall? The front door to your computer.
ZoneAlarm*free

———————————————————————

Free spyware removal programs:
SpyBot
AD-Aware
CW-Shredder

Free Online Trojan Scan

A SQUARED FREE TROJAN SCANNER

Trojan Hunter
TrojanHunter - free trial

Please consider using FireFox instead of Internet Explorer

Replace Java with SunJava

Pop-up stoppers:
GoogleToolBar
Pop-upStopperFree

Don't open e-mail attachments without first scanning them with an up-to-date
anti virus program, even after doing that I would be very careful. Don't click on any executables in e-mails or any other links that you're not sure of.
Watch your surfing habits, don't click on or download anything you're not sure of. Don't install a program that hasn't been recommended by a reputable organization.

Good luck and thanks for using the forum - MrC
As this problem has been resolved the topic will be closed. If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)

The subject of the email must be
"Reopen". Include your post username and details about why you need it reopened, with a valid link to your post.

Thanks, MrC

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI