This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

About:blank Keeps On Comin'

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Let me think about this, we're just going around in circles.

Do you know how to navigate in the registry?

I'll get back to you asap. MrC
I'm afraid not. I've done it before, but with help from a friend who's no longer available, and that was looooong ago. Thanks for continuing to look into this. Mark
Can you post a fresh HJT log and also update AboutBuster

Start AboutBuster, click the update button, check for update, drag the box to the side and hit download updates, close the box

Then download hsremove.exe at the link below:
http://www.hsremove.com/

Thanks, MrC
Prior requests complete.

Thanks,
Mark


+++++

Logfile of HijackThis v1.99.1
Scan saved at 4:58:00 PM, on 4/2/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
c:\program files\comcast\security manager\app\CurtainsSysSvcNt.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.exe
C:\WINNT\system32\msiexec.exe
C:\WINNT\crtn.exe
C:\WINNT\system32\atluf.exe
C:\Security Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\system32\cqagd.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\system32\cqagd.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\system32\cqagd.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\system32\cqagd.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\system32\cqagd.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\system32\cqagd.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=C:\WINNT\system32\AUserInit.exe
O2 - BHO: (no name) - {1DF6F759-A37F-233E-D7C5-4616756486A6} - C:\WINNT\sdkqo32.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [PBReboot] c:\windows\rundll.exe c:\windows\system\setupx.dll,InstallHinfSection DefaultInstall 2 c:\windows\reboot.inf
O4 - HKLM\..\Run: [TridTray] TridTray.Exe
O4 - HKLM\..\Run: [atluf.exe] C:\WINNT\system32\atluf.exe
O4 - HKLM\..\RunOnce: [crtn.exe] C:\WINNT\crtn.exe
O4 - Startup: MySoftware NewsFlash.lnk = C:\Program Files\Common Files\MySoftware\NewsFlsh.exe
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Microsoft Office Shortcut Bar.lnk = C:\Program Files\Microsoft Office\Office\MSOFFICE.EXE
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINNT\system32\spool\drivers\w32x86\3\E_SRCV03.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: ComcastHSI - {55115FE6-33AE-4F7D-A2D2-162E1C6AA4F5} - http://www.comcast.net/ (file missing) (HKCU)
O9 - Extra button: Support - {876E60E4-B886-4E2D-A2A8-99BB468BA4BD} - http://www.comcastsupport.com/ (file missing) (HKCU)
O9 - Extra button: Help - {CF855F93-166F-45E4-8FFF-E6692C62B738} - http://online.comcast.net/help/ (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net/
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/Fuj…ploadClient.cab
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINNT\atlnr.exe (file missing)
O23 - Service: Curtains for Windows System Service (CurtainsSysSvc) - Authentium, Inc. - c:\program files\comcast\security manager\app\CurtainsSysSvcNt.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
Lets try this method I found, I hope it's clear and you should print this out for reference.

Please run HijackThis click on the "Open the Misc Tools Section" button on the open page. Then select "Delete an NT service" on the left-hand side. A "Delete a Windows NT Service" window will pop up. Try entering the following into the box and then click OK:
Remote Procedure Call (RPC) Helper
If that does not work try entering the short name: 11Fßä#·ºÄÖ`I
You will need to cut and paste the short name since the characters are not easily typed.

After doing the above exit HijackThis (I'm going to have you re-run it again in the next step but some people have a hard time find all the menus. So I'm going to have you exit and restart to make it easier.)

Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.

C:\WINNT\crtn.exe
C:\WINNT\system32\atluf.exe

After killing all the above processes, click Back button that is just under the process list next to the Run button.

Select the Delete an NT service on the left-hand side. A Delete a Windows NT Service window will pop up. Try entering the following into the box and then click OK (I'm just double checking to make sure it has not restarted because sometime it does).

Remote Procedure Call (RPC) Helper

If that does not work try cutting and pasing in the following short name: 11Fßä#·ºÄÖ`I
You must use cut and paste since the characters cannot be typed.

Let me know what happens while doing the above. If you are told that the service must be stopped, here's how:

Go to Start->Run and type "Services.msc" (without quotes) then hit Ok
Scroll down and find the service called:
Remote Procedure Call (RPC) Helper
When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close any open windows.

Then repeat the above steps to have HJT Delete this NT Service.

After killing all the above processes and deleting the NT Service, click Back on the lower right. Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now.
DO NOT OPEN ANOTHER BROWSER UNTIL AFTER POWER DOWN AND POWER UP, see below

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\system32\cqagd.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\system32\cqagd.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\system32\cqagd.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\system32\cqagd.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\system32\cqagd.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\system32\cqagd.dll/sp.html#28129
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {1DF6F759-A37F-233E-D7C5-4616756486A6} - C:\WINNT\sdkqo32.dll
O4 - HKLM\..\Run: [atluf.exe] C:\WINNT\system32\atluf.exe
O4 - HKLM\..\RunOnce: [crtn.exe] C:\WINNT\crtn.exe
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINNT\atlnr.exe (file missing)

Click on Fix Checked and exit HijackThis.



Run Windows Explorer and look for and try to delete these files:


C:\WINNT\atlnr.exe
C:\WINNT\crtn.exe
C:\WINNT\sdkqo32.dll
C:\WINNT\system32\cqagd.dll

(and any other files with the same name that end in .dll, .exe or .dat, you may find them right next to each other, example - appsw.exe, appsw.dll, appsw.dat)
If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. if it is uncheck it and try again.

Run AboutBuster and save the log . (make sure you let it do the second scan).

NOW PULL THE POWER PLUG TO YOUR PC! This is very important! I do not want you to power down the normal way.

After that wait a minute or two and then power up into safe mode (still with no internet connection available and do not open any browsers). Only run what I request.

Delete all files in the c:\windows\prefetch folder.

Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure these 3 are checked and then press *ok* to remove:

Temporary Files
Temporary Internet Files
Recycle Bin


Now Reset Web Settings:
Open up Internet Explorer , Tools, General Tab, reset your home page to what you want, now the Programs Tab, click Reset Web Settings
That will change everything back to the default settings.

Run HSremove and then run AboutBuster again and save the log. (let it do second scan)!

Immediately after AboutBuster completes, reboot in normal mode.

Use IE and see how it is, post a fresh HJT log. MrC


================================================
Hello again. The HJT/Delete A Windows NT Service does not identify either Remote Procedure Call (RPC) Helper or the short name in the registry when entered (or pasted, as w/ the latter's case), and am therefore unable to delete. Subsequently was able to kill processes crtn.exe and system32/atluf.exe. A second attempt w/ Delete…Service failed as well. Although I was not told a service s/b stopped, went through services.msc anyway and changed RPC to 'disabled.' (Again got the message "Configuration Manager: General Internal Error Occured," but could still disable.) Tried a third time to Delete A Windows NT Service to no avail. I have not gone any further with your directions. In spite of not being able to find/delete the RPC through HJT, should I plow through anyway, or is it a moot point if I can't get RPC deleted? (I'll be glad to go ahead, but thought I'd ask before I start pulling plugs….) Thanks again, Mark
Well, the good news is that Google returned as the default home page when I rebooted (first time since our initial fix). Unfortunately, about:blank came up the second time I opened IE.

Also, I had a problem getting through this fix that may have introduced additional processes that needed to be killed but I could not identify. As I neared the end and began to run AboutBuster, my "Security Manager" provided by my ISP (Comcast) shut it down and rebooted the system. When I went back into HJT there were additional processes that came up that I don't believe were there before. In any case, I'm just guessing, but it seems as if I muddled through this and failed to fix or remove necessary processes, thanks to the reboot.

Prior to the unplanned reboot, on the initial (re-)try, RPC and the short name were never successfully identified through HJT misc tools.

Also, the following were not found:

HJT:
O2 - BHO: (no name) - {1DF6F759-A37F-233E-D7C5-4616756486A6} - C:\WINNT\sdkqo32.dll
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINNT\atlnr.exe (file missing)

Win Exp:
C:\WINNT\atlnr.exe
C:\WINNT\sdkqo32.dll
other file extensions of any of the 4 filenames

no such folder:
c:\windows\prefetch

Everything else was successfully identified/fixed/removed.

Maybe this approach can work if I can dodge the reboot, which I s/b able to prevent. (It did not shut down AB at the end of the next pass through your instructions, but on that pass the only item I found in HJT from the original list was R3 - Default URLSearchHook is missing)

Thanks,
Mark

+++++

Logfile of HijackThis v1.99.1
Scan saved at 9:09:22 AM, on 4/7/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
c:\program files\comcast\security manager\app\CurtainsSysSvcNt.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Comcast\Security Manager\app\Prism.exe
C:\WINNT\Explorer.exe
C:\Program Files\support.com\bin\tgcmd.exe
C:\WINNT\system32\TridTray.Exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Microsoft Office\Office\MSOFFICE.EXE
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\interMute\SpySubtract\SpySub.exe
C:\Program Files\Common Files\MySoftware\NewsFlsh.exe
C:\WINNT\wincx32.exe
C:\WINNT\system32\atluf.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Security Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\dptoq.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\dptoq.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\dptoq.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\dptoq.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\dptoq.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\dptoq.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=C:\WINNT\system32\AUserInit.exe
O2 - BHO: (no name) - {874FD285-C47C-21B9-74B1-5FF2295BC3DD} - C:\WINNT\system32\javaue.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [PBReboot] c:\windows\rundll.exe c:\windows\system\setupx.dll,InstallHinfSection DefaultInstall 2 c:\windows\reboot.inf
O4 - HKLM\..\Run: [TridTray] TridTray.Exe
O4 - HKLM\..\Run: [atluf.exe] C:\WINNT\system32\atluf.exe
O4 - HKLM\..\RunOnce: [wincx32.exe] C:\WINNT\wincx32.exe
O4 - Startup: MySoftware NewsFlash.lnk = C:\Program Files\Common Files\MySoftware\NewsFlsh.exe
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Microsoft Office Shortcut Bar.lnk = C:\Program Files\Microsoft Office\Office\MSOFFICE.EXE
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINNT\system32\spool\drivers\w32x86\3\E_SRCV03.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: ComcastHSI - {55115FE6-33AE-4F7D-A2D2-162E1C6AA4F5} - http://www.comcast.net/ (file missing) (HKCU)
O9 - Extra button: Support - {876E60E4-B886-4E2D-A2A8-99BB468BA4BD} - http://www.comcastsupport.com/ (file missing) (HKCU)
O9 - Extra button: Help - {CF855F93-166F-45E4-8FFF-E6692C62B738} - http://online.comcast.net/help/ (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net/
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/Fuj…ploadClient.cab
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINNT\atlnr.exe (file missing)
O23 - Service: Curtains for Windows System Service (CurtainsSysSvc) - Authentium, Inc. - c:\program files\comcast\security manager\app\CurtainsSysSvcNt.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
MrC, let me add that if you don't think there's a way to beat this, given what's happening now, I would be willing to do a fresh install of the operating system if that would remove the hijacker. I upgraded to Windows 2000 just 2 months ago and have backup CDs of all files that were on this computer, and can create additional backups for those that have been used/created since rather easily.
If it's not too much of a bother, that would be a good idea.
It's hard to work on a system that's not right in front of you.

O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINNT\atlnr.exe (file missing)


This is the service that's responsible for the hijack and we can't stop it so that's why it keeps reinstalling.

If you want I'll continue to help you or go ahead and reinstall the OS.

If you do, make sure you are fully protected, let me know, MrC




Some preventive maintenance:

——————Must have or do:—————–

Now that you're clean: <—-Important Step!!!!
Delete your system restore files and create a new restore point:
(ME and XP users only)

XP system restore

ME system restore


Visit Windows Update and install all the lastest critical updates.

Install these two free programs, they sit in the backround and protect your system from spy and adware being installed on your system, also from your browser being hijacked. Check for updates weekly.

SpywareBlaster

SpywareGuard


IE-SPYAD
Puts over 5000 sites in your restricted zone, so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
IE-SPYAD

SpyBot has some protection benefits - use them.

Need a free anti virus?
AVG*free
(check for updates - daily)

How about a firewall? The front door to your computer.
ZoneAlarm*free



———-Free malware removal programs:———-

SpyBot
AD-Aware
CW-Shredder

Free Online Trojan Scan

A SQUARED FREE TROJAN SCANNER

Trojan Hunter
TrojanHunter - free trial

Please consider using FireFox instead of Internet Explorer

Replace Java with SunJava

Pop-up stoppers:
GoogleToolBar
Pop-upStopperFree

Don't open e-mail attachments without first scanning them with an up-to-date
anti virus program, even after doing that I would be very careful. Don't click on any executables in e-mails or any other links that you're not sure of.
Watch your surfing habits, don't click on or download anything you're not sure of. Don't install a program that hasn't been recommended by a reputable organization.
MrC, so far things appear to be fine after reinstalling the OS yesterday. Almost have everything back in place (software, etc.) and have added/run most of the programs you suggested above. There is one quirk–the IE toolbar does not seem to be linked to Outlook Express at all. I can open and run OE from the desktop just fine, but when I click on the Mail icon in the IE toolbar to 'read mail,' it is just dead…doesn't do anything (with OE closed OR otherwise running). Can't see how to reset this in Tools. Thoughts? Thanks, Mark
Somehow, I think the system is not recognizing Outlook Express as the default mail client, even though OE itself says it is the default. Going through Control Panel > Internet Options > Programs shows nothing under the email dropdown list. There are no options, not even OE. OE is running fine on its own, but nothing else is utilizing it (digital camera software to email pictures, etc.). I have already un- and reinstalled OE & IE. This seems to be the only hurdle, with the hijacker now blown out. -Mark
See if this setting is correct:

Open up Outlook Express > click Tools, and then click Options.
On the General tab, see if the Default Messaging Programs section states Outlook Express is NOT the default mail handler > if so > click Make Default, and then click OK.
See if that applies or works.

Do you have Office on the system or Outlook?

Let me know, MrC
That tab states that Outlook Express is the default mail (and news) handler. The 'make default' buttons are grayed out. I do not have Office installed in its entirety, just Excel and Word as components, along with Outlook Exp and IE. Would that somehow make a difference or cause problems? Thanks, Mark
I pulled this info from this page:

http://www.okinfoweb.com/moe/mail/mail_006.htm

Basically it's this:
1> Try this first…
Go to start, run copy and paste this in and hit OK
"C:\Program File\Outlook Express\msimn.exe" /reg
After running that command from Start | Run, try again to see if now enabling OE as your default Mail and News client under Tools | Options | General works.
Also recheck IE, tools, IE options, programs.

2> If that doesn't work, download and unzip this file, double click on it and allow it to merge into the registry.
http://www.okinfoweb.com/moe/files/restore_oe_protocols.zip
Then try again, let me know, MrC

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI