This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

about:blank removal

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

What do I need to do to get rid of this thing?????

Logfile of HijackThis v1.99.1
Scan saved at 8:00:48 PM, on 5/2/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\ADVTOOLS\NPROTECT.EXE
C:\WINDOWS\SYSTEM\WINQA32.EXE
C:\WINDOWS\SYSTEM\APIKJ32.EXE
C:\WINDOWS\SYSTEM\NTYK.EXE
C:\WINDOWS\MFCIV32.EXE
C:\WINDOWS\SYSTEM\NETTZ.EXE
C:\WINDOWS\SYSTEM\NTQW32.EXE
C:\WINDOWS\SYSTEM\APPXO32.EXE
C:\WINDOWS\CRUX32.EXE
C:\WINDOWS\D3CV.EXE
C:\WINDOWS\SYSTEM\MFCUN.EXE
C:\WINDOWS\NTMY32.EXE
C:\WINDOWS\ATLMJ32.EXE
C:\WINDOWS\SDKBS.EXE
C:\WINDOWS\SYSTEM\D3KC.EXE
C:\WINDOWS\SDKTF32.EXE
C:\WINDOWS\SYSTEM\WINNV.EXE
C:\WINDOWS\SDKOC32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\PROGRAM FILES\QUICKIDRIVE TOOLS1.1\QUICKIDRIVE.EXE
C:\WINDOWS\SYSTEM\HPZTSB02.EXE
C:\PROGRAM FILES\VIEWPOINT\VIEWPOINT MANAGER\VIEWMGR.EXE
C:\WINDOWS\SYSTEM\JAVATL.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\FINDFAST.EXE
C:\PROGRAM FILES\SONY CORPORATION\IMAGE TRANSFER\SONYTRAY.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\WINQA32.EXE
C:\WINDOWS\CRUX32.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\APIKJ32.EXE
C:\WINDOWS\SYSTEM\APPSJ.EXE
C:\WINDOWS\SYSTEM\APPSJ.EXE
C:\WINDOWS\SYSTEM\SYSHS.EXE
C:\INSTALLS\HIJACK_THIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\wskgq.dll/sp.html#83556
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\wskgq.dll/sp.html#83556
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\wskgq.dll/sp.html#83556
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\wskgq.dll/sp.html#83556
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\wskgq.dll/sp.html#83556
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\wskgq.dll/sp.html#83556
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Frontier
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Class - {A1963F3B-3090-7909-8C1F-E3655DCD0684} - C:\WINDOWS\IEOF32.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~2\ADVTOOLS\ADVCHK.EXE
O4 - HKLM\..\Run: [NPROTECT] C:\PROGRA~1\NORTON~2\ADVTOOLS\NPROTECT.EXE
O4 - HKLM\..\Run: [QUICKIDRIV] c:\program files\quickidrive tools1.1\quickidrive.exe sys_auto_run C:\PROGRAM FILES\QUICKIDRIVE TOOLS1.1
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb02.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [JAVATL.EXE] C:\WINDOWS\SYSTEM\JAVATL.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [NPROTECT] C:\PROGRA~1\NORTON~2\ADVTOOLS\NPROTECT.EXE
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [WINQA32.EXE] C:\WINDOWS\SYSTEM\WINQA32.EXE /s
O4 - HKLM\..\RunServices: [APIKJ32.EXE] C:\WINDOWS\SYSTEM\APIKJ32.EXE /s
O4 - HKLM\..\RunServices: [NTYK.EXE] C:\WINDOWS\SYSTEM\NTYK.EXE /s
O4 - HKLM\..\RunServices: [MFCIV32.EXE] C:\WINDOWS\MFCIV32.EXE /s
O4 - HKLM\..\RunServices: [NETTZ.EXE] C:\WINDOWS\SYSTEM\NETTZ.EXE /s
O4 - HKLM\..\RunServices: [NTQW32.EXE] C:\WINDOWS\SYSTEM\NTQW32.EXE /s
O4 - HKLM\..\RunServices: [APPXO32.EXE] C:\WINDOWS\SYSTEM\APPXO32.EXE /s
O4 - HKLM\..\RunServices: [CRUX32.EXE] C:\WINDOWS\CRUX32.EXE /s
O4 - HKLM\..\RunServices: [D3CV.EXE] C:\WINDOWS\D3CV.EXE /s
O4 - HKLM\..\RunServices: [MFCUN.EXE] C:\WINDOWS\SYSTEM\MFCUN.EXE /s
O4 - HKLM\..\RunServices: [NTMY32.EXE] C:\WINDOWS\NTMY32.EXE /s
O4 - HKLM\..\RunServices: [ATLMJ32.EXE] C:\WINDOWS\ATLMJ32.EXE /s
O4 - HKLM\..\RunServices: [SDKBS.EXE] C:\WINDOWS\SDKBS.EXE /s
O4 - HKLM\..\RunServices: [D3KC.EXE] C:\WINDOWS\SYSTEM\D3KC.EXE /s
O4 - HKLM\..\RunServices: [SDKTF32.EXE] C:\WINDOWS\SDKTF32.EXE /s
O4 - HKLM\..\RunServices: [WINNV.EXE] C:\WINDOWS\SYSTEM\WINNV.EXE /s
O4 - HKLM\..\RunServices: [SDKOC32.EXE] C:\WINDOWS\SDKOC32.EXE /s
O4 - HKLM\..\RunServices: [APPSJ.EXE] C:\WINDOWS\SYSTEM\APPSJ.EXE /s
O4 - HKLM\..\RunServices: [SYSHS.EXE] C:\WINDOWS\SYSTEM\SYSHS.EXE /s
O4 - Startup: PowerReg Scheduler.exe
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Event Reminder.lnk = C:\Program Files\Broderbund\PrintMaster\PMREMIND.EXE
O4 - Startup: Image Transfer.lnk = C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
O8 - Extra context menu item: &AIM Search - res://C:\PROGRAM FILES\AIM TOOLBAR\AIMBAR.DLL/aimsearch.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\INSTALLS\AIM\AIM.EXE
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) - http://download.mcafee.com/molbin/Shared/MGBrwFld.cab
O16 - DPF: {0713E8D2-850A-101B-AFC0-4210102A8DA7} (Microsoft ProgressBar Control, version 5.0 (SP2)) - http://download.mcafee.com/molbin/shared/comctl32.cab
O16 - DPF: {36C417C6-13C6-448B-9784-DD73A93B0582} (McAfee.com Download+Installer Class) - http://download.mcafee.com/molbin/shared/mcinstall.cab
O16 - DPF: {DA28C54E-D95C-11D3-9A01-005004677EF4} (McAfee.com Component Download Manager Class) - http://download.mcafee.com/molbin/clinic/CDM/McCDM.cab
O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - http://216.249.25.152/code/PWActiveXImgCtl.CAB
O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - http://198.190.195.71/CFIDE/classes/CFJava.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://notesmp1.pb.com/iNotes6.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200411…meInstaller.exe
Welcome to the forum.

Please read through the instructions before you start (you may want to print this out).

Please download and install these programs - don't run them yet!!

Please download and unzip
AboutBuster to a folder. Inside the folder is a readme file that has instructions on the use of the program.
AboutBuster MUST be updated before you use it.
Start AboutBuster, click the update button, check for update, drag the box to the side and hit download updates, close the box . Don't run it yet.
AboutBuster Tutorial

Download CW-Shredder at the link below:
http://cwshredder.net/bin/CWShredder.exe

HowToShowHiddenFiles - <—enable this

Reboot into SafeMode. <—MAKE SURE YOU KNOW HOW TO DO THIS!!

+++++++++++++++++++++++++++++++++++++++++++++++++

Here's the fix:

1. SKIP

2. Reboot into Safe Mode

3.Press Control-Alt-Del to enter the Task Manager.
Click on the Processes tab and end the following processes if listed:

WINQA32.EXE
APIKJ32.EXE
NTYK.EXE
MFCIV32.EXE
NETTZ.EXE
NTQW32.EXE
APPXO32.EXE
CRUX32.EXE
D3CV.EXE
MFCUN.EXE
NTMY32.EXE
ATLMJ32.EXE
SDKBS.EXE
D3KC.EXE
SDKTF32.EXE
WINNV.EXE
SDKOC32.EXE
HPZTSB02.EXE
JAVATL.EXE
WINQA32.EXE
CRUX32.EXE
APIKJ32.EXE
APPSJ.EXE
APPSJ.EXE
SYSHS.EXE


If you find the files, click on them, and then click End Process => Exit the Task Manager.


4. CLOSE ALL WINDOWS AND BROWSERS Scan with Hijack This and put checks next to all the following, then click "Fix Checked"

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\wskgq.dll/sp.html#83556
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\wskgq.dll/sp.html#83556
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\wskgq.dll/sp.html#83556
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\wskgq.dll/sp.html#83556
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\wskgq.dll/sp.html#83556
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\wskgq.dll/sp.html#83556
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {A1963F3B-3090-7909-8C1F-E3655DCD0684} - C:\WINDOWS\IEOF32.DLL
O4 - HKLM\..\RunServices: [WINQA32.EXE] C:\WINDOWS\SYSTEM\WINQA32.EXE /s
O4 - HKLM\..\RunServices: [APIKJ32.EXE] C:\WINDOWS\SYSTEM\APIKJ32.EXE /s
O4 - HKLM\..\RunServices: [NTYK.EXE] C:\WINDOWS\SYSTEM\NTYK.EXE /s
O4 - HKLM\..\RunServices: [MFCIV32.EXE] C:\WINDOWS\MFCIV32.EXE /s
O4 - HKLM\..\RunServices: [NETTZ.EXE] C:\WINDOWS\SYSTEM\NETTZ.EXE /s
O4 - HKLM\..\RunServices: [NTQW32.EXE] C:\WINDOWS\SYSTEM\NTQW32.EXE /s
O4 - HKLM\..\RunServices: [APPXO32.EXE] C:\WINDOWS\SYSTEM\APPXO32.EXE /s
O4 - HKLM\..\RunServices: [CRUX32.EXE] C:\WINDOWS\CRUX32.EXE /s
O4 - HKLM\..\RunServices: [D3CV.EXE] C:\WINDOWS\D3CV.EXE /s
O4 - HKLM\..\RunServices: [MFCUN.EXE] C:\WINDOWS\SYSTEM\MFCUN.EXE /s
O4 - HKLM\..\RunServices: [NTMY32.EXE] C:\WINDOWS\NTMY32.EXE /s
O4 - HKLM\..\RunServices: [ATLMJ32.EXE] C:\WINDOWS\ATLMJ32.EXE /s
O4 - HKLM\..\RunServices: [SDKBS.EXE] C:\WINDOWS\SDKBS.EXE /s
O4 - HKLM\..\RunServices: [D3KC.EXE] C:\WINDOWS\SYSTEM\D3KC.EXE /s
O4 - HKLM\..\RunServices: [SDKTF32.EXE] C:\WINDOWS\SDKTF32.EXE /s
O4 - HKLM\..\RunServices: [WINNV.EXE] C:\WINDOWS\SYSTEM\WINNV.EXE /s
O4 - HKLM\..\RunServices: [SDKOC32.EXE] C:\WINDOWS\SDKOC32.EXE /s
O4 - HKLM\..\RunServices: [APPSJ.EXE] C:\WINDOWS\SYSTEM\APPSJ.EXE /s
O4 - HKLM\..\Run: [JAVATL.EXE] C:\WINDOWS\SYSTEM\JAVATL.EXE
O4 - HKLM\..\RunServices: [SYSHS.EXE] C:\WINDOWS\SYSTEM\SYSHS.EXE /s
O4 - Startup: PowerReg Scheduler.exe

Click on Fix Checked and exit HijackThis.


5. SKIP

6. Run AboutBuster . This will scan your computer for the bad files and delete them. It will ask to scan the system again, let it. Save the report (copy and paste into notepad or wordpad and save as a .txt file) and post a copy back here when you are done with all the steps.

7. Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure these 3 are checked and then press *ok* to remove:

Temporary Files
Temporary Internet Files
Recycle Bin

8. SKIP

9. Run CW-Shredder - Hit the FIX button - let it run and fix what it finds.

10. Reboot into normal mode.

11. Download and run this online virus scan:<—Important
http://housecall.trendmicro.com/housecall/start_corp.asp
Make sure you check "AutoClean"

12. Reboot and post a fresh HJT log back here by using the add reply button below, and lets see how we did, MrC
It appears to be gone, I no longer go right to the About:Blank screen. Here is my HJT output after the fix.

Logfile of HijackThis v1.99.1
Scan saved at 10:06:46 PM, on 5/3/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\ADVTOOLS\NPROTECT.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\PROGRAM FILES\QUICKIDRIVE TOOLS1.1\QUICKIDRIVE.EXE
C:\WINDOWS\SYSTEM\HPZTSB02.EXE
C:\PROGRAM FILES\VIEWPOINT\VIEWPOINT MANAGER\VIEWMGR.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\FINDFAST.EXE
C:\PROGRAM FILES\SONY CORPORATION\IMAGE TRANSFER\SONYTRAY.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\INSTALLS\HIJACK_THIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Frontier
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~2\ADVTOOLS\ADVCHK.EXE
O4 - HKLM\..\Run: [NPROTECT] C:\PROGRA~1\NORTON~2\ADVTOOLS\NPROTECT.EXE
O4 - HKLM\..\Run: [QUICKIDRIV] c:\program files\quickidrive tools1.1\quickidrive.exe sys_auto_run C:\PROGRAM FILES\QUICKIDRIVE TOOLS1.1
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb02.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [NPROTECT] C:\PROGRA~1\NORTON~2\ADVTOOLS\NPROTECT.EXE
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Event Reminder.lnk = C:\Program Files\Broderbund\PrintMaster\PMREMIND.EXE
O4 - Startup: Image Transfer.lnk = C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
O8 - Extra context menu item: &AIM Search - res://C:\PROGRAM FILES\AIM TOOLBAR\AIMBAR.DLL/aimsearch.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\INSTALLS\AIM\AIM.EXE
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) - http://download.mcafee.com/molbin/Shared/MGBrwFld.cab
O16 - DPF: {0713E8D2-850A-101B-AFC0-4210102A8DA7} (Microsoft ProgressBar Control, version 5.0 (SP2)) - http://download.mcafee.com/molbin/shared/comctl32.cab
O16 - DPF: {36C417C6-13C6-448B-9784-DD73A93B0582} (McAfee.com Download+Installer Class) - http://download.mcafee.com/molbin/shared/mcinstall.cab
O16 - DPF: {DA28C54E-D95C-11D3-9A01-005004677EF4} (McAfee.com Component Download Manager Class) - http://download.mcafee.com/molbin/clinic/CDM/McCDM.cab
O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - http://216.249.25.152/code/PWActiveXImgCtl.CAB
O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - http://198.190.195.71/CFIDE/classes/CFJava.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://notesmp1.pb.com/iNotes6.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200411…meInstaller.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab

It appears to be gone, I no longer go right to the About:Blank screen. Here is my HJT output after the fix.


You're right! Looks Good! Well Done! :thumbup:



I'll leave you with……..

Some preventive maintenance:

——————Must have or do:—————–

Now that you're clean: <—-Important Step!!!!
Delete your system restore files and create a new restore point:
(ME and XP users only)

XP system restore

ME system restore


Visit Windows Update and install all the lastest critical updates.

Install these two free programs, they sit in the backround and protect your system from spy and adware being installed on your system, also from your browser being hijacked. Check for updates weekly.

SpywareBlaster

SpywareGuard


IE-SPYAD
Puts over 5000 sites in your restricted zone, so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
IE-SPYAD

SpyBot has some protection benefits - use them.

Need a free anti virus?
AVG*free
(check for updates - daily)

How about a firewall? The front door to your computer.
ZoneAlarm*free



———-Free malware removal programs:———-

SpyBot
AD-Aware
CW-Shredder

Free Online Trojan Scan

A SQUARED FREE TROJAN SCANNER

Trojan Hunter
TrojanHunter - free trial

Please consider using FireFox instead of Internet Explorer

Replace Java with SunJava

Pop-up stoppers:
GoogleToolBar
Pop-upStopperFree

Don't open e-mail attachments without first scanning them with an up-to-date
anti virus program, even after doing that I would be very careful. Don't click on any executables in e-mails or any other links that you're not sure of.
Watch your surfing habits, don't click on or download anything you're not sure of. Don't install a program that hasn't been recommended by a reputable organization.

Good luck and thanks for using the forum - MrC
:wavey:
As this problem has been resolved the topic will be closed. If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)

The subject of the email must be
"Reopen". Include your post username and details about why you need it reopened, with a valid link to your post.

Thanks, MrC

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI