Author: Kracker, Location: USAPosted: Thu Apr 22, 2004 9:42 pm Post subject: How do i remove the About:Blank virus????
Ok ive tried everything else, so heres the log from my hijack this, what should i remove to get rid of it?
Logfile of HijackThis v1.97.7
Scan saved at 9:39:55 PM, on 4/22/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Author: Kracker, Location: USAPosted: Fri Apr 23, 2004 7:39 am Post subject:
*bump*
Author: Mosaic1, Location: USAPosted: Fri Apr 23, 2004 9:34 am Post subject:
Go to Add Remove program in Control Panel and remove New.Net.
If not there then follow these removal instructions:
http://www.newdotnet.com/#remove
Let's clean up some of this other junk too.
Boot to Safe Mode and run Hijackthis.
Directions if you need them here:
http://service1.symantec.com/SUPPORT/ts...2409420406
Select these items and press Fix Checked.
R3 - URLSearchHook: (no name) - {0428FFC7-1931-45b7-95CB-3CBB919777E1} - (no file)
R3 - URLSearchHook: (no name) - {00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)
O1 - Hosts: 213.159.117.235 auto.search.msn.com
O2 - BHO: (no name) - {00000EF1-0786-4633-87C6-1AA7A44296DA} - (no file)
O2 - BHO: NavErrRedir Class - {00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)
O2 - BHO: NavErrRedir Class - {0428FFC7-1931-45b7-95CB-3CBB919777E1} - (no file)
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
O3 - Toolbar: (no name) - {F14E6220-14C1-48FB-9A42-39636CEC9B35} - (no file)
O3 - Toolbar: &SearchBar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
O4 - HKLM\..\Run: [CMESys] "C:\Program Files\Common Files\CMEII\CMESys.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SysUpd] C:\WINDOWS\sysupd.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
Delete these folders:
C:\Program Files\MyWay
C:\Program Files\Common Files\CMEII
C:\Program Files\Common Files\GMT
Delete this file:
C:\WINDOWS\sysupd.exe
----------------------------
Boot back to regular Windows.
That doesn't look like a complete log. Please run Hijackthis again and post a new one.
We need some information too please.
Go to start>Run and type regedit. Press enter.
Navigate to:
Open the registry and navigate here:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
Highlight Windows in the left pane.
Look in the right pane for this value:
AppInit_Dlls
You won't see any data there.
But if you right click on that and choose Modify Binary Data you will.
If nothing is there it should just show a few 0's.
But if they are hiding a dll they load to resintall, it will show a path to it.
----------------------------
This is now one looks when there is only one file loading.
0000 00 00 3A 00 5C 00 77 00 ..:.\.w.
0008 69 00 6E 00 64 00 6F 00 i.n.d.o.
0010 77 00 73 00 5C 00 73 00 w.s.\.s.
0018 79 00 73 00 74 00 65 00 y.s.t.e.
0020 6D 00 33 00 32 00 5C 00 m.3.2.\.
0028 6D 00 73 00 6B 00 6B 00 m.s.k.k.
0030 67 00 2E 00 64 00 6C 00 g...d.l.
0038 6C 00 00 00 l...
Notice on the far right. You want to look there. It looks funny because all of the periods.
Look closely and you'll see the path and file name here was:
Windows\system32\mskkg.dll
This was the example. Yours will have its own file name. This is not the same file as you are seeing in your HijackThis log. Get its name the same as I just described.
--------------
Logfile of HijackThis v1.97.7
Scan saved at 4:04:56 PM, on 4/23/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
I am no longer helping to remove this. The new method others are using is so full of holes, exceptions and problems I won't torture you with it.
I would either format and reinstall or use another Browser. However, I cannot guarantee what else is on your drive. They manage to hide files quite nicely.
Deleting IE will not help. You can't anyway. Doing a Repair install will not help. Ther are others working on it. The fix is long and complex and changes all the time. The Trojan Writers are watching what is done to fix this and creating new files they download behind your back to defend against removal. I beleieve that is how they are doing it. Otherwise why would what worked yesterday no longer work?
I can lock this thread and you can post a new one. Possibly someone else will come along and work with you. I cannot justify it at this point. And I cannot tell you what else they may have done. So I won't until I know it is safe and will help.
You do have other problems. But I have to ask you if you have a restore point from BEFORE all this happened. If you do see if you can restore to that date. Then find the nasty files and delete them. Run HijackThis and see if you are clean and post that new log.
To find the name of the nasty file do this.
Go here and downlpoad Find-All.zip
http://www10.brinkster.com/expl0iter/freeatlast/pvtool.htm
Extract the contents.
Run Find-All.bat. It will create a file named output.txt. That will have the name of the one file.
Also, boot to Safe Mode and delete this file:
C:\WINDOWS\sysupd.exe
Fix this entry in HijackThis:
O4 - HKLM\..\Run: [SysUpd] C:\WINDOWS\sysupd.exe
---------------------
You do have other problems. But I have to ask you if you have a restore point from BEFORE all this happened. If you do see if you can restore to that date. Then find the nasty files and delete them. Run HijackThis and see if you are clean and post that new log.