Hi,
I've been having problems trying to view certain webpages through Internet Explorer and Mozilla Firefox, and the symptoms seem very similar to the About Blank problem, but it does not effect my home page. I have tried the most common apps such as Adaware, SpyBot, Spyware Blaster,CWShredder and other apps such as Adaware away which have had no effect.
I did try the free online scanner at
www.spywareinfo.com which does say that I have the About Blank spyware on my PC.
If anyone can help me remove this annoying thing it would be great. This is the 3rd time that I've had it, but previously I had backups to restore from, but not anymore. :-(
Here's a copy of the log from Hijackthis if it's of use :
Logfile of HijackThis v1.99.0
Scan saved at 11:28:51 pm, on 15/03/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\System32\Ati2ev
xx.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\system32\Ati2ev
xx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\htpatch.exe
C:\Program Files\Say the Time\SayTime.exe
C:\WINDOWS\System32\rmctrl
.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.ex
e
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Executive Software\Diskeeper\DkServi
ce.exe
C:\WINDOWS\System32\GEARSe
c.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
C:\PROGRA~1\NORTON~1\NORTO
N~1\NPROTE
CT.EXE
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.ex
e
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\ZoneLa
bs\vsmon.e
xe
E:\HijackThis.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - D:\apps\adobe\Adobe Acrobat 6.0\Acrobat\ActiveX\AcroIE
Helper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
06D7942484
F} - D:\apps\spybot\SDHelper.dl
l
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D
426709BBFE
B} - D:\apps\SPYWAR~1\tools\ies
dsg.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0
445EE16191
0} - D:\apps\adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClien
t.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-1
7DF180C71A
C} - D:\apps\SPYWAR~1\tools\ies
dpb.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-9
05236F6F65
5} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0
819E2EAAC9
3} - D:\apps\adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClien
t.dll
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Say the Time] C:\Program Files\Say the Time\SayTime.exe
O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\System32\rmctrl
.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCh
eck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvC
heck.exe -CheckReg
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dump
rep 0 -k
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.ex
e"
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [STOPzilla] C:\Program Files\STOPzilla!\Stopzilla
.exe /autostart
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\Styl
eXP.exe -Hide
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Ad
obe Gamma Loader.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KE
M.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\apps\office\OFFIC
E11\EXCEL.
EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\j2re1.4.2_05\bi
n\npjpi142
_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\j2re1.4.2_05\bi
n\npjpi142
_05.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4
C56B4E14E8
4} - D:\apps\SPYWAR~1\tools\ies
dpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - D:\apps\office\OFFICE11\RE
FIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {11260943-421B-11D0-8EAC-0
000C07D88C
F} (iPIX ActiveX Control) -
http://www.ipix.com/viewers/ipixx.cabO16 - DPF: {2BC66F54-93A8-11D3-BEB6-0
0105AA9B6A
E} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cabO16 - DPF: {39B0684F-D7BF-4743-B050-F
DC3F48F7E3
B} (FilePlanet Download Control Class) -
http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cabO16 - DPF: {6414512B-B978-451D-A0D8-F
CFDF33E833
C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1097967702434O16 - DPF: {644E432F-49D3-41A1-8DD5-E
099162EEEC
5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cabO16 - DPF: {86A88967-7A20-11D2-8EDA-0
0600818EDB
1} (ParallelGraphics Cortona Control) -
http://www.parallelgraphics.com/bin/cortvrml.cabO16 - DPF: {BDD2F926-8158-4F62-9E0D-B
3B75FD1F07
F} (McObjectFactory Class) -
http://download.mcafee.com/molbin/shared/McMySec/en-us/1,0,0,2/mcmysec.cabO16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0
E40F83B1AD
F} (Live365Player Class) -
http://www.live365.com/players/play365.cabO16 - DPF: {CE3409C4-9E26-4F8E-83E4-7
78498F9E7B
4} (PB_Uploader Class) -
http://static.photobox.co.uk/sg/common/uploader2.ocxO16 - DPF: {FA3662C3-B8E8-11D6-A667-0
010B556D97
8} (IWinAmpActiveX Class) -
http://cdn.digitalcity.com/_media/dalaillama/ampx.cabO18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8
E447D12930
0} - C:\Program Files\HP\hpcoretech\comp\h
puiprot.dl
l
O23 - Service: Adobe LM Service - Unknown - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.
exe
O23 - Service: Ati HotKey Poller - Unknown - C:\WINDOWS\System32\Ati2ev
xx.exe
O23 - Service: ATI Smart - Unknown - C:\WINDOWS\system32\ati2sg
ag.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkServi
ce.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSe
c.exe
O23 - Service: Macromedia Licensing Service - Unknown - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NOD32 Kernel Service - Unknown - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
O23 - Service: Norton Unerase Protection - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTO
N~1\NPROTE
CT.EXE
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PD
Engine.exe
O23 - Service: PDScheduler - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PD
Sched.exe
O23 - Service: StyleXPService - Unknown - C:\Program Files\TGTSoft\StyleXP\Styl
eXPService
.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.ex
e
O23 - Service: TuneUp WinStyler Theme Service - TuneUp Software GmbH - D:\apps\tuneup\WinStylerTh
emeSvc.exe
O23 - Service: Ulead Burning Helper - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs LLC - C:\WINDOWS\system32\ZoneLa
bs\vsmon.e
xe