About:Blank Virus (Please Help!!)

Reply

Join Date: Oct 2005
Posts: 2
Reputation: Green Ace is an unknown quantity at this point 
Solved Threads: 0
Green Ace Green Ace is offline Offline
Newbie Poster

About:Blank Virus (Please Help!!)

 
0
  #1
Oct 14th, 2005
--------------------------------------------------------------------------------
OK, I have a big problem with IE.

When I open up IE it gives me a blank home page with "about:blank" on the address line. I want to configurate my home page to be yahoo.com or whatever.

Here's the kicker, i go into <Tools><Internet Options> and change my homepage to yahoo.com on the address line. Sounds simple, but when I close IE and restart IE again, it won't even start up. IE would appear for 2-3 seconds before it disappears and there would be an error message box saying "IE has encountered a problem and needs to close. bla bla bla" I have the option of "Send error report" or "Don't Send"

Therefore, here is my hijack log. Please help me with this problem. Thank you!

Logfile of HijackThis v1.99.1
Scan saved at 4:39:36 PM, on 10/14/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\UEVURVIA\command.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Spyware tools\hijackthis\HijackThis.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\UEVURVIA\command.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe


Ok, here's another log.

Logfile of HijackThis v1.99.1
Scan saved at 4:54:32 PM, on 10/14/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\UEVURVIA\command.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Spyware tools\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\UEVURVIA\command.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
Reply With Quote Quick reply to this message  
Join Date: Dec 2003
Posts: 6,439
Reputation: DMR will become famous soon enough DMR will become famous soon enough 
Solved Threads: 363
Team Colleague
DMR's Avatar
DMR DMR is offline Offline
Wombat At Large

Re: About:Blank Virus (Please Help!!)

 
0
  #2
Oct 15th, 2005
1. Your HJT logs look very incomplete. Are you sure that you are posting the full contents of the log files?


2. Your versions of Windows XP and Internet Explorer are very out-of-date. Please use Windows' Automatic Update feature to at least get your system upgraded to the most current state of Service Pack 1; I'd hold off on going to Service Pack 2 until we're sure that your system is entirely clean.

Once you've installed the Windows updates, run HJT again and post the new log.
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing


Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.

However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
Reply With Quote Quick reply to this message  
Join Date: Oct 2005
Posts: 2
Reputation: Green Ace is an unknown quantity at this point 
Solved Threads: 0
Green Ace Green Ace is offline Offline
Newbie Poster

Re: About:Blank Virus (Please Help!!)

 
0
  #3
Oct 15th, 2005
Originally Posted by DMR
1. Your HJT logs look very incomplete. Are you sure that you are posting the full contents of the log files?


2. Your versions of Windows XP and Internet Explorer are very out-of-date. Please use Windows' Automatic Update feature to at least get your system upgraded to the most current state of Service Pack 1; I'd hold off on going to Service Pack 2 until we're sure that your system is entirely clean.

Once you've installed the Windows updates, run HJT again and post the new log.
Ok, i just did a windows update and it updated and downloaded a bunch of stuff. On to the hijack log. I ran the log by clicking on "Do a system scan and save a log file". Is there something else I should be doing? I ran the log after I changed the homepage to yahoo.com, but when I close IE and restart it, it would appear for a couple of seconds and disappear. It would show an error message box. Because of this, I can't start up IE unless I go into the line below and check mark and click "fix checked". I would restart IE again and it would start up with a blank page with an about:blank address.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/

Logfile of HijackThis v1.99.1
Scan saved at 4:49:14 AM, on 10/15/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\UEVURVIA\command.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Spyware tools\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\ss4gsx.exe reg_run
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\UEVURVIA\command.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC