My homepage changes to about:blank.heres my HiJackThis log

Reply

Join Date: Jun 2004
Posts: 5
Reputation: DepthCore is an unknown quantity at this point 
Solved Threads: 0
DepthCore DepthCore is offline Offline
Newbie Poster

My homepage changes to about:blank.heres my HiJackThis log

 
0
  #1
Jun 23rd, 2004
plz help me. for over 2 weeks my homepage has kept reseting to about:blank. i have several programs that i've seen in other instances to fix it. i havent been able to figure out what i need to do. plz help me. heres my HiJackThis log
Logfile of HijackThis v1.97.7
Scan saved at 9:44:19 PM, on 6/23/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AIM\aim.exe
C:\Valve\Steam\Steam.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Michael\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Michael\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Michael\LOCALS~1\Temp\sp.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Michael\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Michael\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Michael\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Michael\LOCALS~1\Temp\sp.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {E1EC2C77-DD85-4264-87BD-EFCF53BD67C5} - C:\WINDOWS\System32\eegndl.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [Ad-aware] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe" +c
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Steam] C:\Valve\Steam\Steam.exe -silent
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O8 - Extra context menu item: &iSearch The Web - res://C:\WINDOWS\System32\toolbar.dll/SEARCH.HTML
O9 - Extra button: AIM (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://fpdownload.macromedia.com/get...irector/sw.cab
O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} - http://install.wildtangent.com/Activ...veLauncher.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {FE1A240F-B247-4E06-A600-30E28F5AF3A0} - file://C:\install.cab

if you can plz help me.
Reply With Quote Quick reply to this message  
Join Date: Jun 2004
Posts: 5
Reputation: DepthCore is an unknown quantity at this point 
Solved Threads: 0
DepthCore DepthCore is offline Offline
Newbie Poster

Re: My homepage changes to about:blank. plz help. heres my HiJackThis log

 
0
  #2
Jun 23rd, 2004
also whenever i run spybot search and destroy. something comes up named DSO exploit. it always comes up and labeled as a registry change. thank you for listening to my problem
Reply With Quote Quick reply to this message  
Join Date: Dec 2003
Posts: 2,414
Reputation: alc6379 has a spectacular aura about alc6379 has a spectacular aura about alc6379 has a spectacular aura about 
Solved Threads: 123
Team Colleague
alc6379's Avatar
alc6379 alc6379 is offline Offline
Cookie... That's it

Re: My homepage changes to about:blank. plz help. heres my HiJackThis log

 
0
  #3
Jun 24th, 2004
Before going any further, please read this thread.
http://www.daniweb.com/techtalkforums/thread5690.html

If none of these suggestions help, then ask for assistance. It's more rewarding to help yourself than have someone do all of the work for you!
Alex Cavnar, aka alc6379
Reply With Quote Quick reply to this message  
Join Date: Jun 2004
Posts: 5
Reputation: DepthCore is an unknown quantity at this point 
Solved Threads: 0
DepthCore DepthCore is offline Offline
Newbie Poster

Re: My homepage changes to about:blank. plz help. heres my HiJackThis log

 
0
  #4
Jun 24th, 2004
i understand what you mean but i have most of the programs that protect me from this. i've been searching for solutions to this problem. the main problem is HiJackThis logs change from person to person i have some file that i've seen before on a few others that resemblences to mine but not very close. i dont know the exact date the problem occured but i think it may be building up files. i've been wondering if i could be helped in fixing this problem
Reply With Quote Quick reply to this message  
Join Date: Dec 2003
Posts: 6,439
Reputation: DMR will become famous soon enough DMR will become famous soon enough 
Solved Threads: 362
Team Colleague
DMR's Avatar
DMR DMR is offline Offline
Wombat At Large

Re: My homepage changes to about:blank. plz help. heres my HiJackThis log

 
0
  #5
Jun 24th, 2004
Understood- HJT logs can be very specific.

If you haven't already, please use Windows' Automatic Update facility to make sure that your system has all of the lastest critical security patches and bug fixes installed; that may very well solve the Data Source Object (DSO) exploit issue.
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing


Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.

However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
Reply With Quote Quick reply to this message  
Join Date: Jun 2004
Posts: 5
Reputation: DepthCore is an unknown quantity at this point 
Solved Threads: 0
DepthCore DepthCore is offline Offline
Newbie Poster

Re: My homepage changes to about:blank. plz help. heres my HiJackThis log

 
0
  #6
Jun 24th, 2004
ok well i have all updates except for a few not needed programs. i dont believe that DSO exploit should be to much of a worry. i'm not sure though so. On my other problem i tried a few solutions. like many other people it comes back after rebooting. please help me if you have time to spare to help me. Thank you
Reply With Quote Quick reply to this message  
Join Date: Dec 2003
Posts: 6,439
Reputation: DMR will become famous soon enough DMR will become famous soon enough 
Solved Threads: 362
Team Colleague
DMR's Avatar
DMR DMR is offline Offline
Wombat At Large

Re: My homepage changes to about:blank. plz help. heres my HiJackThis log

 
0
  #7
Jun 24th, 2004
I remember reading someplace that when SpyBot barks about DSO exploits, it has to do with your ActiveX settings in the Internet Options cotrol panel being too "loose". However, I've also read that the DSO warning is either a bug in SpyBot itself, or is triggered by some bug in IE and/or Windows code. You can read more about it in this Google search.

Have HJT fix the following entries and see what happens:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Michael\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Michael\LOCALS~1\Temp\sp.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Michael\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Michael\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Michael\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Michael\LOCALS~1\Temp\sp.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {E1EC2C77-DD85-4264-87BD-EFCF53BD67C5} - C:\WINDOWS\System32\eegndl.dll
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O8 - Extra context menu item: &iSearch The Web - res://C:\WINDOWS\System32\toolbar.dll/SEARCH.HTML
O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} - http://install.wildtangent.com/Acti...iveLauncher.cab
O16 - DPF: {FE1A240F-B247-4E06-A600-30E28F5AF3A0} - file://C:\install.cab

Reboot, and then:

Have the View option in Windows Explorer set to show all hidden and system files
Empty all Tempory Internet folders
Clear your cache and cookies
Find and delete the entire WildTangent folder
Find and delete the C:\install.cab file
Find and delete the C:\WINDOWS\System32\eegndl.dll file
Empty the Recycle Bin
Last edited by DMR; Jun 24th, 2004 at 4:48 pm.
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing


Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.

However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
Reply With Quote Quick reply to this message  
Join Date: Jun 2004
Posts: 5
Reputation: DepthCore is an unknown quantity at this point 
Solved Threads: 0
DepthCore DepthCore is offline Offline
Newbie Poster

Re: My homepage changes to about:blank.heres my HiJackThis log

 
0
  #8
Jun 24th, 2004
earlier before you posted i went to http://forums.spywareinfo.com/index.php?showtopic=942 and i followed the directions told by daemon at the bottom of the page. it fixed my system. after several hours it hasnt come back no files come up with searchs from ad-aware, anything odd in hijackthis, and also spybot search and destroy. the only thing i havent been able to fix is the DSO exploit. if my problem comes back i'll post again and wait for advice. thank you for all yall's help. :lol: :lol: :lol: :lol: :lol:
Reply With Quote Quick reply to this message  
Join Date: Dec 2003
Posts: 6,439
Reputation: DMR will become famous soon enough DMR will become famous soon enough 
Solved Threads: 362
Team Colleague
DMR's Avatar
DMR DMR is offline Offline
Wombat At Large

Re: My homepage changes to about:blank.heres my HiJackThis log

 
0
  #9
Jun 25th, 2004
Whatever the reason for DSO exploit warning in SpyBot- from my experience in using the program, it almost always comes up, and I'm not really convinced that it indicates anything nasty in particular either. I want to research the issue further to get amore definitive answer; when I do I'll post the particulars....
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing


Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.

However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC