plz help me. for over 2 weeks my homepage has kept reseting to about:blank. i have several programs that i've seen in other instances to fix it. i havent been able to figure out what i need to do. plz help me. heres my HiJackThis log
Logfile of HijackThis v1.97.7
Scan saved at 9:44:19 PM, on 6/23/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AIM\aim.exe
C:\Valve\Steam\Steam.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Michael\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Michael\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Michael\LOCALS~1\Temp\sp.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Michael\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Michael\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Michael\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Michael\LOCALS~1\Temp\sp.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {E1EC2C77-DD85-4264-87BD-EFCF53BD67C5} - C:\WINDOWS\System32\eegndl.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [Ad-aware] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe" +c
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Steam] C:\Valve\Steam\Steam.exe -silent
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O8 - Extra context menu item: &iSearch The Web - res://C:\WINDOWS\System32\toolbar.dll/SEARCH.HTML
O9 - Extra button: AIM (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} -
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {FE1A240F-B247-4E06-A600-30E28F5AF3A0} - file://C:\install.cab

if you can plz help me.

Dani AI

Generated

Brief expert summary and safe checklist based on the HiJackThis thread: the log and follow-up indicate an Internet Explorer configuration was repeatedly being rewritten (search/home values pointed at a temporary HTML) and an unsigned Browser Helper Object was present. Those two patterns commonly explain a homepage that keeps reverting to about:blank or to a temporary redirect page. ’s advice to make sure Windows is fully patched is important because many old hijackers abused loose ActiveX/MDAC/IE settings; ’s later post shows the common case where a targeted cleanup sequence can restore normal behavior.

Practical, low-risk workflow (in order): back up the system image and export the registry before editing; install all critical Microsoft updates; boot to Safe Mode for removal work; run a full, up-to-date antivirus scan followed by an updated anti‑spyware pass; use a trusted autorun inspector (for example, Sysinternals Autoruns) to review and disable suspicious autostarts, BHOs and toolbars; inspect scheduled tasks and the hosts file for unexpected entries; empty all temp folders and browser caches; then reboot and verify the settings. If a file cannot be removed because it’s in use, remove its autostart entry, reboot to Safe Mode and delete it, or delete on next-boot.

Additional diagnostics and fallbacks: use Process Explorer to trace which process holds a suspect file handle; run sfc /scannow to repair protected system files; check Group Policy or Internet Options if the homepage field is greyed/locked (that indicates a policy or firewall/management tool). For persistent, hidden infections consider a reputable boot-rescue scanner or a clean OS reinstall if containment fails.

Note on the Spybot “DSO exploit” flag: in the 2003–2004 era that alert often showed up as a heuristic/false positive tied to ActiveX/DSO settings. Keeping Windows/IE/MDAC updated and tightening ActiveX initialization/script permissions removes the real risk and also silences the false positive. ’s plan to research that further is appropriate for anyone who wants certainty.

Recommended Answers

All 8 Replies

also whenever i run spybot search and destroy. something comes up named DSO exploit. it always comes up and labeled as a registry change. thank you for listening to my problem

Before going any further, please read this thread.
http://www.daniweb.com/techtalkforums/thread5690.html

If none of these suggestions help, then ask for assistance. It's more rewarding to help yourself than have someone do all of the work for you!

i understand what you mean but i have most of the programs that protect me from this. i've been searching for solutions to this problem. the main problem is HiJackThis logs change from person to person i have some file that i've seen before on a few others that resemblences to mine but not very close. i dont know the exact date the problem occured but i think it may be building up files. i've been wondering if i could be helped in fixing this problem

Understood- HJT logs can be very specific.

If you haven't already, please use Windows' Automatic Update facility to make sure that your system has all of the lastest critical security patches and bug fixes installed; that may very well solve the Data Source Object (DSO) exploit issue.

ok well i have all updates except for a few not needed programs. i dont believe that DSO exploit should be to much of a worry. i'm not sure though so. On my other problem i tried a few solutions. like many other people it comes back after rebooting. please help me if you have time to spare to help me. Thank you

I remember reading someplace that when SpyBot barks about DSO exploits, it has to do with your ActiveX settings in the Internet Options cotrol panel being too "loose". However, I've also read that the DSO warning is either a bug in SpyBot itself, or is triggered by some bug in IE and/or Windows code. You can read more about it in this Google search.

Have HJT fix the following entries and see what happens:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Michael\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Michael\LOCALS~1\Temp\sp.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Michael\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Michael\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Michael\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Michael\LOCALS~1\Temp\sp.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {E1EC2C77-DD85-4264-87BD-EFCF53BD67C5} - C:\WINDOWS\System32\eegndl.dll
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O8 - Extra context menu item: &iSearch The Web - res://C:\WINDOWS\System32\toolbar.dll/SEARCH.HTML
O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} - http://install.wildtangent.com/Acti...iveLauncher.cab
O16 - DPF: {FE1A240F-B247-4E06-A600-30E28F5AF3A0} - file://C:\install.cab

Reboot, and then:

Have the View option in Windows Explorer set to show all hidden and system files
Empty all Tempory Internet folders
Clear your cache and cookies
Find and delete the entire WildTangent folder
Find and delete the C:\install.cab file
Find and delete the C:\WINDOWS\System32\eegndl.dll file
Empty the Recycle Bin

earlier before you posted i went to and i followed the directions told by daemon at the bottom of the page. it fixed my system. after several hours it hasnt come back no files come up with searchs from ad-aware, anything odd in hijackthis, and also spybot search and destroy. the only thing i havent been able to fix is the DSO exploit. if my problem comes back i'll post again and wait for advice. thank you for all yall's help. :lol: :lol: :lol: :lol: :lol:

Whatever the reason for DSO exploit warning in SpyBot- from my experience in using the program, it almost always comes up, and I'm not really convinced that it indicates anything nasty in particular either. I want to research the issue further to get amore definitive answer; when I do I'll post the particulars....

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.