About:Blank Hijack Log

  1. #1
    latheboy is offline Newbie

    About:Blank Hijack Log

    I have the sickness....

    I have attemped all the normal methods of removal. Spybot, adaware....
    I am also trying to remove the two .dlls to get rid of this thing for good. Problem is, when I use Reg Lite to find the name of the hidden file, i dont see a key labeled \\Applnit_DLLs.

    As you can see in the post below, one .dll is identified by Hijack.
    Any help is appreciatied.

    Logfile of HijackThis v1.99.0
    Scan saved at 12:28:38 PM, on 12/27/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\d3nt.exe
    C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wintz32.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\hijack\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\olalm.dll/sp.html#55135
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\olalm.dll/sp.html#55135
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\olalm.dll/sp.html#55135
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\olalm.dll/sp.html#55135
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\olalm.dll/sp.html#55135
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\olalm.dll/sp.html#55135
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\olalm.dll/sp.html#55135
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {93233A01-64CC-514B-D290-BFA49086D6D5} - C:\WINDOWS\system32\syssf32.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [d3nt.exe] C:\WINDOWS\system32\d3nt.exe
    O4 - Global Startup: Microsoft Broadband Networking.lnk = ?
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/26c4ade0...p/RdxIE601.cab
    O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} - http://64.21.226.243//activex/AMC.cab
    O16 - DPF: {A662DA7E-CCB7-4743-B71A-D817F6D575DF} - http://www.autodesk.com/global/expre...iewerSetup.cab
    O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup.cab
    O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Network Security Service (NSS) - Unknown - C:\WINDOWS\system32\wintz32.exe


  2. #2
    latheboy is offline Newbie
    I have continued to try to remove this thing, with no luck. I tried fixing thru Hijack This, only the ones I knew were bad. I rebooted and ran Hijack again, and it looks like it just made a new file again. Any suggestions?

    Here is my new Hijack log file.



    ogfile of HijackThis v1.99.0
    Scan saved at 3:46:02 PM, on 12/27/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\d3nt.exe
    C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wintz32.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\hijack\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\moyin.dll/sp.html#55135
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\moyin.dll/sp.html#55135
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\moyin.dll/sp.html#55135
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\moyin.dll/sp.html#55135
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\moyin.dll/sp.html#55135
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\moyin.dll/sp.html#55135
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\moyin.dll/sp.html#55135
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {0E21F25B-0D5F-DB07-A23E-096542875F23} - C:\WINDOWS\sdkdw.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [d3nt.exe] C:\WINDOWS\system32\d3nt.exe
    O4 - Global Startup: Microsoft Broadband Networking.lnk = ?
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/26c4ade0...p/RdxIE601.cab
    O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} - http://64.21.226.243//activex/AMC.cab
    O16 - DPF: {A662DA7E-CCB7-4743-B71A-D817F6D575DF} - http://www.autodesk.com/global/expre...iewerSetup.cab
    O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup.cab
    O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Network Security Service (NSS) - Unknown - C:\WINDOWS\system32\wintz32.exe

  3. #3
    latheboy is offline Newbie
    Prior to finding this site i ran CWSHREDDER. It fixed it up for the first startup of IE, bu then went back to about:blank homepage for next startup.

  4. #4
    owen is offline D-A-L Team Member (UK)
    Hello,
    Please could you download and unzip About:Buster from AboutBuster. Leave it for now, we'll use it later. Also download and install Ad-aware from here.

    Once you have installed Ad-aware, run the program and in the bottom right hand corner click Check For Updates. Update Ad-aware following the prompts and then close the program, we will use it later.

    Then boot into Safe Mode and ensure that you are showing Hidden Files and Folders beforehand.

    Go to Start> Run and type services.msc.

    Locate Network Security Service (NSS). Double click it and click the Stop button in the Properties window. Select Disabled from the drop down menu next to Startup Type. Click Ok and exit Services.

    Press Ctrl+Alt+Del to get into Task Manager. Once in Task Manager, end the following processes (if they exist):

    wintz32.exe

    Restart Hijack This and put a checkmark next to these entries and click Fix Checked:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\moyin.dll/sp.html#55135
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\moyin.dll/sp.html#55135
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\moyin.dll/sp.html#55135
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\moyin.dll/sp.html#55135
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\moyin.dll/sp.html#55135
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\moyin.dll/sp.html#55135
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\moyin.dll/sp.html#55135
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {0E21F25B-0D5F-DB07-A23E-096542875F23} - C:\WINDOWS\sdkdw.dll
    O4 - HKLM\..\Run: [d3nt.exe] C:\WINDOWS\system32\d3nt.exe
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/26c4ade...ip/RdxIE601.cab
    O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} - http://64.21.226.243//activex/AMC.cab
    O23 - Service: Network Security Service (NSS) - Unknown - C:\WINDOWS\system32\wintz32.exe

    Delete the following files and folders:

    C:\WINDOWS\system32\wintz32.exe
    C:\WINDOWS\system32\d3nt.exe
    C:\WINDOWS\sdkdw.dll

    Now run the file aboutbuster.exe that we downloaded earlier. When the tool is open press the Ok button, then the Start button, then the Ok button, and then finally the Yes button. If it asks if you would like to do a second pass, allow it to do so.When finished, press the "Save log" button. I will want a copy of that log after all steps are completed here.

    Copy the contents of this quote box to Notepad:

    REGEDIT4

    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\HSA]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\SE]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\SW]
    Click File> Save As. Click the drop down arrow next to Save as type: and select all files. In the filename box type fix.reg. Save it to a convenient location. Once saved, double click it and confirm that you want it to merge with the registry.

    Now Start Ad-aware

    We need to configure Ad-aware for a full scan.

    Click on the Gear icon (second from the left) to access the preferences/settings window

    1. In the General window make sure the following are selected:
    • Automatically save log-file
    • Automatically quarantine objects prior to removal
    • Safe Mode (always request confirmation)
    2. Click on the Scanning button on the left and select :
    • Scan Within Archives
    • Scan Active Processes
    • Scan Registry
    • Deep Scan Registry
    • Scan my IE favorites for banned URL’s
    • Scan my Hosts file
    • Under Click here to select drives + folders, choose:
    • All of your hard drives
    Click on the Advanced button on the left and select:
    • Include additional process information
    • Include additional file information
    • Include environment information
    Click the Tweak button and select:
    • Under the Scanning Engine:
      • Unload recognized processes & modules during scan
      • Include additional Ad-aware settings in logfile
    • Under the Cleaning Engine:
      • Let Windows remove files in use at next reboot
    Click on Proceed to save the settings.

    Click Start and on the next screen choose Activate in-depth Scan at the bottom of the page and then choose:
    • Use Custom Scanning Options
    Click Next and Ad-aware will scan your hard drive(s) with the options you have selected.

    Save the log file when it asks and then click Finish

    When finished, mark everything for removal and get rid of it. (Right-click the window and choose Select All from the drop down menu and click Next).

    Then go to Start> Run and type cleanmgr.

    Put a checkmark next to:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    Click Ok

    Reboot into Normal Mode.

    Note: Two, possibly three files may have been deleted from your computer by the hijacker and may need to be replaced:

    Control.exe. If control.exe is missing go to merijn and download the version of control.exe for your operating system. If you are running Windows 2000, copy it to c:\winnt\system32\. For Windows XP, copy it to c:\windows\system32\.

    hosts (with no extension). Download the Hoster. Press "Restore Original Hosts" and press "OK". Exit Program. Note: if you were using a custom Hosts file you will need to replace any of those entries yourself

    SDHelper.dll (if you are using Spybot Search & Destroy). If you have Spybot S&D installed and SDHelper.dll is missing, replace it with this one. Copy the file to the folder containing your Spybot S&D program (normally C:\Program Files\Spybot - Search & Destroy)

    Additionally, Please check your ActiveX security settings. They may have been changed by this CWS variant to allow all ActiveX. In IE, click Tools> Internet Options and then click the Security tab. Click on Custom Level and make sure that the following settings are correct:

    Download signed ActiveX controls (Prompt)
    Download unsigned ActiveX controls (Disable)
    Initialize and script ActiveX controls not marked as safe (Disable)
    Run ActiveX controls and plug-ins (Enabled) (This actually refers to Java and Flash, not ActiveX)
    Script ActiveX controls marked safe for scripting (Prompt)

    Pay a visit to http://housecall.trendmicro.com and let it scan for and remove any viruses, worms or trojans you may have.

    Then post a fresh Hijack This log and your About:Buster log here.

  5. #5
    latheboy is offline Newbie
    Ok Owen, First and foremost, THANKS A TON! I was able to do nearly everything you told me too.

    I was not able to find the file c:\windows\sdkdw.dll
    I did a few searches, but could locate it.

    I was not able to run cleanmgr. It would start to calulate space that could be made availible and then sit. I literally let it sit for hours. I did clear temp internet files and history from IE tho. And emptied the recycle bin.

    I ran aboutbuster and hijack. The logs are below.

    I ran the virus scan from housecall. It found 13 infected files. 6 files are infected with JAVA_BYTEVER.A The virus scanner cannot access those file to delete them. I do have system restore off. The other 7 files where infected with a trogan named Trog_hideproc.b Those files are now deleted.

    Not sure what to do wth the files infected with the bytever.A
    They have adresses a mile long but i suppose i could manually get them out.
    Maybe there is a cleaner availible for that virus?

    I dont know if the hijack deleted any or all of those 3 files. (contol.exe, hosts, sdhelper.dll) How will i know if they have been deleted?

    THANKS AGAIN

    Latheboy

    Logfile of HijackThis v1.99.0
    Scan saved at 2:09:24 PM, on 12/28/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\Windows Media Player\wmplayer.exe
    C:\hijack\HijackThis.exe

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - Global Startup: Microsoft Broadband Networking.lnk = ?
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe
    O16 - DPF: {A662DA7E-CCB7-4743-B71A-D817F6D575DF} - http://www.autodesk.com/global/expre...iewerSetup.cab
    O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup.cab
    O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

    -------------------------------------------------

    Scanned at: 8:15:25 AM on: 12/28/2004


    -- Scan 1 ---------------------------
    About:Buster Version 4.0
    Reference List : 21


    Removed Data Streams:
    C:\WINDOWS\cmaudio.ini:cnwrt
    C:\WINDOWS\CMISETUP.INI:vohwn
    C:\WINDOWS\CoD.INI:nozjp
    C:\WINDOWS\EventSystem.log:tswvw
    C:\WINDOWS\tmupdate.ini:nsvkj
    C:\WINDOWS\tsoc.log:gtnxm
    C:\WINDOWS\twain.dllzyzc
    C:\WINDOWS\twain_32.dll:kwntz
    C:\WINDOWS\twunk_16.exe:ylgcg
    C:\WINDOWS\unvise32.exe:harmx


    Removed 2 Random Key Entries
    Attempted Clean Of Temp folder.
    Removed Uninstall Key (HSA)
    Removed Uninstall Key (SE)
    Removed Uninstall Key (SW)
    Pages Reset... Done!

    -- Scan 2 ---------------------------
    About:Buster Version 4.0
    Reference List : 21


    Removed Data Streams:
    C:\WINDOWS\cmaudio.ini:cnwrt
    C:\WINDOWS\CMISETUP.INI:vohwn
    C:\WINDOWS\CoD.INI:nozjp
    C:\WINDOWS\EventSystem.log:tswvw
    C:\WINDOWS\tmupdate.ini:nsvkj
    C:\WINDOWS\tsoc.log:gtnxm
    C:\WINDOWS\twain.dllzyzc
    C:\WINDOWS\twain_32.dll:kwntz
    C:\WINDOWS\twunk_16.exe:ylgcg
    C:\WINDOWS\unvise32.exe:harmx


    Attempted Clean Of Temp folder.
    Pages Reset... Done!
    Last edited by latheboy; 28-12-2004 at 09:24 PM.

  6. #6
    latheboy is offline Newbie
    Oh yea,

    The symptoms on about:blank are now gone. No hompage changes, or popups.

  7. #7
    owen is offline D-A-L Team Member (UK)
    You'd probably get error messages, if you aren't getting any, then no worries.

    To fix the Virus, you need to first get to Windows Update (http://windowsupdate.microsoft.com) and run the Express Install. You need to install Service Pack 2 first, which is very important.

    When you have installed all of the updates I specified, go to Start>Run and type cleanmgr. Click Ok.

    The program will perform a quick analysis of your system. When it has finished, put a checkmark next to the following:
    • Temporary Internet Files
    • Recycle Bin
    • Temporary Files

    Click Ok.

    Then return to Housecall and run another scan. If the virus is detected again, you need to note down (in Notepad or a Word Processing program you may have) the location and name of each file. Then post them back here and I'll help you.

  8. #8
    latheboy is offline Newbie
    Save 20% on AVG Internet Security 2012 Suite!
    Thanks for your help. I did install SP2. I updated windows also. As far as the virus, I still couldnot get rid of it thru housecall automaticlly. I just went and manually deleted the related files. I rescanned and found nothing. Also, cleanmgr worked as it should.

    If you would like I can list the files I deleted to get rid of the bytevor.b virus if it helps in the future. LMK. Thanks again.

+ Reply to Thread