Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Aboutblank HELP


  • Please log in to reply

#1
cristiano_7_manu

cristiano_7_manu

    Member

  • Member
  • PipPip
  • 45 posts
Hi i have a problem with my homepage that it is about:blank and i can not seem to change it

I get alot of popups and it slow the computer down

Heres my log

ogfile of HijackThis v1.99.1
Scan saved at 18:31:52, on 15/11/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSRTE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\MCAFEE.COM\PERSONAL FIREWALL\MPFTRAY.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHLD.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSESCN.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\MCAFEE.COM\PERSONAL FIREWALL\MPFAGENT.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\UNZIPPED\HJT\HIJACKTHISL.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://c:\windows\TEMP\se.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://c:\windows\TEMP\se.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {52E5F445-5480-11DA-AEE0-4445B4FFC8F6} - C:\WINDOWS\SYSTEM\LCCCNE.DLL
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHL.DLL
O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\McUpdate.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFTRAY.EXE
O4 - HKLM\..\Run: [sp] rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall
O18 - Filter: text/html - {8323C0E6-5603-11DA-AEE0-D13318B3B5E8} - C:\WINDOWS\SYSTEM\LCCCNE.DLL
O18 - Filter: text/plain - {8323C0E6-5603-11DA-AEE0-D13318B3B5E8} - C:\WINDOWS\SYSTEM\LCCCNE.DLL


It would be great if you could help
  • 0

Advertisements


#2
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 31,671 posts
Download CWShredder - zipped version.
Stand-alone Exe
Stand-alone Exe
Save Shredder to your desktop or unzip to it's own folder but DO NOT run it yet.

Step 2: Download SpSeHjfix for 9x/ME
1. Save to your desktop
2. Right click a blank part of desktop, select new folder and name it spfix.
3. Unzip the file into that folder. DO NOT run it yet.

Step 3: Disconnect from the Internet and Close ALL OPEN PROGRAMS.
1. Run SpSeHjfix and click on "Start Disinfection".
2. When it's finished it will reboot your machine to finish the cleaning process.
3. The tool creates a log of the fix which will appear in the folder.

If it does not find any of the SE files or any hidden reinstallers it will say system clean and not go on to next stage

Warning Note: On a few occasions it has been reported that after using the SPSEHjfix you cannot open Internet Explorer. To fix this, go into Control Panel > Internet Options > Programs & press reset web settings, then you can set your home page to what you want on the general tab.

Step 4: Scan with CWShredder
1. Double-click on cwshredder.exe to start the program.
2. Click the "Fix" button (not "Scan Only").
3. Let it run completely and fix whatever if finds.
4. When the scan is completed and all files are removed, close the program.

Step 5: Reboot and post a fresh HJT log along with the log created by 'SpSeHjfix'.

Regards,
  • 0

#3
cristiano_7_manu

cristiano_7_manu

    Member

  • Topic Starter
  • Member
  • PipPip
  • 45 posts
Thanks for your help again

Here's the Spsehjfix log

(11/17/05 21:04:28) SPSeHjFix started v1.09
(11/17/05 21:04:28) OS: Win98SE A (4.10.67766446)
(11/17/05 21:04:28) Language: english
11/17/05 21:04:30) Disinfect started
(11/17/05 21:04:30) Bad-Dll(IEP): se.dll
(11/17/05 21:04:30) Searchassistant Uninstaller found: regsvr32 /s /u C:\WINDOWS\SYSTEM\LCCCNE.DLL
(11/17/05 21:04:30) Searchassistant Uninstaller - Keys Deleted
(11/17/05 21:04:30) UBF: 6
(11/17/05 21:04:30) UBB: 1
(11/17/05 21:04:30) FilterKey: HKCR\text/html (deleted)
(11/17/05 21:04:30) FilterKey: HKLM\SOFTWARE\Classes\text/html (error while deleting)
(11/17/05 21:04:30) FilterKey: HKCR\CLSID\{8323C0E6-5603-11DA-AEE0-D13318B3B5E8} (deleted)
(11/17/05 21:04:30) FilterKey: HKCR\text/plain (deleted)
(11/17/05 21:04:30) FilterKey: HKLM\SOFTWARE\Classes\text/plain (error while deleting)
(11/17/05 21:04:30) FilterKey: HKCR\CLSID\{8323C0E6-5603-11DA-AEE0-D13318B3B5E8} (error while deleting)
(11/17/05 21:04:30) BHO-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{52E5F445-5480-11DA-AEE0-4445B4FFC8F6} (deleted)
(11/17/05 21:04:30) BHO-Key: HKCR\CLSID\{52E5F445-5480-11DA-AEE0-4445B4FFC8F6} (deleted)
(11/17/05 21:04:30) UBR: 5
(11/17/05 21:04:30) Run-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\sp=rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall (deleted)
(11/17/05 21:04:30) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\windows\TEMP\se.dll/sp.html
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\windows\TEMP\se.dll/sp.html
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
(11/17/05 21:04:30) Stealth-String found: C:\WINDOWS\PSUITEXP.BMP
(11/17/05 21:04:30) File added to delete: c:\windows\system\lcccne.dll
(11/17/05 21:04:30) File added to delete: c:\windows\system\lcccne.dll
(11/17/05 21:04:30) File added to delete: c:\windows\temp\se.dll
(11/17/05 21:04:30) File added to delete: c:\windows\psuitexp.bmp
(11/17/05 21:04:30) Reboot
(11/17/05 21:06:35) SPSeHjFix 2nd Step
(11/17/05 21:06:35) RunServicesOnce-Key: (edited)
(11/17/05 21:06:39) Cleaned


ogfile of HijackThis v1.99.1
Scan saved at 21:10:40, on 17/11/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\MCAFEE.COM\PERSONAL FIREWALL\MPFTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\MCAFEE.COM\PERSONAL FIREWALL\MPFAGENT.EXE
C:\WINDOWS\NOTEPAD.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\UNZIPPED\HJT\HIJACKTHISL.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {02DCA195-602B-4B1F-83FF-381B7E804BDB} - C:\WINDOWS\SYSTEM\HDBHO.DLL
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHL.DLL
O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\McUpdate.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFTRAY.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [sp] rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall
O8 - Extra context menu item: Download All Files by HiDownload - C:\PROGRA~1\HIDOWN~1\HDGetAll.htm
O8 - Extra context menu item: Download by HiDownload - C:\PROGRA~1\HIDOWN~1\HDGet.htm
O8 - Extra context menu item: + Offline &Explorer: Download the link - file://C:\PROGRAM FILES\OFFLINE EXPLORER PRO\Add_UrlO.htm
O8 - Extra context menu item: + Offline E&xplorer: Download the current page - file://C:\PROGRAM FILES\OFFLINE EXPLORER PRO\Add_AllO.htm
O9 - Extra button: HiDownload - {F4FBA929-A891-492C-A0F6-5C79CC4F1742} - C:\PROGRA~1\HIDOWN~1\hidownload.exe

Edited by cristiano_7_manu, 17 November 2005 - 03:17 PM.

  • 0

#4
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 31,671 posts
Check the following items in HijackThis.
Close all windows except HijackThis and click Fix checked:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

O4 - HKLM\..\Run: [sp] rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall

Then reboot and follow the instructions here to set your HomePage to your liking.

Then run HijackThis and post the new log.

Regards,
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP