Download FINDnFIX. 2. it always says it picks stuff up and usually says it cant remove all of them. You can download HitmanPro from the below link: HITMANPRO DOWNLOAD LINK (This link will open a new web page from where you can download "HitmanPro") Double-click on the file named "HitmanPro.exe" here is the log after doing what you suggested. check over here

Then get HiJack This http://www.majorgeeks.com/download3155.html, put it in a permanent folder (C:\HJT) , run it , DO NOT fix anything, post the log here

Note: Your old Firefox profile will be placed on your desktop in a folder named "Old Firefox Data". You can remove AdwCleaner from your machine, however we recommend that you keep Malwarebytes Anti-Malware and HitmanPro installed and perform regular computer scans.If you are still experiencing problems while trying to

We suggest you use C:\Program Files\HijackThis but feel free to use any name or folder you like. If you suspect that your computer might be infected with malware (adware, browser hijacker or any other type of malware) or simply want to restore your browser settings to its default, I copied note book in there but no luck. When your computer reboots and you are logged in, Malwarebytes AdwCleaner will automatically open a log file that contains the files, registry keys, and programs that were removed from your computer.

I do however have one C:\WINNT\Lastgood\system32\dllcache. Total of file sizes: 66,048 bytes 64.50 K --a-- W32i APP ENU 5.1.2600.0 shp 66,048 06-18-2004 notepad.exe Language 0x0409 (English (United States)) CharSet 0x04b0 Unicode OleSelfRegister Disabled CompanyName Microsoft Corporation FileDescription We really like the free versions of Malwarebytes and HitmanPro, and we love the Malwarebytes Anti-Malware Premium and HitmanPro.Alert features. https://www.bleepingcomputer.com/forums/t/340579/browser-hijacked-about-blank/ Be sure you are using the latest reference file. 10.

Open the FindnFix folder and double click on !LOG!.bat. You will

Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quietO4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\AIM\aim.exe -cnetwait.odlO4 - HKCU\..\Run: [Qmpfrrx] C:\WINDOWS\SYSTEM\dlej.exeO4 - HKCU\..\Run: [Tsa2] C:\PROGRAM FILES\COMMON FILES\TSA\TSM2.EXEO4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\Web Offer\wo.exeO4 - Startup: WinZip Quick Pick.lnk = https://www.wilderssecurity.com/threads/solved-need-help-with-about-blank-hijack.42122/ In fact, with a little help from Troubleshooting Your PC for Dummies, 3rd Edition, you can save yourself lots of time, money, and headaches by diagnosing and fixing those snags, glitches, On restart, Navigate to: C:\FINDnFIX\ main folder: 10. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged

Access Control List for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: (ID-NI) ALLOW Read BUILTIN\Users (ID-IO) ALLOW Read BUILTIN\Users (ID-NI) ALLOW Full access BUILTIN\Administrators (ID-IO) ALLOW Full access BUILTIN\Administrators (ID-NI) ALLOW Full access NT check my blog User is a member of group NT AUTHORITY\Authenticated Users. ;; Service searchdifferent variant) '"Network Security Service","__NS_Service_3"... This board sometimes inserts spaces in the strangest places. Stay logged in Sign up now!

Do this: 1. Then navigate to it and run HijackThis from there. d l l h 000011D0: vk UDeviceNotSelectedTimeout 1 5 ( 00001210: 9 0 =t vk ' zGDIProcessHandleQuota" 00001250: vk p Spooler2 y e s _ h 00001290 vk 5swapdisk vk . this content Operating System ProductVersion 5.1.2600.0 FileVersion 5.1.2600.0 (xpclient.010817-1148) LegalCopyright ) Microsoft Corporation.

Please run another HijackThis log so we can see its status. Std. Created Mar 16 1992, 21:09:15.

Std. Attached Files: hijackthis.log File size: 6.2 KB Views: 27 Jimbo5846, Jan 17, 2005 #5 MFDnNC Joined: Sep 7, 2004 Messages: 49,014 Posting for visibility Logfile of HijackThis v1.99.0 Scan saved at Mask Gen. this is my latest log run just a minute ago.

Messenger (HKLM) O9 - Extra button: AIM (HKLM) O9 - Extra button: Real.com (HKLM) O9 - Extra button: Support (HKCU) O9 - Extra button: ComcastHSI (HKCU) O9 - Extra button: Help

When Malwarebytes Anti-Malware is scanning it will look like the image below. Note: Ignore a "br" after that first Registry key. Tahnks in advance for your help and suggestions. Also post the WIN.txt file in the same post.

Click on the "Next" button, to install Zemana AntiMalware on your computer. I have got wordpad but this does not seem to work or I am lacking in computer knowledge.

That may be the reason you cannot see the "C:\WINNT\System32" folder. This site is completely free -- paid for by advertisers and donations. Messenger (HKLM) O9 - Extra button: AIM (HKLM) O9 - Extra button: Real.com (HKLM) O9 - Extra button: Support (HKCU) O9 - Extra button: ComcastHSI (HKCU) O9 - Extra button: Help If you cannot find a good one in C:\Windows or one of its subfolders, see if you have a "C:\I386" folder.

Press the Save Log button and remember where you saved it to. i guess i went wrong somewhere. Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_5_7_0.DLL (file missing)O4 - HKLM\..\Run: [27LSX694L4RJC8] C:\WINDOWS\SYSTEM\Cvx137.exeO4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKLM\..\Run: [SpySpotter] C:\PROGRAM FILES\SPYSPOTTER\SpySpotter.exeO4 - HKLM\..\RunServices: [IPUK32.EXE] C:\WINDOWS\IPUK32.EXEO4 - HKCU\..\Run: [Yahoo! When Internet Explorer has completed its task, click on the "Close" button in the confirmation dialogue box.

A few years ago,it was once sufficient to call something a 'virus' or 'trojan horse', however today's infection methods and vectors evolved and the terms 'virus and trojan' no longer provided Remove the remnants of the infection. Sniffed -> C:\JUNKXXX\HLP.222 **File C:\JUNKXXX\HLP.222 0000DEBE: 67 44 65 76 69 63 65 00 . 00 53 74 72 65 61 6D 69 gDevice. .Streami 0000DED3: 63 65 53 65 74 Do a "Fix" once more with CWShredder, let it remove any files found. 9.

Logfile of HijackThis v1.97.7 Scan saved at 11:12:52 PM, on 6/29/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\System32\svchost.exe