Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etc
   
BullGuard Antivirus Forum > Virus Removal > Removal Help > I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etc  
Forum Quick Jump
 
New Topic Post reply to : I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etc Printable version of : I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etc
[ << Previous Thread | Next Thread >> ]

Joe Richards
New Member


Date Joined Feb 2005
Total Posts : 1
 
   Posted 2-20-2005 3:23 (GMT +1)    Quote: I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etcAlert an admin about: I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etc
help me, i've tried everything(i know of)!
highjackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 9:18:16 PM, on 2/19/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\system32\ezSP_Px.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Easy\TV Capture\RemoteCtl.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\Program Files\Analog Devices\SoundMAX\smagent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
c:\program files\InterMute\SpySubtract\CWShredder.exe
C:\Program Files\InterMute\SpySubtract\CWShredder.exe
C:\Program Files\InterMute\SpySubtract\CWShredder.exe
C:\PROGRA~1\Netscape\Netscape\Netscp.exe
C:\PROGRA~1\NORTON~1\navw32.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {E550B18D-262B-4F71-8CBE-0D82D1642F73} - C:\WINDOWS\system32\mejp.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll,DllInstall
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - HKCU\..\Run: [Mozilla Quick Launch] "C:\Program Files\Netscape\Netscape\Netscp.exe" -turbo
O4 - Startup: Outlook Express.lnk = C:\Program Files\Outlook Express\msimn.exe
O4 - Global Startup: TV Capture Remote Control.lnk = C:\Program Files\Easy\TV Capture\RemoteCtl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Discover deskshop virtual credit card - C:\WINDOWS\Brodia\discover_context_menu.htm
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Win32 Classes -
O16 - DPF: Yahoo! Hearts - http://download.games.yahoo.com/games/clients/y/ht1_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: Yahoo! Spades - http://download.games.yahoo.com/games/clients/y/st2_x.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409
O16 - DPF: {341FF14B-00CB-49F5-A427-A164DF1D5E1F} (MALPlaybackCtrl Class) - http://musicstore.connect.com/assets/activexplayer/SMALStreaming.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\smagent.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Back to Top
 

YOYOYO
New Member


Date Joined Feb 2005
Total Posts : 1
 
   Posted 2-25-2005 7:35 (GMT +1)    Quote: I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etcAlert an admin about: I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etc
About:Blank virus
 
I read a lot about this virus but everybody seems to have failed to notice there is not only one dll but 2.
- SE.DLL wich is loaded by rundll32.exe
- a mutant dll (it is created by se.dll and has a random name of 4 letters like ppfe.dll ).
the mutant dll is a com server that is tied to two registry keys:
- HKEY_CLASSES_ROOT\PROTOCOLS\Filter\"text/html"
- HKLM\SOFTWARE.... Browser helper objects.
the best way to find this dll is to look for the most recent modified dll. you will find it in winnt/system32 folder and its about 30k in size.
 
When Se.dll is running it prevents you from modifying the registry, actually it rewrites the entries you modified. To stop it you need to run a program called pview.exe. that lets you stop the program rundll32.exe or at least the instance running se.dll. you actually can also stop it with the taskmanager you just kill all the instances of rundll32.
Now you can delete se.dll.
 
but the actual reason for there is many people who fails to remove this virus it is because they fail to delete the mutant dll.
to easily know its name go to the registry key described above and copy the Guid wich it looks like {807553E5-5146-11D5-A672-00B0D022E945} it can be any serie of characters.
then you search for this key in the whole registry and once you find it you will know the exact name of th mutant dll.
 
Search for this file in your explorer and try to delete it, if you can't close all the instances of iexplorer.
 
kill this 2 dlls and your problem  is solved
 
 
Back to Top
 

acintra
New Member


Date Joined Feb 2005
Total Posts : 2
 
   Posted 2-26-2005 3:40 (GMT +1)    Quote: I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etcAlert an admin about: I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etc
I was very excited when I found this site and the answer for my problem, however, I don't know why, I couldn't fix the problem in my computer. This "aboutblank" virus is killing my computer. I can't do much with this. I found your instructions very good, but couldn't find files, .dll, pview.exe as specified in your help response. Can you help me again? Thanks a lot.
Back to Top
 

Loaner
New Member


Date Joined Feb 2005
Total Posts : 2
 
   Posted 2-26-2005 5:15 (GMT +1)    Quote: I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etcAlert an admin about: I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etc
I cant find the mutant dll I've looked in the folders and there are no dll files. It's fine getting rid of the se.dll file though.
Back to Top
 

acintra
New Member


Date Joined Feb 2005
Total Posts : 2
 
   Posted 2-26-2005 5:20 (GMT +1)    Quote: I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etcAlert an admin about: I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etc
I guess YOYOYO is the person that can help us....
Back to Top
 

hf
New Member


Date Joined Feb 2005
Total Posts : 1
 
   Posted 2-28-2005 5:11 (GMT +1)    Quote: I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etcAlert an admin about: I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etc
pview.exe is a Process Viewer in the NT Resource Kit.

For a modern version that runs on multiple Windows versions including XP, try:

http://www.sysinternals.com/ntw2k/freeware/procexp.shtml

which will show you process info as well as registry keys being accessed, and will let you kill processes as needed.

Good luck hunting down and killing se.dll and its mutant spawn.
Back to Top
 

Darshu
New Member


Date Joined Feb 2005
Total Posts : 1
 
   Posted 2-28-2005 5:16 (GMT +1)    Quote: I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etcAlert an admin about: I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etc
Hi all. My sis's comp got infected wiv dis Trojan.startpage too. She's using Winxp Home edition SP2 though. Yes yoyoyo is right, the second dll file has a random 4 character name (mutant dll), mine was hijc.dll. You will find it in C:\windows\system32. Before trying to delete it, install microsoft Antispyware (Beta) which is free and is available at microsoft.com. Using microsoft antispyware, go to advanced tools, then look into IE BHO. You will find a complete list of BHO plugins installed in your IE, including the random 4 character name dll file (hijc.dll in my case). Make sure u have done a complete scan wiv ms antispyware and have the real-time blocker active. Block all reported activities (for the time being). Now search for se.dll and look for the mutant dll file in C:\windows\system32 (set the Win explorer view settings to detail mode to list files in order of most recently modded), and delete them both. If it says access denied, make sure all IE instances are closed and rename both the files to something else e.g. to iuwyfiuwhfuwehu so that the virus can't run it can't run it any more. Use ms antispyware to restore all ur browser settings. Now run IE to see if its still around heheh :p ...but for me its goodbye trojan.startpage, it was fun while it lasted lol
Back to Top
 

makija
New Member


Date Joined Feb 2005
Total Posts : 19
 
   Posted 2-28-2005 7:08 (GMT +1)    Quote: I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etcAlert an admin about: I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etc
as i said in other threads http://www.nuker.com/ download that if you can find a crack if not msg i can send you an test it see the resoults other cleaners are no match to this one
Back to Top
 

riverman
New Member


Date Joined Mar 2005
Total Posts : 2
 
   Posted 3-1-2005 9:03 (GMT +1)    Quote: I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etcAlert an admin about: I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etc
I have the same damn virus.....I am not a "newcomer" to the computer but having trouble following YoYO as to where the registry keys are at. I did go into explorere and look in system32 but there is bunch of folders here, can someone narrow it down for me or explain to me how I might be able to find the keys in "laymans terms", if that is possible. Thank you!

RM
Back to Top
 

Loaner
New Member


Date Joined Feb 2005
Total Posts : 2
 
   Posted 3-1-2005 6:02 (GMT +1)    Quote: I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etcAlert an admin about: I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etc
I fouind a file called feik.dll in the system folder. My computer has xp and 98 on it and I had to go onto XP to find it. Anyway I deleted both (se and feik) and it came back.
Back to Top
 

riverman
New Member


Date Joined Mar 2005
Total Posts : 2
 
   Posted 3-2-2005 6:45 (GMT +1)    Quote: I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etcAlert an admin about: I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etc
I have looked all through my hard drive seaching through the search function for "????.dll" and found nothing. I then did a search in just system32 and also found nothing. Perhaps this is a mutant from the about blank that has been around before..who knows. I am taking my machine in tomorrow to let the computer guy fix it for me.

RM
Back to Top
 

iddqd
New Member


Date Joined Apr 2005
Total Posts : 1
 
   Posted 4-2-2005 2:30 (GMT +1)    Quote: I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etcAlert an admin about: I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etc
Hidden infected file size is: (39,936 byte) it is use 49,152 bytes
 
Dll file have not a fixed name but its name only 4 chars and .dll
 
search & destroy it (in safe mode or command prompt)
 
or you can erase this file via use "MoveOnBoot"
 
You can see this file with "Filemon.exe"
Back to Top
 

yzvi
New Member


Date Joined Apr 2005
Total Posts : 1
 
   Posted 4-16-2005 7:53 (GMT +1)    Quote: I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etcAlert an admin about: I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etc
Thank you all. Without you I would not have been able to get rid of "about:blank"
 
I  am a techie but no expert in the registry or things of that level. Not sure what a "key" is or other terms used to describe registry stuff.
 
I eventually found what I think was the infected file withthe trojan in it called "netqx.dll".
 
I found this using the Microsoft Beta Anit Spyware prgram but I want to make it clear thsat this program did not detect the file by itself.
 
It has Advanced tools and two very handy features - "System Explorers" and "Browser Restore". These utilties allow you to see varuious files associated with these improtant functions of your computer. One of them shows detailed information about each file like - author- use - publisher- date etc - you can easily get a feel for something suspicious and thats how I found it - I hope.
 
This thread allowd me to get an idea of whatit was that I was looking for especially the size of the file and that it was a dll file.
 
Also on this thread I found the reference to Spyware Nuker 2005 which finds things that the other Spyware doesn't find.
 
Things to note:-
 
I never found a file called se.dll
 
My Norton kept warning me of a Trojan Horse every time that I opened my Interent Explorer and then it told me the name and folder of the file BUT also said that it couldn't do anything about the file.
 
I called Norton day one and they tried to help me clea it which we did until I rebooted and then it was back with a vengance.
 
Microsoft -India I guess - were very nice people but useless. If they had to go from a - z they had to do the wqhole alphabet and had me actually reading out the entire contents of folders...phew..too much.
 
There was another serch page which kept appearing in a separate and vertical oblong window to the right of my IR window. Ostensibly nothing hostile about it and it looked like a good search engine but I didn't want it thanks and you enver know.
 
Went back to Norton and they said that I had been infected with Spyware and they don't do spyware so goodbye.. Thanks for that.
 
Donwloaded:-
 
AboutBuster:
 
Didn't find anything
 
 
Didn't find anything
 
CleanUp - very good eraser of sorts of stuff that I thought was gone at previous cleanings
 
I have a feeling that there is something still on my computer although eveything except my Microsoft Updates seems to be working OK and so far no sign of a hijack.
 
I also have Spybot, Pest Patrol and NoAdware and Lavasoft. They found things but of course they came back again as soon as I opened an IE window. But they do keep the comp[uter clean and I feel better wit hall of them incredible but thats my experience.
 
Thanks
 
Back to Top
 

Simao
New Member


Date Joined Apr 2005
Total Posts : 1
 
   Posted 4-29-2005 12:24 (GMT +1)    Quote: I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etcAlert an admin about: I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etc
I need help on trojan-spy.html.smitfraud
Back to Top
 
New Topic Post reply to : I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etc Printable version of : I have trojan.startpage about:blank virus, have tried adaware,spybot,spysweeper,trojan remover etc
 
Forum Information
Currently it is Saturday, November 21, 2009 3:47 PM (GMT +1)
There are a total of 73.034 posts in 17.116 threads.
In the last 3 days there were 14 new threads and 71 reply posts. View Active Threads
Who's Online
This forum has 30334 registered members. Please welcome our newest member, sushil.
48 Guest(s), 0 Registered Member(s) are currently online.  Details
5 Latest Threads
Constant scanning andskipped files? (3)21-11-2009 14:33:51 (Dickens)
Cannot install anti-virus softeware or do window updates... need help (17)21-11-2009 13:46:11 (superjesse)
Michael Vick jerseys (1)21-11-2009 09:42:37 (Dickens)
Arizona Cardinals Jerseys (1)21-11-2009 09:37:23 (Dickens)
How to remove this Malware/Virus (0)21-11-2009 06:54:16 (bozzack)