View Single Post
Old 07-15-2005, 01:42 PM   #1 (permalink)
old hickory
I helped the forums.
 
Join Date: Jul 2005
Posts: 39
OS: XP PRO


about blank virus...need help

My computer seems to be infected with about.blank virus

Problems:

1) about.blank web page opens with ie at bootup
2)popups occur and my popup blocker not effective now against these popups
3) computer boots up slow
4)taskbar at bottom has changed
5)zonealarm keeps telling me netwj.exe is trying to access the internet

I couln't do the online virus scan because ie kept needing to shut down.

I tried to follow all the instructions. I used hijack this analyzer to get the "new" log. thanks for any help you can provide. Here is result.txt log:

====================================================================
Log was analyzed using KRC HijackThis Analyzer - Updated on 6/3/05
Get updates at http://www.greyknight17.com/download.htm#programs

***Security Programs Detected***

C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Logfile of HijackThis v1.99.1
Scan saved at 2:20:25 PM, on 7/15/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\system32\SMCSTA.EXE
C:\Program Files\Lexmark 4200 Series\lxbmbmgr.exe
C:\WINDOWS\system32\netwj.exe
C:\Program Files\Lexmark 4200 Series\lxbmbmon.exe
C:\Documents and Settings\TIM\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\lcsnw.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\lcsnw.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\lcsnw.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\lcsnw.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\lcsnw.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\lcsnw.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {8A0DB32B-05DE-FEDD-EFA2-683C23669852} - C:\WINDOWS\system32\ipke32.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_1.dll
O4 - HKLM\..\Run: [SMCSTA.EXE] SMCSTA.EXE START
O4 - HKLM\..\Run: [Lexmark 4200 Series] "C:\Program Files\Lexmark 4200 Series\lxbmbmgr.exe"
O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKLM\..\Run: [netwj.exe] C:\WINDOWS\system32\netwj.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\RunOnce: [netgt.exe] C:\WINDOWS\netgt.exe
O4 - HKLM\..\RunOnce: [ntuk.exe] C:\WINDOWS\ntuk.exe
O4 - HKLM\..\RunOnce: [mskf.exe] C:\WINDOWS\mskf.exe
O4 - HKLM\..\RunOnce: [sdklz.exe] C:\WINDOWS\system32\sdklz.exe
O4 - HKLM\..\RunOnce: [mfcor32.exe] C:\WINDOWS\system32\mfcor32.exe
O4 - HKLM\..\RunOnce: [crfq.exe] C:\WINDOWS\crfq.exe
O4 - HKLM\..\RunOnce: [winxm.exe] C:\WINDOWS\system32\winxm.exe
O4 - HKLM\..\RunOnce: [ipqa.exe] C:\WINDOWS\system32\ipqa.exe
O4 - HKLM\..\RunOnce: [appwi32.exe] C:\WINDOWS\system32\appwi32.exe
O4 - HKLM\..\RunOnce: [atlom32.exe] C:\WINDOWS\system32\atlom32.exe
O4 - HKLM\..\RunOnce: [sdkhj.exe] C:\WINDOWS\sdkhj.exe
O4 - HKLM\..\RunOnce: [mfciv32.exe] C:\WINDOWS\mfciv32.exe
O4 - HKLM\..\RunOnce: [atlgt32.exe] C:\WINDOWS\atlgt32.exe
O4 - HKLM\..\RunOnce: [crbz.exe] C:\WINDOWS\crbz.exe
O4 - HKLM\..\RunOnce: [appsi.exe] C:\WINDOWS\appsi.exe
O4 - HKLM\..\RunOnce: [netzk.exe] C:\WINDOWS\system32\netzk.exe
O4 - HKLM\..\RunOnce: [winun.exe] C:\WINDOWS\winun.exe
O4 - HKLM\..\RunOnce: [javahp32.exe] C:\WINDOWS\javahp32.exe
O4 - HKLM\..\RunOnce: [javaxk.exe] C:\WINDOWS\javaxk.exe
O4 - HKLM\..\RunOnce: [atlzc32.exe] C:\WINDOWS\system32\atlzc32.exe
O4 - HKLM\..\RunOnce: [ipbc32.exe] C:\WINDOWS\system32\ipbc32.exe
O4 - HKLM\..\RunOnce: [netyq.exe] C:\WINDOWS\netyq.exe
O4 - HKLM\..\RunOnce: [crrm32.exe] C:\WINDOWS\system32\crrm32.exe
O4 - HKLM\..\RunOnce: [sdkqd32.exe] C:\WINDOWS\system32\sdkqd32.exe
O4 - HKLM\..\RunOnce: [netmz.exe] C:\WINDOWS\system32\netmz.exe
O4 - HKLM\..\RunOnce: [crev.exe] C:\WINDOWS\crev.exe
O4 - HKLM\..\RunOnce: [netsb32.exe] C:\WINDOWS\netsb32.exe
O4 - HKLM\..\RunOnce: [addyv.exe] C:\WINDOWS\system32\addyv.exe
O4 - HKLM\..\RunOnce: [crze32.exe] C:\WINDOWS\crze32.exe
O4 - HKLM\..\RunOnce: [winxk32.exe] C:\WINDOWS\system32\winxk32.exe
O4 - HKLM\..\RunOnce: [javaad.exe] C:\WINDOWS\system32\javaad.exe
O4 - HKLM\..\RunOnce: [mfczk.exe] C:\WINDOWS\system32\mfczk.exe
O4 - HKLM\..\RunOnce: [sysfe.exe] C:\WINDOWS\system32\sysfe.exe
O4 - HKLM\..\RunOnce: [crpj.exe] C:\WINDOWS\crpj.exe
O4 - HKLM\..\RunOnce: [sdkxv32.exe] C:\WINDOWS\system32\sdkxv32.exe
O4 - HKLM\..\RunOnce: [sysyx.exe] C:\WINDOWS\system32\sysyx.exe
O4 - HKLM\..\RunOnce: [atlul.exe] C:\WINDOWS\atlul.exe
O4 - HKLM\..\RunOnce: [mszf32.exe] C:\WINDOWS\mszf32.exe
O4 - Startup: Palm Desktop.lnk = C:\Program Files\Palm\palm.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\update.exe
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/tech...a/SymAData.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/tech...ActiveData.cab
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\netgt.exe" /s (file missing)


End of KRC HijackThis Analyzer Log.
====================================================================

Last edited by old hickory; 07-15-2005 at 01:48 PM.
old hickory is offline  
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here