Tech Support banner

Status
Not open for further replies.
1 - 16 of 16 Posts

·
Registered
Joined
·
6 Posts
Discussion Starter #1
Hi...I have an odd problem, something similar to the "Search Engine" thread posted earlier. However, in my case, whenever I go into http://www.google.com I don't get an error page, I just get the yellow letter 'o' (like in the Google name) on the top left hand of my screen - the rest of the screen is just blank/white. Even more bizarrely, when I use http://www.google.com.au I get the Greek flag (???!!!! ) at the top left hand of the screen. I'm completely confused, and I've just spent the past few hours searching the 'net, but I can't fix it!

I'm not very computer savvy, but I've run Ad-Aware, Spybot (fully updated), searched for the Qhost Trojan, looked at my HOSTS file (no reference to google.com anywhere), run a repair on IE6, and even downloaded a different browser (Crazy Browser). Nothing helps...nada!! I'm getting slightly poopy!!

This has only happened in the last day or so, and the only thing I can remember doing, is downloading and installing some Java2 thing (I had problems with Internet Banking, and they suggested I do that). I've now uninstalled it, but it hasn't changed anything.

Can anyone please help?

Many thanks,
Ulrika
 

·
Registered
Joined
·
113 Posts
Hi Ulrika

Please Download hijackthis from

http://tomcoyote.org/hjt

Unzip, doubleclick HijackThis.exe, and hit "Scan".

After the scan has finished the "scan" button will turn into a "save log" button

save the log file and paste it here

Do not delete anything yet, as most things hijackthis finds are harmless and needed.

steam
 

·
Registered
Joined
·
6 Posts
Discussion Starter #3 (Edited)
Hi steamwiz

Thanks for the reply, however it appear the problem may have fixed itself (??!). I just tried the Google sites again, and they're coming up as they should, no problems. The only thing I can think, is that one of the numerous things I did last night may have fixed it, but I probably didn't notice it then, b/c I didn't restart my computer after running Ad-ware, Spybot, changing browsers, etc...?

Thanks,
Ulrika
 

·
Registered
Joined
·
6 Posts
Discussion Starter #5
<sigh> I spoke too soon. The problem is back, except now instead of getting the Greek flag, I get the last 'gle' of Google, and the search arrow at the top left hand of my screen. Bugger!!

Ok, I ran HijackThis, and here is the log file:

Logfile of HijackThis v1.97.3
Scan saved at 6:37:29 PM, on 3/11/03
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\INTEL\WEBOUTFITTERTOOLKIT\STTRAY.EXE
C:\PROGRAM FILES\[email protected]\[email protected]
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\PANDA SOFTWARE\PANDA ANTIVIRUS TITANIUM\APVXDWIN.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZONEALARM.EXE
C:\PROGRAM FILES\IOMEGA\TOOLS\IOWATCH.EXE
C:\PROGRAM FILES\IOMEGA\TOOLS\IMGICON.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\PANDA SOFTWARE\PANDA ANTIVIRUS TITANIUM\PAVPROXY.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\WINRAR\WINRAR.EXE
C:\WINDOWS\TEMP\RAR$EX00.909\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.finetimesearch.com/index2.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.clickyestoenter.net/search.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.clickyestoenter.net/search.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.clickyestoenter.net/search.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.clickyestoenter.net/search.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.netscape.com/home/winsearch200.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [WebOutfitterTray] C:\Program Files\intel\WebOutfitterToolkit\sttray.exe
O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
O4 - HKLM\..\Run: [CriticalUpdate] C:\WINDOWS\SYSTEM\wucrtupd.exe -startup
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [seticlient] C:\Program Files\[email protected]\[email protected] -min
O4 - HKLM\..\Run: [mdac_runonce] C:\WINDOWS\SYSTEM\runonce.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus Titanium\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: Iomega Watch.lnk = C:\Program Files\Iomega\Tools\IOWATCH.EXE
O4 - Startup: Iomega Startup Options.lnk = C:\Program Files\Iomega\Tools\IMGSTART.EXE
O4 - Startup: Iomega Disk Icons.lnk = C:\Program Files\Iomega\Tools\IMGICON.EXE
O4 - Startup: Refresh.lnk = C:\Program Files\Iomega\Tools\REFRESH.EXE
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O8 - Extra context menu item: Open Frame in &New Window - C:\WINDOWS\WEB\frm2new.htm
O8 - Extra context menu item: &Highlight - C:\WINDOWS\WEB\highlight.htm
O8 - Extra context menu item: &Web Search - C:\WINDOWS\WEB\selsearch.htm
O8 - Extra context menu item: &Links List - C:\WINDOWS\WEB\urllist.htm
O8 - Extra context menu item: Zoom &In - C:\WINDOWS\WEB\zoomin.htm
O8 - Extra context menu item: Zoom O&ut - C:\WINDOWS\WEB\zoomout.htm
O8 - Extra context menu item: I&mages List - C:\WINDOWS\Web\imglist.htm
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Net2Phone (HKLM)
O9 - Extra 'Tools' menuitem: Net2Phone (HKLM)
O9 - Extra button: Wallpaper (HKLM)
O9 - Extra 'Tools' menuitem: &Toolbar Wallpaper (HKLM)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - http://office.microsoft.com/productupdates/content/opuc.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...apple.com/qt505/us/win/QuickTimeInstaller.exe
O16 - DPF: {CD17FAAA-17B4-4736-AAEF-436EDC304C8C} (ContentAuditX Control) - http://a840.g.akamai.net/7/840/5805...ch.com/audit/includes/ContentAuditControl.cab
O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_01) -
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37862.9399537037



Many thanks again,
Ulrika
 

·
Registered
Joined
·
5,955 Posts
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.finetimesearch.com/index2.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.clickyestoenter.net/search.htm

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.clickyestoenter.net/search.htm

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.clickyestoenter.net/search.htm

R1 - HKCU\Software\Microsoft\Internet
Explorer\Search,SearchAssistant = http://www.clickyestoenter.net/search.htm

O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...meInstaller.exe

O16 - DPF: {CD17FAAA-17B4-4736-AAEF-436EDC304C8C} (ContentAuditX Control) - http://a840.g.akamai.net/7/840/5805...uditControl.cab


Some hijackers and talk backers to fix here. Create a new HJT log, check each of these entries to be fixed. After, with all browser and explorer windows closed, tell HJT to fix them.

Reboot

Nothing got into your system files, so this should do it!

jgvernonco’s
recommended
security
software

Zonealarm Firewall (free edition) Zone Labs:

http://www.zonelabs.com/store/conte...reeDownload.jsp

Free antivirus software

http://www.avast.com/i_idt_153.html


Spyware blocking programs (free):

Spyware Blaster and Spyware Guard (the link will take you to the Blaster page. The menu bar at the top will take you to the Guard page. These two programs, written by the same developer, work hand-in-hand to protect you from invasions).

http://www.javacoolsoftware.com/spywareblaster.html


Spyware Killers (free)!

Spybot Search & Destroy

http://download.com.com/3000-2144-1...&tag=button

Adaware
Ad-aware - Software - Lavasoft

http://www.lavasoftusa.com/software/adaware/

I run both of these, as they occasionally find something that the other did not.

Additionally, Microsoft has made some poor choices about default settings in the OSs, resulting in multiple security weaknesses. Gibson Research has a number of little programs that will help you close security holes without having to edit your registry, wander My Computer, etc., just to get secure. I highly recommend this resource.

Gibson Research Corporation Home Page

http://grc.com/default.htm

The secret to running these programs is to update at least weekly! Update Adaware and Spybot before you run a scan every time. Don’t forget to update Blaster and Guard when you are doing your maintenance. Make sure the antivirus software us up-to-date. Put a note on your computer reminding you to do it!

Last, but not least, if you are a Microsoft user, update, update, update! Put it on your list! The only Trojan that ever made it through my security did not take me down because I was current on my security patches, which limited what the Trojan could do. (It was still a big pain, though). Most of you will have a Windows Update selection when you click “start”, but if you do not, here’s a link:

Microsoft Windows Update

http://v4.windowsupdate.microsoft.com/en/default.asp

Stay safe! Enjoy the WWW!
 

·
Registered
Joined
·
113 Posts
Fix these as well :-

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime


Not malicious - but not needed either

----
And this one......


WUCrtUpd.exe

This info from 'Answers That Work Task List Programs'
http://www.answersthatwork.com/Tasklist_pages/tasklist_w.htm
Wucrtupd WUCrtUpd.exe (Microsoft)

Windows Update Critical Update Notification. This will appear in your Task List if you did a Windows Update at some stage and installed the
"Critical Update Notification" component. In some versions this process is scheduled to run every 5 minutes and you cannot change the schedule (under Windows 98 you can get round it with the "sucrtupd" technique, but not under other versions of Windows).

Recommendation :
Do not walk, run to your "Add/Remove Programs" icon in the Control Panel and immediately de-install Microsoft Windows Critical Updates Notification.
The consequences of some Microsoft Critical Updates have been such that the last thing you need is something to remind you, and therefore entice you to update your Windows environment with the very latest bug fix (which is what critical updates really are) from Microsoft.
It is not just that some of those updates have been quite simply disastrous (remember May/June
2002 ?), it is also that too often for our liking, the full consequences of installing some of those updates are not always clearly spelt out by Microsoft. Yes, some of those updates are needed from a security point of view, but in 98% of cases if you either run a good firewall or your PC is configured securely, then you are
protected anyway, so do not fix what doesn’t need fixing. It is best that you simply do a Windows Update once every two or three months, say, and only at times when you do not require
your PC urgently in the following 24 hours ! Finally, quite aside from the above, WUCRTUPD is also sometimes responsible for illegal operations, 3-seconds mouse freezes, WULOADER error messages, and Invalid Page Faults in KERNEL32. Have we said enough ?

steam
 

·
Registered
Joined
·
6 Posts
Discussion Starter #8 (Edited)
Hi guys......I fixed those entries as suggested, and rebooted, but I'm still having the same problem with Google. :no:

Any other suggestions?

Thanks again,
Ulrika
 

·
Registered
Joined
·
113 Posts
Also try pasting these in your address bar

216.239.37.99

216.239.57.99

These should take you to google

steam
 

·
Registered
Joined
·
6 Posts
Discussion Starter #12
Hello,

Steam, the address I use for google is http://www.google.com or http://www.google.com.au

I tried http://www.google.co.uk and 216.239.37.99 and 216.239.57.99 and they all work. http://www.google.com/mac and http://www.google.com/ie also work; the only ones that don't are the ones that I always use (I use the .au one so I can search only within Australia).

jgvernonco, here follow another HJT log.

Logfile of HijackThis v1.97.3
Scan saved at 9:03:14 PM, on 5/11/03
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\INTEL\WEBOUTFITTERTOOLKIT\STTRAY.EXE
C:\PROGRAM FILES\[email protected]\[email protected]
C:\PROGRAM FILES\PANDA SOFTWARE\PANDA ANTIVIRUS TITANIUM\APVXDWIN.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZONEALARM.EXE
C:\PROGRAM FILES\IOMEGA\TOOLS\IOWATCH.EXE
C:\PROGRAM FILES\IOMEGA\TOOLS\IMGICON.EXE
C:\PROGRAM FILES\PANDA SOFTWARE\PANDA ANTIVIRUS TITANIUM\PAVPROXY.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\WINRAR\WINRAR.EXE
C:\WINDOWS\TEMP\RAR$EX00.990\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://216.239.57.99/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.netscape.com/home/winsearch200.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [WebOutfitterTray] C:\Program Files\intel\WebOutfitterToolkit\sttray.exe
O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [seticlient] C:\Program Files\[email protected]\[email protected] -min
O4 - HKLM\..\Run: [mdac_runonce] C:\WINDOWS\SYSTEM\runonce.exe
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus Titanium\APVXDWIN.EXE" /s
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: Iomega Watch.lnk = C:\Program Files\Iomega\Tools\IOWATCH.EXE
O4 - Startup: Iomega Startup Options.lnk = C:\Program Files\Iomega\Tools\IMGSTART.EXE
O4 - Startup: Iomega Disk Icons.lnk = C:\Program Files\Iomega\Tools\IMGICON.EXE
O4 - Startup: Refresh.lnk = C:\Program Files\Iomega\Tools\REFRESH.EXE
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O8 - Extra context menu item: Open Frame in &New Window - C:\WINDOWS\WEB\frm2new.htm
O8 - Extra context menu item: &Highlight - C:\WINDOWS\WEB\highlight.htm
O8 - Extra context menu item: &Web Search - C:\WINDOWS\WEB\selsearch.htm
O8 - Extra context menu item: &Links List - C:\WINDOWS\WEB\urllist.htm
O8 - Extra context menu item: Zoom &In - C:\WINDOWS\WEB\zoomin.htm
O8 - Extra context menu item: Zoom O&ut - C:\WINDOWS\WEB\zoomout.htm
O8 - Extra context menu item: I&mages List - C:\WINDOWS\Web\imglist.htm
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Net2Phone (HKLM)
O9 - Extra 'Tools' menuitem: Net2Phone (HKLM)
O9 - Extra button: Wallpaper (HKLM)
O9 - Extra 'Tools' menuitem: &Toolbar Wallpaper (HKLM)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - http://office.microsoft.com/productupdates/content/opuc.cab
O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_01) -
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37862.9399537037


Thanks once again,
Ulrika
 

·
Registered
Joined
·
113 Posts
Paste in 216.239.37.99

Once there - click "go to Google.com" - does it go here ?

while at Google, change the address in the address bar to .com.au - do you get Google.au ?

Also you say you have checked the Hosts file - do another search on your computer - you may have 2 or more hosts files.

steam
 

·
Registered
Joined
·
5,955 Posts
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://216.239.57.99/

O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A

The R0 entry is the start page setting for Google. Not this run, but perhaps the next, you might try having HJT fix this and then reset it afterward.

The 04 entry needs to be fixed. It is a leftover from the Purol.A worm (or one of it's cousins)

Open a new HJT log, check that 04 entry and, with all explorer and browser windows closed, tell HJT to fix it.

Reboot

Tell us the result (says with fingers crossed).
 

·
Registered
Joined
·
6 Posts
Discussion Starter #15
Hi,

jgvernonco, I fixed the 04 entry, rebooted, but still no joy... :no:

Steam, when I type 216.239.37.99 and "go to Google.com" I get the same problem (ie. the blank page with the 'gle' and the arrow on the top left of the screen); then when I change it to '.com.au' I get the same problem again (the blank page, with just the yellow 'o').

I also did another search for Hosts files. I only found one Hosts file, (but there were 2 other files in C:\WINDOWS called Hosts.sam, and Lmhosts.sam but when I opened them in Notepad it appeared to be like a 'Help' file on what a Hosts file is), and again couldn't find any reference to Google. I opened it in Notepad and did a search that way, b/c when I tried HostsFileReader.exe it crashed my computer. I tried it a couple of times, but gave up.

Thanks again,
Ulrika
 

·
Registered
Joined
·
113 Posts
Hi Ulrika

The hosts.sam files are sample files or "help files" as you say - ignore them, they're harmless

I always open up the hosts file in notepad, to view or edit.

A couple of more things to try :-

You may have a corrupt cookie - go to C:\WINDOWS\Cookies

Select view/details and delete any cookies for google

If that doesn't work - delete your temporary internet files - there may be a corrupt file in there.

good luck

steam
 
1 - 16 of 16 Posts
Status
Not open for further replies.
Top