Re: about:blank Internet Explorer Worm

From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 05/25/05

  • Next message: shuckie69: "Re: Backdoor.Lateda.C"
    Date: Tue, 24 May 2005 23:03:52 GMT
    
    

    From: "Ben Lord" <ben@NOSPAMbenlord.co.uk>

    | Hi
    |
    | I am running IE6 and everytime I go into it, it always comes up with
    | about:blank and www.startsearches.net as the default home page. I am unable
    | to change this.

    < HJT Log snipped >

    | Any suggestions as to what else I should do? I have run AdAware and it
    | cannot seem to shift it and I have tried removing the Registry entries
    | directly without success.
    |
    | Please help!!!
    |
    | Thanks
    | Ben
    |
    Donk
    Ben:

    Neither alt.comp.virus and microsoft.public.security.virus are the best place to post HJT
    Logs.

    However, a quick look revealed two items of interest...

    O4 - HKLM\..\Run: [Microsoft System Checkup] wnetmgr.exe
    Possible SDbot worm

    O4 - HKLM\..\Run: [NT Logging Service] syslog32.exe

    -------

    Dump the contents of the IE Temporary Internet Folder cache (TIF)
    Start --> Settings --> Control Panel --> Internet Options --> Delete Files

    Dump the contents of the Mozilla FireFox Cache { if you use FireFox }
    Tools --> Options --> Privacy --> Cache --> Clear

    Download CLEAN.EXE from the URL --
    http://www.ik-cs.com/programs/virtools/clean.exe

    It is a self-extracting ZIP file that contains the Kixtart Script Interpreter
    { http://kixtart.org Kixtart is CareWare } three batch files, two Kixtart scripts, two Link
    (.lnk) files and a PDF instruction file.

    GETFILES.BAT -- For downloading (FTP) the files needed to run the McAfee Command Line
    Scanner. You may have to disable your FireWall or allow FTP.EXE to go through your FireWall
    to allow the FTP utility to download the needed files

    CLEAN.BAT -- For running within Windows after running c:\mcafee\GetFiles.BAT. If you choose
    to scan again at a future date, run this batch file. It will automatically check the date
    of the McAfee DAT files and if it is a couple of days old, it will download (FTP) the latest
    signature files and install them before performing the scan.

    DOSCLEAN.BAT -- For use on a Win9x/ME PC or on a Win2K/WinXP PC that is using FAT32 after
    you have booted from an Emergency Boot Disk or DOS disk and have already executed;
    c:\mcafee\GetFiles.BAT from within Windows. DOS disk boot images can be obtained from;
    http://www.bootdisk.com/bootdisk.htm

    I need you to perform the following...

    Execute; CLEAN.EXE
    Choose; Unzip
    Choose; Close

    Execute; c:\mcafee\GetFiles.BAT
    { or Double-click on 'GetFiles Link' in c:\mcafee }

    Reboot the PC into Safe Mode [F8 key during boot]

    Shutdown as many applications as possible !
    It would also help for you to read - "How to perform a clean boot in Windows XP"
    http://support.microsoft.com/kb/310353

    Execute; c:\mcafee\CLEAN.BAT
    { or Double-click on 'Clean Link' in c:\mcafee }

    A final report in HTML format called C:\mcafee\ScanReport.HTML will be generated. At the
    end of the scan, it will be displayed in your browser (Opera, FireFox or Internet Explorer).
    It is suggested that you move the report out of c:\mcafee before performing another scan.
    It would be a good idea to scan in Safe Mode and in Normal Mode and save a copy of the HTML
    report for each session.

    * * * Please report back your results * * *

    -- 
    Dave
    http://www.claymania.com/removal-trojan-adware.html
    http://www.ik-cs.com/got-a-virus.htm
    

  • Next message: shuckie69: "Re: Backdoor.Lateda.C"

    Relevant Pages

    • Re: desktop with no icons
      ... I get the same symptoms booting to safe mode also. ... CLEAN.BAT -- For running within Windows after running c:\mcafee\GetFiles.BAT. ... you have booted from an Emergency Boot Disk or DOS disk and have already executed; ... Execute; CLEAN.EXE ...
      (microsoft.public.windowsxp.security_admin)
    • Re: win32mersting.B - How to remove?
      ... DOS disk boot images can be obtained from; ... Execute; CLEAN.EXE ... It is suggested that you move the report out of c:\mcafee before performing another scan. ... It would be a good idea to scan in Safe Mode and in Normal Mode and save a copy of the HTML ...
      (microsoft.public.security.virus)
    • Re: PGPcoder Trojan
      ... DOS disk boot images can be obtained from; ... Execute; CLEAN.EXE ... It is suggested that you move the report out of c:\mcafee before performing another scan. ... It would be a good idea to scan in Safe Mode and in Normal Mode and save a copy of the HTML ...
      (microsoft.public.security.virus)
    • Re: Trojan Horse
      ... Download and install Ad-aware SE ... DOS disk boot images can be obtained from; ... Execute; CLEAN.EXE ... It would be a good idea to scan in Safe Mode and in Normal Mode and save a copy of the HTML ...
      (microsoft.public.windowsupdate)
    • Re: Backdoor.Trojan virus
      ... | files infected with a Trojan virus, but was unable to quarantine or delete ... DOS disk boot images can be obtained from; ... Execute; CLEAN.EXE ... It is suggested that you move the report out of c:\mcafee before performing another scan. ...
      (microsoft.public.windowsxp.security_admin)