Ok. here is what I've done so far. I hope I haven't made this much worse than it was initially.
It started when I obtained a program called Antivirus Gold form the web, and not by choice. I removed this with the help of I post i found through a google search. in the process I ran hijackthis, ad-aware, spybot S&D, cwshredder, aboutbuster5, killbox, installed ewido security suite, and repaired IE6 via system file checker (sfc /scannow in the run box). The AV gold is gone but the about
:blank remains. Here are the logs I Just ran for hijack this and ewido
Logfile of HijackThis v1.99.1
Scan saved at 5:16:42 PM, on 7/5/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINNT\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\brsvc01a.exe
C:\WINNT\System32\brss01a.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\wanmpsvc.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\valve\steam\steam.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
C:\Program Files\3M\PSN2Lite\Psn2Lite.exe
C:\Program Files\PrintKey2000\Printkey2000.exe
C:\PROGRA~1\3M\PSN2Lite\PSNGive.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\ewido\security suite\securitysuite.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\James Snow\Desktop\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\jplug.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\jplug.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about
:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\jplug.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\jplug.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\jplug.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\jplug.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\jplug.dll/sp.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {3A3A2001-B541-3D27-89C0-16CDF8212342} - C:\WINNT\system32\winjg32.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckOD Ls
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKLM\..\Run: [mfcxk.exe] C:\WINNT\system32\mfcxk.exe
O4 - HKLM\..\Run: [javaxa32.exe] C:\WINNT\javaxa32.exe
O4 - HKLM\..\Run: [d3my.exe] C:\WINNT\system32\d3my.exe
O4 - HKLM\..\Run: [atlis32.exe] C:\WINNT\system32\atlis32.exe
O4 - HKLM\..\Run: [sdknk.exe] C:\WINNT\system32\sdknk.exe
O4 - HKLM\..\Run: [mfczr32.exe] C:\WINNT\mfczr32.exe
O4 - HKLM\..\Run: [winjg32.exe] C:\WINNT\system32\winjg32.exe
O4 - HKLM\..\Run: [crpo.exe] C:\WINNT\crpo.exe
O4 - HKLM\..\Run: [javanh.exe] C:\WINNT\system32\javanh.exe
O4 - HKLM\..\Run: [sdkvk32.exe] C:\WINNT\sdkvk32.exe
O4 - HKLM\..\Run: [apiqs.exe] C:\WINNT\apiqs.exe
O4 - HKLM\..\Run: [syskj32.exe] C:\WINNT\system32\syskj32.exe
O4 - HKLM\..\Run: [addve32.exe] C:\WINNT\addve32.exe
O4 - HKLM\..\Run: [netjv.exe] C:\WINNT\system32\netjv.exe
O4 - HKLM\..\Run: [ntti32.exe] C:\WINNT\ntti32.exe
O4 - HKLM\..\Run: [sysun.exe] C:\WINNT\sysun.exe
O4 - HKLM\..\RunOnce: [mfcuo.exe] C:\WINNT\mfcuo.exe
O4 - HKLM\..\RunOnce: [winku.exe] C:\WINNT\winku.exe
O4 - HKLM\..\RunOnce: [apixm.exe] C:\WINNT\system32\apixm.exe
O4 - HKLM\..\RunOnce: [mfctb32.exe] C:\WINNT\system32\mfctb32.exe
O4 - HKLM\..\RunOnce: [d3rs.exe] C:\WINNT\d3rs.exe
O4 - HKLM\..\RunOnce: [addhf.exe] C:\WINNT\addhf.exe
O4 - HKLM\..\RunOnce: [winvu.exe] C:\WINNT\winvu.exe
O4 - HKLM\..\RunOnce: [mfcyn32.exe] C:\WINNT\mfcyn32.exe
O4 - HKLM\..\RunOnce: [apicf.exe] C:\WINNT\apicf.exe
O4 - HKLM\..\RunOnce: [winsv.exe] C:\WINNT\system32\winsv.exe
O4 - HKLM\..\RunOnce: [apiua.exe] C:\WINNT\apiua.exe
O4 - HKLM\..\RunOnce: [msbu32.exe] C:\WINNT\msbu32.exe
O4 - HKLM\..\RunOnce: [iesl.exe] C:\WINNT\iesl.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [Steam] "c:\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Startup: PowerReg SchedulerV2.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
O4 - Global Startup: Image Transfer.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSN2Lite\Psn2Lite.exe
O4 - Global Startup: Printkey2000.lnk = C:\Program Files\PrintKey2000\Printkey2000.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) -
http://www.alternatiff.com/install/00/alttiff.cab
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) -
http://www.stonyfield.com/coupons/scriptX/smsx.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?link...67&clcid=0x409
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
http://207.188.7.150/03827e2b2a8ca20...p/RdxIE601.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} -
http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe
O16 - DPF: {69432678-2906-2705-1128-068943397621} -
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) -
http://games-dl.real.com/gameconsole...rcadeRdxIE.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C566096D-79E8-4998-9C69-379FF4F0702D}: NameServer = 63.240.76.19,204.127.198.19
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINNT\System32\brsvc01a.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINNT\wanmpsvc.exe
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 5:15:52 PM, 7/5/2005
+ Report-Checksum: 8EF6BC4E
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{0AA0087A-593D-F517-11A6-C2CC0A729D7B} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uni nstall\SE -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uni nstall\SW -> Spyware.CoolWebSearch : Cleaned with backup
C:\Documents and Settings\James Snow\Cookies\james snow@adopt.specificclick[2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\James Snow\Cookies\james snow@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\WINNT\addhf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\addjh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\apicf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\apidq32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINNT\apish32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\apiua.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\BRVIDEO.INI:eapur -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINNT\cdplayer.ini

gzzj -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINNT\d3rs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\d3ye32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\javakq.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINNT\jplug.dll -> Spyware.SearchPage : Cleaned with backup
C:\WINNT\mfcbt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\mfcvl32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINNT\mfcyn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\msbu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\ODBC.INI

twtn -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINNT\system32\addcj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\system32\apixm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\system32\crwj.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINNT\system32\iewu.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINNT\system32\javanf32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINNT\system32\lxwco.dll -> Spyware.SearchPage : Cleaned with backup
C:\WINNT\system32\mfcae.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINNT\system32\mfctb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\system32\sysdm.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINNT\system32\sysii32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINNT\system32\winsv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\UP9ASP.INI:yetggd -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\vbaddin.ini:zdlkh -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINNT\winku.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\winvu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\_default.pif:aeymh -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINNT\_default.pif:dfghuh -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINNT\_default.pif:idfyf -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINNT\_default.pif:iykgz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINNT\_default.pif:vbxqig -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\__delete_on_reboot__apiqs.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
::Report End
Please HELP!!!