1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

About:blank snafu - HJT Logfile enclosed

Discussion in 'Malware and Virus Removal Archive' started by charlie_c, 2005/02/03.

Thread Status:
Not open for further replies.
  1. 2005/02/03
    charlie_c

    charlie_c Inactive Thread Starter

    Joined:
    2004/03/11
    Messages:
    107
    Likes Received:
    0
    I downloaded some sort of Trojan.StartPage hijacker virus - not only does it always show a "search page" as start page - a NAV Alert says "Norton AV has successfully removed the following C:\windows\TEMP\sp.dll and it is ok to start your computer. But when you click "finish" it starts the hijacked page. This NAV notice appears after clicking on any new application. This start page and it's pop-up spyware ads continually interupt.
    Tried to do a virus scan - but NAV said an internal problem has occurred and to uninstall and reinstall NAV. Four attempts at an uninstall/reinstall failed with the same "internal problem..." error message. Apparently NAV has also been sabotaged.

    I tried to run RAV Virus scan online - but says Active-X is turned off.
    But I have security settings set to "default" - which is medium security. Either I somehow changed the settings - or something is wrong here. I feel that many files have been compromised.

    Later, I did get AVG installed. But after it deleted 3 Trojan.StartPage infected files, and I opened my browser - the start page was hijacked again. Also I ran Ad-Aware and it found 60 or so critical objects. But it looks like Ad-Aware gets hung-up before the "deleting files" scan bar finishes. I don't know for sure if these are actually deleted. I'm getting Active-X messages, missing .dll files, a search page for my homepage, pop-up ads for spyware removal and most bothersome - every time I open my Yahoo mail account the search page takes it over in about 2 seconds. I never get a chance to click on "inbox" or anything. It may fill up and start bouncing before I get into the account. I can log into Yahoo groups OK - but every time I click on email this damm page takes over. Now I see the “about: blank” search page when I try to post or reply or send an email from MSN Groups. I have put 5-6 hours into this problem - including Norton's precise detailed instructions for the error codes given. Every time I reinstalled NAV - it gave an internal error message.
    Can't understand this virus. It's dated 2002. I have auto update for NAV data files. I got an update last Wed. and another Friday, I think. I ran the NAV scan on the computer later Friday night - and picked this Trojan up later that same night! This fix was not supposed to be that difficult - according to Norton's site. It must hase been modified to deliver this Trojan.
    I'm limping along for the meantime – waiting to see what becomes disabled next.
    I need a helping hand. HJT Logfile below.
    Thanks,
    Charlie

    --------------------------------HJT Logfile---------------------------
    Logfile of HijackThis v1.99.0
    Scan saved at 3:17:55 PM, on 2/3/05
    Platform: Windows 98 SE (Win9x 4.10.2222A)
    MSIE: Internet Explorer v5.51 SP2 (5.51.4807.2300)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\EXPLORER.EXE
    C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
    C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
    C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
    C:\PROGRAM FILES\JUNO\EXEC.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
    C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
    C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
    C:\WINDOWS\NOTEPAD.EXE
    C:\PROGRAM FILES\NETZERO\EXEC.EXE
    C:\WINDOWS\SYSTEM\RNAAPP.EXE
    C:\WINDOWS\SYSTEM\TAPISRV.EXE
    C:\PROGRAM FILES\NETZERO\EXEC.EXE
    C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\WINWORD.EXE
    C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
    C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\WINWORD.EXE
    C:\WINDOWS\MSAGENT\AGENTSVR.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\PROGRAM FILES\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://c:\windows\TEMP\sp.dll/sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://my.juno.com/s/search?r=minisearch
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://c:\windows\TEMP\sp.dll/sp.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.juno.com/s/search?r=minisearch
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://my.netzero.net/s/sp?r=al&cf=...400000&I=7.NQ2&L=g#10&M=965199600000&N=PL&O=A
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
    R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\PROGRAM FILES\JUSEARCH\SEARCHENH1.DLL
    O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_12_0.DLL
    O2 - BHO: (no name) - {C8C92BA1-7308-11D9-8879-000EF77AF625} - C:\WINDOWS\SYSTEM\FDAB.DLL
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: ZeroBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\PROGRAM FILES\NETZERO\TOOLBAR.DLL
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_12_0.DLL
    O3 - Toolbar: JunoBar - {5854FAC4-5BF0-47DD-B5A9-A5EA8CFF3CF4} - C:\PROGRAM FILES\JUNO\TOOLBAR.DLL
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
    O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
    O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
    O4 - HKCU\..\Run: [NetZero_uoltray] C:\PROGRAM FILES\NETZERO\EXEC.EXE regrun
    O4 - HKCU\..\Run: [Juno_uoltray] C:\PROGRAM FILES\JUNO\EXEC.EXE regrun
    O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0411.DLL
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0411.DLL
    O9 - Extra button: eBay - Homepage - {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A} - C:\Program Files\IrfanView\Ebay\Ebay.htm
    O9 - Extra button: ComcastHSI - {FEB0B8A0-720F-11D8-8879-0030BD0023D9} - http://www.comcast.net (file missing) (HKCU)
    O9 - Extra button: Help - {FEB0B8A1-720F-11D8-8879-0030BD0023D9} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
    O9 - Extra button: Support - {FEB0B8A2-720F-11D8-8879-0030BD0023D9} - http://www.comcastsupport.com (file missing) (HKCU)
    O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
    O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dll
    O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
    O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup152.cab
    O16 - DPF: {768D513A-C75B-4FAA-8452-E906CDAB6545} (FVLiteLoad Class) - http://digitalflip.net/fvlite/fvliteY.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by5fd.bay5.hotmail.msn.com/resources/MsnPUpld.cab
    O16 - DPF: {9A54032D-31F7-400D-B184-83B33BDE65FA} (MSN File Upload Control) - http://sc.groups.msn.com/controls/FileUC/MsnUpld.cab
    O18 - Filter: text/html - {C8C92BA0-7308-11D9-8879-000E983653BE} - C:\WINDOWS\SYSTEM\FDAB.DLL
    O18 - Filter: text/plain - {C8C92BA0-7308-11D9-8879-000E983653BE} - C:\WINDOWS\SYSTEM\FDAB.DLL
     
  2. 2005/02/05
    ehffveeh

    ehffveeh Inactive

    Joined:
    2003/02/21
    Messages:
    1
    Likes Received:
    0
    About:Blank

    About:Blank, may be part of your problem.
    Try the following.

    Clean out the Trusted Sites in Internet Explorer. Click
    Tools>>Internet Options. Select the Security tab. Click Trusted Sites.
    Click Sites. Clean out everything and click OK>>OK.

    Then get
    About:Buster to get rid of
    About:Blank
    It can be found here....<http://www.majorgeeks.com/download4289.html>


    Good Luck.
     

  3. to hide this advert.

  4. 2005/02/06
    charlie_c

    charlie_c Inactive Thread Starter

    Joined:
    2004/03/11
    Messages:
    107
    Likes Received:
    0
    Sorry to say that nothing changed. There was nothing in the "Trusted Sites ". Updated AbtBuster, scanned twice - saved logfile & rebooted. Did this 3 times - and about:blank & a search page for my home page was waiting for me each time.
    They said if it didn't fix the problem to check their forum - but I think I want to stay here. Thanks ehffveeh, anyway.
     
  5. 2005/02/06
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    Download Pocket Killbox.version 2.0.0.76
    If you already have Killbox ensure it is this version
    Unzip the contents of KillBox.zip to a convenient location.

    Download CWShredder ,dont use it yet.

    Copy the list to notepad for later referance.

    Close all Browsers and programs that show in the windows taskbar
    Disconnect from the internet (unplug your modem or router from the computer).Close all Browsers and programs that show in the windows taskbar.

    Double-click on KillBox.exe.
    Click "Delete on Reboot"
    Copy/Paste this file into the top "Full Path of File to Delete" box.

    c:\windows\TEMP\sp.dll
    Click the "Delete File" button which looks like a stop sign.
    [8]Click "Yes" at the prompt.
    Do the same for this file
    C:\WINDOWS\SYSTEM\FDAB.DLL

    Install then run CWShredder Version 2.12 here (as of 1/9/2005) by Merijn Bellekom and run it, hit 'fix' as opposed to 'scan only'.


    Reboot when done, and post a fresh hijackthis log
     
  6. 2005/02/06
    charlie_c

    charlie_c Inactive Thread Starter

    Joined:
    2004/03/11
    Messages:
    107
    Likes Received:
    0
    Thanks Lonny,
    OK - Here it is. I see "about:blank" several places (some are "old" references) - fingers crossed.

    Logfile of HijackThis v1.99.0
    Scan saved at 4:40:53 PM, on 2/6/05
    Platform: Windows 98 SE (Win9x 4.10.2222A)
    MSIE: Internet Explorer v5.51 SP2 (5.51.4807.2300)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\EXPLORER.EXE
    C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
    C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
    C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
    C:\PROGRAM FILES\NETZERO\EXEC.EXE
    C:\PROGRAM FILES\JUNO\EXEC.EXE
    C:\WINDOWS\SYSTEM\RNAAPP.EXE
    C:\WINDOWS\SYSTEM\TAPISRV.EXE
    C:\PROGRAM FILES\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.juno.com/s/search?r=minisearch
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://my.netzero.net/s/sp?r=al&cf=...400000&I=7.NQ2&L=g#10&M=965199600000&N=PL&O=A
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
    R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\PROGRAM FILES\JUSEARCH\SEARCHENH1.DLL
    O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_12_0.DLL
    O2 - BHO: (no name) - {C8C92BA1-7308-11D9-8879-000EF77AF625} - C:\WINDOWS\SYSTEM\FDAB.DLL (file missing)
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: ZeroBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\PROGRAM FILES\NETZERO\TOOLBAR.DLL
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_12_0.DLL
    O3 - Toolbar: JunoBar - {5854FAC4-5BF0-47DD-B5A9-A5EA8CFF3CF4} - C:\PROGRAM FILES\JUNO\TOOLBAR.DLL
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\PROGRAM FILES\NETZERO\TOOLBAR.DLL
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
    O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
    O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
    O4 - HKCU\..\Run: [NetZero_uoltray] C:\PROGRAM FILES\NETZERO\EXEC.EXE regrun
    O4 - HKCU\..\Run: [Juno_uoltray] C:\PROGRAM FILES\JUNO\EXEC.EXE regrun
    O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0411.DLL
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0411.DLL
    O9 - Extra button: eBay - Homepage - {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A} - C:\Program Files\IrfanView\Ebay\Ebay.htm
    O9 - Extra button: ComcastHSI - {FEB0B8A0-720F-11D8-8879-0030BD0023D9} - http://www.comcast.net (file missing) (HKCU)
    O9 - Extra button: Help - {FEB0B8A1-720F-11D8-8879-0030BD0023D9} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
    O9 - Extra button: Support - {FEB0B8A2-720F-11D8-8879-0030BD0023D9} - http://www.comcastsupport.com (file missing) (HKCU)
    O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
    O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dll
    O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
    O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup152.cab
    O16 - DPF: {768D513A-C75B-4FAA-8452-E906CDAB6545} (FVLiteLoad Class) - http://digitalflip.net/fvlite/fvliteY.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by5fd.bay5.hotmail.msn.com/resources/MsnPUpld.cab
    O16 - DPF: {9A54032D-31F7-400D-B184-83B33BDE65FA} (MSN File Upload Control) - http://sc.groups.msn.com/controls/FileUC/MsnUpld.cab
    O18 - Filter: text/html - {C8C92BA0-7308-11D9-8879-000E983653BE} - C:\WINDOWS\SYSTEM\FDAB.DLL
    O18 - Filter: text/plain - {C8C92BA0-7308-11D9-8879-000E983653BE} - C:\WINDOWS\SYSTEM\FDAB.DLL
     
  7. 2005/02/06
    charlie_c

    charlie_c Inactive Thread Starter

    Joined:
    2004/03/11
    Messages:
    107
    Likes Received:
    0
    Update:

    Good news. Been fooling around while watching the Superbowl - seems like I can do everything w/o the search page and pop-ups. I have still to try to reinstall my NAV - where there was a missing .dll (if I remember). That is a paid subscription. I have AVG Free edition now. Not sure if this is good enough to keep. I may work on replacing NAV a little later.
    Thanks so much - you have been a great help. I appreciate your help - as well as everyone else gererously giving their own time here.

    Charlie
     
  8. 2005/02/06
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    While all browsers are closed run hijackths and fix these items
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    O2 - BHO: (no name) - {C8C92BA1-7308-11D9-8879-000EF77AF625} - C:\WINDOWS\SYSTEM\FDAB.DLL (file missing)
    O18 - Filter: text/html - {C8C92BA0-7308-11D9-8879-000E983653BE} - C:\WINDOWS\SYSTEM\FDAB.DLL
    O18 - Filter: text/plain - {C8C92BA0-7308-11D9-8879-000E983653BE} - C:\WINDOWS\SYSTEM\FDAB.DLL

    If Norton is uninstalled fix this also >
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    ===================================

    I recommend avgfree over norton any day :)

    Let us know of any problems
     
  9. 2005/02/08
    charlie_c

    charlie_c Inactive Thread Starter

    Joined:
    2004/03/11
    Messages:
    107
    Likes Received:
    0
    Not sure if a problem - but after uninstalling NAV and running HJT - the "o2 - NAV Helper..." entry was missing. I ran "fix" on the other 9 items.
    Do you need to see a new log?
     
  10. 2005/02/09
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    No, not unless there are problem's

    If all is ok now go change this >" "MSIE: Internet Explorer v5.51 SP2" "
    Go Get all available critical updates at windows update, it will take more than one trip, http://v4.windowsupdate.microsoft.com/en/default.asp
    Always restart the PC when prompted.


    Be sure to read our pinned topics in the security area.

    Regards
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.