Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
Hi (again)...for a couple weeks, I've been beseiged by hijacks of the 'about:blank' home page redirect variety. I've managed to cleanse my system many times lately, via CWShredder, Spybot, Hijack This, Registry first aid, etc etc. I also use the firewall and antivirus at all times.
HOWEVER...I've got a redirect now that is so bloody tenacious...I have run, this morning alone, all the above programs many times, rebooted, and I still have the redirect. The problem seems to centre around one .dll in my Windows\system folder...I can't erase it manually because, of course, Windows is using it.
This is getting so very frustrating, and I work at home on this comp, so even more so! I can't seem to find a solution this time. Of interest also, I can clean the system before I shut down for the night, and the next day, it all comes back. Any ideas? Please help!
Thanks in advance
Jon

goto control panel...then to systems click on performence....file system then troubleshooting then check disable restore system and restart......you should be able to deleat the file in question as windows shouldnt be using it. after you have run through all you virus programs (sorry i know u already have done but do it just to make sure) go back to system in control panel and uncheck the system restore and re-boot. hope this works as ive learnt a few niffty tricks from the guys who use this forum...they are really great!!!! linda x
i have the downloader swizzor trojan on my pc, i cannot access my documents or anything other than programs i have put there, eg anti virus ect. ive done all the usuall checks and i have chased the tr

Thanks for the attempt, Linda, but no go. This one is totally baffling me. I can't eliminate the .dll in windows, and it is the one cited in Hijack This that runs rampant in various capacities. Each time I clean with Adaware, Hijack This, Trojan Remover, and CWShredder, it says clean, and I can see no further culprits. On reboot, it's back.
The .dll in my Windows/system folder that is cited in Hijack This is "kcabgaa.dll", says created this a.m. but I can't get rid of it as Windows is using it.
Please, any more insight?
Thanks!
Jon

Hi Jon, Linda, hello everyone
Jon,
Post your hijackthis log for us to take a look at.
Best Regards,
Mesich

Mesich: I am grateful to see you! I have checked out your other fixes with other people. Remember, all the wrongful entries below have been cleansed dozens of times. It is something that refreshes, that seems to reinstall the problem. The .dll file named "KCABGAA.DLL" cannot be erased from the Windows System folder, it states created today. I am hoping to slay this beast, and your help is appreciated.
Running processes:
C:\WINDOWS.002\SYSTEM\KERNEL32.DLL
C:\WINDOWS.002\SYSTEM\MSGSRV32.exe
C:\WINDOWS.002\SYSTEM\mmtask.tsk
C:\WINDOWS.002\SYSTEM\MPREXE.exe
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.exe
C:\PROGRAM FILES\NORTON PERSONAL FIREWALL\NISUM.exe
C:\PROGRAM FILES\NORTON PERSONAL FIREWALL\CCPXYSVC.exe
C:\WINDOWS.002\SYSTEM\STIMON.exe
C:\PROGRAM FILES\NORTON ANTIVIRUS\ADVTOOLS\NPROTECT.exe
C:\WINDOWS.002\SYSTEM\MSTASK.exe
C:\WINDOWS.002\SYSTEM\RESTORE\STMGR.exe
C:\WINDOWS.002\EXPLORER.exe
C:\WINDOWS.002\TASKMON.exe
C:\WINDOWS.002\SYSTEM\SYSTRAY.exe
C:\WINDOWS.002\LOADQM.exe
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.exe
C:\WINDOWS.002\SYSTEM\LVCOMS.exe
C:\WINDOWS.002\SYSTEM\WMIEXE.exe
C:\PROGRAM FILES\WINDOWS MEDIA COMPONENTS\ENCODER\WMENCAGT.exe
C:\WINDOWS.002\SYSTEM\PSTORES.exe
C:\WINDOWS.002\SYSTEM\SPOOL32.exe
C:\WINDOWS.002\SYSTEM\DDHELP.exe
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.exe
C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS.002\SYSTEM\KCABGAA.DLL/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS.002\SYSTEM\KCABGAA.DLL/sp.html (obfuscated)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS.002\SYSTEM\KCABGAA.DLL/sp.html (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS.002\SYSTEM\KCABGAA.DLL/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS.002\SYSTEM\KCABGAA.DLL/sp.html (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS.002\SYSTEM\KCABGAA.DLL/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main\,HomeOldSP = about:blank
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\ACROBAT\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {2B2AA4D2-59B8-4DCB-A69F-839E0AFEB04E} - C:\WINDOWS.002\SYSTEM\KCABGAA.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS.002\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS.002\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [LVComs] C:\WINDOWS.002\SYSTEM\LVComS.exe
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\ADVTOOLS\ADVCHK.exe
O4 - HKLM\..\Run: [NPROTECT] C:\PROGRA~1\NORTON~1\ADVTOOLS\NPROTECT.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS.002\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [ccEvtMgr] C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O4 - HKLM\..\RunServices: [Nisum] C:\Program Files\Norton Personal Firewall\NISUM.exe
O4 - HKLM\..\RunServices: [ccPxySvc] C:\PROGRA~1\NORTON~2\CCPXYSVC.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS.002\SYSTEM\STIMON.exe
O4 - HKLM\..\RunServices: [NPROTECT] C:\PROGRA~1\NORTON~1\ADVTOOLS\NPROTECT.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - Startup: Encoder Agent.lnk = C:\Program Files\Windows Media Components\Encoder\WMENCAGT.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.exe
O4 - Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37881.4912268519
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {C4847596-972C-11D0-9567-00A0C9273C2A} (Crystal Report Viewer Control) - https://secure.equinoxfinancial.ca/viewer/activeXViewer/activexviewer.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cabThanks!
Jon

Hi Jon, hello everyone
I'm not highly confident that this will take care of everything but let's give it a go anyway. It certainly won't hurt, too much anyway. :-)
Remove these items using hijackthis and then restart the computer.
Post back with a new log after doing such.
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS.002\SYSTEM\KCABGAA.DLL/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS.002\SYSTEM\KCABGAA.DLL/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS.002\SYSTEM\KCABGAA.DLL/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS.002\SYSTEM\KCABGAA.DLL/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS.002\SYSTEM\KCABGAA.DLL/sp.html (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS.002\SYSTEM\KCABGAA.DLL/sp.html (obfuscated)
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {2B2AA4D2-59B8-4DCB-A69F-839E0AFEB04E} - C:\WINDOWS.002\SYSTEM\KCABGAA.DLL
Best Regards,
Mesich

Hi again: Here is the log after cleaning up. Note that so far, all remains status quo, with the 'about:blank'redirect still there, and I would imagine, the log in hijack this would look like the pre-cleaned state if I ran it again.
Running processes:
C:\WINDOWS.002\SYSTEM\KERNEL32.DLL
C:\WINDOWS.002\SYSTEM\MSGSRV32.exe
C:\WINDOWS.002\SYSTEM\mmtask.tsk
C:\WINDOWS.002\SYSTEM\MPREXE.exe
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.exe
C:\PROGRAM FILES\NORTON PERSONAL FIREWALL\NISUM.exe
C:\PROGRAM FILES\NORTON PERSONAL FIREWALL\CCPXYSVC.exe
C:\WINDOWS.002\SYSTEM\STIMON.exe
C:\PROGRAM FILES\NORTON ANTIVIRUS\ADVTOOLS\NPROTECT.exe
C:\WINDOWS.002\SYSTEM\MSTASK.exe
C:\WINDOWS.002\SYSTEM\RESTORE\STMGR.exe
C:\WINDOWS.002\EXPLORER.exe
C:\WINDOWS.002\TASKMON.exe
C:\WINDOWS.002\SYSTEM\SYSTRAY.exe
C:\WINDOWS.002\LOADQM.exe
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.exe
C:\WINDOWS.002\SYSTEM\LVCOMS.exe
C:\WINDOWS.002\SYSTEM\WMIEXE.exe
C:\PROGRAM FILES\WINDOWS MEDIA COMPONENTS\ENCODER\WMENCAGT.exe
C:\WINDOWS.002\SYSTEM\PSTORES.exe
C:\WINDOWS.002\SYSTEM\SPOOL32.exe
C:\WINDOWS.002\SYSTEM\DDHELP.exe
C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.exeO2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\ACROBAT\ACTIVEX\ACROIEHELPER.OCX
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS.002\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS.002\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [LVComs] C:\WINDOWS.002\SYSTEM\LVComS.exe
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\ADVTOOLS\ADVCHK.exe
O4 - HKLM\..\Run: [NPROTECT] C:\PROGRA~1\NORTON~1\ADVTOOLS\NPROTECT.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS.002\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [ccEvtMgr] C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O4 - HKLM\..\RunServices: [Nisum] C:\Program Files\Norton Personal Firewall\NISUM.exe
O4 - HKLM\..\RunServices: [ccPxySvc] C:\PROGRA~1\NORTON~2\CCPXYSVC.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS.002\SYSTEM\STIMON.exe
O4 - HKLM\..\RunServices: [NPROTECT] C:\PROGRA~1\NORTON~1\ADVTOOLS\NPROTECT.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - Startup: Encoder Agent.lnk = C:\Program Files\Windows Media Components\Encoder\WMENCAGT.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.exe
O4 - Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37881.4912268519
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {C4847596-972C-11D0-9567-00A0C9273C2A} (Crystal Report Viewer Control) - https://secure.equinoxfinancial.ca/viewer/activeXViewer/activexviewer.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cabAny further ideas? Thanks!
Jon

That's what I just got as well mesich.
You godda stand, cheer and admire Norton though :) 0_o

Hi Jon, hello everyone
Jon,
Your log is clean as it stands.
When is Internet Explorer being redirected to About Blank?
Best Regards,
Mesich

Hi Viking, Jon, hello everyone
I think I am lost at what exactly the problem is, as the log is clean and shows no redirects. Might need a simpliar explaination for my old, tiring mind. :-)
Best Regards,
Mesich

The problem began a few days ago. I've had the redirect before that makes my home page 'about:blank' several times, but each time the various tools cleaned it up, and it stayed cleaned up. This time, the payload of the infection seems tougher to get rid of. For instance, even if I clean at night before shutting down, the next morning, the redirect is back, along with the dirty log for hijack this. Adaware, spybot, cwshredder, and ht have always been able to remove the problem before. Each time, the file that infected the system had a different name. This one corresponds to a particular .dll in windows/system. Again, each time I reboot. the problem resurfaces. That is what is so frustrating about it. The system seems clean, but the problem persists!
Thanks again
Jon

Hello everyone,
Jon,
Pardon me for not being able to understand exactly whats going on, sometimes it's just not all so clear when communicating via the keyboard. :-)Are you having the problem right now, with the clean log?
Do a search on the computer for a file named sp.reg. Let us know if it exist.
I understand you have an Antivirus program installed but also recommend you perform an on-line scan here
.Is your Spybot up to date? It should be looking for 12,481 different parasites.
Best Regards,
Mesich

Hi again: The problem only is cured for the moment after fixing via hijack this. As soon as the computer reboots, or a browser is opened, it happens again. I did not locate the file 'sp.reg'. I have tried an online scan at Housecall, but I get an error...strange eh? My spybot may not be totally up to date, mind you. Any idea why I can't perform the online scan at Trendmicro? Also, I hope it's a bit clearer as to what is wrong. Again, as soon as I clean, the problem reappears with reboot or reopening a browser. Other, previous redirects did not do this.
Thanks!
Jon

Jon,
Try a different scan at Panda Active Scan. See what happens there. Housecall can sometimes not play ball, although it'd be interesting to hear what the error message was.

Hello everyone,
Viking,
Thanks for jumping in. I have some other ideas but would like to first get an on-line scan done, Panda sounds good to me. :-)
Jon,
Yes, I have done a refresh on the ol' memory and am good to go. :-)
Thanks for the assistance in helping clear out the cobwebs. :-)
Best Regards,
Mesich

I am performing the Panda scan now...thanks for the recommendation. I will post the results.
In the meantime, the error message at Housecall is a generic windows error, the one where it states would you like to send a report, and/or restart IE.
I am still baffled as to the redirect, but will keep plugging away and all further opinions are welcome!
Thanks
Jon

sorry it's taking so long with Panda...but 100K files takes a bit of time! Care to pass the time with your alternate thoughts as to what it could be? No infection yet, 50% done...
thanks!
Jon

See what the scan comes up with first and then a scan with a fully updated Spybot S&D and AdAware.
It could well be a (new) CWS variant. I'd also do a search for files and folders and search for KCABGAA.DLL and then I'd right click it and open it with notepad or a hex editor and see if there is any recognisable English in it, no matter how small. Your looking for clues.
You already have full, real time, virus scanning protection on. But that's just me.

Hi Viking: I am not sure how to do the notepad thingie you mentioned...all I know is this is the most tenacious hijack I've ever had. The Panda Active Scan is making progress, and does indicate 2 infections...do I get a report after the scan is done? I am surprised my Norton which is updated innumerable times daily didn't catch anything?
I've played cat and mouse with this issue for a couple days, and it's frustrating to see the cleansed issues reappear.
I'll post when the scan is done, thanks again.
Jon

Yep, Panda asks you if you want to auto disinfect somewhere along the line. Before you do write all the details down of the infections, that's important. So you can double check the virus/trojan details and see if any aditional reg editing is needed.
See what the disinfection gives you before trying opening that dll in notepad. Sort that out after if it's needed.

Hi Viking (and Mesich if you are still around)...I hope one of you will be around for a bit, I know this issue can be resolved, but it will take the proper steps. I can't believe, though, that constant and repeated Adaware, CWshredder, Spybot, Hijack this and Registry First Aid scans and fixes have done little to improve the matter. The dirty logs in Hijack this all correspond to that pesky .dll in Windows system folder (KCABGAA.DLL), which claims Browser Helper Objects and more...I can't manually delete it though...as Windows is using it?
Hmmm...

Hi Jon, Viking, hello everyone
I'm still around and will be. :-)
What was the final results of the Panda scan?
Best Regards,
Mesich

Hi Mesich: Panda scan is about 75% done, with 2 alleged infections so far, albeit ones that Norton with updated definitions didn't seem to find (???what's up with that?). I am patiently waiting for the results, and as per Viking's advice, will be writing them down prior to disinfecting. I wonder if the .dll in the Windows folder is itself a virus? But why would Norton not find it? And we still want to know why the redirects after cleansing the system.
Hold tight, I'll post when it's done.
Jon

Hello Jon, mesich, viking,
Might find this, a interesting read. As the others, on that page.
Good Luck,

Argh...this web page finally froze, and thusly shutting down also killed the Panda Scan, but I am rescanning, and it seems to be moving at a better speed this time (rescan?...thusly I am needing to be patient again, and I'm hoping one of you can stay along for the ride. Again, upwards of 80% scanned, two alleged infections, identity pending!
Thanks again for all the help, but I ain't done yet!
Jon

I've read the Merjin.org page before, I have located the .dll file in the system folder, but so far I've been unable to delete because Windows is using it apparently. I hope that after the scan, and the cleanse, I can get rid of this sucker.
Jon
p.s. hope this is still a matter of interest for you helpful souls!

Hello everyone,
Jon,
I'm still around, not going anywhere for a while. :-)
Let us know how it comes out.
CrazyOne,
Very nice link. The information provided shall be very useful in the near future if not the present. :-)
Always good to hear from you, hope everything is well with you and yours.
Best Regards,
Mesich

Hello everyone,
Jon,
Let's wait for the results of the scanner.
I'm not one to give up, nor is Vicking, or CrazyOne. :-)
Best Regards,
Mesich

Jon, I think about:blank can be removed in ME by dowloading and updating Ad-aware 6.0 then configure to these setting:
Make sure the following settings are made and on -------"ON=GREEN"
From main window :Click "Start" then " Activate in-depth scan"Click "Use custom scanning options>Customize" and have these options on: "Scan within archives" ,"Scan active processes","Scan registry", "Deep scan registry" ,"Scan my IE Favorites for banned URL" and "Scan my host-files"
Go to settings(the gear on top of AdAware)>Tweak>Scanning engine and tick "Unload recognized processes during scanning" and "Let windows remove files in use at next reboot" click "proceed" to save your settings.
Run a HT scan and remove the new about blank items.
Reboot the computer to safe mode and run AD-aware(From safe mode).
When scan is finished mark everything for removal and get rid of it including quarintined items. Restart the computer in normal mode.

Thanks, I have printed that off and will digest it...I haven't used safe mode for over a year (how do access again? f8 at boot?)
I will attempt that fix, but shall I first let the Panda Scan finish? It is about 65% there...
2 alleged infections, unknown at this time, found.
Thanks for hanging around, all.

Just concentrate on what your doing and what you've got so far Jon. You have enough on your plate at the moment, so don't start getting distracted :) ..leave AdAware settings and details till you need them ...later.
Let the scan finish and leave the results here, someone will be around to go through it. If not leave it over night and I'll check back in tomorrow morning.

If you think deleting that DLL in the WINDOW.002 folder will help or solve your problem, then make a Windows ME Startup boot diskette (Control Panel, Add/Remove Programs, Startup disk tab). Use it to boot your system to the DOS A: prompt. Then CD to the WINDOWS.002 directory, locate the DLL and DEL the file using DOS commands.
However, something is loading that DLL and you need to find out what is doing it.
Some of your comments and problems make me suspect that the WININIT.exe file in the Windows.002 folder is missing or corrupted. Make sure a clean copy of WININIT.exe with the 06-08-00 date is there (it is what drives the deleting of active system files when your reboot). After booting but before running and cleaning programs, look and see if there is a copy of the WININIT.INI file in the Windows.002 folder. If there is, then delete WININIT.INI and WININIT.BAK files (not WININIT.EXE), and then reboot. If necessary, Extract a clean copy of WININIT.exe from the system CAB files.
(The next time you reinstall Windows ME over the top of itself, be sure to set the install folder back to C:\WINDOWS so that you are using the default folder name instead of WINDOWS.002 or WINDOWS.003. Then you can delete the extra copy of the Windows system folder.)

Well, here it is morning (where I am), and the scan is still going (!)...up to 126K files now, still the 2 alleged infections, i.d. still unknown. I am anxious to find out what the infections were. I am also going to check into the file as per Jack's advice above. If any of yesterday's altruistic individuals are still kicking around for the finale of the show, I'd as always appreciate the added ideas!
I'll keep you posted.
Thanks as always
Jon

Scan results are in, and I hope nobody is disappointed! Seems that Panda would not cleanse the two files, and they are in fact in my Hijack This backups...specifically it claims the files are 'Trojan, Startpage DI', and their location is, again, in my JT backup files. However, it did not indicate that the .dll in my Windows/System folder, recall, 'kcabgaa.dll' was a problem, although that is the .dll cited in Hijack This as being the cause of all the problems, and which I can erase thru HT but then reloads each boot or browser opening. Recall, I also could not delete that .dll manually in the folder.
Any further ideas? Will getting rid of the two HT backup files manually remove the alleged infections indicated in Panda?
Thanks!
Jon

Here's a quick plan ...man. May's well be thorough (ish)
1) Finish your scan, jot the details down, disinfect whatever it is that's there, post the names of the infections.
2) Run fully updated versions of adaware and spybot, using the setup details you got for adaware. Clean whatever is there.
Also use the latest CWS shredder.
3) Go find KCABGAA.DLL and put your cursor over it and right click it, In the menu, select "open" or "open with" and choose Notepad -- but making sure that the little check box at the bottom, that says "always open with this" (paraphrase) does NOT have a check in it.
(If it won't let you open it try doing it in safe mode.)
When Notepad is open look through it all and look for any English words, or vague sentences in English. If you find some, post them at the same time as the virus/trojan details. Close Notepad.
4) Now follow JackG's post.
Right, where does that now leave you ?

You posted before me. The rest still applies, at least you know you aren't infected with something else.

As per Jack's post, I have the following in Windows.002:
WININIT.BAK has a date of 08-06-2004
WININIT.EXE has a date of 08-06-2000 (coincidence or what)
WININIT.SAV has a date of 19-11-2003
wininitlog.old has a date of 08-06-2004.Now, I'm proficient enough for the macro stuff, but I don't know how to extact from system CAB files, nor am I confident in deleting those files with the recent date! I am now going to do some other scanning, as advised above, but feel just as 'quagmired' as before!
Thanks
Jon

as an added interest piece, if you look above at the 'english' headings in the notepad results, I believe the english headings are the ones you find on the about:blank search page.
I wish I could delete that file!

Hi Mesich: As I have not needed to access via safe mode for over a year, please give indication of how I do that? Is it toggle F8 at startup? Did the guts of the .dll file above lead you to this conclusion? Thanks as always, I look forward to further advice. I have also run an updated version of Spybot (1.3 vs. 1.1), and this got rid of some other matters, but not the pesky one we are dealing with.
Thanks
Jon

yep, F8 usually does the trick. After you've attempted to delete it in safe mode. Run CWShredder v1.59.0 -- http://209.133.47.12/~merijn/files/CWShredder.exe (download page link)
The dll info has gone, I meant for you to take the code out and leave the bulk of English. No worries though. We knew it shouldn't be there anyway. The crap that was inside it just confirmed it.

Hi Viking...very odd...in safe mode, the suspect .dll was gone...now back in regular mode, and searching in Windows/System, the .dll is still gone. I have no idea what scrubbed it, maybe the 1.3 Spybot?
You know the totally bizarre thing about that .dll? All the other hijacks I had, which were similar, could be cleaned INCLUDING the suspect .dll file, with an Adaware scan. This one, however, didn't allow for it, and in fact, an Adaware scan did NOT show it as being something to remove, although as you now know, the Hijack This scan was screaming it out to us.
So...can I assume it is remedied (for now?) My home page is my home page again, FYI.
Thanks for all the time, info, help, advice, etc etc...Each time I get screwed by some corruption, it adds to my knowledge base too!
Thanks people...I'll post again in a new thread if the problem seems to persist.
Jon

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |