Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old January 16th, 2005, 12:00 AM
sarment sarment is offline
Infrequent Poster
 
Join Date: Jul 2004
Posts: 27
Default about|blank home page hijacker

I had the about|blank on my son's computer last June (04). After MUCH research and effort I was able to remove it by basically following computer cops Ttime2Early's posting on May 22. (http://computercops.biz/postlite43426-blank.html) It went away.

His computer just got it again. (I can't believe that STILL Norton NAV & NIS, AdAware, Spybot, SpywareBlaster, and Trojan Hunter can't catch it coming in AND can't find it after the fact.)

I can't get rid of it by Ttime2Early's method because the "hidden" file does not have a name. The value on "applnit_dll" is blank (no value). Is there a different hidden file now?

Just in case I did the "hijack this" run and removed all the about|blank entries. But it still come back. (Immediately!) (Removeing the hidden file was the key before. Without getting rid of the "hidden" file, none of the other fixes stay fixed.) Something interesting in the hijack this log though, this line:
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

I'm hoping that there is some new info on the really bad old bug.

Help??
  #2  
Old January 16th, 2005, 12:09 AM
Sweetie(*)(*)'s Avatar
Sweetie(*)(*) Sweetie(*)(*) is offline
Frequent Poster
 
Join Date: Aug 2004
Location: Venus
Posts: 419
Default Re: about|blank home page hijacker

Hi I think it would be worth trying the new Microsoft Anti-Spyware beta 1, also if that is not sucsseful download HiJackThis run and save the log file you can then post it on forums that will advise you of what to remove (Wilders no longer allows HJT logs to be posted here)

LINK to download Microsft Anti-Spyware, you will need 2 do a windows authentication first. (small download provided by MS at the same site)
__________________
"Well behaved women rarely make history"
Laurel Thatcher Ulrich

Last edited by Sweetie(*)(*) : January 16th, 2005 at 12:18 AM.
  #3  
Old January 16th, 2005, 12:14 AM
Sweetie(*)(*)'s Avatar
Sweetie(*)(*) Sweetie(*)(*) is offline
Frequent Poster
 
Join Date: Aug 2004
Location: Venus
Posts: 419
Default Re: about|blank home page hijacker

Just a further note if you are using Spybot do u have the immunize function running and updated?

To protect yourself in future try using an alternate browser to IE, Mozilla an Opera have free browsers that are safer and arguably faster than IE.

Allot of the Spyware gets past your defenses because it comes via downloading a program that has a EULA (end user license agreement)
__________________
"Well behaved women rarely make history"
Laurel Thatcher Ulrich
  #4  
Old January 16th, 2005, 12:25 AM
bigc73542's Avatar
bigc73542 bigc73542 is offline
Retired Moderator
 
Join Date: Sep 2003
Location: SW. Oklahoma 28.360USB, 27.385LSB, 147.255+
Posts: 23,602
Default Re: about|blank home page hijacker

Quote:
Originally Posted by sarment
I had the about|blank on my son's computer last June (04). After MUCH research and effort I was able to remove it by basically following computer cops Ttime2Early's posting on May 22. (http://computercops.biz/postlite43426-blank.html) It went away.

His computer just got it again. (I can't believe that STILL Norton NAV & NIS, AdAware, Spybot, SpywareBlaster, and Trojan Hunter can't catch it coming in AND can't find it after the fact.)

I can't get rid of it by Ttime2Early's method because the "hidden" file does not have a name. The value on "applnit_dll" is blank (no value). Is there a different hidden file now?

Just in case I did the "hijack this" run and removed all the about|blank entries. But it still come back. (Immediately!) (Removeing the hidden file was the key before. Without getting rid of the "hidden" file, none of the other fixes stay fixed.) Something interesting in the hijack this log though, this line:
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

I'm hoping that there is some new info on the really bad old bug.

Help??


you might look here

and see if it is relevant to your problem

bigc
__________________
The Only Safe Computer Is Unplugged
MEMBER ASAP since 2004
Alliance of Security Analysis Professionals
  #5  
Old January 16th, 2005, 01:06 AM
sarment sarment is offline
Infrequent Poster
 
Join Date: Jul 2004
Posts: 27
Default Re: about|blank home page hijacker

Been there. Done that. The process linked a couple times on that posting got rid of it the first time. Now I don't see a value for the hidden file. It has to be somewhere else now.

Do you know anything about adware away? (www.adwareaway.com)
  #6  
Old January 16th, 2005, 01:55 PM
sarment sarment is offline
Infrequent Poster
 
Join Date: Jul 2004
Posts: 27
Default Re: about|blank home page hijacker

sweetie-
Thanks.
1 Yes we "immunize" and keep spybot up to date.
2 I am reluctant to download a new program unless I am reasonably sure it can detect and remove this particular problem since I already have so many protections in place and scans to run regularly.
3 You say "Allot of the Spyware gets past your defenses because it comes via downloading a program that has a EULA (end user license agreement)" Do you know of a way to protect yourself in these situations?
4 Maybe I will try one of the other browsers on my computer. (I try things here first before installing them on other computers.)
5 I already ran hijack this and removed the about:blank entries. The problem with about:blank is the hidden file that needs to be identified and removed. I don't know the location of "my" particular hidden file.

bigc-
Thanks. I used the information on these links to get rid of the last about:blank infection. It doesn't work this time because the hidden file is in a different location.
  #7  
Old January 17th, 2005, 07:20 AM
Blackspear's Avatar
Blackspear Blackspear is offline
Global Moderator
 
Join Date: Dec 2002
Location: Gold Coast, Queensland, Australia
Posts: 15,114
Default Re: about|blank home page hijacker

Quote:
Originally Posted by sarment
1 Yes we "immunize" and keep spybot up to date.
A good practice.


Quote:
Originally Posted by sarment
2 I am reluctant to download a new program unless I am reasonably sure it can detect and remove this particular problem since I already have so many protections in place and scans to run regularly.
Agreed, with this issue I would think you are going to need specialists help from A-SAP.

Have you tried running all your security programs while in “Safe Mode” as discussed in General Cleaning


Quote:
Originally Posted by sarment
3 You say "Allot of the Spyware gets past your defenses because it comes via downloading a program that has a EULA (end user license agreement)" Do you know of a way to protect yourself in these situations?
I would suggest Process Guard 3 by DCS.

This is what works really well for me, very simple to use and maintain. and also extremely secure.


Quote:
Originally Posted by sarment
4 Maybe I will try one of the other browsers on my computer. (I try things here first before installing them on other computers.)
It is a step in the right direction.


Quote:
Originally Posted by sarment
5 I already ran hijack this and removed the about:blank entries. The problem with about:blank is the hidden file that needs to be identified and removed. I don't know the location of "my" particular hidden file.
I believe with this issue as stated above, you will need to post your log at one of the forums found at A-SAP.

The two bigger forums for HijackThis log processing, (meaning they process more log threads each day than most others) are: SpywareInfo.com and CastleCops.com. Be sure to read their posting policy in the links at their log review forum sections prior to posting.

Once your system is clean I would also suggest taking a look here: Why did I get infected in the first place? Also, for further discussions on security and how to make your system that much stronger, see here and here

Cheers

Blackspear.
__________________
"Illegitimis non carborundum"
translation:
"Don't let the bastards grind you down"
U.S. General Joseph W. "Vinegar Joe" Stilwell (1883-1946)
Two Photographers
  #8  
Old January 17th, 2005, 01:17 PM
Bubba's Avatar
Bubba Bubba is offline
Global Moderator
 
Join Date: Apr 2002
Posts: 11,279
Default Re: about|blank home page hijacker

Quote:
Originally Posted by sarment
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
That registry entry is a policy to dis-allow that current signed on user to run regedit.exe. If you want to give that current user the ability to edit or view the registry....either change the 1 to 0....or....delete the Dword value DisableRegedit totally. It is not an Dword entry that is installed by default.
  #9  
Old January 18th, 2005, 01:24 PM
sarment sarment is offline
Infrequent Poster
 
Join Date: Jul 2004
Posts: 27
Default about|blank home page hijacker - adware away removed it

FYI-

I downloaded and ran Adware Away (at the suggestion of site moderator at castle cops, formerly computer cops http://castlecops.com/modules.php?na...=430702#430702) It was qwesome!

The last time I had "about blank" it took me days of research, some trial and error, and lots of manual manipulation to remove it.

This time I ran Adware Away and it was gone.

They even say that they will customize their program if you have a variant that the standard program doesn't remove. Currently the program removes 8 variants of "about blank"

I would choose this route over the others I tried earlier to remove this NASTY hijacker.
  #10  
Old January 18th, 2005, 01:33 PM
sarment sarment is offline
Infrequent Poster
 
Join Date: Jul 2004
Posts: 27
Default Re: about|blank home page hijacker

blackspear-

Thanks for the info. I followed the links and saw what you load on your computer. Most helpful.

I generally try software on my machine and then put in on others in our house if.... (For example, I have Process Guard on my computer. I like it but decided it is not appropriate for eveyone else's.)

Anyways, a couple questions about your list.

1 - how does "system safety monitor" compare with "registry protect"

2 - with process guard are these others (registry, script, etc.) needed?
  #11  
Old January 18th, 2005, 06:01 PM
Blackspear's Avatar
Blackspear Blackspear is offline
Global Moderator
 
Join Date: Dec 2002
Location: Gold Coast, Queensland, Australia
Posts: 15,114
Default Re: about|blank home page hijacker

Quote:
Originally Posted by sarment
Thanks for the info. I followed the links and saw what you load on your computer. Most helpful.
My pleasure, and glad it was helpful.


Quote:
Originally Posted by sarment
I generally try software on my machine and then put in on others in our house if.... (For example, I have Process Guard on my computer. I like it but decided it is not appropriate for eveyone else's.)
That’s a good practice, it is what I do as well.


Quote:
Originally Posted by sarment
1 - how does "system safety monitor" compare with "registry protect"
I used to use SSM, however it caused a conflict with the latest version of Nod32, so it got the heave ho, and I started using Prevx which I’m very impressed with.


Quote:
Originally Posted by sarment
2 - with process guard are these others (registry, script, etc.) needed?
Yes, still needed to monitor the registry, see here for comparrisions:

http://www.wilderssecurity.com/showthread.php?t=32823

I use MJ Registry Watcher http://www.jacobsm.com/index.htm#sft

Hope this helps…

Cheers
__________________
"Illegitimis non carborundum"
translation:
"Don't let the bastards grind you down"
U.S. General Joseph W. "Vinegar Joe" Stilwell (1883-1946)
Two Photographers
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:15 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums