Hijack Browser

S

Steve

Can any help with getting rid this browser hijacker: Afer
running a deep scan it finds the following,
Possible Browser Hijack Internet Explorer Search page 1.
Antispyware cleans it, reboot and it finds in again.
This is changing my home page to About:blank which
displays all types of pain in ass the spyware pages to go
to.
I have downloaded and run CCleaner... this was no help.
Does anyone know where to look for sometype of script or
file that starts this process.

Any advise would be helpful

Bye
Steve
 
E

Ethan Lerch

Have you tried running a virus scan? Download and run AVG Free (after
installing any updates). You may have a virus or trojan.
 
G

Guest

Yes I have run Norton scans....its finds nothing
-----Original Message-----
Have you tried running a virus scan? Download and run AVG Free (after
installing any updates). You may have a virus or trojan.




.
 
P

plun

CCleaner don´t remove about:blank, it cleans
up all crap in temporarily folders.

about:blank is difficult to remove, beacuse of several
new variants and so called rootkits.

I would advice to follow this and in step 8 if your fault
remains, register and post your log in forum.

Do all steps otherwise they will not help you.

http://aumha.org/a/quickfix.php
 
A

AndyManchesta

Hi Steve Im going to try help you out with this one as it
seems to be causing people alot of grief.There's alot of
programs we can use to get rid but lets take it a step at
a time and we can use them if this doesnt work,

Getting Prepared; Steps to be sure your system is ready
to be scanned:

Disable System Restore temporarily (WinXP & WinME only)
if you are infected; Any trojans, spyware, etc. you may
have picked up could have been saved in System Restore
and are waiting to re-infect you. Since System Restore is
a protected directory, your tools can not access it to
delete files, trapping viruses inside. Please follow
instructions to do that here:
(Start>Right click my computer>Properties>System
Restore>Disable then apply and exit)


Network Security, Workstation Netlogon Services & Remote
Procedure Call (RPC) Helper (Windows XP, 2K, NT); Only do
this step if you have the about:blank

You need to check to see if any of the following three
Windows services are running:

Network Security Service
Workstation Netlogon Service
Remote Procedure Call (RPC) Helper

To do this, click Start, Run, and enter the following in
the Open box: "services.msc" (without the quotes). Then
click OK. Now, in the Services window that pops up look
for exactly the following service names (no
others) "Network Security Service" or "Workstation
Netlogon Service" or "Remote Procedure Call (RPC)
Helper".

(NOTE: DO NOT DISABLE: Remote Procedure Call (RPC) or
Remote Procedure Call (RPC) Locator. They are both
required services and are unrelated to the hijacker.).
You could have more than one of the 3 mentioned bad
services, so look for all of them. If you find these
services, you must right click on it to bring up the
service Properties window and do the following :


Step 1: Stop the service by click the Stop button.

Step 2: Now, disable it by changing the Startup type to
Disabled and click Apply


If you do not find these exact services, do not worry and
just skip this step. DO NOT DISABLE ANYTHING UNLESS THE
EXACT WORDING OF THE SERVICE NAMES IS MATCHED.

Enable viewing of hidden files and folders and
extensions; Some programs can hide this way by not being
visible in Windows. Start Windows Explorer and click on
your main hard drive, usually c:\. Then select Tools from
the top of Windows Explorer and then Folder Options. Go
to the View tab. Scroll down to the folder icon that says
Hidden files and folders and check show hidden files and
folders. Also, right below it, uncheck the hide file
extensions for known types.

Download the following tools and save in your favorite
download folder or create one, for example C:\Temp or
C:\Downloads. And then install, update, and configure as
indicated below.


CWShredder......No installation required! Just unzip it
to a folder.

http://cwshredder.net/bin/CWShredder.exe

About:Buster......No installation required! Just unzip it
to a folder. Click Update and download any before
scanning.

http://majorgeeks.com/downloadget.php?
id=4289&file=1&evp=ae3de3780275c1771c4e5047af537d4a

Download the Hoster from here:

http://members.aol.com/toadbee/hoster.zip


Now once you have all these above tools and have them
updated reboot into safe mode(Tapping F8 on reboot) and
stay in safe mode !!!


First I want you to check the registry.If you havent used
regedit before its a simple enough thing to use,Just take
your time and only delete what i mention If you see other
references to About:Blank then you can Modify them as
well.

Go to Start then Run and Type:

regedit


Find these values and click Modify if found:(Example
click HKEY_CURRENT_USER then the + beside it,then go to
SOFTWARE and click the + beside it,then to MICROSOFT and
the + beside it and so on to you get to the MAIN folder)

HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL
= http://about-blank.ws/page/

HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar
= http://about-blank.ws/page/

HKCU\Software\Microsoft\Internet
Explorer\Main,Default_Search_URL = http://about-
blank.ws/page/

HKCU\Software\Microsoft\Internet Explorer\Main,Start
Page_bak = http://about-blank.ws/

If they are found for now replace them with this line by
right clicking and choosing Modify:

http://www.microsoft.com/isapi/redir.dll?
prd=ie&pver=6&ar=msnhome


Next we need to get rid of the Hijack files from your pc
this is a tricky one as it drops a randomly named file
plus uses the Windows file name svchost but where theres
a will there's a way :)

You can search for this assuming you have enabled the
hidden files and unchecked the hide for known file types
which i explained above:

go to the search bar and choose to look in my computer
for all files and folders and then type in:

svchost

The legitimate one is in the system32 folder but this
adds its own in the windows folder,You will find a few if
you have upgraded to service pack2 but if you find any
other than these and its in the windows folder delete it!!

svchost -C\Windows\prefetch 23Kb
svchost.exe-C\Windows\system32 14Kb
svchost.exe-C\Windows\ServicePackFiles\i386 14Kb
svchost.exe-C\Windows\SoftwareDistribution\Download 14Kb

these are genuine and essential windows files but if you
find one in the windows folder(svchost.exe) delete it

The next step is even more tricky as it's a randomly
names file but the clue its connected to this trojan is
that they are either 1079 or 1087 bytes in size and will
typically be in the system32 folder heres a example of
one previously found(xea2508l.6zt)so if you find it
delete that also but if unsure leave it for now and the
About Buster program will hopefully pick it up

Now Run CWShredder and uncheck the'Move files found to
recycle bin' and then press fix

Next run the Hoster Program and on this choose

'Restore Original Hosts'

Then exit once its been reset

Then That's it we should of killed it now id advise
rebooting into normal mode and check thats its gone,If
you are still having problems or its still present then
go for the About Buster program you downloaded but i
wanted to go for this manually as it involves scvhost and
the random files so wanted to explain about them so you
know which are bogus or genuine.




Good Luck

Andy
 
P

plun

Ethan said:
Nice, I would've never thought of that. Tell me if that works.

Well, for about:blank we have a lot of traps and several
variants and if something
goes wrong these tools are dangerous. Everyone must be real
careful
if they tries to follow this.

All Forums within the whole world helps people with these pests
and others.

You have a lot of information within these forums, left menu

http://www.a-sap.org/

Also search with Google about about:blank
http://www.google.com/search?hl=en&q=about:blank&btnG=Google+Search
 
A

AndyManchesta

When you get to the last step before rebooting also use
CCleaner(Crap Cleaner) to remove all temp and unused
files otherwise they might be able to regenerate if they
are still on your system.

Another way is to do it this way:

Next: Delete Temp Internet files :
Open a internet browser window, click Tools then Internet
Options.
Click on the Delete Cookies and the Delete Files buttons
(Choose to delete all offline content)
then click OK and close the browser window.

Next: Delete Windows Temporary Files - (start,run then
type %temp% delete all files you can in this folder
The Windows temporary directory (usually located at
C:\windows\temp).

All the best

Andy
 
A

AndyManchesta

Hi Plun,

These tools are not dangerous at all mate (CWShredder)
and (About Buster) will not cause any problems for users
and the latter About Buster wouldnt even be needed if the
other steps are done correctly.

The Hoster File which i advise is essential in resetting
the hosts file,especially for people who do not
understand the hosts file setup as all they need to do it
click restore original hosts and then it goes back to the
Microsoft default setup(So again no danger involved)

The svchost part is a risky one but it should not be in
the windows folder the legitimate one is in the system
folder and this About:Blank adds one to the windows
folder so if you want to remove about blank you also need
to remove this.Any reference to svchost apart from the
ones i listed as genuine is connected to About:Blank
Trojan so again no danger involved by killing a trojan
file.

Resetting the Home page and Start Pages in Registry
causes no problems as nothing is being deleted we are
only resetting the pages back to Microsofts default pages
by modifying them(Again No Danger Involved)

CCleaner removes temp and unused files so No danger in
using that also

So i appreciate you are just trying to advise people
about the possible down side of removing files but you
are wrong to say my steps are dangerous.Im just showing
how to kill the About:Blank trojan .

If MS antispy was any sort of spyware remover then i
wouldnt even have to get involved with manual removal
methods but MS antispy is abit of a toy remover at
present so feel this is the only way to go as im sure you
have noticed on here alot of basic spyware and adware
isnt being deleted.This one comes under Trojan/Search
Hijacker in my view so i doubt if MS Antispy would ever
help user's for this one even when its released fully.

Have a nice day

Andy
 
P

plun

AndyManchesta said:
So i appreciate you are just trying to advise people
about the possible down side of removing files but you
are wrong to say my steps are dangerous.Im just showing
how to kill the About:Blank trojan .

Well, Ive seen this "down side" many times
and I sees it in all modern board forums.

Download but "Do not run before you are adviced to".

I can with help from Hijackthis logs see what
next step probably will be but If I dont have any logs
this can damage a users computer or a user
will be mislead to a endless fault solving.

So my proposal again for solving this to MS.

- 1 Windows 2003 server
- 1 SQL server 2005
- 1 Invision board
and some PHP.
 
K

karl

I think I have finally defeated this thing after 3 months
You will need hijack this and a program called fixagent.
I was ready to reload my PC. Fix agent found the trojan
and upon reboot NAV found and quaranteened a file
HLPJ.DLL. Seems to have finally removed it
 
S

skip

-----Original Message-----
Can any help with getting rid this browser hijacker: Afer
running a deep scan it finds the following,
Possible Browser Hijack Internet Explorer Search page 1.
Antispyware cleans it, reboot and it finds in again.
This is changing my home page to About:blank which
displays all types of pain in ass the spyware pages to go
to.
I have downloaded and run CCleaner... this was no help.
Does anyone know where to look for sometype of script or
file that starts this process.

Any advise would be helpful

Bye
Steve
.
Hi Steve......! Well you can download,
www.WinPatrol.com (free edition).........This program
will let you know if your Browser is being changed.Then
you can make correction....Bye Skip
 
G

Guest

I have a pesky hijack browser the indepth method listed
by andy is a bit extreme for my PC skills - could you
email me where to download the programs you used to get
rid of the hijacker.

Hijack this
Fixagent

thanks nic
 
A

AndyManchesta

Hi There,The programs you mention can be got from these
links id also advise getting Ccleaner to remove all temp
and unused files once you have finished the removal
process.

I will try make this abit easier to follow compared to my
original posting,Its like i said in that mail there is
alot of tools we can use to remove this but each has
positive and negative results so this is why i wanted to
go one step at a time.

The problem with this About:Blank is their is in many
casy a underlying mechanism that keeps it installed this
is what Fix Agent looks for plus other programs like
startdreck and from running msinfo from the run box etc..


Fix Agent

http://www.greyknight17.com/spy/FixAgent.zip

Hijack This

http://www.greyknight17.com/spy/HijackThis.exe

CCleaner.............Install only, then exit

http://majorgeeks.com/downloadget.php?
id=4191&file=11&evp=a12d758b021af1a4f0a6bfe45b0c7a82


With Fixagent

Fix Agent utility messes up your permissions and so we
have to repair those if it finds anything.

Download FixAgent and unzip it. Run FixAgent.exe. It
should fix something. If something is found, also
download home_missing_114

http://www.greyknight17.com/spy/home_missing_114.zip

and unzip it. Run the Home winkey missing batch file.


Remember: ONLY run home_missing_114 if FixAgent found
something.


Reboot into Safe Mode (hit F8 key until menu shows up).
Make sure to close any open browsers. Run a scan in
HijackThis. Check any of the following or any entries
with About:Blank with R1 or R0 and hit 'Fix checked'
(after checking them):

R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start
Page = about:blank
R0 - HKLM\Software\Microsoft\Internet
Explorer\Search,SearchAssistant = about:blank
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,HomeOldSP = about:blank

Then run Ccleaner and clear all temp files.

Then reboot into normal mode and run Hijack this again
incase their is still some entries that didnt show up in
safe mode if there is choose fix checked and delete them.
If it comes back then its regenerated so the dll filename
will have changed so you need to start again or reply and
we will take it from another angle as theres alot of ways
to do this.

Hope this helps

Andy
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top