Help! Ad-aware found: Registry--> Possible Browser Hijack attempt

  • Thread starter Thread starter Debbie
  • Start date Start date
D

Debbie

Hello-
Two days ago Ad-aware found:
Possible Browser Hijack attempt -
RegData -HKEY_CURRENT_USER:Software\Microsoft\Internet Explorer\Main"Start
Page" ("about:blank")
So, I just got rid of it (even the quarantine one) . Then, TODAY, it found
it again. My question is: What do I do??!?!?!
I'm running WinXP.

Thanks
 
Debbie said:
Hello-
Two days ago Ad-aware found:
Possible Browser Hijack attempt -
RegData -HKEY_CURRENT_USER:Software\Microsoft\Internet Explorer\Main"Start
Page" ("about:blank")
So, I just got rid of it (even the quarantine one) . Then, TODAY, it found
it again. My question is: What do I do??!?!?!
I'm running WinXP.

If it's Hijackware, then you need the following, and it's free. Let
HiJackThis take care of it. Follow the instructions carefully.

HiJackThis: - Free

Go to
http://computercops.biz/downloads-cat-14.html ,
or
http://tinyurl.com/2oce8
or
http://tinyurl.com/2atxk

and download HiJackThis. Unzip to a folder other than your Desktop or the
Temp folder, doubleclick HiJackThis.exe, and hit "Scan".

When the scan is finished, the "Scan" button will change into a "Save Log"
button. Press that, save the log some place you remember where it is. Most
of what it lists will be harmless or even required, so DO NOT fix anything
yet.

Open a the copy of your log in NotePad and made a copy. Then you can go here
to post you log:
http://forum.aumha.org/

Go to the HiJackThis section on the forum list and click to open. You can
post as a guest. It's also a good site to keep for reference. The experts
there will analyze the log and report back the results. Please allow at
least a few hours or a days time for a response.

Remember, you must return to the HJT site to get your answer. It is a good
idea to click the "Notify" box so that you will get an electronic
notification by e-mail to let you know when a response has been posted.
But, you must still return to the site of your answer

Help with Hijackware & Scumware Information - Free
http://aumha.org/a/parasite.htm
http://aumha.org/a/quickfix.htm
http://mvps.org/winhelp2002/unwanted.htm
http://inetexplorer.mvps.org/Darnit.htm


HTH

Jan :)
 
That depends on whether you set the Start Page to about:blank
yourself, either deliberately or by not having a Start Page.
What happens if you just change it to something else in
IE-Tools-Internet Options?

Of course, if you want a blank Start Page, then just ignore it in
AdAware along with any other items that it indicates are problems when
you are certain they are not. Ad-Aware can be a little over zealous.

....Alan

--
Alan Edwards, MS MVP W95/98 Systems
http://dts-l.org/index.html


In microsoft.public.windows.inetexplorer.ie6.browser, "Debbie"
 
Debbie said:
Hello-
Two days ago Ad-aware found:
Possible Browser Hijack attempt -
RegData -HKEY_CURRENT_USER:Software\Microsoft\Internet Explorer\Main"Start
Page" ("about:blank")
So, I just got rid of it (even the quarantine one) . Then, TODAY, it found
it again. My question is: What do I do??!?!?!
I'm running WinXP.

Here's a good way to check, change it to something besides about:blank and
then run Adaware again and see if it shows it again. If it does, then you
know you've got a bug. If not, then you are ok. But, with a bug out there
that is taking advantage of that to do some dirty work , I'd suggest that
you find a different default page and put that in there as your home page.
That way if it ever shows up, then you know you've got a problem.

When you find it, run HiJackThis and let the experts tell you what to
delete. But, if it were me, right now I'd run HJT anyway, just to be safe.
It's free, and only takes a couple seconds to run. Follow all instructions
carefully.

HiJackThis: - Free

Go to
http://computercops.biz/downloads-cat-14.html ,
or
http://tinyurl.com/2oce8
or
http://tinyurl.com/2atxk

and download HiJackThis. Unzip to a folder other than your Desktop or the
Temp folder, doubleclick HiJackThis.exe, and hit "Scan".

When the scan is finished, the "Scan" button will change into a "Save Log"
button. Press that, save the log some place you remember where it is. Most
of
what it lists will be harmless or even required, so DO NOT fix anything yet.

Open a the copy of your log in NotePad and made a copy. Then you can go here
to post you log:
http://forum.aumha.org/

Go to the HiJackThis section on the forum list and click to open. You can
post as a guest. It's also a good site to keep for reference. The experts
there will analyze the log and report back the results. Please allow at
least a few hours or a days time for a response.

Remember, you must return to the HJT site to get your answer. It is a good
idea to click the "Notify" box so that you will get an electronic
notification by e-mail to let you know when a response has been posted.
But, you must still return to the site of your answer

Help with Hijackware & Scumware Information - Free
http://aumha.org/a/parasite.htm
http://aumha.org/a/quickfix.htm
http://mvps.org/winhelp2002/unwanted.htm
http://inetexplorer.mvps.org/Darnit.htm

HTH

Jan :)
 
Thanks for all your suggestions.
Sorry for not being specific in my first post on what I've done. I've always
had my homepage as about:blank. So, this is what I did:
- I've ran (all updates installed): CWShredder (first), Ad-Aware (second),
Spybot S&D (third), and I deleted what Ad-Aware found (the others didn't
find anything).
- I also cleared out all the Temp files, cookies, history. And also, for the
"Check for newer versions of stored pages," the "Every visit to the page" is
checked-- but it keeps resetting to 'Automatically.' The TIF folder is set
to 50MB.
- Then, I went to http://forum.aumha.org/viewforum.php?f=30 and did the
"Quick Fix" first.
- After trying the "Quick Fix," I got HijackThis, and I already posted my
results at http://forums.spywareinfo.com--> and fixed what PA Bear told me
to fix.
**After I ran CWShredder, Ad-Aware (& I got rid of the "Possible Brower
Hijack" thing), and Spybot S&D, I rebooted. And guess what? I opened IE, and
the homepage had changed to "msn.com" And I usually have it as
"about:blank." What I've noticed is that everytime I get rid of the
"Possible Browser Hijack" RegData that Ad-Aware finds, & restart, my
homepage changes to msn.com
It's happened two times already. The last time was when I started this
thread.

I'm going to run all those again, and see if Ad-Aware finds it again. When I
get finished, I'll post back. :)

Thanks again,
Debbie


| Here's a good way to check, change it to something besides about:blank and
| then run Adaware again and see if it shows it again. If it does, then you
| know you've got a bug. If not, then you are ok. But, with a bug out
there
| that is taking advantage of that to do some dirty work , I'd suggest that
| you find a different default page and put that in there as your home page.
| That way if it ever shows up, then you know you've got a problem.
|
| When you find it, run HiJackThis and let the experts tell you what to
| delete. But, if it were me, right now I'd run HJT anyway, just to be safe.
| It's free, and only takes a couple seconds to run. Follow all
instructions
| carefully.
|
| HiJackThis: - Free
|
| Go to
| http://computercops.biz/downloads-cat-14.html ,
| or
| http://tinyurl.com/2oce8
| or
| http://tinyurl.com/2atxk
|
| and download HiJackThis. Unzip to a folder other than your Desktop or the
| Temp folder, doubleclick HiJackThis.exe, and hit "Scan".
|
| When the scan is finished, the "Scan" button will change into a "Save Log"
| button. Press that, save the log some place you remember where it is. Most
| of
| what it lists will be harmless or even required, so DO NOT fix anything
yet.
|
| Open a the copy of your log in NotePad and made a copy. Then you can go
here
| to post you log:
| http://forum.aumha.org/
|
| Go to the HiJackThis section on the forum list and click to open. You can
| post as a guest. It's also a good site to keep for reference. The experts
| there will analyze the log and report back the results. Please allow at
| least a few hours or a days time for a response.
|
| Remember, you must return to the HJT site to get your answer. It is a good
| idea to click the "Notify" box so that you will get an electronic
| notification by e-mail to let you know when a response has been posted.
| But, you must still return to the site of your answer
|
| Help with Hijackware & Scumware Information - Free
| http://aumha.org/a/parasite.htm
| http://aumha.org/a/quickfix.htm
| http://mvps.org/winhelp2002/unwanted.htm
| http://inetexplorer.mvps.org/Darnit.htm
|
| HTH
|
| Jan :)
|
|
 
Debbie said:
Thanks for all your suggestions.
Sorry for not being specific in my first post on what I've done. I've always
had my homepage as about:blank. So, this is what I did:
- I've ran (all updates installed): CWShredder (first), Ad-Aware (second),
Spybot S&D (third), and I deleted what Ad-Aware found (the others didn't
find anything).
- I also cleared out all the Temp files, cookies, history. And also, for the
"Check for newer versions of stored pages," the "Every visit to the page" is
checked-- but it keeps resetting to 'Automatically.' The TIF folder is set
to 50MB.
- Then, I went to http://forum.aumha.org/viewforum.php?f=30 and did the
"Quick Fix" first.
- After trying the "Quick Fix," I got HijackThis, and I already posted my
results at http://forums.spywareinfo.com--> and fixed what PA Bear told me
to fix.
**After I ran CWShredder, Ad-Aware (& I got rid of the "Possible Brower
Hijack" thing), and Spybot S&D, I rebooted. And guess what? I opened IE, and
the homepage had changed to "msn.com" And I usually have it as
"about:blank." What I've noticed is that everytime I get rid of the
"Possible Browser Hijack" RegData that Ad-Aware finds, & restart, my
homepage changes to msn.com
It's happened two times already. The last time was when I started this
thread.

I'm going to run all those again, and see if Ad-Aware finds it again. When I
get finished, I'll post back. :)

Thank you, Debbie, we appreciate all your information and feedback as well.
It helps us help you. :-)

Jan :)
 
:) Hello again!
Thanks for all your suggestions.
This what I did:
--I changed my homepage to yahoo.com. Ran Ad-Aware. Results: 0 New Objects
Found.
--Then I changed it to msn.com. Ran Ad-Aware. Results: 0 New Objects Found.
--THEN I changed it to about:blank. Ran Ad-Aware. Results: Possible Browser
Hijack attempt - RegData - HKEY_CURRENT_USER:Software\Microsoft\Internet
Explorer\Main"Start Page" ("about:blank")

So, perhaps it's just a false alarm.....??

Thanks again!

Debbie

P.S.: Sorry for taking so long. But school's out!! So, I'll see you guys
around! =)


| | > One would assume this is Debbie's thread:
| > http://forum.aumha.org/viewtopic.php?p=30802
| >
| > (See you back there, Debs!)
|
| So it seems. :-)
|
| Thanks.
|
| Jan :)
|
|
 
Alright, thanks. :)

| If you chose 'about:blank' and Ad-aware flags it, yes, it's a false
positive
| which may be ignored.
| --
| HTH - Please Reply to This Thread
|
| ~Robear Dyer (PA Bear)
| MS MVP-Windows (IE/OE), AH-VSOP
|
| AumHa Forums
| http://forum.aumha.org
|
| What You Should Know About Spyware
| http://www.microsoft.com/mscorp/twc/privacy/spyware.mspx
|
| Debbie wrote:
| > :) Hello again!
| > Thanks for all your suggestions.
| > This what I did:
| > --I changed my homepage to yahoo.com. Ran Ad-Aware. Results: 0 New
Objects
| > Found.
| > --Then I changed it to msn.com. Ran Ad-Aware. Results: 0 New Objects
| > Found.
| > --THEN I changed it to about:blank. Ran Ad-Aware. Results: Possible
| > Browser Hijack attempt - RegData -
| > HKEY_CURRENT_USER:Software\Microsoft\Internet Explorer\Main"Start Page"
| > ("about:blank")
| >
| > So, perhaps it's just a false alarm.....??
| >
| > Thanks again!
| >
| > Debbie
| >
| > P.S.: Sorry for taking so long. But school's out!! So, I'll see you guys
| > around! =)
| >
| >
| > | >> | >>> One would assume this is Debbie's thread:
| >>> http://forum.aumha.org/viewtopic.php?p=30802
| >>>
| >>> (See you back there, Debs!)
| >>
| >> So it seems. :-)
| >>
| >> Thanks.
| >>
| >> Jan :)
|
 
TODAY, it found it again. My question is: What do I do??!?!?!
I'm running WinXP.

It looks as if that proxy if it is going to work has to be running somewhere
on your machine (e.g. ProxyServer address like 127.0.0.1)
If so, you could probably see it with
netstat -ao
(e.g. that would show "listening" PID so then you would match up the PID
with an imagename using Task Manager.)

Since you know the port involved you can actually make the output even
more particular with the following pipeline:

netstat -ano | find /i ":9002"

XP's netstat can give you even more detail about the process involved
including the .dlls it is using.

netstat -abvon -p tcp

However, the -b option seems to slow it down absurdly.

What I would do instead is once I got the PID from the -o option
I'd use the tasklist command and use the PID for a filter criterion.
E.g. say your netstat told you that the PID was 1234 then the tasklist
command you would enter would be:

tasklist /m /fi "PID eq 1234"

That gives essentially the same information much quicker.


Since you suspect that "something" is adding those registry entries
another diagnostic I would use is RegMon with an input filter of Proxy
(RegMon is freeware from SysInternals.) This would be especially easy
if the changes are being made after boot time but RegMon for NTx also
has a way of tracing activity during the boot too. To set the filter I find it
simplest just to press Ctrl-L then type my input criteria in the Include box.
Alternatively use the filter icon in the toolbar. Unless you find a good reason
to use a more inclusive input criterion I think you may find that that one
is sufficient without being overwhelming.


Good luck

Robert Aldwinckle
 
Robert, both current versions of Ad-aware and Spybot are identifying this
and some other keys as /possible/ hijacking*. If user has intentionally
selected a blank homepage (about:blank), the report should be viewed as a
false-positive and ignored.

*CWS.Aboutblank, CWS.Searchx, et alia
 
Two days ago Ad-aware found:
Robert, both current versions of Ad-aware and Spybot are identifying this
and some other keys as /possible/ hijacking*.


Oops. I think I must have been replying to something in the AUMHA
thread. My reply doesn't make much sense just from the point of view
of this one. There the only problem with Home page mentioned was
having About:Blank change to MSN.com. The last I saw of the thread
she was still complaining about seeing undesired changes in proxy settings. That is what my reply was addressing.


Sorry for the confusion.

Robert
 
-----Original Message-----
Hello-
Two days ago Ad-aware found:
Possible Browser Hijack attempt -
RegData -HKEY_CURRENT_USER:Software\Microsoft\Internet Explorer\Main"Start
Page" ("about:blank")
So, I just got rid of it (even the quarantine one) . Then, TODAY, it found
it again. My question is: What do I do??!?!?!
I'm running WinXP.

Thanks
run adaware and spybot search and destroy, then run
pestsscan, www.lavasoft.com (spybot)
www.pestscan.com for Pestscan.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads


Back
Top