new hijacker sets home page to about:blank

G

Guest

Once a PC is highly infected it may have to be rebooted into SAFE MODE to
run the virus, spybot & adaware.

There are 5 very important software programs every PC that has access to the
Internet needs & most are free.

1. Spy Bot Search & Destroy
http://www.download.com/3000-8022-10122137.html

2. Ad-Aware SE Personal Edition 1.05
http://www.download.com/Ad-Aware-SE-Personal-Edition/3000-8022_4-10319876.html?tag=lst-0-2

3. Google Toolbar 2.0.113
http://www.download.com/Google-Toolbar/3000-2379_4-10306581.html?tag=lst-0-2

4. Any Anti Virus from a major company such as McAfee or Norton, etc.
AVG Anti-Virus Free Edition 7.289
http://www.download.com/3120-20_4-0.html?qt=avg&tg=dl-2001

5. WIndows Update
http://windowsupdate.microsoft.com

"Imagination...is the irrepressible revolutionist."
 
G

Guest

Hi all:

I have encounter what appears to be a new IE hijacker. It sets the home page
to about:blank then displays a search site whose links all point to
nyam-nyam.biz. This appear similiar to the coolweb one. The PC is running
Winxp home

I have tried:
Spy Sweeper - which finds it but doesn't permanantely fix it
Hijack This - doesn't work on it
Editing the registry to remove about:blank and looked in the current
version/run settings

I know it has a plug that reloads it in winnt/systems32 but I can't find it
manually either.

thanks :)
 
J

Jan Il

Hi Air :)

You have a nasty hijacker on your system causing this problem. Thus, in
addition to running your updated anti-virus program, you should do the
following to be sure none of these are present on
your system. Although you may have already run one or more of the programs,
please do so again according to the instructions below. Be aware that, some
very aggressive and damaging variants of malware can replicate themselves
repeatedly if not removed properly. Please follow all instructions
carefully to be sure your system is thoroughly cleaned


Dealing with Unwanted Spyware and Parasites:
http://mvps.org/winhelp2002/unwanted.htm
Be sure to run CWShredder here

http://www.majorgeeks.com/download3019.html

and AdAware and Spybot.
Download the newest version of HiJackThis here:
http://www.bleepingcomputer.com/files/hijackthis.php




Also visit these two sites to test for parasites and help basic cleaning:

On-Line Check

http://aumha.org/a/noads.htm

and

Quick-Fix Protocol.
http://aumha.org/a/quickfix.php

Basically, throw everything here at your "infection".

And be sure to use the HijackThis. Please DO NOT post your log to this
newsgroup, but, to the HiJackThis Support Forums below:
http://www.hijackthis.de/forum/forumdisplay.php?f=10&guestlanguageid=4
the Aumha HiJackThis Forum
http://forum.aumha.org/viewforum.php?f=30

or Bleeping Computer Forum

http://www.bleepingcomputer.com/forums/forum22.html

to allow the experts there to evaluate your log and advise you of any
necessary steps to clean your system.

(Note: You will have to Register before posting on these Forums. Please
follow all posting instructions carefully to avoid having your log deleted
or ignored.


Also this program searches for hidden .dlls that recreate the malware.
Download and run it as well.
About Buster:
http://www.majorgeeks.com/download4289.html

CAUTION!!!!! Before you try to remove spyware using any of the programs
below, download a copy of LSPFIX from any of the following sites:
http://www.cexx.org/lspfix.htm
http://www.spychecker.com/program/winsockxpfix.html
(if your OS is Win2k or XP) The process of removing certain malware may kill
your internet connection. If this should occur, this program, LSPFIX, will
enable you to regain your connection.

You should also get a copy of WINSOCKXPFIX available at:
http://www.spychecker.com/program/winsockxpfix.html
and
WinsockXP Fix- WinXP
http://www.spychecker.com/program/winsockxpfix.html
with instructions, at
http://www.iup.edu/house/resnet/winfix.shtm
Also
From LavaSoft- all versions of Windows-
http://digital-solutions.co.uk/lavasoft/whndnfix.zip
(NOTE: It is reported that in XP SP2, the command netsh winsock reset
will fix this problem without the need for these programs.)

or ........if you don't have XP:

Winsock Fix Utility
http://www.dfwonline.net/files/WinsockFix.zip

Also.........

Courtesy of Jim Byrd -

Download Sysclean.com, from Trend Micro, here:
http://www.trendmicro.com/download/dcs.asp along with the latest pattern
file, here:
http://www.trendmicro.com/download/pattern.asp
Be sure to read the "How-to" info here:
http://www.trendmicro.com/ftp/products/tsc/readme.txt
You might also want to get Art's updater, SYS-UP.Zip, here for future
updating of these: http://home.epix.net/~artnpeg/.
(If you download and use the updater from the beginning, it will
automatically handle downloading the other files. Place them in a dedicated
folder after appropriate unzipping, and then run. This scan may take a long
time, as Sysclean is VERY extensive and thorough

NOTE: If you can not download these programs from the Internet, if your PC
has CD read capabilities, go to another computer with CD-ROM burning
capabilities. Create a folder on the hard drive of the other computer called
HOLD, download the programs to that folder, then burn that folder to a CD.
Copy the HOLD folder to your HD and then install the programs from there
and run them. After you have IE access again, update all programs where
possible to get the latest definitions and run them again in Safe Mode to be
sure there are no lingering items on the system.





If these steps do not resolve your problem, or you need help with the above,
please post back to this thread with the details and any error messages.

Hope this helps

Jan :)
Smiles are meant to be shared,
that's why they're so contagious.

Replies are posted only to the newsgroup for the benefit or other readers.
How to make a good newsgroup post:
http://www.dts-l.org/goodpost.htm
 
G

Guest

Air said:
Hi all:

I have encounter what appears to be a new IE hijacker. It sets the home page
to about:blank then displays a search site whose links all point to
nyam-nyam.biz. This appear similiar to the coolweb one. The PC is running
Winxp home

I have tried:
Spy Sweeper - which finds it but doesn't permanantely fix it
Hijack This - doesn't work on it
Editing the registry to remove about:blank and looked in the current
version/run settings

I know it has a plug that reloads it in winnt/systems32 but I can't find it
manually either.

thanks :)

About Buster- http://www.spychecker.com/program/aboutbuster.html
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top