auto:blank browser hijacker

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Wombat29, Dec 9, 2008.

  1. Wombat29

    Wombat29 Private E-2

    To start, congrats on a very helpful site. It's awesome that there are people out there happy to help others less knowledgeable.

    I am having major issues with the auto:blank browser hijacker. I have completed the steps in "Read & Run me first" so now I have spybot and SAS telling me my home page is trying to be redirected...

    Surfing the net is painful with these warnings popping up all the time..

    Help please!

    I'm not a beginner - but far from an expert. I have attached the logs for your review - hoping I have done so correctly....

    System specs:
    Intel core 2 duo CPU
    300gb hard drive
    DVD burner, etc
    (sorry - thought I knew more about my computer than that...)
     

    Attached Files:

  2. Wombat29

    Wombat29 Private E-2

    Other log attached.

    Any help greatly appreciated.

    Thanks

    WOMBAT29
    ooo
    O
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you still having issues? I am not seeing anything in your logs at this time.

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Tell me exactly what problems you are still having.
     
  4. Wombat29

    Wombat29 Private E-2

    Thanks for the reply.

    Completed the ATF cleaning process but still having problems.

    When I load Firefox or IE, Spybot comes up with a warning saying value change, start page changing from old home page to about:blank.

    I can accept or deny the changes through Spybot and I haven't been allowing these changes.

    Is this possibly why the logs are clean?

    After completing the "read and run me first" from MajorGeeks I know also have SAS telling me the same thing (that home page is trying to being changed to auto:blank).

    So major problem is my homepage in the browser is trying to be redirected to auto:blank.

    Not sure what to do next.

    Thanks

    WOMBAT29
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then let us reset your IE default.....you will have to disable your AV and AS programs and allow this to merge:

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Tell me if you get a success message.
     
  6. Wombat29

    Wombat29 Private E-2

    Followed the instructions and merged the text with the registry - no problems.

    Unfortunately browser is still being hijacked to auto:blank!

    For some reason Firefox hasn't gone to auto:blank but IE has.

    Spybot and SAS are still warning me that my homepage is being changed (whether I'm in IE or Firefox).

    Each time the Spybot or SAS warnings come up I "block" or "deny" the change (seems a bit late for IE though - it's already changed...).

    Please help!

    Thanks

    Wombat29
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well, that's just rude!! :)

    Please Disable Spybot's TeaTimer

    * Run Spybot and click Mode
    * Select Advanced Mode.
    * Then click Tools and select Resident.
    * Now in the right window pane, uncheck TeaTimer.
    * Also while this is open, in the left column now select IE Tweaks
    * and then in the right pane make sure all the Miscellaneous locks are unchecked.
    * Now quit Spybot!

    Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  8. Wombat29

    Wombat29 Private E-2

    Ok.

    Have disabled teattimer and run HijackThis.

    Log attached.

    How did we go?

    WOMBAT29
     
  9. Wombat29

    Wombat29 Private E-2

    Sorry - can't seem to attach the log..

    Do I need to start a new post / thread to be able to do this?

    Not sure where l've gone wrong.....
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just go to the C:\MGTools folder, double click on analyse.exe and do the scan and attach that log.
     
  11. Wombat29

    Wombat29 Private E-2

    We have a problem....

    SAS still popping up with a warning saying that my homepage is trying to be directed.

    Also the "attach files" option (in forum) doesn't have any buttons on it, i.e. I can't manage attachments and can't attach the log.

    Scan is completed - but how do I get it to you?

    Do I need to start a new thread so I can attach files to it again?

    Sorry for the hassles...

    WOMBAT29
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  13. Wombat29

    Wombat29 Private E-2

    Bingo!!

    Here is the log.

    Thanks
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This procedure explains how to get to the BitDefender Online Scan sites and how to setup and perform an online scan. It also explains how to obtain a log so you can attach it to a message. You must use Internet Explorer to run this scan and make sure your Sun Java version it current. Get Sun Java here: Sun Java Runtime EnvironmentBefore installing the current version, you should uninstall all previous versions first!!!!

    ****NOTE**** DO NOT INSTALL Bitdefender's Antivirus program. Make sure you follow the directions below and run the ONLINE SCANNER only.


    To start the online scan go here: Bitdefender

    • Agree to the license and then select Scan.
      • DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. That will make your logs huge and we don't need to see clean files.

    • Once Bitdefender completes the scan:
      • Click-on the Detected Problems tab. Then select Click here to export the scan report
      • When the window comes up to save the report, change the Save as type: box to Text (Tab Delimited) (*.txt)
      • And then in the File name box enter bdscan then click save. This will save a file named bdscan.txt in whatever folder you are currently in when you save the file (take notice of where you are at so you can find it later). This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html. If you do not follow these step, you will have an incorrect log or worse a log summary which is useless to us.

    • Post the bdscan.txt file as an ATTACHMENT. See: HOW TO: Attach Items To Your Post
    • If you run BitDefender Online scan and have previously run PandaActive scan, the below false detection may be seen in BitDefender:

      C:\WINDOWS\system32\ActiveScan\pskahk.dll
      Infected with: Generic.Malware.SIMDWYNVdprn.D9407F4E
     
  15. Wombat29

    Wombat29 Private E-2

    Scan attached.

    It didn't detect any viruses.

    Thanks
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then lets try removing ALL IE toolbars and disabling all add-ons. This is typically a browser helper object. The other alternative is to uninstall IE run ccleaner then reboot and re-install IE.
     
  17. Wombat29

    Wombat29 Private E-2

    Ok. I disabled all add ons in IE - wasn't sure how to remove the tool bars though... I haven't installed any toolbars in IE previously & I had a look in view toolbars and the only ones there were "Standard Button", "Address Bar" & "Links".

    So after I disabled all of the add ons it all seemed to work fine. Hooray!

    Then when I was in Mozilla the warning came up from SAS again that my homepage was trying to be redirected.

    Then it came up in IE!! Damn!!

    So I decided I'd try to uninstall IE - but I can't find where to do that. It doesn't come up as an option in CCleaner or the Windows add remove programs. I tried to just delete the directory but it said there was a file in use and I couldn't do that.

    I'm at my wits end with this thing - is there anyway out!!??

    Sorry to be presenting such a troublesome issue.

    Any advice greatly appreciated (I'm hoping formatting that hard drive isn't the next step!).

    Will await your advice.

    Thanks again

    WOMBAT29
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    To where is your homepage being directed? I suspect it is something you have downloaded or installed that is causing this. But you need to tell me what SAS is saying.
    Did you open SAS / preferences / hijack protection....and check the boxes to protect your homepage?
     
    Last edited: Dec 15, 2008
  19. Wombat29

    Wombat29 Private E-2

    Sorry for the lack of detail.

    Warning from SAS is saying homepage is trying to be redirected to auto:blank.

    I just went into SAS preferences / hijack protection and checked the boxes to protect your homepage.

    Hopefully this will do it.

    Just to clarify - the issue consistent all the way through - homepage is tryong to be redirected to auto:blank.

    This seems to be most vulnerable in IE. SAS or Spybot generally come up with a warning that the home page is "trying" to be redirected to auto:blank.

    Thanks
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I might also suggest a good firewall...but that is covered in these final instructions:

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds