about:blank has defeated me!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by moosickboy, Sep 20, 2004.

  1. moosickboy

    moosickboy Private E-2

    I am seriously about ready to give up on this one. I followed every single step outlined in this thread on Friday, taking me 2-3 hours to finally complete, and I still have the stupid thing.

    Is there anything else I should know?
     
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

  3. moosickboy

    moosickboy Private E-2

    Ok, I followed everything in the post, and still have the stupid thing. I've attached my latest hijack log. I noticed that the thing seems to have changed names... I noticed a few days ago that it was called something else... the dll files in the hijacklog now have a new name. Tricky. Any advice you could give would really help me out. Thank you.
     

    Attached Files:

  4. moosickboy

    moosickboy Private E-2

    I should also mention that not only do I have the about:blank start page, but I also have the annoying "only the best" pop-ups. Are these related?
     
  5. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Sadly, theres a whole nother tutorial for that, get ready:

    http://forums.majorgeeks.com/showthread.php?t=38772

    I hate to do this, but if you could run that, we can go back to Hijack This. I can see that Hijack now in these lines:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\hhwxg.dll/sp.html#29126
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\hhwxg.dll/sp.html#29126
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\hhwxg.dll/sp.html#29126
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\hhwxg.dll/sp.html#29126
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    MA,

    Moosic did try the Generic Solution once (mention in his first message as a link). Sadly it is going to have to be run again. However the first thing that must be done is to get the proper version of HijackThis. 1.97.7 is out of date.

    Moosic, get version 1.98.2 of HJT and post another HJT log and we will point out the problem lines. Also not I added some more details into the steps today on an RPC Helper service that must now be check for.

    After posting the new log, do not shutdown or reboot your PC. This typically can cuase mutation of the filenames making the HJT log useless. You can disconnect your PC from the internet (physically if need be) but no reboots.
     
  7. moosickboy

    moosickboy Private E-2

    OK, thanks for letting me know about the out of date Hijack. Here is the new log.
     

    Attached Files:

  8. IT_eagle

    IT_eagle Private E-2

    Don't give up. I got about: blank on my birthday 9-8-04. Just fixed it today.
    I am not going to say it was easy but try this.

    Ad Away and then run SWshredder. reboot
    then run Ad Away then run SWshredder again.
    This did it for me.
    Over the last few days I have been running Adaware Se Personal and Spybot.
    SO if you want to be through run in this order
    Adaware-Spybot-Adware away then SWshredder reboot change home page
    Adaware-Spybot-Adware away then SWShredder reboot. open IE fixed.

    Good luck
    IT_eagle :)
     
  9. moosickboy

    moosickboy Private E-2

    Where can you get SWshredder?
     
  10. Kodo

    Kodo SNATCHSQUATCH

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\hhwxg.dll/sp.html#29126
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\hhwxg.dll/sp.html#29126
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\hhwxg.dll/sp.html#29126
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\hhwxg.dll/sp.html#29126
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\hhwxg.dll/sp.html#29126
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\hhwxg.dll/sp.html#29126
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:8010
    R3 - Default URLSearchHook is missing


    I also question the following 2 items.
    O4 - HKLM\..\Run: [ierx.exe] C:\WINDOWS\system32\ierx.exe
    O4 - HKCU\..\Run: [Prae] C:\Documents and Settings\Randy O'Neal\Application Data\estr.exe
     
  11. IT_eagle

    IT_eagle Private E-2

  12. moosickboy

    moosickboy Private E-2

    Ok, I'm a bit new to all of this, and so what exactly do I do with lines that hijackthis found? Do I just check them and delete them? Surely it's more difficult than that.....
     
  13. Kodo

    Kodo SNATCHSQUATCH

    Check the box to the corresponding items listed and click "Fix Checked" ..
     
  14. IT_eagle

    IT_eagle Private E-2

    Thank you VERY much Major Attitude for your post. I have lost many hours with this virus and wanted to thank you.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do not need to go anywhere else to get CWShredder. It is right here on MG's. In fact if you had read and executed everything we gave you in the READ ME FIRST tutorial, you should already have it.

    Even more importantly you should always use our links because they are for current versions. The link IT_eagle supplied is way out of date and is definitely not what you should be using. CWShredder does not fix about:blank or HSA hijack problems. Even the creator of the application will tell you that. It does not hurt to run it though since you could have other CWS problems.
     
    Last edited: Sep 21, 2004
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    While you are welcome to try what IT_eagle indicated worked, I don't think it will resolve true about:blank or HSA hijacks. In addition while the lines Kodo has pointed out are indeed part of the problem several items are missing in particular:

    C:\WINDOWS\vmmreg32.dll:afwda
    O2 - BHO: (no name) - {C6A80F1C-5BB1-CC67-601F-59499EF2AC5B} - C:\WINDOWS\crns.dll

    These are both part of th hijack. However simply fixing this line with HijackThis will do nothing to fix the problem. It will just cause more files to be created on your PC with new names. You must follow the steps in the Generic Solution thread and insert the appropriate lines at the correct places. You must also search as indicated in the Generic Solution for NSS, WNS, and RPC Helper services to find any additional hidden processes that can respawn the problem.

    If you do not know what lines to use in what steps of the Generic Solution, just ask and I will help you. The key is to follow ALL the steps exactly as written (skipping nothing) from beginning to end without rebooting or connecting to the internet during the procedure unless specified. You must also have the correct versions of all programs linked in the Solution.
     
  17. moosickboy

    moosickboy Private E-2

    Ok, I ran through everything again that were in the directions in this thread. I noticed it's still on there now after I rebooted in normal mode. I ran I hijack log before I connected back to the internet and I'm posting it again. I also ran about:Buster before I got back on the internet, but it found nothing (in normal mode). This sucker sure is tricky. Any more ideas?
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to be providing feedback on the steps in the generic solution. You should be indicating whether you found any of the 3 services running (NSS, WNS, or RPC Helper) . You should be posting the About:Buster logs along with the HJT log. You should be telling me whether each step executed properly or if there were any problems. For example, when you were suppose to be deleting particular files, did you have problems finding them or deleting them.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These two lines are part of the problem:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\hhwxg.dll/sp.html#29126
    O2 - BHO: (no name) - {F28B1256-59AF-E0AE-9F80-A3E878D7AC87} - C:\WINDOWS\system32\apiyr32.dll

    You need to fix them too. But that will now work just by clicking fix in HijackThis. I would bet by now if you have opened and closed a few Internet Explorer sessions that you have more R0 & R1 lines and an O4 line too. If not, they will probably be there after a reboot.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds