about:blank & Only the Best -- Where to start?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by planders, Aug 23, 2004.

  1. planders

    planders Private E-2

    Our computer has been infected with the about:blank homepage hijack and Only the Best pop-ups. I'm a complete novice at all this and don't know where to start.

    I have printed:
    "When all else fails - try Generic Solution to HSA"
    "Basic Spyware, Trojan, and Virus Removal"
    Hijack Tutorial

    I've downloaded:
    Ad-aware
    Spybot S&D
    HSRemover
    HijackThis
    Ccleaner
    ProcessExplorer NT/2K/XP
    CWShredder

    I just don't know where to start. Should I try the "Basic..." first? I do have a HijackThis log that I'll attach. HELP!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First before getting started on the hijackers, you need to run the stuff from "Basic Spyware, Trojan, and Virus Removal" first.

    Also do you recognize the two IP address from your O17 line:
    217.237.150.33 = [ www-proxy.F2.srv.t-online.de ]
    194.25.2.129 = [ dns03.btx.dtag.de ]

    If not, you should run HijackThis and put check marks on that O17 line along with the O16 & O18 line shown below and then click fix.

    O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\kiqkfwxj.exe
    O17 - HKLM\System\CCS\Services\Tcpip\..\{4544A61D-25FF-4950-A0D0-9A76623AE18B}: NameServer = 217.237.150.33 194.25.2.129
    O18 - Protocol: icoo - {4A8DADD4-5A25-4D41-8599-CB7458766220} - (no file)

    After running thru all the steps of the Removal tutorial and fixing the lines I gave you above, if you are still having a problem with the hijacks, post a new HJT log attachment but do not reboot or shut down your computer (or the problem will mutate). You can disconnect from the internet but keep your PC running until you here back from me. I will get you pointed in the right direction on using the Generic Solution thread based upon the HJT log you post.
     
  3. planders

    planders Private E-2

    Thank you for your help. I followed the steps in "Basic Spyware..." and things seem to be good. When I restarted IE, I got my home page, not about:blank. I haven't had an Only the Best pop-up since I've been on.

    RE the O17 line: I am in Germany, and I recognized the first IP as my provider (t-online). 'de' seems to be a common extension for websites in Germany. I don't know about the other one, though.

    Should I go back and run HJT and delete 16 and 18??

    Again, thank you, thank you, thank you...
     
  4. planders

    planders Private E-2

    "Spoke" too soon. My start page is redirected to about:blank again.

    Attached is the new HJT log.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that is the typical behavior. These problems are quite stubborn and can look like they are gone for a short while. Then after open and closing a few browsing sessions and or rebooting, it is back again. Don't get frustrated. It sometimes takes multiple attempts and repetition of things already tried a few times to get rid of these issues.

    So you now have to use my Generic Solution thread: http://forums.majorgeeks.com/showthread.php?t=38772

    Follow directions EXACTLY. Read thru them first and make sure you understand everything before you start. You cannot do partial steps or skip around. You must do everything from beginning to end. The only item you can skip is the one I mention in step 6 but that is only if you do not find the services mentioned running. It is also advisable to do this in one continous flow (as best as you can).

    The items from your log that are visible to me (you will have to look for other items indicated in the procedure yourself) :

    This process (part of step 8):
    C:\WINDOWS\system32\crkj.exe

    These R0&R1 lines (needed in step 12):
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\esbri.dll/sp.html#12802
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\esbri.dll/sp.html#12802
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\esbri.dll/sp.html#12802
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\esbri.dll/sp.html#12802
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\esbri.dll/sp.html#12802
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\esbri.dll/sp.html#12802

    Thus the DLL file you will blank out in step 5 is C:\WINDOWS\esbri.dll

    Your O2 line BHO is (needed for step 7):
    O2 - BHO: (no name) - {574F8EC4-FA78-8A43-7216-A401257D764A} - C:\WINDOWS\system32\sysdd.dll

    Your O4 startup process line is (needed for step 8):
    O4 - HKLM\..\Run: [crkj.exe] C:\WINDOWS\system32\crkj.exe

    In step 12 when you are having HijackThis fix the R0&R1 lines, also add this line to the list to fix:
    O18 - Protocol: icoo - {4A8DADD4-5A25-4D41-8599-CB7458766220} - (no file)
     
    Last edited: Aug 24, 2004
  6. planders

    planders Private E-2

    I’ve read your directions to the Generic Solution and have a few questions. Thanks in advance for all your help and patience!

    In step 2, where is Windows Explorer on the XP interface? I know that’s a dumb question, but I’m actually a Mac user (please don’t hold that against me!). I remember it in the start menu in older OSs, but can’t “find” it here.

    In step 5, does it matter what name I save the empty file with? Where do I save it? I am a little confused about #5.

    In step 10, do I do a search (on the HD) for all the DLL and EXE files in step 7 and 8 and delete them from there? What do you mean by “delete the file indicated in the Path to executable” (Network Security Service)? Where do I delete? If I find it, do I include the /s in the delete?

    In step 11, do I use “Search” to find c:\windows\Prefetch ?

    Thanks,
    planders
     
  7. planders

    planders Private E-2

    One more question:
    In an earlier post you told me not to reboot because the problems might mutate. In step 1, you tell us to disable system restore and reboot. Should I reboot?

    planders
     
  8. gdb

    gdb Private E-2

    Hi, I'm also experiencing these problems (only the best and search-to-find pop-ups, and about:blank). I've already downloaded and run ad-aware and spybot search and destroy and have removed all files but the problem still occurs. I'm trying to follow the Generic solution for HSA (only the best) hijack, and have run hijack this. However I'm not sure what to fix. I've tried to create a logfile, but I was unable to save a log file as it says Error Runtime error 6 overflow when I try to save it. It seems to think that my hard drive is a read-only device when I run hijackthis (it gives it as an error message, however it still scans fine). Any help would be greatly appreciated
     
  9. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Start your own thread please. It is considered rude and confusing to start a problem in someone elses thread. Imagine your in the store waiting at the customer service line and decide to walk right past everyone and just start asking your question while the other person is talking to the customer service rep. That pretty much what you just did :)
     
  10. gdb

    gdb Private E-2

    Sorry
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can find Windows Explorer by clicking Start, All Programs, Accessories and you should then see it in the list (I always put a shortcut to it on my desktop). You can also right click on MyComputer (if it is on your desktop) and select Explore. Also, you can right click the Start button and select Explore. There are many ways to bring up Windows Explorer.

    In step 5, you are saving it to the same file name you loaded but it is just an empty file.
    If you just follow that step exactly as written, it is all taken care of for you. Basically you are loading a file into notepad, deleting all the info in the file, and writing it back out where it came from. The after doing that you need to use Windows Explorer to navigate to the directory where your file is located, right click on it, select properties, and change the attribute to read only. So for the log you gave me, you need to get to the C:\WINDOWS directory and right click on the file esbri.dll.

    In step 10, I did not say search but that could be done if you setup the search program to locate hidden files, folders, system files, etc (sort of like I had you do for Windows Explorer in step 2). It would be faster to just use Windows Explorer again though because you can see many files all at once rather that having to search for on at a time. Once found, right click on the file and select Delete.

    If you find the Network Security Service and/or the Workstation Netlogon Service running, you just need to note the full path to the filename as I indicated in step 6. In step 10, I specifically stated the /s has nothing to do with the file name. So for my example the full path said C:Windows\system32\javajt32.exe /s , you just need to go to c:\windows\system32 locate the file javajt32.exe and right click on it and select Delete. Don't forget that is an example filename. Yours (if found) will most likely be different.

    In step 11, do not use Search. Again it is too slow. Use Windows Explorer.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Remember that this Generic Procedure is written for someone going thru the steps by themselves. So they could reboot at that point and get a new HJT log and find all the correct information again.

    Since I'm trying to help you bu giving you specific names, if you reboot at that point it could change the names and you will have a problem. So if you have not rebooted or powered down since sending me the log, do not reboot after disabling system restore. Just disable it and click no if asked to reboot. Your reboot will then occur in Step 10 when we boot to Safe Mode.

    Make sure you print the information in the Generic Solution. Because it is very important that you do what step 4 indicates:

    4) Physically disconnect from the internet (pull your ethernet cable if you have DSL or cable modem. If you have an analog modem, drop your connection and unplug the telephone line to the modem.) Also at this point, you must exit all Internet Explorer sessions (it would be a good idea to exit anything that is not necessary).
     
  13. bern

    bern Sergeant

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That link will not help! It has no fixes for the about:blank problem. It also implies that CWShredder fixes the problem when it does not and never has. The only tools that have comes closes to fixing true about:blank and HSA hijacks are about:Buster and HSremove and even they don't work most of the time. At least not all by themselves. Thus, that is why I wrote the GENERIC SOLUTION FOR "Only the Best" aka "HSA" HIJACKER . While it initially was for the HSA hijack it can be use for some forms of the about:blank hijack too since there are many similarities between HSA and about:blank.


    Edit: Well reading into all those posts a lot further I found some additional posts that did have useful info. But it was the same things I have done here on MGs many times (like erasing AppInit_DLLs value if found in the registry). Nothing new.
     
    Last edited: Aug 30, 2004
  15. coboy

    coboy Private E-2

    Re: about:blank & Only the Best -- i got lost?

    hi there, i am only new to this site so i hope that you can help me, i have been following the step by step guide on how to delete the auto:blank pop-up from the computer. this is what happens, and it ONLY happens when i check my mail. what happens is that i log onto yahoo to check the mail and then when i enter my details in and i am forwarded to the mailbox the auto:blank kicks in, now it only happens when i go into the mail box, but no other page.

    i have downloaded spyware doctor, ad-aware, hijackthis, spysweeper, spybot and auobuster, i have turned off the system back up, and before this i updated everything, i then scanned the computer with all of them in saf mode, adn deleted all the files that were threats.

    i then followed the instrcutions on the http://forums.majorgeeks.com/showthread.php?t=38772 page but i got stopped by some problems, these were : Windows Registry Editor , i didnt know what key i was sposed to back up.
    however the major problem was the opening of the notepad, on the tutorial it reads ads the following: ) Now we are going to use notepad to erase the contents of the DLL file shown in the R0 & R1 lines of your HijaakThis log. To do this click Start, Run, and enter the following command "notepad c:\path\xxxxx.dll" (without the quotes) and click OK.
    an that we must change the extension name as there is no generic extension, that is fine, so what i did was take the address from the hijacklist and then tried to run it, but it sed that there was no destination of that kind. OK, so i just searched for it manually, the xxxxx.dll that is, and i found it, and then i opened it with notepad, but it was empty, even the properties says that there was 0-Bytes, so at this stage i just gave up, because it ses that the steps MUST be followed.
    Can someone please tell me what i am sposed to do to get rid of this problem,
    thank you for any help that i may receive,
    Coboy
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: about:blank & Only the Best -- i got lost?

    You are the second person to come in and try to hijack this thread. You need to start your own thread for your problem. We will be more than happy to answer you questions there. So begin a New Thread and post your questions again.

    If you don't know how to start a thread, read this: http://forums.majorgeeks.com/showthread.php?t=31333
     
  17. planders

    planders Private E-2

    Okay, here I am again:

    -I did shutdown this afternoon due to a storm that moved through the area. Probably unnecessary. Ran HJT again and thought I knew what I was doing (famous last words). I've just finished going through the steps to clean things up.

    - The HJT log that I did showed the same exe file (crkj.exe) that I know I deleted. Can you tell how I messed up?

    - In the HJT log an O2 line has a new suspicious .dll -- ipmb.dll

    -When I rebooted and started IE again I immediately got an Only the Best pop-up.

    During the clean-up:
    - Found Network Security Service and disabled. The path was this: C:\WINDOWS\REGULOCS.OLD:bsqtm /s I was looking for an exe (I thought). When I found it, I chickened out at the last minute and didn't delete. It didn't have the :bsqtm after it. Just went now and NSS had been started again.
    -Steps 13b,c,d. I ran regedit and did a search from the edit menu. Was that right?

    Attached are the two logs. I'm so frustrated, but thanks for your help!
     

    Attached Files:

  18. planders

    planders Private E-2

    Wish I could remember it all in one post - sorry for that...

    Norton Anti-Virus says that it's found a virus on my machine with this .exe:
    nettk.exe. It's in the Windows32 folder. I found it. Can I delete?
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Wow! about:Buster keeps finding a load of crap, doesn't it.

    From the HJT log you just gave me, the problem is not yet back in full swing. There were no R0&R1 lines yet. You may need to open and close a few Internet Explorer sessions and then get another HJT log. All that should right now was:

    O2 - BHO: (no name) - {EBC21DD1-18C4-74D7-C935-89E653731491} - C:\WINDOWS\ipmb32.dll
    O4 - HKLM\..\Run: [crkj.exe] C:\WINDOWS\system32\crkj.exe

    As far as finding "C:\WINDOWS\REGULOCS.OLD:bsqtm /s " . This is a new one. Are you sure you were looking at the "Network Security Service" (exact wording). Also, did you find a Workstation Netlogon Service running?

    Did you do all the steps in order? Did you have any problems finding or deleting any of the files as required (other than NSS)?
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's probably part of this hijack, and if you run another log now you will probably see it running. Running thru the procedure again will most likely remove it too. Check the two services again (NSS and WNS) to see if they are running. You will probably not be able to delete nettk.exe unless you kill the process with Process Explorer. But if other aspects of the hijacker are still running. They will just spawn a new process with a new name.
     
  21. planders

    planders Private E-2

    From the HJT log you just gave me, the problem is not yet back in full swing. There were no R0&R1 lines yet. You may need to open and close a few Internet Explorer sessions and then get another HJT log.
    The R0 and R1 lines are there now. I also have a new questionable (I'll go and check online to see if it's a legit .exe): apppi.exe. I've attached the new HJT log.​

    As far as finding "C:\WINDOWS\REGULOCS.OLD:bsqtm /s " . This is a new one. Are you sure you were looking at the "Network Security Service" (exact wording). Also, did you find a Workstation Netlogon Service running?
    I've attached a screen shot of the NSS window. I couldn't figure out how to add it the post. I think I have the right thing. It keeps on re-starting itself. Also, I did not find a Workstation Netlogon Service. There was a "Workstation", but it seemed legit.​

    Did you do all the steps in order?
    Yes​

    Did you have any problems finding or deleting any of the files as required (other than NSS)?
    I was confused in steps 13b,c,d. I didn't know how to search the registry, but I thought I'd figured it out. I went to Start->Run->Regedit. Then I did a Find from the Edit menu. Was that the right thing to do? I did not find any of the files (thought I was almost home free). I also did not find any thing in steps 13l or 13m. Also did not find any of the files mentioned in Step 15.​
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes this new process is bad: C:\WINDOWS\apppi.exe

    Your new R0 & R1 lines are:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\osfvg.dll/sp.html#12802
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\osfvg.dll/sp.html#12802
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\osfvg.dll/sp.html#12802
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\osfvg.dll/sp.html#12802
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\osfvg.dll/sp.html#12802
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\osfvg.dll/sp.html#12802

    Thus, the file to edit with notepad is C:\WINDOWS\osfvg.dll

    The new O2 BHO line is:
    O2 - BHO: (no name) - {EBC21DD1-18C4-74D7-C935-89E653731491} - C:\WINDOWS\ipmb32.dll

    And the O4 lines are:
    O4 - HKLM\..\Run: [crkj.exe] C:\WINDOWS\system32\crkj.exe
    O4 - HKLM\..\Run: [apppi.exe] C:\WINDOWS\apppi.exe


    That NSS file "C:\WINDOWS\REGULOCS.OLD:bsqtm /s " is still a new one to me but you do have it disabled. I believe it looks like this because they are using ADS (Alternate Data Streams to hide it). Hopefully about:buster can get rid of it.

    If you did not find those items in steps 13b,c, d, l or m or the ones in step 15 that's okay. We always need to check though everytime because you never know when they will occur. Sometimes about:Buster cleans them up for us.

    Run thru the process again from start to finish with the new information. Sometimes it just takes repetition to beat this sucker.
     
  23. planders

    planders Private E-2

    I'm a little afraid to say this, but things looked good on the last HJT log. I've attached the two requested. Had some weird things happen, though:

    -When I went to delete NSS (Step 6), I was able to stop it (it had re-started), but when I clicked on Properties, I got these messages: 1)Configuration Manager: A required entry in the registry is missing or an attempt to write to the registry failed, and then 2) The system cannot find the file specified. Didn't know what to do, so I just continued on with the process. Also couldn't find a path, then, in step 10.
    -In step 10 did not find apppi.exe but found apppi.exe.bak. Had no idea what bak meant, but like a crazed fool that's spent too much time on this, I deleted it. I also could not find ipmb.dll or crkj.exe. Just to be sure I did a Search. The only thing close was 3 files in C:\RECYCLER\S-1-21-18577.... and 1 file in Prefetch.


    Questions (assuming the problem has been fixed -- yes, I know what happens when you "assume"):
    1. Has this also taken care of the Only the Best pop-ups?
    2. At some point, do I need to go back and undo the "Show System Files" stuff? The tutorial said to wait a few days for the System Restore, but I didn't know about this step.
    3. I have the following programs. To make sure this doesn't happen again and/or to keep the HD in good condition, which ones should I use on a regular basis and how often (I have Nortons Antivirus and Internet Security running)? I feel like I'm asking a lot with this question. I hope it's not out of line.
    Ad-aware
    Spybot S&D
    HSRemover
    about:Buster
    HijackThis
    Ccleaner
    ProcessExplorer
    SpywareBlaster
    4. (The most important): If I haven't fixed this and/or get into trouble again, should I start a new thread or come back to this one? I've really, really appreciated your help and patience.

    Thanks and I hope this is the last you hear from me,
    planders
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    My step by step procedure mentions emptying the Recycle Bin & Prefetch in steps 11, 13g, and in 13i Ccleaner should also empty the recycle bin.

    Yes, if fixed, only the best popups should be gone.

    Leaving the show system files is a personal preference. I always have it that way. It does not hurt to leave it that way. It is sort of a Windows protecting you from yourself thing but I do not like anything hidden.

    Scanning suggestions:
    Ad-aware <--- make sure it is Ad-aware SE and run a scan bi-monthly unless you do lots of surfing, then do it weekly. If you only surf very little, you could make it monthly.
    Spybot S&D <--- Same as above
    HSRemover <--- only when needed for HSA hijacks
    about:Buster <--- only when needed for HSA or About:Blank hijacks
    HijackThis <--- only when instructed unless you want to save a snapshot of a good system and compare periodic scans to see if anything has been added that you did not know about.
    Ccleaner <--- Periodic as with Ad-aware based on surfing habits
    ProcessExplorer <--- only when instructed (unless you want to watch the Processes running on your system)
    SpywareBlaster <--- if you installed this and enable its protecting features, just leave it be and periodically check for updates. It is not a scanner, it is a blocker.

    If the problem comes back, stay in this thread.
    Right now you log looks clean. Hope it stays that way.

    And you're welcome! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds