About blank problem....what should I take out of this hijack this log????

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by skd44, Aug 16, 2004.

  1. skd44

    skd44 Private First Class

    I recently ran into the web browser hijacker known as about blank. After alot of research on how to remove it from my computer (all of which was either unsuccessful or I did not understand it) I came across the hijack this program and used it but I am not sure what I am supposed to remove as I read it can be harmful to remove the wrong things. I know the line ending with about:blank needs to go but I tried that alone and yet it still came back right away!!!! Can anyone help....here is my log file from hijack this:

    Logfile of HijackThis v1.98.2
    Scan saved at 4:12:40 PM, on 8/16/2004
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)
     
    Last edited by a moderator: Aug 16, 2004
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to follow some guidelines. HijackThis is the last step not the first. See the stickies on the main page of the Spyware Forum.

    Please follow all the steps in this Sticky thread < READ ME FIRST: Basic Spyware, Trojan And Virus Removal > If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    NOTE: Per the tutorial in this Sticky thread < Hijack This Tutorial And How To Post Your Log File > your log file file has been removed.

    Update! Due to Hijack This logs destroying search engine and web site searches, we now ask you do not post your Hijack This log file unless requested by us. It is for advanced users, so if you do not understand how to use it, you do not need it....yet. Instead, please tell us in your post what symptoms you are experiencing so we can try and resolve it that way. When, and if, we ask you to post your log file, please attach it as a file. To do this save the log file and select manage attachments in a new thread to upload it. All running programs should be closed, including your web browser, e-mail, items in the tray, anything you can close... Close before running Hijack This!

    Do not to install Hijack This to the Desktop, a temp folder or choose run from the download. Place it in its own folder, for example C:\Program Files\HJT


    Make sure you have the proper versions for each program! Pay particular attention to running the HSremove and About:Buster programs.
     
  3. skd44

    skd44 Private First Class

    Thank you for your input and quick response to my question. I also want to apologize for trying to post my log file when you have specifically instructed people not to do so unless asked....I had not seen that thread before I posted mine so again, I am sorry for that. I will try what you have recommended as I am willing to do whatever it takes to rid myself of this annoyance. Thank you for your response and I will reply again if I run into problems.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Let us know either way (success or failure)!
     
  5. skd44

    skd44 Private First Class

    For step #3 in the getting prepared secion of basic spyware and trojan removal article I do not have a listing for Network Security Service so I could not stop it.....does that mean I can't continue to steps 4,5,6 or can I just move on. Thanks again!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just continue on. If you do not find it, it just means it is not running.
     
  7. skd44

    skd44 Private First Class

    Should I download all of the recommended programs that you list in steps 1-6 of the section titled Time to Start Scanning and Cleaning? I have done everything up until that point but I have not yet rebooted in safe mode nor have I run the scans recommended yet because I am not sure if I am supposed to only run them in safe mode. I have already downloaded spybot, ccleaner, and adaware but I have not run them yet nor downloaded the other removal tools you list because I am not sure if I need them all or only some. Thanks again....I would be lost without this site.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run the TrendMicro and PandSoftware scans first!
    Then do the following:
    - install Ad-aware SE & SpyBot S&D. Make sure you update them immediately after installing. You do not need to run them yet.
    - install Ccleaner and Run it and on the Windows tab (you'll see when you run it) leave the defaults and click Run Cleaner
    - download and extract CWShredder to a directory you can find later
    - download and extract about:Buster to a directory you can find later
    - download and extract Kill2Me to a directory you can find later
    - Run about:Buster once in normal boot mode (right now)

    - immediately reboot in safe mode and run the following:
    - about:Buster
    - Ad-aware SE - fix what it finds
    - SpyBot - fix what it finds
    - Kill2Me
    - CWShredder (be sure to click FIX)

    Now reboot in normal mode and run about:Buster one more time.
    Come back here and tell me how things are working. If still having a problem, post a new HijackThis log (as an attachment).
     
  9. skd44

    skd44 Private First Class

    I can't seem to run aboutbuster. I keep getting a runtime error every time I try to run it. I downloaded and extracted it and yet it won't run....that runtime error message keeps popping up.
     
  10. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

  11. skd44

    skd44 Private First Class

    Thank you very much for all the help. Despite the fact that I moved at a snails pace I used all the recommedations you provided me with chaslang and finally it seems there is no more aboutblank problem on my computer. I apologize if it seemed I was a moron asking questions with each step but I have never worked in safe mode before nor have I ever downloaded and used so many spyware programs. I truly appreciate all the help and I now know there is a great place to go for computer idiot's like myself. Thanks again for all your help.
     
  12. skd44

    skd44 Private First Class

    Well I was rid of the aboutblank problem for about half an hour, or so I thought. I logged off my computer and just turned it back on and my homepage was right back to aboutblank. I am going to attempt to attach my hijack this log as an attachment now for your viewing. I am only doing so after being told I could if all other options failed and they seem to have so here goes.....
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is the typical behavior for About:Blank and HSA hijacker problems. They appear to be gone and they come back either after a couple reboots or after opening and closing a few Internet Explorer sessions. These buggers are very difficult to remove and always require repeatitive processes (and some new ones interleaved here and there).

    Now it is time to post me a current HijackThis log (as an attachment).
     
  14. skd44

    skd44 Private First Class

    I finally figured out how to correctly attach my hijack this log to this reply. I hope it is correct. Thanks again.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do not have the About:Blank hijack. You have the HSA hijack. You should start looking at my Generic Solution thread to see if you have any questions understanding what to do there. This procedure needs to be executed in one continuous flow (you should not stop and continue later) and absolutely do no reboot or shutdown once started (unless indicated in the steps) or you will have wasted all your time up to that point. I look at your current log and give you a few pointers while you look over the procedure (do not reboot or shutdown after I give you these pointers otherwise the names of files may change). I'll post that info in a little while.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is your file for step 5: C:\WINDOWS\system32\gdaoe.dll
    This is your line for step 7: O2 - BHO: (no name) - {FA991F0E-1BD9-6EAD-EFEC-2317207D5E37} - C:\WINDOWS\apitv32.dll
    This is your line for step 8: O4 - HKLM\..\Run: [javaeb32.exe] C:\WINDOWS\javaeb32.exe

    In step 10: you will be delete:
    C:\WINDOWS\apitv32.dll
    C:\WINDOWS\javaeb32.exe
    and any file you may have found from step 6 with Network Security Service

    In step 12: you lines are:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\gdaoe.dll/sp.html#96676
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\gdaoe.dll/sp.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\gdaoe.dll/sp.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\gdaoe.dll/sp.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\gdaoe.dll/sp.html#96676
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\gdaoe.dll/sp.html#

    But also fix this line too right now:
    O18 - Protocol: icoo - {4A8DADD4-5A25-4D41-8599-CB7458766220} - (no file)

    See if you can take it from there.
     
  17. skd44

    skd44 Private First Class

    I don't want this to seem stupid but if I don't have the aboutblank then was does my homepage always open as about blank and when I go into tools, internet options to change my hompepage back it says about blank. I don't mean to ask an already answered question but its all confusing.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I think it is due to this one line:
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank

    It is possible this is one of the many forms of about:blank but it looks more like the original HSA hijack problems so that is why I said that and recommend the Generic Solution.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds