about:blank Problem!!!!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by diamonddave76, Sep 11, 2004.

  1. diamonddave76

    diamonddave76 Private E-2

    I am having problems when I open internet explorer it goes to some search page and when I go to change my homepage it lists about:blank as the homepage. I have tried changing this but it resets itself. Also if I go to certain webpages it suddenly pops up the about:blank page. I have tried to go to windows update but it jumps to the about:blank page here also. I hope you can help me with this problem. Thanks.
     
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

  3. diamonddave76

    diamonddave76 Private E-2

    I tried all the stuff in the thread you provided and it worked for a little while but then it came back and started doing the same thing again.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  5. diamonddave76

    diamonddave76 Private E-2

    Ok here you go. I hope this helps solve the problem.
     

    Attached Files:

  6. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    I dont see Chaslang online, so going to get you started. Please remove:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\TEMP\sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\WINDOWS\TEMP\sp.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\TEMP\sp.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\WINDOWS\TEMP\sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\WINDOWS\TEMP\sp.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\WINDOWS\TEMP\sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    O2 - BHO: (no name) - {3DF009ED-54BF-4A31-AADC-679997254A74} - C:\WINDOWS\SYSTEM\AIGHKH.DLL
    O15 - Trusted Zone: *.windupdates.com
    O15 - Trusted Zone: *.searchmiracle.com
    O15 - Trusted Zone: *.skoobidoo.com
    O15 - Trusted Zone: *.my-internet.info
    O15 - Trusted Zone: *.mt-download.com
    O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie
    O18 - Filter: text/html - {7CC1DA6A-B893-4E55-997E-8046D9F77D8B} - C:\WINDOWS\SYSTEM\AIGHKH.DLL
    O18 - Filter: text/plain - {7CC1DA6A-B893-4E55-997E-8046D9F77D8B} - C:\WINDOWS\SYSTEM\AIGHKH.DLL
     
  7. diamonddave76

    diamonddave76 Private E-2

    Ok it is working for now hopefully this has fixed it for good. I will let you know within the next day or so if it comes back. Thanks.
     
  8. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Good, I am always glad to hear that. Come on back anytime.
     
  9. diamonddave76

    diamonddave76 Private E-2

    Well it worked for like a day and then it came back. Well I guess we can try again. Hopefully we can can fix it for good this time.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I want you to download the following two programs
    Win98Fix - http://www10.brinkster.com/expl0iter/freeatlast/pvtool.htm
    StartDreck - http://members.blackbox.net/hp_links/21/nikolaus.rameis/download/startdreck.htm

    Unzip them to a place where you can find them later to run. We are only going to run StartDreck right now.

    This step is very important - you need to be completely disconnected from the internet (physically disconnecting the line to your analog modem or ethernet cable from your computer is best way to be positive).
    What we are going to try to do is identify the hidden file that is causing the problem. So now we are ready.

    - Run StartDreck.exe
    - Click on: Config
    - Click on: Unmark all
    - Check only the following boxes:
    - Registry | run keys
    - System/drivers | Running processes
    - Click on OK

    Post the log of results AS A TEXT ATTACHMENT.
     
  11. stevo4

    stevo4 Private E-2

    Hi,
    I'm following this thread to better educate myself.

    Is it possible that this person has successfully cleaned his computer, but hasn't closed the access point? So, his computer is fine until he revisits the problem website and gets reinfected again?

    If this were the case, how does one begin to determine which web page, and what port, etc. needs to be closed to prevent it?

    Do you just have to have all the spyware software running in the background at all times?

    Thanks,

    stevo
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    About:Blank and HSA hijacks come back all the time. They are very difficult to remove. While it is obviously a problem that can come back if you go back and do the same things that cause it in the first place, that is not typically the problem. The normal problem as to why it comes back is the the cleanup process did not find all the components of the hijacker (many of the them are super hidden).
     
  13. diamonddave76

    diamonddave76 Private E-2

    Ok here it is.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First the Prep work:

    The hidden installer is this one: C:\WINDOWS\SYSTEM\WDMK.DLL

    Please download and unzip CWShredder but do not run - http://www.majorgeeks.com/download4086.html

    Make sure you have downloaded and installed (do not run a scan yet) the current version of
    Ad-aware SE - http://www.majorgeeks.com/download506.html
    Make sure you immediately update to the current reference list by clicking
    the "Check for updates now" button.

    Now you must disconnect physically from the Internet and remain disconnected until I tell you to reconnect. You should therefore print or save this instructions locally.

    Now we need to find the problem file:
    Now use Windows Explorer to get to the directory where you saved the Win98Fix.zip
    file I had you download in my last message. Unzipped the Win98Fix.zip to a folder.
    Then doubleclick on RunFix.reg file and click Yes on the prompt.

    Now you must Reboot your computer! Do not run Internet Explorer after
    rebooting and remain disconnected from the Internet.

    The hidden file should now be visible. Click on Start, Find, Files or
    Folders and enter the name of the file (WDMK.DLLL). It will be located in
    C:\WINDOWS\SYSTEM\WDMK.DLL Once you find it, right click on it and
    select delete.

    Now please run CWShredder and make sure you select the Fix button.
    Next run Adaware by clicking on the Scan Now button and select "Perform full system scan".
    When scan is finished, make sure you select all items found and have them fixed.

    Now run HijackThis and have it fix the following lines (these came from your previous HijackThis log, hopefully they have not mutated. If so, see if you can locate the similar problem lines to fix. Otherwise we may need to start over again.)


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\TEMP\sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\WINDOWS\TEMP\sp.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\TEMP\sp.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\WINDOWS\TEMP\sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\WINDOWS\TEMP\sp.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\WINDOWS\TEMP\sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    O2 - BHO: (no name) - {3DF009ED-54BF-4A31-AADC-679997254A74} - C:\WINDOWS\SYSTEM\AIGHKH.DLL
    O18 - Filter: text/html - {7CC1DA6A-B893-4E55-997E-8046D9F77D8B} - C:\WINDOWS\SYSTEM\AIGHKH.DLL
    O18 - Filter: text/plain - {7CC1DA6A-B893-4E55-997E-8046D9F77D8B} - C:\WINDOWS\SYSTEM\AIGHKH.DLL

    Right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot again and reconnect to the internet. Come back here and post a new HijackThis log ATTACHMENT.
     
  15. diamonddave76

    diamonddave76 Private E-2

    I did all the other stuff you said but when I ran Hijackthis the lines you said to fix did not show up. Here is a copy of my log file from hijackthis.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Questions:
    1) Is this from your ISP:
    O2 - BHO: PeoplePC FixedBandBHO - {3DE88907-3E38-11D4-BEB2-CBE76C0598DD} - C:\PROGRAM FILES\ISP50\BIN\BANDOBJECT.DLL

    2) And am I correct in assuming you still have system restore disabled?

    I don't know where you are surfing but problems from your first HJT log have returned. You need to install some protection tools before we can fix this. I would recommed you download and install these two free tools:

    http://majorgeeks.com/download2859.html SpyWare Blaster <--- enable all of its protections
    http://majorgeeks.com/download3045.html SpyWare Guard

    Then reboot! And run HijackThis and fix the below lines (make sure no browser windows are open):
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
    O15 - Trusted Zone: *.windupdates.com
    O15 - Trusted Zone: *.searchmiracle.com
    O15 - Trusted Zone: *.skoobidoo.com
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/12ee51d9cfedb46c7805/netzip/RdxIE601.cab
    O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=230270dab455d0e176941480ba0fc85f2978d245429f93809c10f10b815c8a96c9ba5c54063f7603d4945ab86ee97ff22322f046:375a82d108ec2e9d584f880889783bc3

    Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com (you can set it to your desired home page if you prefer something different). Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot. And before running anything else, run HJT and save an HJT log (log1.txt).
    Now do some surfing opening and closing Internet Explorer sessions a few times.
    Run HJT again and save an HJT log (log2.txt)

    Post both HJT logs as attachments here.
     
  17. diamonddave76

    diamonddave76 Private E-2

    OK I did all the stuff you said to do and hopefully we have fixed the problem now. Here are the 2 HJT logs.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not answer my questions!
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis and put checks on the following lines BUT DO NOT CLICK FIX until all browsers sessions including the one you are reading in right now are closed:
    O2 - BHO: (no name) - {260352B0-91F7-471B-BADB-6CF2B764D70E} - C:\WINDOWS\SYSTEM\AEOFB.DLL (file missing)
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O18 - Filter: text/html - {68E94CDF-73FB-4445-8504-F2BF4B8C87E5} - C:\WINDOWS\SYSTEM\AEOFB.DLL
    O18 - Filter: text/plain - {68E94CDF-73FB-4445-8504-F2BF4B8C87E5} - C:\WINDOWS\SYSTEM\AEOFB.DLL

    Reboot and post a new HJT log. Tell me how things are working.
     
  20. diamonddave76

    diamonddave76 Private E-2

    Sorry, yes PeoplePC is my ISP and I do still system restore disabled.
     
  21. diamonddave76

    diamonddave76 Private E-2

    Ok things seem to be working 100% better now. It does not open the about:blank page anymore when I open internet explorer. Thank you very much. Here is the HJT log you requested. Let me know if you notice anything in it that is messed up. Thanks again.
     

    Attached Files:

  22. mungo

    mungo Private E-2

    you might want to add that these programs should be run in safe mode.
     
  23. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Log file looks squeaky clean. Only thing you could remove, though not harmful is

    O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - (no file)

    Simply because of the no file at the end it is not useful.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Agreed!! Looking good now! Like a diamond, Dave! ;)
     
  25. diamonddave76

    diamonddave76 Private E-2

    OK thanks for all the help.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds