HijackThis=Hijacker

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by forumfollower, Sep 7, 2004.

  1. forumfollower

    forumfollower Private E-2

    Friend who has downloaded HijackThis from your link has discovered that default start page in configuration of this program is aboutblank. Do you think this a tad of a problem? :)
     
  2. solaris89

    solaris89 First Sergeant

    That means it's setting your start page to nothing.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The default start page is set on your computer, not by HijackThis. HijackThis just reads the registry and tells you what you have it set to. If you want it set to about:blank, that's okay. If you have the about:blank hijack, that's a problem.
     
  4. Sammo

    Sammo Private E-2

    Hallo All,
    Please note; I am not hijacking this thread, I am replying!
    Dear forum follower,
    I did not say "hijack this=hijacker"; I asked why hijack this would use "about:blank" to cure hijacked browsers. Chaslang (band breaks out "in hail to the chief")explained the difference. My home page has not been hijacked, I stay away from "dodgy" sites;
    "HELP!!!!!!!!!" I think I'm becoming a Geek.

    God Bless all at MG,
    Best regards

    Sammo
     
  5. Kodo

    Kodo SNATCHSQUATCH

    because HiJackThis doesn't know what you want your home page to be, it makes it the default blank page. You must then reset it to what you wish.
     
  6. taooat

    taooat Private E-2

    i am the friend with about blank hijacker. after a number of attempts i finally got registered. thanks to forum follower for posting my problem. i have followed the instructions for killing about blank as posted here. being poor i do not have the plug ins for ad aware but i am using:
    mcafee firewall and virus scan
    bazooka
    cwshredder kill2me
    aolspyware
    aboutbuster
    spyware blaster
    spybot search and destroy
    winpatrol
    ad aware 6
    no adware
    hijack this
    i also have the windows firewall.
    i have earthlink and aol service, in internet options i have earthlink as my start page.
    after running hijack this about blank is listed in configuration as my start page.
    i have noticed that the reconnect sevice from earthlink has a reset password that i cannot change.
    after running the sequence for cleaning posted here winpatrol always says that it has detected my start page being reset to google. i decline.
    does about blank hide in the toolbar from earthlink?
    as my harddrive died about a month ago i don't have much to lose on it and i am about ready to dump the whole thing and reinstall windows.
    it only took three tries with the men from mombay at dell support screwing me up the first two times but i've put more time in trying to stop about blank then it took to reinstall. will that get rid of my problem?
    spybot always finds the same five bad keys when i run the sequence.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Get rid of NoAdware, it is a rogue/fake spyware remover.
    You never even gave us an OS?

    Have you look at When all else fails - try Generic Solution to HSA (Only the Best) hijack

    It will work on about:Blank issues too if you fit the format as described for HSA.

    And yes, a clean install of you system will obviously fix the problem. But if you still do not have the correct protection on your system and surf wherever you have been surfing, you will most likely get the problem again (or even the HSA hijack next time).
     
  9. taooat

    taooat Private E-2

    i'm running windows xp home on a dell dimension 4600c.
    i looked at the posting but did not find the services mentioned so did not think it applied.
    got the updated se version of adaware and deleted the no good one.
    could not figure out how to get free plug ins.
    se version found nothing.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  12. taooat

    taooat Private E-2

    here's the last one
     

    Attached Files:

    Last edited by a moderator: Sep 8, 2004
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's not an attachment. That's what we call inline text. You need to read the HijackThis tutorial again. I'll fix it for you this time.

    Also you are running HijackThis from the ZIP file:
    C:\DOCUME~1\Owner\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

    You must extract the hijackthis.exe file into its own folder (not a temp folder and not to your desktop). Do this immediately.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must remember to shutdown ALL unnecessary applications too before running HijackThis. Again I say read the tutorial please. Why do you have these running:
    C:\Documents and Settings\Owner\Desktop\AboutBuster\AboutBuster.exe
    C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe

    Also note, that the About:Buster tool try to change your start page to google.com when it runs. It does this so that you know it has run and also because it has no idea what you want it set to.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I see no signs of an about:blank hijack. Did you post your log after already fixing it and while there were no problems? Or are the problems gone?

    Care to explain exactly what problem you are having? What are you doing step by step to get whatever problem you think you have?
     
  16. taooat

    taooat Private E-2

    every time i close an internet explorer window about blank appears and internet explorer has to close. dr watson post problem analyzer starts and then has to close. about blank does not respond to close program. these all generate report problem to microsft boxes.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    None of those symptoms appear to be related to an about:blank hijack.

    What do you mean by "about blank does not respond to close program"? Are you talking about the Internet Explorer session? Sounds more like you have an installation problem or corrupted files then spyware.

    The original message said your start page was getting set to about:blank.
     
  18. taooat

    taooat Private E-2

    following the tutorial i ran the recommended tools before using hijack this.
    blaster got the search for it toolbar
    it had returned by the time i ran spybot which also found 4 DSO EXPLOIT HKEYs.
    many of the instructions in the tutorial and here seem unclear to me. i will try to find someone geekier to help me with them.
    thanks for your time
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    ??? blaster got the search for it toolbar ??? What??

    Ignore the DSO Exploits with SpyBot. It is a well known bug.

    Read the tutorial again. We made some changed just today.

    I'm still not convinced you have a spyware/malware problem.
     
  20. taooat

    taooat Private E-2

    you were right it wasn't the hijacker. some how i had hit the custom button while on msconfig and restoring the default fixed the problem. it has been quite the learning experience doing something stupid. thanks for your time.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Cool! Glad I could help!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds