Search to find, Only the best, about:blank. Help!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by gdb, Aug 24, 2004.

  1. gdb

    gdb Private E-2

    Hi,
    Yesterday my computer got infected by some spyware virus or whatever. The symtoms are:
    -'Only the Best' advertising windows pop up randomly (although not in the past hour, since I did the stuff listed below, but I wouldn't bet that it's gone)
    -My home page is constantly changed to about:blank
    -When I search google or yahoo (and I'm guessing any other search engine) a new window appears at search-to-find.com with another engine searching for what I typed in google (or yahoo etc). It has a help page which says it can be removed from add/remove programs but this doesn't work (gives a error message).

    Initially I tried deleting various files which were modified at the time when I got the virus, but this did nothing, indeed some files came back. I downloaded and ran Ad-Aware, Spybot- Search & Destroy and CW Shredder. They found and fixed a lot files but the problem remains. I have looked at threads on removing viuses and followed the 'READ ME FIRST: Basic Spyware, Trojan And Virus Removal' thread to no avail. I have printed the 'When all else fails - try Generic Solution to HSA (Only the Best) hijack' thread and think maybe I should follow it. However the site advises to ask before using HijackThis. I did do a scan with it but for some reason it wouldn't let me save a log file, giving the error message 'Runtime error 6 overflow'. When I load HiajackThis it gives a message saying I am running it from a read-only device even thogh it's on my hard drive (it was in My Documents, then I gave it it's own directory in Program Files, but it seems to make no difference).

    Her is my system info:
    Make: Gateway
    Processor: Pentium 3 500MHz
    RAM: 256 Mb
    Hard Disk: Approx.40Gb , most of which is free
    Operating System: Windows 98

    Please could someone help me in removing this.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Where did you download HijackThis from?
    If not from MGs, download it here

    And try to run it again. If that still gives you an error, boot in safe mode and try running it. Let's see if that works.

    You probably will need to use the 'When all else fails - try Generic Solution to HSA (Only the Best) hijack' thread. I would bet that you hijack has come back by now.
     
  3. gdb

    gdb Private E-2

    I downloaded HijackThis fromt the MajorGeeks website on Monday night, but just to make sure I downloaded again from your link (and put it in it's own directory in the Programs folder). But it still has the same error message, even in safe mode. When I run the program it says:
    "It looks like you're running HijackThis from a read-only device like a CD or a locked floppy disk. If you want to make backups of items you fix, you must copy HijackThis.exe to your Hard Drive first, and run it from there.
    If you continue, you might get 'Path/File Access errors' - Do NOT e-mail me those please."
    Then it goes into to the program and everything works fine, including the scan. But when I try to 'save log' it says "Run-time error '6' Overflow".
    There is then a file created called "hijackthis.log" but it is 0kb in size, so is obviously empty.

    I think I should use the 'When all else fails - try Generic Solution to HSA (Only the Best) hijack' thread but if I can't post the log file I will have to work out which lines are bad by myself (I'm not really familiar with the technical stuff in it). What do you think?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Use Windows Explorer to get to the directory where you put HijackThis. Right click on the directory name and select Properties. Now look at the attributes and make sure it is not Read Only or Hidden.

    Edit: Try the above but I don't think that is the problem.

    Please download and run these:
    http://www.majorgeeks.com/download4113.html
    http://www.majorgeeks.com/download4086.html

    And then try HJT again.

    Also, have you run scandisk on your drive recently? If not, please do so.
    Also please run these online scans and let me know if they find anything:
    http://www.bitdefender.com/scan/license.php
    http://www.pandasoftware.com/activescan/com/activescan_principal.htm
    http://housecall.trendmicro.com/housecall/start_corp.asp
    http://www.windowsecurity.com/trojanscan/
    http://www.ravantivirus.com/scan/
     
    Last edited: Aug 24, 2004
  5. gdb

    gdb Private E-2

    Ok I'll try that, but I'm going away for few days so I probably won't be able to do it till at least monday. I'll post back here around then, and thanks a lot for the help.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Talk to you then.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds