RSS Forums RSS

About:Blank homepage ...

Please support our Viruses, Spyware and other Nasties advertiser: Programming Forums
Closed Thread
Posts: 9
Reputation: Ohhhhhhhhhh is an unknown quantity at this point 
Solved Threads: 0
Ohhhhhhhhhh Ohhhhhhhhhh is offline Offline
Newbie Poster

About:Blank homepage ...

  #1  
Apr 25th, 2004
Hey, i run hijackthis and removed what i've been told before .. and it works great untill i reboot my computer, it's all back !

Anyways, after running HijackThis and removing the files, i also run adware and i also run cwshredder, everything seems to work great .. i also delete all of my cookies and clear ie 6's history !

As soon as i reboot, about:Blank is set back as my homepage.

anyways here's what i get after running hijackthis ...

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Free Surfer\fs20.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\SIMONG~1\LOCALS~1\Temp\Rar$EX00.422\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\ecmdca.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\ecmdca.dll/sp.html (obfuscated)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\ecmdca.dll/sp.html (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\ecmdca.dll/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\ecmdca.dll/sp.html (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\ecmdca.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {CF960536-98BA-40AD-A2E2-1BC8763B6920} - C:\WINDOWS\System32\ecmdca.dll
O4 - HKLM\..\Run: [freesurfer] C:\Program Files\Free Surfer\fs20.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O9 - Extra button: Free Surfer (HKLM)
O9 - Extra 'Tools' menuitem: Free Surfer (HKLM)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -


Any help would be great ! Thanks
AddThis Social Bookmark Button
 
Posts: 9,294
Reputation: crunchie is a name known to all crunchie is a name known to all crunchie is a name known to all crunchie is a name known to all crunchie is a name known to all crunchie is a name known to all 
Solved Threads: 596
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: About:Blank homepage ...

  #2  
Apr 25th, 2004
This was written by Mosaic 1, a security expert on another forum. Follow instuctions exactly. At the moment there is no easy way.

Get the latest CWShredder from this page. Do not run it yet:
CWShredder

Download TheKillbox from this link: here.
------------------
Sign off the internet.
Run CWShredder and press the fix Button to clean.


Stay off the internet!
Step Two:
Remove the reinstaller:
Go to start>Run and type regedit. Press enter.

Navigate to:
Open the registry and navigate here:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
Highlight Windows in the left pane.

Look in the right pane for this value:
AppInit_Dlls

You won't see any data there.

But if you right click on that and choose Modify Binary Data you will.

If nothing is there it should just show a few 0's.

But if they are hiding a dll they load to reinstall, it will show a path to it.


----------------------------
This is how one looks when there is only one file loading.
0000 00 00 3A 00 5C 00 77 00 ..:.\.w.
0008 69 00 6E 00 64 00 6F 00 i.n.d.o.
0010 77 00 73 00 5C 00 73 00 w.s.\.s.
0018 79 00 73 00 74 00 65 00 y.s.t.e.
0020 6D 00 33 00 32 00 5C 00 m.3.2.\.
0028 6D 00 73 00 6B 00 6B 00 m.s.k.k.
0030 67 00 2E 00 64 00 6C 00 g...d.l.
0038 6C 00 00 00 l...

Notice on the far right. You want to look there. It looks funny because all of the periods.

Look closely and you'll see the path and file name here was:
Windows\system32\mskkg.dll

This was the example. Yours will have its own file name. This is not the same file as you are seeing in your HijackThis log. Get its name the same as I just described.
--------------

Once you have the filename unzip TheKillBox and run it.

In the "Paste Full Path of File to Delete" box, copy and paste the following:

c:\windows\system32\filename Where filename is what you found as the filename in the appinit_dlls key in the registry.

Don't click any of the buttons though, instead please click on the Action menu and choose "Delete on Reboot". On the next screen, click on the File menu and choose "Add File". The c:\Windows\system32\filename listing should show up in the window. If that's successful, choose the Action menu and select "Process and Reboot". You'll be prompted to reboot. Restart the Computer.

When you get back into Windows reset your Search and Home pages.

Look in the registry and remove the entry which should now be clearly visible and no longer hidden.


This last part and removing the AppInit_Dlls entry and its corresponding file is removing the reinstaller. So you do not get reinfected. Do not go on the internet until you have performed all of the steps.
--------------------------------
Proud member of ASAP (Alliance of Security analysis Professionals).
Opera AVAST anti-virus Comodo Firewall Spywareblaster

Please do not PM me for help, (I will ignore you if you do). Instead, post in the public forum where others may benefit.
 
Posts: 9
Reputation: Ohhhhhhhhhh is an unknown quantity at this point 
Solved Threads: 0
Ohhhhhhhhhh Ohhhhhhhhhh is offline Offline
Newbie Poster

Re: About:Blank homepage ...

  #3  
Apr 26th, 2004
Hey Crunchie !

Thanks a lot -- i did what you told me and i rebooted my computer and it's now set to whatever i wanted !

Thanks again, this experience was just soo damn frustrating !!
Anyways take care buddy !
 
Posts: 9,294
Reputation: crunchie is a name known to all crunchie is a name known to all crunchie is a name known to all crunchie is a name known to all crunchie is a name known to all crunchie is a name known to all 
Solved Threads: 596
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: About:Blank homepage ...

  #4  
Apr 26th, 2004
Thanx to Mosaic1. Cheers.
Proud member of ASAP (Alliance of Security analysis Professionals).
Opera AVAST anti-virus Comodo Firewall Spywareblaster

Please do not PM me for help, (I will ignore you if you do). Instead, post in the public forum where others may benefit.
 
Posts: 1
Reputation: autorep is an unknown quantity at this point 
Solved Threads: 0
autorep autorep is offline Offline
Newbie Poster

Help If you still have problems after all this

  #5  
May 19th, 2004
I figured I would drop a short note, as none of the above referenced suggestions would help me this go around. Between Norton Antivirus & Firewall, CWShredder, Spybot Search & Destroy, and Hijack This (all good programs) I could not fix this problem this time. My homepage would still revert back to the about:blank search page no matter what I did! After fooling around with my computer for nearly 4 hours, I finally fixed it by logging in as the administrator under safe mode and running the CWShredder, man that program is awesome (thanks merjin)!. Normally, my anti-virus would pick up everything under safe mode, or CWShredder would normally pick up everything in regular Windows operation, but not this time, my home page would still revert back to the about:blank. So I guess the virus coming in would effect even at the administrator level.

Anyway, hope that helps someone. I swear these viruses are getting more and more nasty! They seem to start spoofing or blocking themselves from being detected by my anti-virus and even start controlling it, like keeping my Live update from working and stopping from detecting viruses as well! It's getting harder and harder to stop the attacks! Thinking about getting a Mac instead!! LOL. Either that or stay away from the porn sites!!!
 
Posts: 6,439
Reputation: DMR will become famous soon enough DMR will become famous soon enough 
Solved Threads: 339
Colleague
DMR's Avatar
DMR DMR is offline Offline
Wombat At Large

Re: If you still have problems after all this

  #6  
May 19th, 2004
Originally Posted by autorep
Thinking about getting a Mac instead!!

Bah! - just install Linux on your PC. :mrgreen:

Actually, just switching to a browser other than IE will protect you from a lot of this stuff if you need to stick with Windows.
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing


Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.

However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
 
Posts: 9,294
Reputation: crunchie is a name known to all crunchie is a name known to all crunchie is a name known to all crunchie is a name known to all crunchie is a name known to all crunchie is a name known to all 
Solved Threads: 596
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: About:Blank homepage ...

  #7  
Jun 13th, 2004
Originally Posted by frustrated
Hi, my homepage has been set to about:blank and everytime i tried to fix the problem with CWShredder, it comes back everytime I restart the computer.

Splitting out your post to it's own thread so that you can recieve better assistance

http://www.daniweb.com/techtalkforums/thread6943.html
Proud member of ASAP (Alliance of Security analysis Professionals).
Opera AVAST anti-virus Comodo Firewall Spywareblaster

Please do not PM me for help, (I will ignore you if you do). Instead, post in the public forum where others may benefit.
 
Posts: 4
Reputation: happyguy is an unknown quantity at this point 
Solved Threads: 0
happyguy happyguy is offline Offline
Newbie Poster

Re: About:Blank homepage ...

  #8  
Jun 15th, 2004
about:blank trojan removed!
(aka HomeOldSP hijacker)

I tried most adware programs to no avail.
The wicked pest kept returning.
Now I am happy to report that there is a cure:
Adware Away.
It is as easy as pie to use.
The about:blank trojan was killed in minutes.

Click "more" on Adware Away's menu.
Icons with names of various hijackers are displayed.
Click on those bothering you, and they're gone!!

In fact it also trashed
CoolWebSearch, Lycos SideSearch and IstBar -
trojans I didn't even know I had. All I can say,
"Adware Away is FANTASTIC".

www.AdwareAway.com
 
Posts: 6,439
Reputation: DMR will become famous soon enough DMR will become famous soon enough 
Solved Threads: 339
Colleague
DMR's Avatar
DMR DMR is offline Offline
Wombat At Large

Re: About:Blank homepage ...

  #9  
Jun 15th, 2004
Originally Posted by happyguy
Now I am happy to report that there is a cure:
Adware Away.

Which is, unfortunatley, only a 5-day trial; after that you have to buy it. Funny that you'll find no mention of the fact that the trial is a download unless you dig to the bottom of their FAQ... :rolleyes:
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing


Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.

However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
 
Posts: 9,294
Reputation: crunchie is a name known to all crunchie is a name known to all crunchie is a name known to all crunchie is a name known to all crunchie is a name known to all crunchie is a name known to all 
Solved Threads: 596
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: About:Blank homepage ...

  #10  
Jun 16th, 2004
Originally Posted by kuelze
I have or possibly had the about:BLANK malware problem. I took a lot of actions getting rid of the malware BHO dll that puts the the keys in the register and loads the SP.HTML page but I could not figure out how to find the malware dll that installs the BHO dll until I saw your post. I thought this was the solution so I traced your path HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows and guess what I don't have a windows under current version. I said oh well and searched the register for appinit_dll keys and guess what-- it has none. Do you have any idea how I could have this malware problem but without the indicators you describe. Earlier today this problem struck--I could not open the Iexplorer and than suddenly it opened at least 10 Iexplorer windows and my firewall router started to blink so fast I thought it was going to bounce off the table. I unplugged it. After unplugginig and rebooting I took all the Hijackthis and Adware actions to clean out all possible register entries and delete the DHO dll. I plugged back in the router and have been working okay since then (8 hr's ago). I am wondering that by unplugging and re-plugging my router the router will assign new local IP addresess on my LAN and this prevents the Malware from accessing the computer which had the malware problem. Any ideas on this or any other way I can find the hidden malware dll.


Have split out your post to it's own thread.
Proud member of ASAP (Alliance of Security analysis Professionals).
Opera AVAST anti-virus Comodo Firewall Spywareblaster

Please do not PM me for help, (I will ignore you if you do). Instead, post in the public forum where others may benefit.
 
Closed Thread

Only community members can participate in forum threads. You must register or log in to contribute.



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum
Views: 27079 | Replies: 14 | Currently Viewing: 1 (0 members and 1 guests)

 

Thread Tools Display Modes
Forums | Blogs | Tutorials | Code Snippets | Whitepapers | RSS Feeds | Advertising
All times are GMT -4. The time now is 12:55 pm.
Newsletter Archive - Sitemap - Privacy Statement - Acceptable Use Policy - Contact Us
Forum system based on vBulletin Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
©2003 - 2008 DaniWeb® LLC