HolidayBuyer's Guide

Spyware, Viruses, & Security forum

General discussion

NEED HELP/ADVICE

by Jodi / September 1, 2004 5:50 PM PDT

Today while surfing the internet two extra IE browser windows popped up, one read welcome, the other about blank. I knew about blank was a bad thing so I shut down, restarted ran spybot s&d, anti vir9x, panda online scan, and trend micro's house call-sll empty handed. I searched the web for an outside opinion and ran a scan that found something that may have said bagle (32?), and gave a location of HKEY_LOCAL_MACHINE\software\microsoft\windows\current version or something like that, the tool wouldn't remove it unless I coughed up $30, and I didn't so I need info on how/where to investigate further, and fix problem. THANKING YOU IN ADVANCE! I run windows 98 second edition...please note: I tried to locate the about blank discussion in the security archive and to no avail?!?

Discussion is locked
You are posting a reply to: NEED HELP/ADVICE
The posting of advertisements, profanity, or personal attacks is prohibited. Please refer to our CNET Forums policies for details. All submitted content is subject to our Terms of Use.
Track this discussion and email me when there are updates

If you're asking for technical help, please be sure to include all your system info, including operating system, model number, and any other specifics related to the problem. Also please exercise your best judgment when posting in the forums--revealing personal information such as your e-mail address, telephone number, and address is not recommended.

You are reporting the following post: NEED HELP/ADVICE
This post has been flagged and will be reviewed by our staff. Thank you for helping us maintain CNET's great community.
Sorry, there was a problem flagging this post. Please try again now or at a later time.
If you believe this post is offensive or violates the CNET Forums' Usage policies, you can report it below (this will not automatically remove the post). Once reported, our moderators will be notified and the post will be reviewed.
Collapse -
Re: NEED HELP/ADVICE
by Donna Buenaventura / September 1, 2004 7:37 PM PDT
In reply to: NEED HELP/ADVICE

Hi Jodi,

Have you tried running Ad-aware SE? Give it a run to see if it'll find any hijacker/spyware.
Using Ad-Aware SE to remove Spyware & Hijackers from Your Computer

If the hijacker/spyware is still there after using Ad-aware, download HijackThis from any download locations below:
http://www.spywareinfo.com/~merijn/files/HijackThis.exe
http://www.spywareinfo.com/~merijn/files/hijackthis.zip
http://www.allsecpros.com/download/HijackThis.zip
http://www.zerosrealm.com/downloads/hjt.zip
http://www.downloads.subratam.org/hijackthis.zip

Where to put and how to use HijackThis:

It is important that you will run HijackThis.exe in its own folder so the backup files that HijackThis file will create will not be accidentally deleted.

Open 'My Computer', then double-click to open C:\ (or the drive letter that your Windows is installed)
In the menu bar, click File-->New-->Folder.
That will create a folder named New Folder, which you can rename to "HJT" or "HijackThis". Now you have C:\HJT\ or C:\HijackThis\ folder. Put your HijackThis.exe there, and double click to run it.

Click 'Scan' button. Click 'Save log' button. Save the 'hijackthis.log' in your desktop. Copy and paste the content of 'hijackthis.log' and post it any forums listed in http://www.a-sap.org/ that offer HijackThis analysis.

Collapse -
Re: NEED HELP/ADVICE
by Jodi / September 2, 2004 8:17 AM PDT
In reply to: NEED HELP/ADVICE

Got Adaware SE, and nothing. Will try Hijack This next. Could it be possible that I saw about blank and do not have related malware? Thanks so much!

Collapse -
Re: NEED HELP/ADVICE
by dawillie / September 2, 2004 9:21 AM PDT
In reply to: Re: NEED HELP/ADVICE

'about blank ' is a registry entry I believe and sometimes I see it as a 'pop under' a link to some of the US newspapers that I get form ppl I know.

it does not mean that your browser has been hijacked.

make sure your patches are up to date and practise the usual security precautions such as current AV definitions, Ad-Aware scans and firewall protection.

Collapse -
Yep, See My Response...
by Grif Thomas Forum moderator / September 2, 2004 9:48 AM PDT
In reply to: Re: NEED HELP/ADVICE
Collapse -
Re: Yep, See My Response...
by dawillie / September 2, 2004 10:29 AM PDT

thanks Grif.

you are absolutely correct about the browser hijack.

david

Collapse -
Re: NEED HELP/ADVICE
by Donna Buenaventura / September 2, 2004 2:53 PM PDT
In reply to: Re: NEED HELP/ADVICE
Will try Hijack This next. Could it be possible that I saw about blank and do not have related malware?

Hi again Jodi,

HijackThis is a powerful diagnostic tool. User will lose nothing in trying to scan and post the HijackThis log in the appropriate forum that offer HijackThis log analysis. Some hijacker hides a hidden file (most of the time a .dll) that most anti-spyware and AV cannot delete or detect so I think you should go ahead and try to post your HijackThis in any forums listed in www.a-sap.org
If the HJT experts analysis is "clean" that will be cool to know Happy

I also agree with Grif that not all about:blank means browser is hijacked. AFAIK, SpyCatcher (an anti-spyware program) protects the about:blank from Hijackers.

May I ask what program did you use to scan the system that detects that your system is maybe infected with bagle and that the path is HKEY_LOCAL_MACHINE\software\microsoft\windows\current version ?
Collapse -
Re: NEED HELP/ADVICE
by Jodi / September 2, 2004 6:25 PM PDT
In reply to: Re: NEED HELP/ADVICE

Thanks again. I am trouble getting any help in the forums but read a great tutorial at http://hometown.aol.co.uk/jrmc137/hjttutorial/tutorial.htm which has allowed me to research my log results. I believe maybe all of my software has somehow stopped or fixed the problem...just one more thing-spyware blaster shows me C:WINDOWS\SYSTEM\blank.htm, which does not show up as a R0 problem in hijack this (I am just guessing it's because there is no registry value?-HKEY.......). Spyware blaster does give me the option to change/remove it but warns that care should be taken in altering the file...ANY IDEAS?

Collapse -
Re: NEED HELP/ADVICE
by Donna Buenaventura / September 2, 2004 7:34 PM PDT
In reply to: Re: NEED HELP/ADVICE
I am trouble getting any help in the forums but read a great tutorial at http://hometown.aol.co.uk/jrmc137/hjttutorial/tutorial.htm which has allowed me to research my log results. I believe maybe all of my software has somehow stopped or fixed the problem

Jodi, most forums that offers HJT analysis is overwhelmed Sad
Most users need to wait. Just be careful in fixing anything using HijackThis (if you will). If no more problem (which is good!) then I think you don't have to worry now Happy

just one more thing-spyware blaster shows me C:WINDOWS\SYSTEM\blank.htm, which does not show up as a R0 problem in hijack this (I am just guessing it's because there is no registry value?-HKEY.......). Spyware blaster does give me the option to change/remove it but warns that care should be taken in altering the file...ANY IDEAS?

I dont think it's a good idea to edit/change the browser page item blank.htm because that is by default, the path of Windows Local Page.

See - http://img72.exs.cx/img72/7300/blank1.jpg and http://img75.exs.cx/img75/4771/blank2.jpg that I have here as per SpywareBlaster. Are you seeing that info/prompt?
Collapse -
Re: NEED HELP/ADVICE
by Jodi / September 2, 2004 9:08 PM PDT
In reply to: Re: NEED HELP/ADVICE

It read closer to the first one. I will not change it. Thank you so very much for all help. I don't know if you got to see the tutorial about Hijack This- but it's really great and full of helpful links (maybe of use to someone else?) Anyways thanks again!!

Popular Forums
icon
Computer Newbies 10,686 discussions
icon
Computer Help 54,365 discussions
icon
Laptops 21,181 discussions
icon
Networking & Wireless 16,313 discussions
icon
Phones 17,137 discussions
icon
Security 31,287 discussions
icon
TVs & Home Theaters 22,101 discussions
icon
Windows 7 8,164 discussions
icon
Windows 10 2,657 discussions

The Samsung RF23M8090SG

One of the best French door fridges we've tested

A good-looking fridge with useful features like an auto-filling water pitcher and a temperature-adjustable "FlexZone" drawer. It was a near-flawless performer in our cooling tests.