Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

about:blank fix...anyone?
me ^ | 8/19/04 | self

Posted on 07/19/2004 11:15:57 PM PDT by jra

Does anyone have a fix for this homepage hijacker BESIDES telling me to load Mozilla?


TOPICS: Miscellaneous
KEYWORDS:

1 posted on 07/19/2004 11:15:57 PM PDT by jra
[ Post Reply | Private Reply | View Replies]

To: jra

Don't visit Drudge is the first step you can take. His sight is riddled with unsafe spyware. That's likely where you picked it up.


2 posted on 07/19/2004 11:18:27 PM PDT by BJungNan (Stop Spam - Do NOT buy from junk email.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: jra
http://www.refdesk.com/anti.html

Download one or two of the utility programs, and run them. You likely have a trojan or some other malware.
3 posted on 07/19/2004 11:19:31 PM PDT by Keith in Iowa (Michael Moore has made "documentary" a 1-word oxymoron.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: jra

Go to what was once your homepage in Internet Explorer by typing the URL in the address bar. Once the page has loaded, locate the icon in the Address bar, hold the left mouse key down and drag it over the "home" icon and drop it there, that will set that page as your home page.


4 posted on 07/19/2004 11:20:02 PM PDT by BigSkyFreeper (While Bush plays "rope a dope", Kerry/Edwards play "grope a dope".)
[ Post Reply | Private Reply | To 1 | View Replies]

To: BJungNan

I've been going to the Drudge Report for about 6 years.

I've never picked up spyware or anything else dangerous from it in all that time.


5 posted on 07/19/2004 11:20:45 PM PDT by DB (©)
[ Post Reply | Private Reply | To 2 | View Replies]

To: jra

Not exactly sure to what you are referring, but try AdAware, SpyBot Search & Destroy 1.3, and CW Shredder.

Get thee behind a firewall, preferably hardware and software.

Check out this site: http://www.zone-x.com/spybot.php for some other helpful info.


6 posted on 07/19/2004 11:20:46 PM PDT by Chummy (RepublicanAttackSquad.biz: "A vote 4 Kerry is a vote for Osama")
[ Post Reply | Private Reply | To 1 | View Replies]

To: jra
If you don't have this program, you should download and install it and run it regularly.

Spybot Search and Destroy

7 posted on 07/19/2004 11:21:45 PM PDT by TheMole
[ Post Reply | Private Reply | To 1 | View Replies]

To: jra

Load Opera? ;-)


8 posted on 07/19/2004 11:24:03 PM PDT by Still Thinking
[ Post Reply | Private Reply | To 1 | View Replies]

To: BJungNan
Don't visit Drudge is the first step you can take. His sight is riddled with unsafe spyware. That's likely where you picked it up.

His site is riddled with popup advertising. Popup advertising and spyware are two different beasts.

9 posted on 07/19/2004 11:24:33 PM PDT by BigSkyFreeper (While Bush plays "rope a dope", Kerry/Edwards play "grope a dope".)
[ Post Reply | Private Reply | To 2 | View Replies]

To: jra

Could you give a little more detail about your problem? It sounds like you just need to set your homepage to some URL - whatever you want.


10 posted on 07/19/2004 11:28:06 PM PDT by Jeff Gordon (LWS - Legislating While Stupid. Someone should make this illegal.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: jra

Here's even more:

http://computercops.biz/article-5199-nested-0-0.html

Thanks for calling this to attention; I learned something.

Good luck!


11 posted on 07/19/2004 11:31:18 PM PDT by Chummy (RepublicanAttackSquad.biz: "A vote 4 Kerry is a vote for Osama")
[ Post Reply | Private Reply | To 1 | View Replies]

To: DB

Drudge is necessary for me too. Never had a problem.


12 posted on 07/19/2004 11:32:07 PM PDT by thegreatbeast (Quid lucrum istic mihi est?)
[ Post Reply | Private Reply | To 5 | View Replies]

To: jra

Download a program called "Hijack This". I fix many of my friends computers, and they'll pick up this problem sometimes at questionable websites. More than likely, besides hijacking your current home page setting, the javascript or active x component also changed registry settings which will change it back again after you fix it when you reboot. You'll likely need to change those registry settings to prevent a re-occurance. The easiest way for a novice is third-party utilities such as Hijack This. I believe the utility is still available as freeware at cnet.com, for example.


13 posted on 07/19/2004 11:35:02 PM PDT by SoDak
[ Post Reply | Private Reply | To 1 | View Replies]

To: jra

What operating system do you have?


14 posted on 07/19/2004 11:40:37 PM PDT by AntiGuv (™)
[ Post Reply | Private Reply | To 1 | View Replies]

To: jra

Is your "About Blank" home page being hijacked to MSN.com?


15 posted on 07/19/2004 11:44:44 PM PDT by RJL
[ Post Reply | Private Reply | To 1 | View Replies]

To: jra
After several friends were afflicted with this problem, I posted a page of links, directions, and resources that should help you out:
Dealing with Spyware and Adware
16 posted on 07/19/2004 11:45:20 PM PDT by happydogdesign
[ Post Reply | Private Reply | To 1 | View Replies]

To: jra

Details here:

http://www.freerepublic.com/focus/f-news/1168134/posts
Hijacked! New Browser Exploits Plague Web
various sites | 07-09-04 | The Heavy Equipment Guy

The good news? It can be fixed-

The not-so-good?
You will have to learn a lot of new stuff, probably join the forums listed, quit using Internet Exploder, except for MS updates. But it can be cured, only took me 2-3 weeks...


17 posted on 07/19/2004 11:45:28 PM PDT by backhoe ("It's so easy to spend someone else's money." [ My Dad, circa 1958])
[ Post Reply | Private Reply | To 1 | View Replies]

To: jra
First - Most pop-up's do load spy ware on computers, including the hijacker you are referring to.

Second get a pop-up stopper, try www.panicware.com for a free version that works great!

Third go to www.webroot.com for Spy Sweeper, a spy ware program that not only can scan and remove spy ware that is planted but can stop new ones from being deposited. Oh, and it can reset your homepage for you automatically.

Fourth, and the actual answer to your question - you have a Trojan Spy ware program probably know as Cool Web Search or one of it's variants. Typically ad-aware or even Spy Sweeper can't clean the entire thing because it plants about 75 different items in your registry. Many of these just cause the program to reload so if you manage to clean up 70 of them the registry can cause the program to reload the entire thing. A firewall won't help with this one - except it will prevent your Cool Web Trojan from calling home. The program attempts to use your notepad program to call home - believe it or not. If you use a good Firewall like Zone Alarm (probably the best free one www.zonealarm.com) you can tell that you have a new infection because your notepad will try to access the Internet. That is NOT something that you should allow.

This program also resets your home page each and every time you start your browser - and sometimes at regular intervals. it points you back to a site that gets paid per hit.

Okay, to clean it download a program called CWShredder - you can search Google for a copy this one might work, http://www.computing.net/security/wwwboard/forum/12148.html but I haven't tried this specific site.

As time goes on most browsers can get infected because of the nature of the pop-up craze (invading scums in my opinion!)

Anyway, run the Shredder, install and use the firewall and Spy Sweeper and the Pop-Up Stopper and DEFINATELY stay away from that infected site that gave you this nasty infection - always wear your Internet condoms, but abstinence is always best.

And for full discloser, I am not affiliated with any of these products or web sites.
DKK
18 posted on 07/19/2004 11:51:16 PM PDT by LifeTrek
[ Post Reply | Private Reply | To 1 | View Replies]

To: jra

Are you talking about the thing where Ad Aware insists that "about:blank" is a malicious web site, and that some Evil Bad Guy is trying to take over your machine because IE is set to wake up in about:blank?

My provisional theory is that a programmer at AdAware has a rectal-cranial inversion. Yes, there is a hack that uses the name "about:blank," but that is also the name of the default blank page. Surely any programmer who can find Russian spies on your computer could figure out a way to tell the difference between the default blank page and a box of malware named "about:blank."


19 posted on 07/19/2004 11:53:46 PM PDT by Nick Danger (Be shuh two zee da nuuuu Ahnold Schwohza-naygah moooovie)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Calpernia

ping


20 posted on 07/19/2004 11:59:08 PM PDT by nw_arizona_granny (You could do a general Google search for: jihad internet today)
[ Post Reply | Private Reply | To 13 | View Replies]

To: jra

Any time you have something like this come up, just put the name into GOOGLE.. You will get any number of sites that are dedicated to getting rid of this trash..

http://computercops.biz/article-5199-nested-0-0.html

The above link contains the following instructions...

1) With “Reglite.exe” find name of hidden file:

Double Click on “AppInit_DLLs” located in “HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWindows” The “value” window reveals the hidden file name. (mine was “hlpl.dll”, yours may be different!) In this example let’s call it “hidden.dll”

2) Rename the hidden file:

Close Windows and reboot using “Windows Recovery Console” Go to “c:Windowssystem32” and do two things. Change file from read only by typing “attrib –r hidden.dll” Then rename it (I don’t know why, but this procedure did not work until I renamed it) type “rename hidden.dll nasty.dll” (and remember that “hidden.dll” is for this explanation only use the name you found earlier) Type “exit” and reboot to Windows.

3) Edit registry to remove hidden file

Run “reglite.exe” again. Double Click on “AppInit_DLLs” located in “HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWindows” Delete the file in “value” window, the “size” window changes also. “Apply” changes and exit “reglite.exe”

4) Edit registry to remove the second file

Run “HiJackThis.exe” and scan the registry. Check the boxes to remove the following entries:
“R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = res://C:WINDOWSSystem32jheckb.dll/sp.html (obfuscated)
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = res://C:WINDOWSSystem32jheckb.dll/sp.html (obfuscated)
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = res://C:WINDOWSSystem32jheckb.dll/sp.html (obfuscated)
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = res://C:WINDOWSSystem32jheckb.dll/sp.html (obfuscated)
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = res://C:WINDOWSSystem32jheckb.dll/sp.html (obfuscated)
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = res://C:WINDOWSSystem32jheckb.dll/sp.html (obfuscated)
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,HomeOldSP = about:blank” (as you can see my second .dll was called “jheckb.dll” yours may be different) For this example let’s call it “obvious.dll”.

Finally delete the two .dlls (“hidden.dll” and “obvious.dll”) You should be running again.

By the way, if you go offline with Internet Explorer and type OK To these nasty adware windows you will see the guys who benefit. From this hijacker. I found:
www.palsol.com
www.likesurfing.com
www.vn.msie.cc (the real web page)

They seem to be selling “adware/spyware protection” Pass the word, Boycott them, Who needs to be extorted for “protection money”?


21 posted on 07/20/2004 1:14:20 AM PDT by Drammach (Freedom; not just a job, it's an adventure..)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Drammach; jra

I wouldn't suggest messing around in the registry file unless you know what you are doing. The slightest typo will possibly render your system unbootable.


22 posted on 07/20/2004 1:57:03 AM PDT by BigSkyFreeper (While Bush plays "rope a dope", Kerry/Edwards play "grope a dope".)
[ Post Reply | Private Reply | To 21 | View Replies]

To: jra
Does anyone have a fix for this homepage hijacker BESIDES telling me to load Mozilla?

Laugh!

Or telling you to get a Mac or switch to Linux. I know what you mean. You ask for help with a tune-up and folks tell you to get a new car.

23 posted on 07/20/2004 2:07:15 AM PDT by Flyer (I will never reference my tag line in my posts)
[ Post Reply | Private Reply | To 1 | View Replies]

To: BigSkyFreeper
His site is riddled with popup advertising. Popup advertising and spyware are two different beasts.

From what I have been reading, that is where the spyware comes from. But no matter, a visit to Drudge will result in anywhere from 3 to 7 spyware programs being desposited into your computer. A debate over where they came from only clouds the issues.

24 posted on 07/20/2004 4:07:18 AM PDT by BJungNan (Stop Spam - Do NOT buy from junk email.)
[ Post Reply | Private Reply | To 9 | View Replies]

To: DB
I've been going to the Drudge Report for about 6 years. I've never picked up spyware or anything else dangerous from it in all that time.

It is easy enough to test for. Do you have a spyware removal program?

25 posted on 07/20/2004 4:08:48 AM PDT by BJungNan (Stop Spam - Do NOT buy from junk email.)
[ Post Reply | Private Reply | To 5 | View Replies]

To: jra

Use Firefox, like me. I only use IE for sites that refuse to use standard html style.


26 posted on 07/20/2004 5:51:37 AM PDT by NativeNewYorker (Don't blame me. I voted for Sharpton.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: RJL

That periodically happens to me, whenever I remove a "data miner" via Ad-Aware. What's up with that? I just assume it's some form of crap I get for using Media Player.


27 posted on 07/20/2004 5:55:55 AM PDT by 1rudeboy
[ Post Reply | Private Reply | To 15 | View Replies]

To: Flyer

The Mac folks are the best. You ask for help with your Chevy, and they tell you to buy a Lexus.


28 posted on 07/20/2004 5:57:01 AM PDT by 1rudeboy
[ Post Reply | Private Reply | To 23 | View Replies]

To: BigSkyFreeper

"I wouldn't suggest messing around in the registry file unless you know what you are doing. The slightest typo will possibly render your system unbootable."

Neither do I, that's why I use Hijack This. It prints out a registry log and you simply check the registry files you wish deleted.

Checking the wrong file could be a problem, but there is risk in everything we do...just be careful and double check.


29 posted on 07/20/2004 6:04:13 AM PDT by Rebelbase (To democrats the truth is personal.)
[ Post Reply | Private Reply | To 22 | View Replies]

To: 1rudeboy

If you use “about Blank” as your home page and it’s getting hijacked to MSN.com, it may be Lavasoft’s Ad-aware doing it.

It seems that some hacker is disguising itself with the “About Blank” home page setting.

To combat this, Ad-aware version 6.181 flags the “About Blank” home page setting as a “Possible” hijack attempt. If you allow Ad-aware to fix it, Ad-aware will reset your home page to the Windows default, MSN.com.

To avoid this, when the Ad-aware scan is done and the bad guys are listed, right click on possible browser attempt and select “Add selection to the ignore list” this will stop Ad-aware from resetting your home page to MSN.com.


30 posted on 07/20/2004 8:30:52 AM PDT by RJL
[ Post Reply | Private Reply | To 27 | View Replies]

To: BJungNan

Ad-aware and SpyBot.

I've never been infected. The only thing they ever find is tracking cookies. No big deal there.


31 posted on 07/20/2004 11:55:26 AM PDT by DB (©)
[ Post Reply | Private Reply | To 25 | View Replies]

To: BJungNan

I visit Drudge several times a day. Never have I picked up any Spyware or browser Hijackers.

As far as browsers go, I have Netscape 4.7, Opera, Mozilla, IE and iRider all installed and used at one time or another. They've all been to Drudge Report one time or another. No program installations of any kind short of temporary Java stuff.

Pop-up ads and cookies are another matter. iRider is very effective with pop-up ads so I very rarely ever see one. Cookies are deposited on my machine by nearly every Web site I visit. I don't consider that much of an issue. I let Ad-aware and SpyBot clean those up every so often.

I do keep my MS security patches current along with Norton AV.


32 posted on 07/20/2004 12:06:20 PM PDT by DB (©)
[ Post Reply | Private Reply | To 24 | View Replies]

To: DB
You are getting programs loaded on to your computer and you just don't know it.Do you have a spybot/spyware removal program installed on your computer
33 posted on 07/20/2004 5:53:24 PM PDT by BJungNan (Stop Spam - Do NOT buy from junk email.)
[ Post Reply | Private Reply | To 32 | View Replies]

To: BJungNan
Ad-aware and SpyBot are removal programs.

http://www.lavasoftusa.com/software/adaware/

http://www.spybot.info/en/index.html

And no, I'm not getting programs loaded onto my computer from the Web (other than the usual Java scripts).

I've been a heavy user of computers for the last 20 years. I'm an engineer as well. I pay close attention to what is on my computer as it is my primary work tool.

Perhaps you should simply accept the fact that the Drudge Report isn't the real source of your infestations.

34 posted on 07/20/2004 6:38:08 PM PDT by DB (©)
[ Post Reply | Private Reply | To 33 | View Replies]

To: DB
Perhaps you should simply accept the fact that the Drudge Report isn't the real source of your infestations.

I would accept it if that were true. But I have tested it. You can too.

1. Clear your computer of all spybots/spyware using a program like Adaware (Lavasoft).

2. Go to Drudge's site and no other site.

3. Run your spybot/spyware program again.

4. You will find anywhere from 3 to 7 programs have been loaded on to your computer.

Repeat the process going to a site like MyWay.com or GoGov.com that do not put spyware on your computer and see what happens.

If you have a way to prevent Drudge from loading up your computer then by all means let us know about it. There are many dial-up connection people that would love it if their computers were not coming to a grinding halt from all the junk loaded and runniing on their systems by Drudge. Many have reported back that their systems are significantly faster after clearing their computers of spyware and after they stopped using Drudge as their home page.

Really, you should share your secret. Why are you keeping it from everyone?

35 posted on 07/20/2004 9:15:33 PM PDT by BJungNan (Stop Spam - Do NOT buy from junk email.)
[ Post Reply | Private Reply | To 34 | View Replies]

To: BJungNan
I have and use Ad-aware. I also use SpyBot Search and Destroy.

I go to Drudge many times a day.

I scan every once and awhile using Ad-aware (and SpyBot and I keep them updated).

It never finds any Web related programs loaded on my computer. None. I don't scan very often because it never finds anything important so it is a waste of time to do it more often.

It does find tracking cookies from various sites. That's a whole different issue.

I am not doing something "secret".

You have something broken.

Without serious security holes in your system hijack/malware/spy programs don't just find their way onto your system easily.

36 posted on 07/20/2004 9:26:29 PM PDT by DB (©)
[ Post Reply | Private Reply | To 35 | View Replies]

To: BJungNan

Perhaps you don't know the difference between cookies and "programs".


37 posted on 07/20/2004 9:28:27 PM PDT by DB (©)
[ Post Reply | Private Reply | To 35 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson