View Full Version : about:blank... anyone know how to kill this bugger?
Mug Funky
2nd May 2005, 10:12
hi. sorry for the off-topic-ness, but it is DVD backup related insofar as i haven't got effective use of my computer in order to do backups.
anyway. some of you may have heard of (or experienced) the "about:blank" coolwebsearch browser hijack. i currently have this, and most of the internets out there say that it's nigh on impossible to get rid of. certainly my attempts to destroy it have been completely ineffective (and i'm a pretty experienced win-tinkerer who knows what he's doing most of the time).
worse still, all the programs that purport to get rid of this are payware and sold under rather untrustworthy pretences. i am absolutely not going to pay for something that either (a) doesn't work, or (b) is probably written by the author of the virus in the first place.
i doubt i'd have contracted this spyware/virus/whatever but for the fact that i'm not the only person who uses my home machine, and the other user likes to do their Ebaying in Internet Explorer without the firewall running (no matter how many times i've screamed at him to use a real browser).
i'd have posted on a spyware/techie forum, but didn't feel like signing up to a new forum and doing the newbie thing today :)
Edit:
Ahh...the nasty "about:blank:" hijack trojan. I had it earlier this year and I was frustrated on trying to fix it. How I understood it during my ruthless searches, an unknown .dll or .dat file is ran and an .exe or .dat file is created. This .exe file is the one doing all your horrible changes. So, if you delete this .exe, it'll still comeback to haunt you. You need to find the culprit .dll or .dat file. I think I had used hijack this! Sorry, it's been awhile since I purged that trojan out and I also purged the knowledge on what I had to do. Perhaps, this link (http://forums.spywareinfo.com/index.php?showtopic=6670) could help you?
Mug Funky
2nd May 2005, 10:57
that post looks pretty useful. thanks. will try it out when i get home :)
I found you more help.
http://www.pchell.com/support/aboutblank.shtml
http://www.securiteam.com/securityreviews/5RP0L0UD5U.html
SeeMoreDigital
2nd May 2005, 11:44
A friend of mine got this after he plugged his laptop into a hotel's network.....
Anyway, he cured the problem by using a bit of software called HijackThis (www.TomCoyote.org/hjt).
Cheers
Paulcat
2nd May 2005, 12:25
Cool Web Search removal tool
http://www.majorgeeks.com/download4086.html
vion11
2nd May 2005, 12:39
My system was hijacked with something similar.
With taskman, autorunners(SysInternals) and HijackThis,
I found out there are two exes loaded during startup,
both control running state of the other, so when I kill
task of one the other loads it jit again.
I've found the files, but they were in use and deleting
was not an option. Renaming the folder leaded to success.
After killing the bad tasks and cleaning registry
system becomes proper again.
Too bad the guys develop such stuff surf the internet
and can read the tipps as well......
Originally posted by Paulcat
Cool Web Search removal tool
http://www.majorgeeks.com/download4086.html
That's a link to an old version by original author.
"Originally developed by Merijn Bellekom of the Netherlands, CWShredder™ is now owned and maintained by InterMute. CWShredder has been updated to include new CoolWebSearch variants."
http://www.intermute.com/spysubtract/cwshredder_download.html
mpucoder
2nd May 2005, 15:36
In the old days if a file was in use you would reboot in DOS to delete it - Thanks MS for taking it away. Anyway, I don't have this bugger, but I've run into others on my gf's computer (she loves games - ugh!). This isn't for everyone, but here all drives are mounted on trays - so to delete a stubborn file I just remove the drive and put it in another computer as the D: drive. I never thought of changing the folder name - but most of the time the bad file is in a folder needed to boot Windows.
fccHandler
2nd May 2005, 16:19
You can still boot to DOS from a floppy, and XP can still make a DOS bootable floppy. Problem is, DOS can't access an NTFS partition. I once read about a driver (google for "NTFSDOS") which allows DOS to access NTFS. (Never actually tried it myself.)
Mug Funky
3rd May 2005, 05:18
mpucoder: that's a pretty good idea...
i might do some compu-surgery tonight - unfortunately i can't boot from USB, or i could just whack win2k on my flash disk and boot from there, then run anti-spyware stuff
however, i can make my portable hard-drive non-portable for long enough to remove the virus (and do some defragging while i'm there).
I never make my boot partition NTFS for this very reason (and because it simplifies emergency recovery). :)
Arachnotron
3rd May 2005, 17:09
this site (http://www.nu2.nu/pebuilder/) tells you how to make a bootable CD/DVD with a running windows XP on it which you can use to do maintenance on a NTFS partition. (like deleting files which would otherwise be locked by the OS)
Cyberia
3rd May 2005, 17:24
CoolWeb is a BITCH to get out permanently.
Basically it uses an exe to reinfect your system, and uses another exe to reinstall the first exe when it gets deleted.
Use HiJackThis to determine the culprit exe files.
You have to kill the process of the first exe AND then delete BOTH exe files AND clear your history/reset home page before it's gone.
AdAware gets most of the CW variants, but not all.
MuttLover
3rd May 2005, 20:27
My brother had this and tried a number of removal tools. He finally got rid of it with Giant Antispyware. This was sold to Microsoft and is now available from them as free betaware. If the 'magic' is still in it, you might give it a try. Go to www.microsoft.com and type spyware in the search window to find the way to the download, and good luck!
zilog jones
4th May 2005, 11:32
Originally posted by fccHandler
You can still boot to DOS from a floppy, and XP can still make a DOS bootable floppy. Problem is, DOS can't access an NTFS partition. I once read about a driver (google for "NTFSDOS") which allows DOS to access NTFS. (Never actually tried it myself.)
I dunno about XP, but with Win2k you can just boot from the installation CD and go to the "recovery" mode thing. Then it's pretty much just NT command prompt - not DOS, but pretty much the same thing, and with NTFS support ^_^
And Mug Funky - you do what my friend did with his PCs after previous disasters from spyware and viruses - mostly caused by the rest of his family. He's deleted all shortcuts to IE and blocked it with the firewall. I don't know how to avoid turning off the firewall though...
mpucoder
4th May 2005, 15:32
You could also backup your C: drive. I keep my C: partitions relatively small, about 2G. This makes the time to do the backups and restore reasonable. Backups don't need to be done a lot, just after the initial install and basic stuff has been added (called a golden backup) and then whenever something really useful and safe has been added.
Hiro2k
5th May 2005, 03:44
What ever happened to booting into safe mode? Before windows starts loading push F8 and go into safe mode. There you can delete any file and I was able to get rid of CWS with CWSShredder linked above. Then after that was gone I ran HijackThis and all was fixed.
Rail-Runner
5th May 2005, 04:28
Ad-Aware SE Personal and MS Antispyware Beta 1 will cover many of the current spyware threats, when both are used they are a very potent weapon for all threats.
zilog jones
5th May 2005, 22:26
Spybot seems to get stuff that Ad-aware doesn't get as well. Though since I've started using Opera only and ZoneAlarm, all I ever get is the odd tracking cookie.
Rail-Runner
5th May 2005, 23:41
I used to run Spybot, but found it rarely updated its definations, then when I added SE & MS and ran all 3 for 2 months only MS & SE would find any new threats dureing scans, and Spybot would never find any new threats when run after MS & SE, telling me that Spybot was not worth running if it was not catching anything the others would, it just became an extra scan process that was not yeilding any new threats.
eppy_tommy
8th May 2005, 17:44
Yea if you have it it's Zero disc time. I had to wipe my drive and reinstall..Some useful tips for keeping it off there once you reinstall your OS is three programs. SpywareBlaster, Spybot (search and destroy) and Ad-Aware SE. All free-ware cept you pay 10 dollars to update SpywareBlaster. With Norton Internet Security (completely password protected!!!) and these three for defense and cleaning I've been stable as a rock for a long time. I'm sure you know that doesn't mean that some real hacker can't mess you up again. But with these at least the surf aliens can't load their malicious crap on your sys.
eppy_tommy
8th May 2005, 17:50
Oh....and about spybot not finding any new threats...it immunizes from the ones on it's database. That's why. And as a side...Spybot defers to SpywearBlaster's threat database. SpywearBlaster can't be turned off which makes it hack-proof. There is also a feature in Spybot that helps alot too..The Tea Timer. If any program accesses the root directory, Tea Timer flags the attempt and you push allow to complete the change.
zilog jones
8th May 2005, 18:57
I no longer have any trust in Norton.
Earlier this week, I noticed my friend's laptop was doing some dodgy things, then it started doing Sasser-like restarts. I new it must have been a virus... or 10. I ran Norton Anti-Virus Corporate Edition (given to all campus residents by the university; the deifnitions were updated this week), just scanning the Windows directory (I thought I wouldn't have much time in case it reset again). It found nothing.
Then I tried AVG Free. It found over 30 viruses, most of which were in the Windows directory. He's now uninstalled Norton...
Also, I don't get Norton Internet Security either. Me, and and a fellow Computer Systems graduate, couldn't make heads or tails of why it wouldn't let someone's laptop go on the internet in a LAN or access other people's shared files. It took us quite a while to get it to work. Thank God we didn't try playing any online games it! Compared to that, ZoneAlarm just makes sense - it's just a no-nonsense firewall. And it's free.
theReal
8th May 2005, 21:16
I had a nasty spyware/trojan combination a few months ago (sorry I forgot the name, but it permanently opened a website with advertising plus it was using my computer as a spam relay...)
AntiVir Personal never found any trojan, Ad-Aware half-bakedly removed the advertising stuff (it came back after a while...) but no software was able to stop the spam-relaying (I tried several, including Hijack this).
By the way: I only found out my computer was sending spam mails after I had installed AVG personal and the E-Mail scanner kept popping up (AVG had allegedly removed the trojan, but then it reported continuous mailing and returned the undeliverable spam mails to my mail address...)
I finally formatted and reinstalled windows with another admin password to be 100% sure.
After that nasty experience I changed my whole behaviour: I only use my admin account to install stuff, other than that I have a normal user account with no installation rights. I am finally using Mozilla as my only browser plus I'm using AVG Anti Virus and Zonealarm (in addition to a strictly configured Draytek Vigor hardware firewall).
What seems to do the trick mostly is not to use the administrator account for anything else than administrative things.
zilog jones
8th May 2005, 23:05
Good point, and something people should consider, especially with family PCs and less "tech-savvy" members of the family.
I never use the main administrator account, though I have one for myself and another for my brother - I don't know if this makes it any safer though. My mother's only a User though - yeah, I'm mean :D
Rail-Runner
9th May 2005, 02:19
Originally posted by Rail-Runner
I used to run Spybot, but found it rarely updated its definations, then when I added SE & MS and ran all 3 for 2 months only MS & SE would find any new threats dureing scans, and Spybot would never find any new threats when run after MS & SE, telling me that Spybot was not worth running if it was not catching anything the others would, it just became an extra scan process that was not yeilding any new threats. P.S. forgot to mention I kept the Spywareblaster when I deleted Spybot from my system as it is a immuniser that updates regularly and I have never had to pay for an update with this program. Also a tech show I seen showed Spybot was lacking in many areas of threats caught. But MS & SE covered them all includeing the 30% to 40% that Spybot would miss.
eppy_tommy
9th May 2005, 03:40
Yea...the reason i use these is because what one doesn't get the other does. And i totally agree about the Norton. Mc Afree isn't any better. Basically i have given up totally on having a secure system and i govern myself accordingly. I just assume there are many in my comp....if they want me they can have me. So its all about backing my stuff up.
As for a hacker ruining my OS...well i just know the fastest and easiest way to load the OS for when i need to. And i keep all my personal stuff on a separate drive including my updates, drivers, and downloads. That way all i have to do is load OS and plug in my storage drive. I get it all back in a few hours..Sweet huh? Means i dont have to fix anything. Just reload and start clean.
Shinigami-Sama
9th May 2005, 06:38
while on het thopic of "bitch to get rid of"
has anyone every gotten "ctfmon" I've tried everytiung short of physicly scratching out the sectors with a hammer where that bitch is...
spybot/adware, regedit, win-serch.crap, safe mode,
the onlything I cna think of is trying to use my old win98 hdd thats dieing as a primary and delting it that way but I'm not sure that would work seeign as how I seem to miss one key part of it whne I purge it and unfortunatly I can do a full format else I would;ve long ago
any help here?
zilog jones
9th May 2005, 14:26
ctfmon.exe is part of MS Office's language bar thingy. There's settings for it somewhere on the Control Panel. Or can it get hi-jacked or something?
theReal
9th May 2005, 17:38
especially with (...) less "tech-savvy" members of the family.That's what I thought - "the normal user accounts are for the dummies, I can use the administrator account because I know what I'm doing" ... well it turned out I knew what I'm doing but the trojan was better than me. I didn't click on any stupid messages and I didn't open any strange mail attachments but still I got this mean trojan - I don't know where from.
Now I'm using a normal user account myself, 99% of all programs work in the normal account and I can always switch users when I need to.
This principle has been applied to all Unix/Linux systems from the beginning: NEVER use your root account for normal work, otherwise you are yourself the system's biggest safety hole ;)
Shinigami-Sama
9th May 2005, 19:53
Originally posted by zilog jones
ctfmon.exe is part of MS Office's language bar thingy. There's settings for it somewhere on the Control Panel. Or can it get hi-jacked or something?
thats not what spybot says and it;s only come up in past 3 months, never had it before..
winxp home sp
attached screenie crop from spybot
@Shinigami-Sama
Check out "Frequently asked questions about Ctfmon.exe"
http://support.microsoft.com/kb/q282599/
Found it by "googling". ;-)
/Maria
Shinigami-Sama
9th May 2005, 23:44
hm came up in Japanese again godamed m$ pages always do that to me -_-
but I was jsut going by what spybot said this time seeign as ho ctfmon came up three weeks before I installed anyother windows stuff and a week before I installed teh eat asain fonts too strange..
cwshredder 2.14 should fix this
http://cwshredder.net/bin/CWShredder.exe
http://www.spywareinfo.com/~merijn/downloads.html
and install spybot s&d,spywareblaster,spysweeper etc.etc....;)
vBulletin® v3.8.11, Copyright ©2000-2026, vBulletin Solutions Inc.