Help - Search - Members - Calendar
Full Version: Hijacked by about blank
Gladiator Security Forum > Malware Help Forum > HELP! Think you are Infected?
jennie
about blank has taken over as my home page. I've run HijackThis and AdAware and deleted the about blank but it keeps coming back. Please help.
After reading other postings, I updated AdAware and ran it again. I downloaked CWShredder and my problem seems to be fixed. rolleyes.gif

I removed my HijackThis log because I've run the above programs since the scan. Hope it's fixed now.
CalamityJane
Hi Jennie,

Having followed your threads here for a week or so here....I think you are the victim of the latest Coolwebsearch hijack for which a sure cure has not been found yet (it will probably be back :( )

I'm not seeing any good permanent fixes on this one yet that I can find, however, I found some workarounds to do in the meantime.

Step 1. Lets see if we can prevent the CWS hijackers reinfecting you try this. The workaround seems to be install a good firewall if you haven't already got one and block these ranges of ports, both incoming and outgoing 209.66.114.0-209.66.115.255 and 81.211.105.0-81.211.105.255

That stops the known CWS servers responding or the hidden files on your computer updating. This works sometimes but not always, however it seems to be a help in some cases. The problem with this approach is that some good sites might also be blocked.

Then, run CWShredder again. After its done its fixes hit the"How do i prevent reinfection" tab. In particular pay attention to the patches for the operating system regarding the ByteVerify vulnerability which is possibly how you got infected in the first place.

Keep watching Adaware and CWShredder for new updates (We have a Security Software Updates Forum here where the latest are always posted as soon as they are available)


Step 2 Download an alternative browser such as Opera www.opera.com or Mozilla Firefox http://www.mozilla.org/products/firefox/
Both are free and are less prone to hijacking.

You will need to hang on to IE for getting Windows updates but for now you might be able to browse in peace until we get a final fix on this awful nasty hijacker.

Keep in touch here as we will been keeping tabs on how it progresses to get a fix for this one. Then when we have a guaranteed working cure for it we can advise how to fully remove it.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.