IPB

Welcome Guest ( Log In | Register )

 
Reply to this topicStart new topicStart Poll

Outline · [ Standard ] · Linear+

> about:blank hijack

artzelda
post Jun 10 2004, 05:32 PM
Post #1


The MAN
****

Group: Private Member
Posts: 455
Joined: 18-March 04
Member No.: 26



Well a friend of mine got his IE hijacked by about:blank resulting in the launching of rapid fire popups that the popup stoppers could not prevent. Went to the merjn site to find out about it and it is a "nasty malware". Believe me it is nasty. All the solutions there did not work because this was a new variant of this malware. I used BPS spyware to remove some of the shit this put on his system but it kept coming back.

Eventually I had to go into the registry and do a search for "about" and "blank". If both are not eliminated the malware keeps coming back. The problem there is a lot of stuff in the registry called 'about' and 'blank' that are asociated with other programs. So the deletion was time consuming and tedious but it worked.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
mcelb1200
post Jun 11 2004, 03:51 AM
Post #2


nFm [ Level 1 ]
***

Group: Full Member
Posts: 240
Joined: 29-April 04
From: Melbourne, Australia
Member No.: 94



Just out of interest... did you happen to keep a record of thye location of the registry keys the about:blank registered?


--------------------
user posted image
... just let me see if I can get that log out of your eye...
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
artzelda
post Jun 11 2004, 03:43 PM
Post #3


The MAN
****

Group: Private Member
Posts: 455
Joined: 18-March 04
Member No.: 26



Sorry, no I didn't. But it was in a number of locations. Be sure to do a separate search for blank and about
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Taggard
post Jun 23 2004, 08:38 PM
Post #4


nFm [ stuck around ]
**

Group: Members
Posts: 16
Joined: 14-June 04
Member No.: 117



Does anyone have any updated info on the about:blank hijacker. It seems to not be fully removed by spybot or adaware and I am wondering if there is a quick fix for it. I have come across it a number of times in the past week.


--------------------
THINK or slow down evolution...You choose, but use your brain to make that choice.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
artzelda
post Jun 24 2004, 08:10 PM
Post #5


The MAN
****

Group: Private Member
Posts: 455
Joined: 18-March 04
Member No.: 26



What do you call info dated 6-10 and 6-11. I don't think there is newer info than this. If you find it let me know.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

Reply to this topicTopic OptionsStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:
 

Lo-Fi Version Time is now: 30th April 2024 - 09:33 AM