Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Adware in MS Outlook express

Thread Tools
 
Search this Thread
 
Old 12 September 2004, 09:43 PM
  #1  
mark@wrx
Scooby Regular
Thread Starter
 
mark@wrx's Avatar
 
Join Date: Sep 2002
Location: Cumbrian Scoobs
Posts: 2,616
Likes: 0
Received 0 Likes on 0 Posts
Default Adware in MS Outlook express

I had a problem recently where my homepage kept changing to about:blank. I can't sort that and now when I open "create new mail" in OE I get a copy of the homepage for about:blank.

I've tried Spywareblaster, Adaware6, Norton anti virus and Hijack this but still can't get rid of either. Has anyone got any suggestions please. I'm not too good with computers so laymen terms please. Thanks, Mark
Old 12 September 2004, 10:00 PM
  #2  
Soulgirl
Scooby Regular
 
Soulgirl's Avatar
 
Join Date: Dec 2002
Location: Here!
Posts: 5,145
Likes: 0
Received 0 Likes on 0 Posts
Default

Adaware SE should take care of that.. download the latest

Otherwise this thread gives instructions that are the long way round
http://www.d-a-l.com/help/showthread.php?t=1798
Old 12 September 2004, 10:02 PM
  #3  
lordharding
Scooby Regular
iTrader: (1)
 
lordharding's Avatar
 
Join Date: Oct 2000
Location: cumbria
Posts: 6,802
Likes: 0
Received 1 Like on 1 Post
Wink

Hi mark

not often i lurk on the computer section but i have the same problem


with about blank on my home page i just got it back from my friendly <geek> who couldnt sort it neither


A Rusty viras prehaps
Old 12 September 2004, 10:14 PM
  #4  
BAH
Scooby Regular
 
BAH's Avatar
 
Join Date: Mar 2003
Location: Tyne Tees Scoobies
Posts: 2,689
Likes: 0
Received 0 Likes on 0 Posts
Default

As above adware, but if that dont get it ist some messsing in the registry or a better alternative, bin it and reload everything and start a fresh.

Get some Anti-virus & firewall software
Old 12 September 2004, 10:19 PM
  #5  
Nicks VR4
Scooby Regular
 
Nicks VR4's Avatar
 
Join Date: May 2003
Posts: 1,165
Likes: 0
Received 0 Likes on 0 Posts
Default

You could try this too

Homepage hijackers are an effect caused by some toolbar programs, trojans or malware. The hostile application changes the default homepage of Internet Explorer to something undesired and does not allow the user to set the homepage.

Below are several tools which can be used to find and remove malware which causes the effect. Presented here is also a manual step-by-step method of removing more persistent homepage hijackers.
Please reboot the machine after each step before checking if the removal was successful.

Spyware / trojan removal tools:
Spybot - Search & Destroy can detect and remove spyware of different kinds from your computer. Spyware is a relatively new kind of threat that common anti-virus applications do not yet cover. If you see new toolbars in your Internet Explorer that you didn't intentionally install, if your browser crashes, or if you browser start page has changed without your knowing, you most probably have spyware.

CWShredder - A general homepage hijackers detector and remover. Initially based on the article Hijacked!, but expanded with almost a dozen other checks against hijacker tricks. It is continually updated to detect and remove new hijacks.

AVG antiVirus - An antivirus tool which also deals with some hijackers.

Manual step-by-step:
If a persistent hijacker is not removed by the tools listed above, manual removal should be used.

To Remove "About:Blank" Hijacker Adware In Windows XP Home edition Service Pack 1 with Internet Explorer 6.0
(probably works in NT and 2000 with some directory name changes only) follow this procedure:

Programs Needed:
* Reglite.exe

* Microsoft Recovery Console (an application available on your Windows installation disc). To access the recovery console run the following command: D:\i386\winnt32.exe /cmdcons
(Where D should be replaces with the CD driveletter)

* HiJackThis.exe

Removal Procedure:
There are two application extensions (.dll) files that Need to be deleted. One is hidden (thanks Akadia!), one is detected with "HiJackThis.exe"

1) With "Reglite.exe" find name of hidden file:
Double Click on "AppInit_DLLs" located in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\ The "value" window reveals the hidden file name. (mine was "hlpl.dll", yours may be different!)
In this example we'll call it "hidden.dll"
Browse to the file, right click it, select Properties. Under the General tab, uncheck Hidden and Read-Only. Select the Security tab and Check the 'Full control' check box to allow deleting it.
Try deleting the file (Shift + Del or right click and Delete) If it was impossible to delete the file, continue to step 2. Otherwise skip to step 3.

2) Rename the hidden file:
Close Windows and reboot using "Windows Recovery Console"
Bwose to the system32 directory located at: C:\Windows\system32\
Replace this path with your system32 dir. In order to know your system32 run cmd and type:
echo %WINDIR%\System32

After finding your system32 directory do the following:
a) Change file from read only by typing attrib -r hidden.dll
b) Rename the file (For some reason this only works after rename) type: rename hidden.dll nasty.dll
(and remember that "hidden.dll" is for this explanation only use the name you found earlier)
Type "exit" and reboot to Windows.

3) Edit registry to remove hidden file:
Run "reglite.exe" again.
Double Click on "AppInit_DLLs" located in
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\
Delete the file in "value" window, the "size" window changes also.
"Apply" changes and exit "reglite.exe"

4) Edit registry to remove the second file:
Run HiJackThis.exe and scan the registry.
Check the boxes to remove the following entries:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
res://C:\WINDOWS\System32\jheckb.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
res://C:\WINDOWS\System32\jheckb.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
res://C:\WINDOWS\System32\jheckb.dll/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
res://C:\WINDOWS\System32\jheckb.dll/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
res://C:\WINDOWS\System32\jheckb.dll/sp.html (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
res://C:\WINDOWS\System32\jheckb.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP =
about:blank
(as you can see the second .dll in the example was called "jheckb.dll" yours may be different) For this example let's call it "obvious.dll".

* Note: As there are MANY variations to this hijacker, the registry entries might differ from the ones listed above. If the entries are different, look for entries containing the name of the second dll, in this example jheckb.dll.

Finally delete the two .dlls ("hidden.dll" and "obvious.dll")

That's it! You should be running again

By the way, if you go offline with Internet Explorer and type OK To these nasty adware windows you will see the guys who benefit from this hijacker. Time2Early found:
www.likesurfing.com
www.vn.msie.cc (the real web page)

They seem to be selling adware/spyware protection...
Old 13 September 2004, 11:26 AM
  #6  
mark@wrx
Scooby Regular
Thread Starter
 
mark@wrx's Avatar
 
Join Date: Sep 2002
Location: Cumbrian Scoobs
Posts: 2,616
Likes: 0
Received 0 Likes on 0 Posts
Default

Wow, thanks Nick
Old 13 September 2004, 05:22 PM
  #7  
Brendan Hughes
Scooby Regular
 
Brendan Hughes's Avatar
 
Join Date: Oct 2000
Location: same time, different place
Posts: 11,313
Likes: 0
Received 4 Likes on 2 Posts
Default

My spyware just manifested itself in the clipboard; I pasted something without copying beforehand, and suddenly got several lines of http address.
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
powerwrx
Non Scooby Related
21
03 October 2015 11:31 PM
WREXY
Non Scooby Related
7
15 August 2001 12:09 PM
TelBoy
Non Scooby Related
2
31 July 2001 06:55 AM
Gastro
Non Scooby Related
7
17 July 2001 03:17 PM
sickboy
ScoobyNet General
5
28 October 2000 09:59 PM



Quick Reply: Adware in MS Outlook express



All times are GMT +1. The time now is 06:56 AM.