about blank gets around Microsoft Antispyware

E

Engel

about:blank is difficult to remove because different means
are used to hide the infecting file.

1 - Check the Services to see if a phantom Service has
been implemented Stop, then disable the Service from
running on Startup. Then attempt to rename the .dll file
in Normal mode, reboot to Safe Mode and delete it.

2 - Check the registry with Registrar Lite to see if
AppInit_DLLs has a hidden file. Here's a webpage that
describes how to use this method :
http://www.silentrunners.org/sr_cwsremoval.html

3 - See if you can view the hidden .dll files. A hidden
file may have been injected into one of these 2 processes -
Explorer.exe or IExplore.exe :

Download ProcessViewer : http://tools.zerosrealm.com/pv.zip
Extract it to the Desktop. Open the pv folder and double-
click "runme.bat".
A DOS box will open. Select Type 2 for Internet Explorer
Dll's and press Enter.

OR, Type 1 for Explorer Dll's.

Notepad will open with text in it. You'll need to know
exactly which file(s) needs to be deleted. Removing
required ones can render the system unstable.

Removing the file(s) requires using Hijack This or KillBox
to do so on a reboot. Best to let an expert at a spyware
forum assist you with this.

Get HijackThis.exe from
http://tomcoyote.org/hjt/hjt199//HijackThis.exe

Save it to C:\hjt (new folder) then Open it and select
Scan and Save Log. Note where you saved the log then send
it to Ron Kinner as an attachment. He can probably
identify the problem and tell you how to get rid of it for
good.

Ron email address. (e-mail address removed)
He will tell you what to do next. Put Hijack in the
subject so he will know it's not spam.

For information
HijackThis tutorial:
http://www.bleepingcomputer.com/forums/index.php?
showtutorial=42

If the malware problem comes back further specialised
assistance is available via the Hijackthis forum at
http://forum.aumha.org - make sure you read the top
announcements about pre-post steps you should take before
generating a hijackthis log.

http://www.bleepingcomputer.com/files/killbox.php

Here's a few of the reputable spyware forums where you'll
be able to find assistance. Please read the guidelines of
the one you choose prior to posting there :

http://www.bleepingcomputer.com/forums/forum22.html
http://forums.net-integration.net/index.php?showforum=32
http://forum.aumha.org/viewforum.php?f=30
http://spywarewarrior.com/viewforum.php?
f=2&sid=3ce3e4c9a40b25268d1bac3189d22184
http://computercops.biz/forum67.html
 
F

Furious user

Ty Engel that's at least some usefull info's & systematic

*I tryed already some of what u said as blocking the
startup but i try again as u said
*About renaming the DLL i tryed that too but the
Antispyware is precisely blocking also ( grrr !!) any
changing on DLL so they are automatically recreated...but
i saw that just recently...
*About the registry i mentionned also that the spyware is
usiing some 'RunOnce' key but it's chaging it's changing
it's name anytime u start yr system or try to run
IEXPLORER...so i need to fix the startup problem first I
think...grrr
Other thing in the registry is a Key called 'SW' with is
obviously generatig the false favorites so far I know
*I tryed even to rename the .exe files but all this
doesn't work...just becoz I think the startup is running
the Internet Exporer each time u reboot the machine and
some exe are just not visible coz for sure resident into
the Ram already...
The Antispyware detect some of them but not all because I
checked again with NORTON ANTIVIRUS and this one found
other *.exe Beta Anti spyware didn't found...etc etc etc

Sorry if I mixed up some elements...but it's really
tiring to have this spyware on yr computer and using a
product as the GlobalAntispyware...who does all the time
the same..( a lot indeed & good detecetion but
incomplete) but not the necessary things >>blocking the
unsollicited Start of IExplorer

Ty ENGEL again...
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top