About Blank

S

Snide

I have run MSAS a number of times but cant seem to get
rid of the about blank homepage hijacker. Every time I
run the scan it detects the same hijacker, removes it
only to reappear. The pop ups havent stopped as well. Any
suggestions?
 
G

Guest

Have had same problem for a number of weeks, tried
deleting the registry key but it reappears when i restart
the computer. Any suggestions much appreciated
 
P

plun

-----Original Message-----
I have run MSAS a number of times but cant seem to get
rid of the about blank homepage hijacker. Every time I
run the scan it detects the same hijacker, removes it
only to reappear. The pop ups havent stopped as well.
Any suggestions?

Latest versions of About:blank is difficult to remove.
A real "hide&run" with antispywareprograms.
Special tools are often needed and therefore a user
need guidance from a skilled technician.

Try this forum and do this first:

http://aumha.net/viewtopic.php?t=4075

and then post your Hijack log if needed.
 
G

Guest

-----Original Message-----


Latest versions of About:blank is difficult to remove.
A real "hide&run" with antispywareprograms.
Special tools are often needed and therefore a user
need guidance from a skilled technician.

Try this forum and do this first:

http://aumha.net/viewtopic.php?t=4075

and then post your Hijack log if needed.

--
plun


.
THANK YOU PLUN!!!
 
A

Andymanchesta

Ive just replied to a similar problem so wanted to resend
you my post Hope it helps

I will try help you remove this CWS Trojan but its not a
easy thing to do as like Plus says its a real hide & run
type trojan and the makers are very talented in what they
do,they know how to manipulate windows and where to put
things where they cannot be removed without causing other
problems but follow these tips and hopefully it will sort
it for you at the very least it will provide you with
protection and clean any malicious files from your system


Getting Prepared; Steps to be sure your system is ready
to be scanned:

1: Disable System Restore temporarily (WinXP & WinME
only) if you are infected; Any trojans, spyware, etc. you
may have picked up could have been saved in System
Restore and are waiting to re-infect you. Since System
Restore is a protected directory, your tools can not
access it to delete files, trapping viruses inside.
Please follow instructions to do that here:
(Start>Right click my computer>Properties>System
Restore>Disable then apply and exit)


2: Network Security, Workstation Netlogon Services &
Remote Procedure Call (RPC) Helper (Windows XP, 2K, NT);
Only do this step if you have the about:blank or home
search hijack. You need to check to see if any of the
following three Windows services are running:
Network Security Service
Workstation Netlogon Service
Remote Procedure Call (RPC) Helper
To do this, click Start, Run, and enter the following in
the Open box: "services.msc" (without the quotes). Then
click OK. Now, in the Services window that pops up look
for exactly the following service names (no
others) "Network Security Service" or "Workstation
Netlogon Service" or "Remote Procedure Call (RPC)
Helper". (NOTE: DO NOT DISABLE: Remote Procedure Call
(RPC) or Remote Procedure Call (RPC) Locator. They are
both required services and are unrelated to the
hijacker.). You could have more than one of the 3
mentioned bad services, so look for all of them. If you
find these services, you must right click on it to bring
up the service Properties window and do the following :


Step 1: Stop the service by click the Stop button.

Step 2: Now, disable it by changing the Startup type to
Disabled and click Apply


If you do not find these exact services, do not worry and
just skip this step. DO NOT DISABLE ANYTHING UNLESS THE
EXACT WORDING OF THE SERVICE NAMES IS MATCHED.



3: Enable viewing of hidden files and folders and
extensions; Some programs can hide this way by not being
visible in Windows. Start Windows Explorer and click on
your main hard drive, usually c:\. Then select Tools from
the top of Windows Explorer and then Folder Options. Go
to the View tab. Scroll down to the folder icon that says
Hidden files and folders and check show hidden files and
folders. Also, right below it, uncheck the hide file
extensions for known types. Not doing this could allow
file extensions commonly used by trojans and spyware to
be hidden, for example a file ending in .exe or dll
making manually finding it, if needed, difficult to
impossible.


4: Downloading Tools; Download the following tools and
save in your favorite download folder or create one, for
example C:\Temp or C:\Downloads. And then install,
update, and configure as indicated below. While this may
seem like overkill, there currently is no one perfect
removal tool. Because of this, to properly find and fix
your problem, you need to try a variety of programs.

Ad-Aware SE.......Install, click Check for Updates now
and get any updates, then exit.

http://www.majorgeeks.com/downloadget.php?
id=506&file=11&evp=8dbaff7daca8f4b55bf695220993fc0f

Ad-Aware VX2 Cleaner Plug-In.....Install only

http://majorgeeks.com/downloadget.php?
id=4283&file=1&evp=34312f31f5a8511bfb7cf839b1eaff0b

CCleaner.............Install only, then exit

http://majorgeeks.com/downloadget.php?
id=4191&file=11&evp=a12d758b021af1a4f0a6bfe45b0c7a82

Spybot................Install, do the search for updates
now and get any updates, then exit.

http://www.majorgeeks.com/downloadget.php?
id=2471&file=11&evp=2470f9bfb0cc682334ff8c4459556118

Spybot - Search and Destroy DSO Exploit Fix - Install
this patch on top of Spybot to fix the DSO Exploit bug

http://www.majorgeeks.com/downloadget.php?
id=4392&file=1&evp=17a4645dc80f11461d8549719a9350e0

SpywareBlaster...Install, click Download Latest
Protection Updates, Check for Updates, and then Enable
All Protection, then exit. It does a great job of
blocking known vulnerabilities as well as known malicious
websites.

http://majorgeeks.com/downloadget.php?
id=2859&file=11&evp=61b0e8ad41924a03c37615f4682b4cef

McAfee AVERT Stinger.....No installation required! Ready
to run as is.

http://majorgeeks.com/downloadget.php?
id=4063&file=1&evp=9cf4d4f57a4c688fe042954e1ef29968


CWShredder......No installation required! Just unzip it
to a folder.

http://cwshredder.net/bin/CWShredder.exe

Kill2me..............No installation required! Just unzip
it to a folder.

http://www.majorgeeks.com/downloadget.php?
id=4166&file=1&evp=e994cf5e9abe6c93b47c01f2922c271f

about:Buster......No installation required! Just unzip it
to a folder. Click Update and download any before
scanning.

http://majorgeeks.com/downloadget.php?
id=4289&file=1&evp=ae3de3780275c1771c4e5047af537d4a

HSRemove........No installation required! Ready to run as
is.

http://majorgeeks.com/downloadget.php?
id=4286&file=11&evp=71f181068920b47d2133db96f04fb442


Your system is now ready to be properly scanned for
spyware, trojans and viruses.

Scanning And Cleaning Steps: (note steps 1 thru 4 are NOT
optional!)

1: Virus And Trojan Scanning (do not skip these two scans)

a) Win9x (Windows 95, 98, 98SE) users boot normal mode.

do an online scan at Trend Micro's Free Online Virus Scan

http://housecall.trendmicro.com/housecall/start_corp.asp

do an online scan at Symantec Security Check

http://security.norton.com/sscv6/default.asp?
langid=ie&venid=sym

now boot in safe mode (and remain there) and run McAfee
AVERT Stinger.

How to boot in safe mode: To boot into safe mode, restart
your computer and tap the f8 key (after first black and
white screen, but before the Windows splash screen) until
you get to a black and white screen asking you what to
do. With Windows XP, 2000, NT, ME: Use your arrow keys
and select "safe mode with networking support".

Booting in safe mode is important because best results
are achieved since safe mode disables most drivers and
running programs.


Clean Your Hard Drive; Remove temporary internet and
other files not needed with CCleaner. Run CCleaner with
the default options to clean out temporary files.

3: Main Spyware Scan And Removal; Scan your machine with
Ad-Aware SE (remember to install the Ad-Aware VX2 Cleaner
Plug-In for it) and Spybot. Look for the Immunize feature
in Spybot and use it. Make sure you install the Spybot
DSO Exploit patch before running a scan with Spybot.

4: Secondary Spyware Scan And Removal: Other Removal
Tools; Run the other programs you downloaded; CWShredder
(make sure you select Fix), Kill2me, about:Buster and
HSRemove. They are free, standalone and easy to use.

Note: about:Buster and HSRemove need only be run if you
are having about:blank or HomeSearchAssistent hijacks.
Also, note that HSRemove is not compatible with Win9x or
WinMe systems.


If these items fail then the next step is Hijack this but
that isnt a simple program to use as any mistakes can
seriously damage your pc,

Please repost though and let me know how you get on,Same
if you have any problems just repost and i will help
where i can



Regards Andy

..
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads

about blank hompage hijacker 6
about blank 1
spyware.65 2
about blank homepage hijacker 4
ABetterInternet and related adware 3
same two spyware hits 3
about:blank 4
Failure to Remove Aurora 6

Top