problem removing about:blank browser hijacker

  • Thread starter Thread starter Ryan
  • Start date Start date
R

Ryan

I went to the following site:

http://www.pchell.com/support/aboutblank.shtml

it says to look in the registry for:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Windows\\AppInit_DLLs


I don't have an AppInit_DLLs in that directory? Is there a new variant of
about:blank.

or am I reading it wrong. Just before AppInit_DLLs there are two \\, does
that signify something other then the directory?
 
Ryan said:
I went to the following site:

http://www.pchell.com/support/aboutblank.shtml

it says to look in the registry for:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Windows\\AppInit_DLLs


I don't have an AppInit_DLLs in that directory? Is there a new variant of
about:blank.

or am I reading it wrong. Just before AppInit_DLLs there are two \\, does
that signify something other then the directory?

Ad-Aware's (ADS) feature scans for that second .dll mention in the article
you posted.Also About Buster will scan for it as well.
Ad-Aware SE - http://www.lavasoftusa.com/software/adaware/
About Buster- http://www.spychecker.com/program/aboutbuster.html
LSP-fix- http://www.cexx.org/lspfix.htm
Spybot S&D - http://www.safer-networking.org/en/index.html
SpywareBlaster - http://www.javacoolsoftware.com/spywareblaster.html

These two programs will notify you of changes to your home/startpage as it
is happening and will give you a name/location of the .dll that is doing it.
WinPatrol - http://winpatrol.com
SpywareGuard - http://www.javacoolsoftware.com/spywareguard.html

The article says that it is tied to a "BHO" this free program will show you
all BHO's in IE and gives you and option to disable them
BHODemon - http://pcworld.com/downloads/file_download.asp?fid=23611&fileidx=1
 
Ryan said:
I went to the following site:

http://www.pchell.com/support/aboutblank.shtml

it says to look in the registry for:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Windows\\AppInit_DLLs


I don't have an AppInit_DLLs in that directory? Is there a new variant
of about:blank.

or am I reading it wrong. Just before AppInit_DLLs there are two \\,
does that signify something other then the directory?

That is not exactly the whole story. It is better explained at the
SilentRunners site referenced below in Step 2. In order to remove the
about:blank hijacker, run the following tools:

1) Scan in Safe Mode with current version (not earlier than 2003)
antivirus using updated definitions;

2) remove spyware with Spybot Search & Destroy
(www.safer-networking.org) and Ad-aware (www.lavasoftusa.com). These
programs are free, so use them both since they complement each other.
There is a new version of CWShredder from
http://www.intermute.com/spysubtract/cwshredder_download.html. I would
not install the other Intermute programs, however. Alternately, there
are CoolWebSearch malware removal steps at
http://www.silentrunners.org/sr_cwsremoval.html. A combination of
HijackThis and About:Buster (http://www.majorgeeks.com) works well in
removing homepage hijackers. Always read the instructions before
running a spyware removal tool. Be sure to update these programs before
running, and it is a good idea to do virus/spyware scans in Safe Mode.
Make sure you are able to see all hidden files and extensions (View tab
in Folder Options);

3) If you are running Windows ME or XP, you should disable/enable System
Restore because malware will be in the Restore Points. With ME, you
must disable System Restore completely. With XP, you can delete all but
the most recent (presumably clean) System Restore point from the More
Options section of Disk Cleanup (Run>cleanmgr).

4) make sure you've visited Windows Update and applied all security
patches. Do not install driver updates from Windows Update;

5) run a firewall.

Malke
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Back
Top