• 0

about:blank homepage HIJACK!


Question

It keeps coming back, i delete it and clear everything, run spyware checks and clear my cookies and temp internet files. After 10 minutes, ITS BACK! It takes over the about:blank and turns it into some crappy search engine and keeps setting the homepage to about:blank. And the CRAPPY search engine pop's up dumb windows saying SPYWARE DETECTED BUY THIS DUMB PIECE OF **** TO REMOVE! and you just know it is them who are making the damn ads pop-up!

Link to comment
https://www.neowin.net/forum/topic/181371-aboutblank-homepage-hijack/
Share on other sites

Recommended Posts

  • 0

OK guys.. I work with computers all day professionally... WE got in a @$$load of computers today with this problem and I can tell you what it is... But I'm still workin on a way to REMOVE it permanently.. You've got one of the Downloader.*** viruses... Now I could remove it with AVG EVERY F'N time, but as soon as you restart the computer it reinstalles itself silently... So as of right now I know of no way to remove it ... That's even with the newest virus definitions... I'll try to keep you guys updated if I figure it out... But I was wrestling with it at work all day... heheh IT's a total BIACH !!!

- Primalgoo :alien:

  • 0

Dont have it anymore :no:(the log). But i think i got rid of it, there were some files in the system32 folder that i deleted, then i ran spybot, then i ran ad-aware, then i cleared my cookies and temp internet files, then in this one registry editor i deleted the thing that has oldstartpage. i think it is gone ill tell if it comes back! :angry:

  • 0

Ok. I actually had this nasty bugger for about 2 weeks abefore I finally, finally removed it permanently. If you look on that Merijn.org page with the various CoolWebSearch variants, you in all likelihood have the toughest and most annoying one of them all, #39, RealYellowPage. That is the same one that I had, and it is the biggest pain the rear to remove! CWShredder does a fine job of removing the secondary DLL file responsible for it, but it will not remove the primary one.

Here is what your case probably looks like:

-your homepage is about:blank

-instead of being the real about:blank, you actually have a search-type thing that links to searchx.cc

-after scanning with Ad-Aware, Spybot, HiJack This, and CWShredder, it seems to have been removed

-after some randomly determined period of time, your IE homepage will once again be reset to about:blank, and the problem will come back once again to haunt you

For now, I'm not going to give you full instuctions on how to remove it, because you may not need them. In your last post, you say that it is gone. If it stays gone for over 24 hours, I can say that you are rid of this nasty trojan.

If it comes back, I will explain to you how to remove it, step-by-step, and you should also print out the instructions, as you will need to have IE closed for it.

  • 0

It is gone, i keep checking my System32 folder and nothing is coming. Gota do everything at once without even opening and web browser during doing everything.

1) Remove new DLL's in your System32 folder (dated to when problem started)

2) Run Ad-Aware

3) Run Spy-Bot

4) in the registry delete OldStartPage and StartPage

5) Run HijackThis and delete everything suspecious

I think it is gone now been over 12 hours and no homepage change or dumb search thing!

  • 0

I had this problem for a while before. Its called CoolWebSearch searchx (CWS.searchx) head over to this site and read the instructions in response number 6. i did what it said, and it worked. let me know what happens!http://www.computing.net/security/wwwboard/forum/11527.html

  • 0

mrp04, you should be able to follow ice87's instructions from his last post, but the following will also work (I know because it worked for myself and two others with this problem).

Print out the following instructions to make it easier to walk through them.

You will need several things to get rid of it:

1. a Registry editor, such as REGEDIT or Registrar Lite, which are both mentioned below

2. CWShredder, which can be found on the site posted earlier in this thread

3. HiJack This

4. your Windows XP CD

5. Ad-Aware (optional)

I hope you still have your Windows XP CD available somewhere, as you will need it for this procedure. If not, you will need to access the Recovery Console either via floppy disks or by installing it.

Anyway, here we go.

Now, you can do this using the regular Windows Registry Editor (REGEDIT), but I believe it will be easier to do this using a freeware program called Registrar Lite, which you can download from its official website.

Navigate to the following location in your Registry (In Registrar Lite, you can just copy it into the Address Bar and hit Enter):

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows

Locate the key named AppInit_DLLs. Now, here is why I suggest Registrar Lite over REGEDIT. REGEDIT may or may not display the proper information in it when you open this key; Registrar Lite will display the proper information. If you have the CoolWebSearch trojan (and we have determined that you do already), you will see the address to a DLL file that you will be unable to locate using any method within Windows, but it does exist. This is the primary DLL file that you must remove in order to be rid of this nasty trojan, and it is this DLL file which randomly recreates the secondary DLL file that is actually identified under a different filename with each recurrence and each subsequent removal. Once you remove the primary DLL, you can safely remove everything else associated with it once and for all.

Now, write down the path of the DLL file that is specified in the AppInit_DLLs key. There may be periods in between the characters which can be ignored (except the period separating the filename and extension of the DLL file). This is the DLL file which you must remove using the command line in Recovery Console.

Now, you may run CWShredder followed by HiJack This and fix the lines that point to the DLL file with the strange filename. After this, reboot your computer with the Windows XP CD in your CD drive.

Boot from the CD. When you reach the Welcome to Windows Setup screen, just press the "R" key to access the Recovery Console. Choose which Windows installation you want (probably the first one), and then type in your Administrator password (if you have one).

You will then be given a command prompt. Now manually navigate to the folder with the DLL file that you wrote down earlier (the one found in the AppInit_DLLs key). It was probably in your System32 directory, so you can get there by typing cd c:\windows\system32 at the prompt. You can verify the DLL file's existence using the DIR command if you wish, but it is unnecessary.

Here is the most important part. The file is both a system file and a hidden file, so you must remove these attributes from the file. Type in attrib -s -h filename.dll, where "filename" is the name of the DLL file, which is different on each system. This will remove the hidden and system attributes from the file, which will now allow you to delete the file. Type in del filename.dll, where "filename" is the same name you typed in for the previous command above.

The primary filename is now deleted, and the biggest culprit in the whole mess with this trojan is now gone. You may reboot your computer back into Windows.

I recommend running a scan with Ad-Aware to remove an last remnants of the CoolWebSearch trojan, if there are any left, followed by another scan with CWShredder and HiJack This.

Having followed all the instructions in this post, you will be permanently rid of the CoolWebSearch trojan. You may reset your homepage in Internet Explorer to whatever you like now. It will stay that way.

  • 0
start -> run -> regedit

HKEY_LOCAL_MACHINE/SOFTWARE/MICROSOFT/INTERNET EXPLORER/MAIN

they keys u gotta edit r there.... they will say about:blank or sp.html

whereever the about:blank is change it to the address u want

whereever the sp.html is delete it

thats wah i did today n its workin soo :p

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Glad these prices are starting to come down, but that is still crazy. I bought the 2TB 9100 Pro (slightly more expensive version with PCIe 5.0) last year for $240.
    • The 2TB Samsung 990 PRO NVMe SSD hits lowest price in over three months by Sayan Sen Yesterday, we covered a really good deal wherein you can get a 4TB TeamGroup T-FORCE G50 NVMe PCIe Gen4 SSD for a low price of just $400 with a special discount coupon. That's just $100 per TB, making it a very good offer during these hard times. The deal is still live, so you can check it out in its dedicated article here if you do not want to miss out. Meanwhile, if you don't have that kind of budget but still wish to buy an SSD for a good price, the 2TB variant of the TeamGroup SSD at $280 its lowest price in over three months. Meanwhile, those seeking 2TB but faster performance can check out Samsung's 990 PRO, which has hit the lowest price also in the last quarter or so, as it's on sale for $370 (purchase links under the specs table down below). Thus, you want a faster drive, get the 990 Pro, or you want more capacity, grab the TeamGroup 4TB linked in the first para. The 990 PRO is a PCIe Gen4 NVMe SSD and still one of the fastest drives available today for under $500. Speaking of fast, sequential reads and writes are rated at 7450 MB/s and 6900 MB/s, respectively. The random throughputs for reads and writes are 1400K IOPS and 1550K IOPS, respectively. The 990 PRO is based on Samsung's 7th Gen V-NAND flash, and it too is TLC. It packs 2 gigs of LPDDR4 DRAM cache, which helps the random performance. The endurance rating for this is 1200 TBW (terabytes written), which should be sufficient for most users. The Samsung 990 PRO is compatible with the PlayStation 5, but if you are going to use the 990 PRO on a PC, check out the Samsung Magician app that lets you track your drive's health, update its firmware, customize various settings, and more. The tech specs are given below: Specification TeamGroup T-FORCE G50 2TB Samsung 990 PRO 2TB Interface PCIe 4.0 x4, NVMe 1.4 PCIe Gen 4.0 x4, NVMe 2.0 Form Factor M.2 2280 M.2 2280 Controller InnoGrit Controller Samsung In-house Controller NAND Flash 3D TLC 3D TLC DRAM Cache None (HMB supported) 2GB LPDDR4 Sequential Read (Max) 5,000 MB/s 7,450 MB/s Sequential Write (Max) 4,500 MB/s 6,900 MB/s Random Read (4K) Up to 600,000 IOPS Up to 1,400,000 IOPS Random Write (4K) Up to 700,000 IOPS Up to 1,550,000 IOPS TBW (Endurance) 1,300 TBW 1,200 TBW MTBF 3,000,000 hours 1,500,000 hours Operating Temperature 0°C to 70°C 0°C to 70°C Storage Temperature -40°C to 85°C -40°C to 85°C Shock Resistance 1,500G / 0.5ms 1,500G / 0.5ms Heatsink Patented Graphene Heat Spreader No Get them at the links below: Samsung 990 PRO SSD 2TB (MZ-V9P2T0B/AM): $369.99 (Sold and Shipped by Amazon US) TEAMGROUP T-Force G50 2TB SSD (TM8FFE002T0C129): $279.99 (Sold by TeamGroup, Shipped by Amazon US) Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
    • If you can't spell a simple word that 2nd graders learn, your entire argument is suspect.
    • And here goes the "Won't someone think of the children" brigade. Get stuffed mate. This has NOTHING to do with making the internet safe. It's about tracking adults, spying on your online activity, and sending the boys around when they don't like something you post. Also, again, parliament have voted TWICE against this, and Starmer is going ahead anyway. THAT is anti-democratic bullsh**. They will use this law to track you, they will use this law to control you, and they will use this law to punish you if they don't like what you do, even if it's legal. And your data? Say bye bye to that. It'll be on the darkweb in weeks. I'm not some rando online. I've been an IT professional for 40 years, many of it in security. I know exactly what this means and what will happen to your data. I do not consent and I will not comply.
    • "...but it may not be Microsoft's fault" seems like a reasonable way to tease what is going on without leaving the user with a false impression that an update is the problem. A title isn't a summery, it is meant to entice the user to read the article. It should not contain a misleading premise; which this title does not. You could maybe complain that the first paragraph should have included that detail. The writing style popularized over 100 years ago in newspapers will cover the most important information as soon as possible with details and nuance added later; the idea being that with each new paragraph you have less of the reader's focus.
  • Recent Achievements

    • First Post
      Jocimo earned a badge
      First Post
    • Week One Done
      suprememobiles48 earned a badge
      Week One Done
    • One Month Later
      Windows Guy earned a badge
      One Month Later
    • One Month Later
      Prasann earned a badge
      One Month Later
    • Week One Done
      Prasann earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      520
    2. 2
      +Edouard
      174
    3. 3
      PsYcHoKiLLa
      90
    4. 4
      Steven P.
      81
    5. 5
      ATLien_0
      70
  • Tell a friend

    Love Neowin? Tell a friend!