• 0

about:blank homepage HIJACK!


Question

It keeps coming back, i delete it and clear everything, run spyware checks and clear my cookies and temp internet files. After 10 minutes, ITS BACK! It takes over the about:blank and turns it into some crappy search engine and keeps setting the homepage to about:blank. And the CRAPPY search engine pop's up dumb windows saying SPYWARE DETECTED BUY THIS DUMB PIECE OF **** TO REMOVE! and you just know it is them who are making the damn ads pop-up!

Link to comment
https://www.neowin.net/forum/topic/181371-aboutblank-homepage-hijack/
Share on other sites

Recommended Posts

  • 0

OK guys.. I work with computers all day professionally... WE got in a @$$load of computers today with this problem and I can tell you what it is... But I'm still workin on a way to REMOVE it permanently.. You've got one of the Downloader.*** viruses... Now I could remove it with AVG EVERY F'N time, but as soon as you restart the computer it reinstalles itself silently... So as of right now I know of no way to remove it ... That's even with the newest virus definitions... I'll try to keep you guys updated if I figure it out... But I was wrestling with it at work all day... heheh IT's a total BIACH !!!

- Primalgoo :alien:

  • 0

Dont have it anymore :no:(the log). But i think i got rid of it, there were some files in the system32 folder that i deleted, then i ran spybot, then i ran ad-aware, then i cleared my cookies and temp internet files, then in this one registry editor i deleted the thing that has oldstartpage. i think it is gone ill tell if it comes back! :angry:

  • 0

Ok. I actually had this nasty bugger for about 2 weeks abefore I finally, finally removed it permanently. If you look on that Merijn.org page with the various CoolWebSearch variants, you in all likelihood have the toughest and most annoying one of them all, #39, RealYellowPage. That is the same one that I had, and it is the biggest pain the rear to remove! CWShredder does a fine job of removing the secondary DLL file responsible for it, but it will not remove the primary one.

Here is what your case probably looks like:

-your homepage is about:blank

-instead of being the real about:blank, you actually have a search-type thing that links to searchx.cc

-after scanning with Ad-Aware, Spybot, HiJack This, and CWShredder, it seems to have been removed

-after some randomly determined period of time, your IE homepage will once again be reset to about:blank, and the problem will come back once again to haunt you

For now, I'm not going to give you full instuctions on how to remove it, because you may not need them. In your last post, you say that it is gone. If it stays gone for over 24 hours, I can say that you are rid of this nasty trojan.

If it comes back, I will explain to you how to remove it, step-by-step, and you should also print out the instructions, as you will need to have IE closed for it.

  • 0

It is gone, i keep checking my System32 folder and nothing is coming. Gota do everything at once without even opening and web browser during doing everything.

1) Remove new DLL's in your System32 folder (dated to when problem started)

2) Run Ad-Aware

3) Run Spy-Bot

4) in the registry delete OldStartPage and StartPage

5) Run HijackThis and delete everything suspecious

I think it is gone now been over 12 hours and no homepage change or dumb search thing!

  • 0

I had this problem for a while before. Its called CoolWebSearch searchx (CWS.searchx) head over to this site and read the instructions in response number 6. i did what it said, and it worked. let me know what happens!http://www.computing.net/security/wwwboard/forum/11527.html

  • 0

mrp04, you should be able to follow ice87's instructions from his last post, but the following will also work (I know because it worked for myself and two others with this problem).

Print out the following instructions to make it easier to walk through them.

You will need several things to get rid of it:

1. a Registry editor, such as REGEDIT or Registrar Lite, which are both mentioned below

2. CWShredder, which can be found on the site posted earlier in this thread

3. HiJack This

4. your Windows XP CD

5. Ad-Aware (optional)

I hope you still have your Windows XP CD available somewhere, as you will need it for this procedure. If not, you will need to access the Recovery Console either via floppy disks or by installing it.

Anyway, here we go.

Now, you can do this using the regular Windows Registry Editor (REGEDIT), but I believe it will be easier to do this using a freeware program called Registrar Lite, which you can download from its official website.

Navigate to the following location in your Registry (In Registrar Lite, you can just copy it into the Address Bar and hit Enter):

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows

Locate the key named AppInit_DLLs. Now, here is why I suggest Registrar Lite over REGEDIT. REGEDIT may or may not display the proper information in it when you open this key; Registrar Lite will display the proper information. If you have the CoolWebSearch trojan (and we have determined that you do already), you will see the address to a DLL file that you will be unable to locate using any method within Windows, but it does exist. This is the primary DLL file that you must remove in order to be rid of this nasty trojan, and it is this DLL file which randomly recreates the secondary DLL file that is actually identified under a different filename with each recurrence and each subsequent removal. Once you remove the primary DLL, you can safely remove everything else associated with it once and for all.

Now, write down the path of the DLL file that is specified in the AppInit_DLLs key. There may be periods in between the characters which can be ignored (except the period separating the filename and extension of the DLL file). This is the DLL file which you must remove using the command line in Recovery Console.

Now, you may run CWShredder followed by HiJack This and fix the lines that point to the DLL file with the strange filename. After this, reboot your computer with the Windows XP CD in your CD drive.

Boot from the CD. When you reach the Welcome to Windows Setup screen, just press the "R" key to access the Recovery Console. Choose which Windows installation you want (probably the first one), and then type in your Administrator password (if you have one).

You will then be given a command prompt. Now manually navigate to the folder with the DLL file that you wrote down earlier (the one found in the AppInit_DLLs key). It was probably in your System32 directory, so you can get there by typing cd c:\windows\system32 at the prompt. You can verify the DLL file's existence using the DIR command if you wish, but it is unnecessary.

Here is the most important part. The file is both a system file and a hidden file, so you must remove these attributes from the file. Type in attrib -s -h filename.dll, where "filename" is the name of the DLL file, which is different on each system. This will remove the hidden and system attributes from the file, which will now allow you to delete the file. Type in del filename.dll, where "filename" is the same name you typed in for the previous command above.

The primary filename is now deleted, and the biggest culprit in the whole mess with this trojan is now gone. You may reboot your computer back into Windows.

I recommend running a scan with Ad-Aware to remove an last remnants of the CoolWebSearch trojan, if there are any left, followed by another scan with CWShredder and HiJack This.

Having followed all the instructions in this post, you will be permanently rid of the CoolWebSearch trojan. You may reset your homepage in Internet Explorer to whatever you like now. It will stay that way.

  • 0
start -> run -> regedit

HKEY_LOCAL_MACHINE/SOFTWARE/MICROSOFT/INTERNET EXPLORER/MAIN

they keys u gotta edit r there.... they will say about:blank or sp.html

whereever the about:blank is change it to the address u want

whereever the sp.html is delete it

thats wah i did today n its workin soo :p

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • First time clicking on a Sayan Sen article after he started making clickbait, vague headlines recently. Didn't read, just came here to say the headline doesn't look like very cheap, vague clickbait this time. Are you okay?
    • Good review, and yeah the benchmark breakdown is pretty clear but also a little messy in a good way. It’s kinda interesting to see where the RX 9070 GRE slides in between the 7800 XT and the 9070 XT , especially when it comes to AI tasks and Blender style workloads. The side by side with Nvidia’s RTX 5070 and 4070 makes it feel obvious just how competitive the mid range GPU scene has gotten lately, and that’s great for creators and gamers too since you can pick based on your priorities rather than only chasing one single thing.
    • That's it. I finally uninstalled Firefox because they often keep pushing buggy updates, only to test them later and make users suffer. No longer is it my alternative browser to Edge. What a waste of energy. Firefox is bad for the environment, just like Chrome (wasting RAM/energy).
    • Microsoft Weekly: new Surface, Windows 11 26H2, and more by Taras Buria This week's news recap is here, with Microsoft announcing Windows 11 version 26H2, launching new Surface devices powered by Snapdragon X2 processors, GTA VI preorder date and cover art, fresh Windows 11 preview builds, a quirky phone-sized e-reader with a physical dial, and more. Quick links: Windows 10 and 11 Windows Insider Program Updates are available Reviews are in Gaming news Great deals to check Windows 11 and Windows 10 Here, we talk about everything happening around Microsoft's latest operating system in the Stable channel and preview builds: new features, removed features, controversies, bugs, interesting findings, and more. And, of course, you may find a word or two about older versions. Windows 11 version 26H2 is now official. Alongside Windows 11's new preview builds released this week, Microsoft confirmed version 26H2, which is coming later this year as an enablement package based on the same platform as versions 24H2 and 25H2. A newly published blog post details what IT admins should do to prepare for the upcoming launch. Next, we have new Windows 11 bugs. Users report that this month's security updates for Windows 11 cause all sorts of issues, including BitLocker bugs, OneDrive issues, black screens of death, and third-party integration in Office apps. Microsoft has not confirmed those yet, but it acknowledged other issues with its operating system. What Microsoft has confirmed is a bug where Recycle Bin delete prompts display internal file names instead of actual ones, and a year-old Windows JScript compatibility bug caused by security-focused engine changes. Moving to more positive news, Microsoft and Adobe are working on improving Windows performance in popular creative apps like Photoshop. Thanks to SPGO optimizations, users can expect up to 20% better performance. Finally, we have a few useful articles that can help you recover your PC or make it perform better. For one, we published a guide detailing what to do if your computer cannot boot after a clean Windows 11 install. There are two important steps you can try to get your system back to working in no time. Additionally, there is a more detailed guide on various CPU performance modes that could notably improve performance. Windows Insider Program Here is what Microsoft released for Windows Insiders this week: Builds Canary Channel Builds 28120.2315 and 29613.1000 These two builds include a new built-in audio driver, improvements to audio Settings, and more. Dev Channel Builds 26300.8697 and 26220.8690 Not much is available here. Some File Explorer improvements, Start menu enhancements, bug fixes, and more. However, build 26300.8697 is now officially marked as version 26H2. Updates are available This section covers software, firmware, and other notable updates (released and coming soon) delivering new features, security fixes, improvements, patches, and more from Microsoft and third parties. This week, Microsoft announced its newest Surface devices powered by Qualcomm's latest Snapdragon X2 processors. There is the 12th-gen Surface Pro and the 8th-gen Surface Laptop. Both devices feature little to no visual differences compared to their predecessors from 2024, and most changes hide inside, including a better processor, faster graphics, enhanced NPUs, and more. The Surface Laptop also received a new haptic trackpad. Mozilla is currently working on a major Firefox redesign, and earlier this week, it published a roadmap of upcoming features and highlights of the upcoming "Project Nova" rework. Files, one of the best file managers for Windows 10 and 11, has been updated in the Preview channel with a long-requested feature. Tree View is finally available in version 4.1.4, allowing you to quickly browse deeply nested folders without leaving the main view. In addition, the update improved the Windows Fonts folder, allowing you to preview each font without opening the default viewer. Rufus, another useful Windows 11 utility, also received a notable update. Version 4.15 arrived as beta with important fixes for silent Windows 11 installation. It also includes patches for ARM-based Windows PCs, OneDrive removal improvements, and more. Here are other updates and releases you may find interesting: Microsoft faces shareholder lawsuit over masking AI costs and slowing Azure growth Microsoft now allows you to tweak Visual Studio to new extremes Microsoft brings Planner Agent to all Microsoft 365 Copilot users Microsoft fixes one of Excel Copilot's most frustrating limitations Microsoft will finally let you sign in to Edge with a Google account Here are the latest drivers and firmware updates released this week: NVIDIA 610.62 with support for Empulse and various fixes. Reviews are in Here is the hardware and software we reviewed this week Earlier this week, we reviewed the DuRoBo Krono, a portable, phone-sized e-reader with some interesting physical controls. This device has an Apple Watch-like dial for page turning, frontlight adjustment, and more. Software is simple and no-nonsense, but it also lacks some useful features and customization. Overall, the device proved interesting, but not flawless. On the gaming side Learn about upcoming game releases, Xbox rumors, new hardware, software updates, freebies, deals, discounts, and more. Forza Horizon 6 received two big updates this week. Alongside the Series 2 content update, developers pushed plenty of bug fixes and balancing tweaks. However, they also had to acknowledge the Eliminator CR-farming exploit and shut down the online mode temporarily. Luckily, only a few days later, another fix arrived, which re-enabled Eliminator and patched the exploit. Microsoft announced new games for Game Pass subscribers. Those include EA Sports FC 26, Junkster, Call of Duty: Vanguard, Abyssus, RV There Yet?, and more. Some existing games are leaving the catalog, so be sure to check out the full list here. New games are also available for GeForce NOW subscribers, and they include Embers of the Uncrowned Demo, Aphelion, Megastore Simulator, OPERATOR, Citizen Sleeper, and more. Rockstart Games had plenty of GTA-related news this week. For one, the company gave GTA V players another free update. Those still playing the game on Xbox One and PlayStation 4 are no longer required to pay $40 to upgrade to the latest-gen version. More importantly, Rockstar Games revealed the GTA VI cover art and announced the preorder date. The Epic Games Store is giving away two games: Citizen Sleeper and Roboeat. These two titles are up for grabs until next Thursday, but if they are not up to your taste, you can always check out the latest Weekend PC Game Deal issue, which is usually full of discounts and specials that let you save a lot of money on new games. Great deals to check Every week, we cover many deals on different hardware and software. The following discounts are still available, so check them out. You might find something you want or need. GEEKOM X16 Pro at GEEKOM - $1,119.67 | 17% off Acer 4K Webcam for PC/Mac with All-Metal Unibody Sculpted - $59.99 | 14% off Samsung 990 PRO SSD 2TB - $369.99 | 42% off Nothing Ear Wireless Earbuds Bluetooth - $73.15 | 51% off PowerColor Reaper AMD Radeon RX 9070 16GB - $579.99 | 17% off This link will take you to other issues of the Microsoft Weekly series. You can also support Neowin by registering for a free member account or subscribing for extra member benefits, along with an ad-free tier option.
  • Recent Achievements

    • Week One Done
      Supreme Spray LV earned a badge
      Week One Done
    • One Month Later
      Genuinetonerink- Dubai earned a badge
      One Month Later
    • Week One Done
      Genuinetonerink- Dubai earned a badge
      Week One Done
    • One Year In
      hhgygy earned a badge
      One Year In
    • Week One Done
      AMV earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      506
    2. 2
      +Edouard
      163
    3. 3
      PsYcHoKiLLa
      84
    4. 4
      Steven P.
      74
    5. 5
      Michael Scrip
      71
  • Tell a friend

    Love Neowin? Tell a friend!