Can't get rid of about:blank!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by afdon104, Sep 6, 2004.

  1. afdon104

    afdon104 Private E-2

    I've tried using Norton AV, Spybot S&D, CWShredder, HiJackthis!, Adaware and a combination of all of them. I've even tried following the instructions on Symantecs website to edit the registry while in safe mode. Nothing works!!!! If you guys can't help me I'm just going to format my hard drive...

    AFDon
     
  2. smokinbls

    smokinbls the title thing is overrated

    Last edited: Sep 6, 2004
  3. PhilliePhan

    PhilliePhan Guest

    Hi afdon,

    I suggest you follow all of the steps in this tutorial first. They include about:buster. READ ME FIRST: Basic Spyware, Trojan And Virus Removal

    Make note of the steps that you are able to complete and the ones that give you trouble. This will make it easier for the experts to assist you, should you still need help after following the tutorial ;)

    Best luck,

    PP
     
  4. afdon104

    afdon104 Private E-2

    Oh yeah, I tried that, too. Everything I've tried so far has done exactly bupkis. I'm obviously missing something.

    And I realize HJT doesn't remove anything, I meant I used it to look for files that didn't belong. Unfortunately I'm not system smart enough to narrow it down.

    Still need help!
     
  5. PhilliePhan

    PhilliePhan Guest

    If you give us some detail - OS, symptoms, the steps you were able to complete, etc... - then we might be able to tell you what you are missing.

    -Are all your priority updates up to date?
    -Are all of the removal tools up to date?
    -Safe mode?
    -System restore off?
    -Did you find Network Security Service?

    I know this is a frustrating process. If you read some of the other posts, you'll see that many others have the same problem. Hang in there :)

    PP
     
  6. afdon104

    afdon104 Private E-2

    I turned off the system restore and rebooted in safe mode. I didn't find network security service.

    I checked to make sure all of my programs were up to date and ran them:

    Norton anti-virus
    Spybot S&D
    CWShredder
    aboutbuster
    trojanhunter 4.0
    kill2me
    hsremove
    ccleaner

    I can even clean out a few files listed in the symantec webpage and on READ ME FIRST: Basic Spyware, Trojan And Virus Removal

    when I reboot it comes up clean. Then on either the second or third reboot the homepage is hijacked again, even though I have autoprotect running and the windows firewall up.

    what next?
     
  7. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Sounds like you need to get some files out in safe mode. The tutorial was updated today using Nortons online scan. Can try that again and or Stinger from safe mode as well. From there, please attach your log file & I will look at it.
     
  8. afdon104

    afdon104 Private E-2

    Following the directions didn't work and the Norton scan found nothing, so...

    I ran Spybot S&D and adawre before generating a logfile:
     

    Attached Files:

    Last edited by a moderator: Sep 10, 2004
  9. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Uninstall Spyware Cop

    Remove:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    O2 - BHO: (no name) - {8E27E34F-79E4-4C88-8F37-5290D5862C14} - C:\WINNT\system32\llfnea.dll
    O4 - HKCU\..\Run: [Spyware-Cop] "C:\PROGRA~1\SPYWAR~1\Spyware-Cop.exe" /s
     
  10. afdon104

    afdon104 Private E-2

    I deleted the files in Hijackthis. After three reboots it looks like it's fixed! I'll wait a day or two before I declare victory.

    So what was it that hijacked my computer?


    Thanks for all the help. You guys rock!

    AFDon
     
    Last edited: Sep 10, 2004
  11. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Our pleasure.

    Those lines are what load the hijacked pages, which is where Hijack This comes in handy allowing you to remove the lines, then manually reset. It also pointed out running programs where I spotted Spyware-Cop.

    Hope it hold out, you need to be sure you went to safe mode and ran Stinger and the 2 links to online virus scanners provided in the tutorial.
     
  12. afdon104

    afdon104 Private E-2

    My homepage is still where I want it after two days, It worked!

    I think I must have deleted some of the spyware cop files instead of uninstalling it. I remember getting rid of it, that's for sure.

    Thanks once again,

    Don
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds