Help with about:blank

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by BadgerBoy, Sep 15, 2004.

  1. BadgerBoy

    BadgerBoy Private E-2

    Hi

    I have read the tutorials about removing this problem and followed everything to the word but still no joy. I have attached the log file from HiJack This. What should I do next?

    Thanks
     
  2. BadgerBoy

    BadgerBoy Private E-2

    Heres the file:
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Go back and read them again. You still have not run everything you were told to run. For one example, no online scans were run. Also no one asked you to post a log. If you had read the HJT tutorial you would know that you must not post a log until we ask you to.

    Do you know why you have these settings:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.1.50.1:8080
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = avc-intranet;10.1.50.1;<local>
     
  4. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    As alway, please create a backup in case you have any problems.

    Remove:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://c:\windows\TEMP\sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://c:\windows\TEMP\sp.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://c:\windows\TEMP\sp.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://c:\windows\TEMP\sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://c:\windows\TEMP\sp.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://c:\windows\TEMP\sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

    These lines need to be verified by you if your running a proxy server OR possibly installed by your ISP. If unsure, leave for now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.1.50.1:8080
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = avc-intranet;10.1.50.1;<local>

    Continue removing, (next lines could be why the stuff is returning):

    O2 - BHO: (no name) - {C9C0BEA3-0676-11D9-A70A-0000BFBE37C4} - C:\WINDOWS\SYSTEM\BLBDEPA.DLL
    O18 - Filter: text/html - {C9C0BEA2-0676-11D9-A70A-0000D0F2925F} - C:\WINDOWS\SYSTEM\BLBDEPA.DLL
    O18 - Filter: text/plain - {C9C0BEA2-0676-11D9-A70A-0000D0F2925F} - C:\WINDOWS\SYSTEM\BLBDEPA.DLL

    Reset your home page and cross your fingers. Let us know!
     
  5. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Sorry, Chaslang, didnt even see you online, nonetheless in this thread.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem! By the way, in most cases, just fixing those lines will not cure the about blank problem. There is typically a hidden process (Streaming I/O) that must be removed. So expect it to return. I just wanted the remaining steps of the READ ME to be followed first before I got into it.
     
  7. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Roger that, I assumed he ran everything as promised and since he was removing items from Hijack This and posted it properly, again assumed he removed the online scan lines and jumped in. We will have to wait to see what he says. Again, sorry to step on toes, just trying to get peoples questions answered. Ill go away for a bit now, but just like herpes, ill be back ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds