Computing.Net > Forums > Security and Virus > Getting rid of About:Blank How ?

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Getting rid of About:Blank How ?

Reply to Message Icon

Name: Niels Henrik Nielsen
Date: June 14, 2004 at 10:52:46 Pacific
OS: Windows XP
CPU/Ram: Inter 256 K
Comment:

How do I get rid of About:Blank ?

I have tried everything to delete it. But it keeps coming back.

Can anyone help ?

Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainStart Pageabout:blank

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "about:blank"
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Main
Value : Start Page
Data : "about:blank"

Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainStart Pageabout:blank

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "about:blank"
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Internet Explorer\Main
Value : Start Page
Data : "about:blank"



Sponsored Link
Ads by Google

Response Number 1
Name: Abnormal
Date: June 14, 2004 at 12:31:37 Pacific
Reply:

Answer below;
http://www.lavahelp.com/articles/v6/04/05/1801.html

From SpyDie:
Remove that entry and your Start-page for IE will be reset to msn.com. Now, reset it again to About:Blank. Re-run a new scan with Ad-aware and place that object on the ignore list (right-click on the item in the 'results' window and select 'Add selection to Ignorelist')

If you had the real coolweb hijack, you
would have more problems then that.


0

Response Number 2
Name: joopdog
Date: June 21, 2004 at 09:06:44 Pacific
Reply:

Follow the link on Manual removal of of this nasty little variant. It worked for me.

http://www.spywareinfo.com/~merijn/cwschronicles.html#realyellowpage


0

Response Number 3
Name: norwaldial
Date: June 21, 2004 at 22:04:31 Pacific
Reply:

I battled this nasty boy for 2 days. Most solutions are temporary because there is a hidden .dll file. Check out this link, It worked for me.

http://www.computercops.biz/postt43426.html

Don't forget to plug the hole that allows this. The problem is in Virtual Machine (VM). You need to do your cridical updates from Microsoft to prevent future infections.


Here we go again!


0

Response Number 4
Name: earlofgrey
Date: June 22, 2004 at 20:39:38 Pacific
Reply:

Norwal, I can't find anything with the suffix .dll when I use Reglite.exe. Can you help?


0

Response Number 5
Name: hollywoode46
Date: July 1, 2004 at 06:28:38 Pacific
Reply:

You are getting this because a remote system is connecting your your network using port 138 which is Netbeui over TCP/Ip. It uses this to establish itself as a node on your network at IP address x.x.x.255 (x is the value of your internal ip address, for me it would be 192.168.1.255).

This is the same exploit which is used by the Downloader.Trojan.

I have backtracked one source IP to 195.190.118.131. Enter that into a browser and it has a downloadable Uninstaller!!!!

I have registered that IP address with the District Attourney's Internet Task Force. They are investigating it now.

Download Norton Personal Firewall.
Configure a rule to always block Port 138
Configure a rule to completely block IP address 192.168.1.255 (or other x.x.x.255, depending on your network) and this should stop about:blank.

www.astral-computing.com
Network Engineers

Astral Computing
We Take Care of I.T.
Network Engineers
Web Hosts for Business


0

Related Posts

See More



Response Number 6
Name: hollywoode46
Date: July 1, 2004 at 06:49:11 Pacific
Reply:

having trouble removing it,

goto ftp.astral-computing.com

download the about:blank remover

it's a self extracting zip

extract to the root c:\
run ie.bat

make sure you backup your registry first.

This removes the dll, associations to the file, resets all IE registry settings and sets your home page to google, then launches Internet Explorer.

If you keep getting infected with this hijack because you haven't configured Norton Personal Firewall to block port 138
put a shortcut on your desktop to ie.bat
and use that to launch Internet Explorer.
It will wipe the hijack everytime you launch IE.

Astral Computing
We Take Care of I.T.
Network Engineers
Web Hosts for Business


0

Response Number 7
Name: hollywoode46
Date: July 7, 2004 at 13:26:03 Pacific
Reply:

or put a packet sniffer on your ethernet and figure out how he's getting in.

Astral Computing
We Take Care of I.T.
Network Engineers
Web Hosts for Business


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Getting rid of About:Blank How ?

how to get rid of about: blank? www.computing.net/answers/security/how-to-get-rid-of-about-blank/18389.html

Hijacked by About:blank - can anyo www.computing.net/answers/security/hijacked-by-aboutblank-can-anyo/14983.html

How do I get rid of w32/trojan.ay www.computing.net/answers/security/how-do-i-get-rid-of-w32trojanay/21324.html