Home > About Blank > About:Blank &-? CWS.Homepage

About:Blank &-? CWS.Homepage

I have tried a multitude of things but cannot get rid of it as it seems to be 're loading' each time Ad-Aware/Spybot sees it?? hit go and moved on to internet funtionality, thus I am here now.Thanks,Below is the latest HJT Logfile:Logfile of HijackThis v1.99.1Scan saved at 2:53:00 AM, on 3/31/2005Platform: Windows XP (WinNT 5.01.2600)MSIE: This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected)1. If you have the HijackThis_sfx.exe file then double-click on it and click the Unzip button to install the program properly.Step #2Start HijackThis and click the Scan button to perform a scan. this contact form

Thanks. To learn more and to read the lawsuit, click here. Site Map | Legal Terms | Site Feedback | Global Sites | Contact Us Site Map Legal Terms Site Feedback Global Sites Contact Us Copyright © 1997-2017 BitdefenderAll rights reserved. Rename the HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows folder to Windows2. 2. http://www.bleepingcomputer.com/forums/t/14667/aboutblank-cwshomepage/

I have the infamous homepage "about.blank" page on my personal laptop. I set killbox to delete on reboot, rebooted into safe mode to run the anti spyware programs and then rebooted into normal mode. If you are still having difficulty, I recommend giving them a try. Thanks.Logfile of HijackThis v1.97.7Scan saved at 7:31:31 PM, on 5/23/2004Platform: Windows 2000 SP4 (WinNT 5.00.2195)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINNT\System32\smss.exeC:\WINNT\system32\winlogon.exeC:\WINNT\system32\services.exeC:\WINNT\system32\lsass.exeC:\WINNT\system32\svchost.exeC:\WINNT\system32\spoolsv.exeC:\PROGRA~1\Grisoft\AVG6\avgserv.exeC:\WINNT\System32\CTsvcCDA.EXEC:\WINNT\System32\svchost.exeC:\Program Files\CA\eTrust\InoculateIT\InoRpc.exeC:\Program Files\CA\eTrust\InoculateIT\InoRT.exeC:\Program Files\CA\eTrust\InoculateIT\InoTask.exeC:\WINNT\LogWatNT.exeC:\WINNT\Explorer.EXEC:\WINNT\system32\regsvc.exeC:\WINNT\system32\MSTask.exeC:\WINNT\system32\stisvc.exeC:\WINNT\System32\WBEM\WinMgmt.exeC:\WINNT\System32\mspmspsv.exeC:\WINNT\system32\svchost.exeC:\WINNT\system32\devldr32.exeC:\Program Files\CA\eTrust\InoculateIT\realmon.exeC:\WINNT\system32\CTHELPER.EXEC:\WINNT\System32\spool\drivers\w32x86\3\hpztsb04.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\Program Files\Creative\ShareDLL\CtNotify.exeC:\Program Files\Creative\SBLive2k\RemoteCenter\Rc\Rcman.exeC:\Program Files\Creative\SBLive2k\AudioHQ\AHQTB.EXEC:\Program Files\QuickTime\qttask.exeC:\PROGRA~1\PESTPA~1\PPMemCheck.exeC:\PROGRA~1\PESTPA~1\PPControl.exeC:\Program

They start with Windows and can restore their Windows startup settings if they've been deleted. Back to top #10 Grinler Grinler Lawrence Abrams Admin 42,754 posts ONLINE Gender:Male Location:USA Posted 23 May 2004 - 06:00 PM Give us another log please Lawrence Abrams Don't let Income is earned by its owners and affiliates if you visit any of these paid ad links. If you were successful in deleting cihost.exe, post another HijackThis log.

REG.EXE VERSION 2.0 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings MinorVersion REG_SZ ;SP1;Q837009;Q832894; *Google Toolbar version and Attributes: Defaults: "A" ;"R" Path not found - C:\Program Files\google Path not found - C:\Program Files\google *UserAgent: REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Restart your computer.3. as it had after the CWS problem started. A menu should come up where you will be given the option to enter Safe Mode.Run AboutBuster-Click Start to begin the process-Click OK on the Buster Report dialogue box to start

Step 7 Reboot to Safe Mode Restart your computer and as soon as it starts booting up again continuously tap F8. All Activity Home Malware Removal Help Malware Removal for Windows Resolved Malware Removal Logs Homepage hijacked to About:Blank? The time now is 03:17 PM. That is why we use multiple tools to make sure that computers are clean.

BleepingComputer is being sued by Enigma Software because of a negative post of SpyHunter. http://www.wilderssecurity.com/threads/cws-searchx-and-about-blank-home-page.29528/ Place a check against each of the following, making sure you get them all and not any others by mistake:R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\bdrqn.dll/sp.html#14044R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = I would just get rid of : O4 - Startup: Microsoft Data Helper.lnk = C:\WINNT\system32\cihost.exe O15 - Trusted Zone: http://*.windowsupdate.microsoft.com Reboot into safe mode and see if you can delete : I can be contacted at spywaresubmit at aol.com Mon 05/24/2004 6:29p Backing up Registry Hive The operation completed successfully Deleting Windows Key The operation completed successfully Adding Test Windows Key The

Clicked find - here's the log: Log for VX2.BetterInternet File Finder Files Found--- Guardian Key--- is called: User Agent String--- Back to top #8 Guest_Plimsol_* Guest_Plimsol_* Guests OFFLINE Posted 23 weblink I presume that i will have to do all this through the registery and not hijackthis? You can check the Microsoft KB articles below for step by step instructions: How to Change your Windows Internet Explorer home page Note: use the down arrow from the right side Step 8 Scan with Hijack This and put checks next to all the following, then click "Fix Checked" R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\biwde.dll/sp.html#72780 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =

Annoying sure, but nothing to really worry about once you understand why. click 'Autosearch Settings' select a search engine and click OK. 3) Otherwise, if the Customize button isn't shown: click the 'Search' button. Install and open Adaware and click on *Check for Updates Now* and then *Connect*. navigate here click 'Reset'.

Please re-enable javascript to access full functionality. A case like this could easily cost hundreds of thousands of dollars. This is a popular program that does not require payment for removals: Download Malwarebytes Anti-Malware Delete all your temporary files - click Start, click Run and type 'cleanmgr', hit Enter.

Site Changelog Community Forum Software by IP.Board Sign In Use Facebook Use Twitter Need an account?

Please use them so that others may benefit from your questions and the responses you receive.OldTimer Back to top Back to Virus, Trojan, Spyware, and Malware Removal Logs 0 user(s) are Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0527.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} We invite you to contact our Bitdefender Support Team and kindly ask you to allow approximately 10 minutes for your call to be taken. Thread Tools Search this Thread Rate Thread Display Modes #1 09-13-2004, 07:21 AM nivek Offline Registered User Join Date: Sep 2004 Posts: 12 Home page about blank: i

Several functions may not work. Click *ok* and let it download and install the updates by clicking on *Finish* .This will return you to the main screen. Make sure these 3 are checked and then press *ok* to remove: Temporary Files Temporary Internet Files Recycle Bin Step 12 Find the cwsserviceremove.reg that you downloaded in Step one. his comment is here If you found this web page useful please help others to remove about:blank homepage hijackers by clicking the Like or Share button below, copy and paste the url, or by placing

Please use them so that others may benefit from your questions and the responses you receive.OldTimer Back to top #3 rcnet rcnet Topic Starter Members 2 posts OFFLINE Local time:03:17 Can't find a solution for your problem? About:Blank &-? When I connected and selected IE, in the address line was - About: blank.No redirect.Thought the window stayed blank...

If a product would come out that could find every piece of malware out there and clean it effectively then all of us volunteers would be able to spend our time SoftwareTipsandTricks Forum > Operating Systems > Windows XP Home page about blank: i think i have cws. So until you remove these lines using hijackthis you will get that error. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates,

However, the main cause of this problem is due to CWS browser hijacker infections also known as the HomeOldSP hijacker. Sign In Use Facebook Use Twitter Use Windows Live Register now! Did you unhide files and folders as recommended by Plimsol? rndnam.trojan and cws.homepage Started by carmineloconte , Apr 29 2005 08:18 PM Please log in to reply #1 carmineloconte Posted 29 April 2005 - 08:18 PM carmineloconte New Member Member 1

They will add 1000's of sites to your resticted zone and block some hijacks from happening. Back to top #5 babaganoosh babaganoosh Topic Starter Members 20 posts OFFLINE Posted 23 May 2004 - 04:31 PM I fixed the hjt entries as you directed. Go to Start > Run and type in the box: cleanmgr. Please do the following:Download VX2Finder from HERE.

Yeah tried it but avout blank still nicked my home page. Back to top #11 babaganoosh babaganoosh Topic Starter Members 20 posts OFFLINE Local time:04:17 PM Posted 23 May 2004 - 06:11 PM Here is recent hjt log.