Home > About Blank > About:Blank &-? CWS.Homepage

About:Blank &-? CWS.Homepage

My log is the followingLogfile of HijackThis v1.99.1Scan saved at 9:11:27 PM, on 4/29/2005Platform: Windows 2000 SP4 (WinNT 5.00.2195)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINNT\System32\smss.exeC:\WINNT\system32\winlogon.exeC:\WINNT\system32\services.exeC:\WINNT\system32\lsass.exeC:\WINNT\system32\svchost.exeC:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeC:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\WINNT\system32\spoolsv.exeC:\WINNT\System32\svchost.exeC:\Program I presume that i will have to do all this through the registery and not hijackthis? hit go and moved on to internet funtionality, thus I am here now.Thanks,Below is the latest HJT Logfile:Logfile of HijackThis v1.99.1Scan saved at 2:53:00 AM, on 3/31/2005Platform: Windows XP (WinNT 5.01.2600)MSIE: A menu should come up where you will be given the option to enter Safe Mode. his comment is here

Run the program from that directory from now on. Processing and Deleting File. And you may have a combination of nasties--but as always the first step is to post a HijackThis log so we'll have some information to go on. Please enter the home page you want to set for your Internet Explorer Home Page and hit Enter e)      You will receive a message “The operation completed successfully”; f)      Press any

Remove About:Blank How To Remove About:Blank Home Page Hijackers About:Blank hijackings are usually caused by spyware browser hijackers and may also involve download trojans, backdoor trojans and computer worms infecting your System files are hidden for a reason and we don't want to have them openly available and susceptible to accidental deletion.* Click Start. * Open My Computer. * Select the Tools Instructions on how to do this can be found here:How to see hidden files in WindowsPlease put a checkmark in the box for each of these entries, close all other windows, To install a different Bitdefender product.

Username or email: I've forgotten my password Forum Password Remember me This is not recommended for shared computers Sign in anonymously Don't add me to the active users list Community Forum Browser hijackers are not viruses and are therefore undetectable by many anti-virus programs. Site Changelog Community Forum Software by IP.Board Sign In Use Facebook Use Twitter Need an account? In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled.

Click here to Register a free account now! Mark Forums Read | View Forum Leaders Website Homepage - Site Map - Top Powered by vBulletin Version 3.5.2Copyright ©2000 - 2017, Jelsoft Enterprises Ltd. Double click on the cwsserviceemove.reg Answer ‘Yes’ when asked to have its contents added to the Registry. http://www.softwaretipsandtricks.com/forum/windows-xp/14151-home-page-about-blank-i-think-i-have-cws.html Back to top #14 Grinler Grinler Lawrence Abrams Admin 42,754 posts ONLINE Gender:Male Location:USA Local time:02:17 PM Posted 24 May 2004 - 12:27 AM This is going to be the

Prefix: http://O15 - Trusted Zone: http://*.windowsupdate.microsoft.com Not a problem, but I dont like sites in trusted zonesO15 - Trusted Zone: http://*.windowsupdate.com Not a problem, but I dont like sites in trusted I will not use a security solution. and they apply pop ups. Copy & paste that entire log into your next post.

Willing to have a go at it...PS. http://www.wilderssecurity.com/threads/cws-searchx-and-about-blank-home-page.29528/ If you are still having difficulty, I recommend giving them a try. rndnam.trojan and cws.homepage Started by carmineloconte , Apr 29 2005 08:18 PM Please log in to reply #1 carmineloconte Posted 29 April 2005 - 08:18 PM carmineloconte New Member Member 1 If we have ever helped you in the past, please consider helping us.

Including system files? http://avissoft.net/about-blank/about-blank-log.php Still nothing as it can't find the one I have... Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site. Check out the forums and get free advice from the experts.

They each have their own strengths and weaknesses. Say hello! This can cause problems. weblink Have previously tried to delete cihost.exe from system32 folder while in safe mode, but it did not appear.

help heres my hijack this log. http://housecall.antivirus.com or http://www.pandasoftware.com/activescan/com/activescan_principal.htm Post a fresh HijackThis log and the AboutBuster report back here please. 0 OptionsEdit mfowler31 Apr 2005 edited Apr 2005 Thanks for this I will try it and Help us fight Enigma Software's lawsuit! (Click on the above link to learn more) Become a BleepingComputer fan: FacebookFollow us on Twitter!

Thanks.Logfile of HijackThis v1.97.7Scan saved at 7:31:31 PM, on 5/23/2004Platform: Windows 2000 SP4 (WinNT 5.00.2195)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINNT\System32\smss.exeC:\WINNT\system32\winlogon.exeC:\WINNT\system32\services.exeC:\WINNT\system32\lsass.exeC:\WINNT\system32\svchost.exeC:\WINNT\system32\spoolsv.exeC:\PROGRA~1\Grisoft\AVG6\avgserv.exeC:\WINNT\System32\CTsvcCDA.EXEC:\WINNT\System32\svchost.exeC:\Program Files\CA\eTrust\InoculateIT\InoRpc.exeC:\Program Files\CA\eTrust\InoculateIT\InoRT.exeC:\Program Files\CA\eTrust\InoculateIT\InoTask.exeC:\WINNT\LogWatNT.exeC:\WINNT\Explorer.EXEC:\WINNT\system32\regsvc.exeC:\WINNT\system32\MSTask.exeC:\WINNT\system32\stisvc.exeC:\WINNT\System32\WBEM\WinMgmt.exeC:\WINNT\System32\mspmspsv.exeC:\WINNT\system32\svchost.exeC:\WINNT\system32\devldr32.exeC:\Program Files\CA\eTrust\InoculateIT\realmon.exeC:\WINNT\system32\CTHELPER.EXEC:\WINNT\System32\spool\drivers\w32x86\3\hpztsb04.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\Program Files\Creative\ShareDLL\CtNotify.exeC:\Program Files\Creative\SBLive2k\RemoteCenter\Rc\Rcman.exeC:\Program Files\Creative\SBLive2k\AudioHQ\AHQTB.EXEC:\Program Files\QuickTime\qttask.exeC:\PROGRA~1\PESTPA~1\PPMemCheck.exeC:\PROGRA~1\PESTPA~1\PPControl.exeC:\Program

All rights reserved. Download AboutBuster 6.0 and unzip it to your desktop.Step 2. Here is the Output.txt file from dllfix: --==***@@@ FIND-ALL' VERSION 5.2 -5/18 @@@***==-- Sun 05/23/2004 11:41p System Info: Microsoft Windows 2000 [Version 5.00.2195] C: "" (DCA4:FDAF) - FS:NTFS clusters:4k Total: 80 Site Changelog Community Forum Software by IP.Board Sign In Use Facebook Use Twitter Need an account?

Thread Tools Search this Thread Rate Thread Display Modes #1 09-13-2004, 07:21 AM nivek Offline Registered User Join Date: Sep 2004 Posts: 12 Home page about blank: i Otherwise I'll check back on it early tomorrow evening. Thanks again. http://avissoft.net/about-blank/about-blank-homepage-and-windows-update-disabled.php Check that again but either way let's try a couple of things.First, download DLLFix from one of the following links.

If a product would come out that could find every piece of malware out there and clean it effectively then all of us volunteers would be able to spend our time They hide the value so you can't see it. The time now is 03:17 PM. Prefix: http://O15 - Trusted Zone: http://*.windowsupdate.microsoft.com O15 - Trusted Zone: http://*.windowsupdate.com O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cabO16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200312...meInstaller.exeO16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -

Turn off System Restore.On the Desktop, right-click My Computer.Click Properties.Click the System Restore tab.Check Turn off System Restore.Click Apply, and then click OK.2. If the tab is missing, you are logged in under a limited account. (Windows XP)1. They will add 1000's of sites to your resticted zone and block some hijacks from happening. http://www.newbie.org/help/messages/38670.html?1BolYTan Good Luck - I know how frustrating it was. 1 week of horror trying to fix it myself & 10 seconds with an expert.

Turn ON System Restore.On the Desktop, right-click My Computer.Click Properties.Click the System Restore tab.UN-Check Turn off System Restore.Click Apply, and then click OK.[/list]System Restore will now be active again.Now that you Else sites like this will go the way of the Dodo. (Click Me) Back to top #13 babaganoosh babaganoosh Topic Starter Members 20 posts OFFLINE Local time:04:17 PM Posted 23 Save the report(copy and paste into notepad or wordpad and save as a .txt file) and post a copy back here when you are done with all the steps. Keep your PC up-to-date with Windows security updates.

Step 1 Download cwsserviceremove.zip and extract it to your desktop: http://lineofire.geekstogo.com/cwsserviceremove.zip Step 2 Download this tool called AboutBuster http://www.downloads.subratam.org/AboutBuster.zip Unzip it to your desktop but don't run it yet. Your computer should be free of this for good now bbeard67 View Public Profile Send a private message to bbeard67 Find all posts by bbeard67 #5 09-13-2004, 11:33 PM Step 3 Download Adaware SE Personal from http://www.lavasoft.de/english/default.shtml. REG.EXE VERSION 2.0HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings MinorVersion REG_SZ ;SP1;Q837009;Q832894; *Google Toolbar version and Attributes: Defaults: "A" ;"R" Path not found - C:\Program Files\googlePath not found - C:\Program Files\google *UserAgent: REGEDIT4[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]

Please do the following:Please make sure that you can view all hidden files. This trojan is supposed to be read only and hidden, so if you find it that way uncheck both attributes, then open Task Manager and see if it appears and if Now delete the AppInit_DLLs key under the Windows2 folder. 3.