stubborn about:blank browser hijacker

lozina

Lifer
Sep 10, 2001
11,709
8
81
I'm trying to clean up my friend's laptop from a hell of alot of viruses/trojans he had and I still seem to be getting an about:blank hijacking of his Internet Explorer.

I ran AVG Antivirus, The Cleaner, AdAware SE and finally Hijack this. They all found something which I promptly took care of.

I rebooted then ran Hijack This again and noticed an R3 item and several R0 items re-appeared on the list, incuding somehting about about:blank. So apparantly there is still something which all these tools missed.

What to try now?
 

Dahak

Diamond Member
Mar 2, 2000
3,752
25
91
You can try also Microsoft Anti Spyare as well as
About Buster
and spybot search and destroy as well.
Aslo go in and clean out all the temp directories as well, there a temp in each user as well as under the hidden folder "local settings" temp in each user
 

lozina

Lifer
Sep 10, 2001
11,709
8
81
oh forgot to mention this is Windows ME, so the microsoft spyware tool is not compatible.

but I'm running SpyBot S&D now and it's picking up yet more stuff! hopefully this will be the final nail in the coffin so I can give this guy his laptop back clean and ready for more abuse!
 

lozina

Lifer
Sep 10, 2001
11,709
8
81
Well I'm still having a problem with this damned about:blank hijacker...

I'm convinced a process called ctfmon.exe is behind some of this... when I use Hijack This to scan one of the entries is a registry key to run ctfmon.exe. I have it fixed (remove it) and I end the current ctfmon.exe process running using process explorer. Then I hit Internet Explorer and immediately that ctfmon.exe process starts up and that registry key returns...
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Try McAfee's manual scanner, preferably while in Safe Mode: instructions Also you may try Webroot Spysweeper, they have a 30-day trial and I think it does work on 98/ME.
 

Eltano1

Golden Member
Aug 6, 2000
1,897
0
0
Something that you can do is remove the System restore, and reboot on safe mode, and run all of those proggies all over again. Sometimes those piece of junk will reside on the system restore, and will come back time after time.

Eltano
 

boomerang

Lifer
Jun 19, 2000
18,890
642
126
CCleaner is great for deleting temp files which a lot of bad stuff hangs in also. I run this and turn off System Restore as my first steps. Oh, and run everything in Safe Mode.
 
Jul 26, 2005
41
0
0
Although I wouldn't suggest it, unless you're a glutton for punishment like me, I like to reformat my computer about once a year. You could try that. Make sure you back-up all his/her important files first.
Also, the best defense against spyware/viruses/trojan horses, ect is to teach him/her how to avoid them...and at the very least teach him/her how to run the anti-spyware programs you're using on his/her system.
Good Luck.
 

Jeff7

Lifer
Jan 4, 2001
41,599
19
81
Also download the standalone version of CWShredder. My experiences with about:blank turned out to be the insidious CoolWebSearch.
 

Nocturnal

Lifer
Jan 8, 2002
18,927
0
76
Download and use Spy Sweeper in safe mode. Also use CCleaner to clean out all your temp files.
 

lozina

Lifer
Sep 10, 2001
11,709
8
81
Thanks for all the advice guys!

I just manually moved that ctfmon.exe file out of windows\system then searched the registry for anything pointing to it, then rmeoved those registries (after creating a backup reg file for each one). Rebooted and now it's finally all clean. Ran all those tools again in safe mode and now nothign new is being picked up.

Besides that I defragged the system, installed all the latest windows security/critical updates and sygate personal firewall. He should be good for a while now.

And yeah, I think the first thing I did was clean out the damn temp files. It took a really long time but it freed up about a gig of space! (on a hard drive with only 9 gigs)
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |