User Name Password Register
DaniWeb IT Discussion Community
All
What is DaniWeb IT Discussion Community?
You're currently browsing the Viruses, Spyware and other Nasties section within the Tech Talk category of DaniWeb, a massive community of 397,131 software developers, web developers, Internet marketers, and tech gurus who are all enthusiastic about making contacts, networking, and learning from each other. In fact, there are 3,603 IT professionals currently interacting right now! Registration is free, only takes a minute and lets you enjoy all of the interactive features of the site.
Please support our Viruses, Spyware and other Nasties advertiser:

Yet another IE home page hijacking

Join Date: Apr 2004
Posts: 1
Reputation: lynchmob is an unknown quantity at this point 
Rep Power: 0
Solved Threads: 0
lynchmob lynchmob is offline Offline
Newbie Poster

Re: Yet another IE home page hijacking

  #4  
Apr 13th, 2004
Originally Posted by TallCool1
Before you remove anything, turn off System Restore to keep stuff from coming back. While I cannot identify the hijacker, I can identify which files to remove. You need to remove the 02 - BHO (browser helper object) item, as well:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\ankli.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\ankli.dll/sp.html (obfuscated)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\ankli.dll/sp.html (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\ankli.dll/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\ankli.dll/sp.html (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\ankli.dll/sp.html (obfuscated)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

O2 - BHO: (no name) - {D38BDAB3-3A14-45EE-B059-5EFF27D479F4} - C:\WINDOWS\System32\ankli.dll

After fixing, reboot into Safe Mode and delete C:\WINDOWS\System32\ankli.dll

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Here's three resource wasters to remove:

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Last but not least, replace Netscape 7 with Mozilla--it's a much newer version. Netscape 7 is based on Mozilla 1.01 or 1.3, Mozilla is at v1.6 right now.

First time posting here, so please bare with me if this is screwed up coming in. I had the same about:blank situation and followed these basic steps. Everything was cool until today and I had to run through the procedure again, something must activate it and set it off again from time to time, does that sound correct. Basically is this a fix that makes us feel better for the time being or is it really kicking this spyware (or whatever is giving us this "about:blank) off the comp? That thing was driving me mad for 2 weeks, so I'm glad I came across this page, but I don't want to have to keep doing this every other day. Weren't comps created to make life easier??? It's only slowin' mine up and giving me a migrane!

Thanks,
D
Reply With Quote  
All times are GMT -4. The time now is 3:00 am.
Forum system based on vBulletin Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
©2003 - 2008 DaniWeb® LLC