| | |
About:Blank homepage ...
Thread Solved
![]() |
•
•
Join Date: Jun 2004
Posts: 1
Reputation:
Solved Threads: 1
•
•
•
•
Originally Posted by crunchie
This was written by Mosaic 1, a security expert on another forum. Follow instuctions exactly. At the moment there is no easy way.
Get the latest CWShredder from this page. Do not run it yet:
CWShredder
Download TheKillbox from this link: here.
------------------
Sign off the internet.
Run CWShredder and press the fix Button to clean.
Stay off the internet!
Step Two:
Remove the reinstaller:
Go to start>Run and type regedit. Press enter.
Navigate to:
Open the registry and navigate here:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
Highlight Windows in the left pane.
Look in the right pane for this value:
AppInit_Dlls
You won't see any data there.
But if you right click on that and choose Modify Binary Data you will.
If nothing is there it should just show a few 0's.
But if they are hiding a dll they load to reinstall, it will show a path to it.
----------------------------
This is how one looks when there is only one file loading.
0000 00 00 3A 00 5C 00 77 00 ..:.\.w.
0008 69 00 6E 00 64 00 6F 00 i.n.d.o.
0010 77 00 73 00 5C 00 73 00 w.s.\.s.
0018 79 00 73 00 74 00 65 00 y.s.t.e.
0020 6D 00 33 00 32 00 5C 00 m.3.2.\.
0028 6D 00 73 00 6B 00 6B 00 m.s.k.k.
0030 67 00 2E 00 64 00 6C 00 g...d.l.
0038 6C 00 00 00 l...
Notice on the far right. You want to look there. It looks funny because all of the periods.
Look closely and you'll see the path and file name here was:
Windows\system32\mskkg.dll
This was the example. Yours will have its own file name. This is not the same file as you are seeing in your HijackThis log. Get its name the same as I just described.
--------------
Once you have the filename unzip TheKillBox and run it.
In the "Paste Full Path of File to Delete" box, copy and paste the following:
c:\windows\system32\filename Where filename is what you found as the filename in the appinit_dlls key in the registry.
Don't click any of the buttons though, instead please click on the Action menu and choose "Delete on Reboot". On the next screen, click on the File menu and choose "Add File". The c:\Windows\system32\filename listing should show up in the window. If that's successful, choose the Action menu and select "Process and Reboot". You'll be prompted to reboot. Restart the Computer.
When you get back into Windows reset your Search and Home pages.
Look in the registry and remove the entry which should now be clearly visible and no longer hidden.
This last part and removing the AppInit_Dlls entry and its corresponding file is removing the reinstaller. So you do not get reinfected. Do not go on the internet until you have performed all of the steps.
--------------------------------
Ok, I'm having the problem too. Im not good with computers AT ALL. but I managed to get up to the part with the "few 0's." I just dont know what to do from there. Like I said, computers arent my best area so any help would be welcomed with open arms.
•
•
•
•
Originally Posted by Iced
Ok, I'm having the problem too. Im not good with computers AT ALL. but I managed to get up to the part with the "few 0's." I just dont know what to do from there. Like I said, computers arent my best area so any help would be welcomed with open arms.
Download dllfix from the following link.
http://tools.zerosrealm.com/dllfix.exe
Create a folder on your desktop, doubleclick on the dllfix and install it into the folder you just created.
1.Run start.bat and press option 1. 'output.txt' will be created in the folder. Post the results of the log here.
Download HijackThis from here & unzip it into it's own, permanent folder, (Not a temporary folder or the desktop & not directly on your hard drive).
If you have anything disabled in MsConfig, please re-enable it/them.
Start HJT & with all browser windows closed, press the scan button. When the scan is finished the scan button will change to save. Save the log to a text file, copy the entire contents of the text file & paste it into the body of your post. DO NOT FIX ANYTHING YET. Most of what is there is necessary for the running of your system.
Start your own thread when you have done the above plz.
•
•
Join Date: Apr 2005
Posts: 10
Reputation:
Solved Threads: 1
Your links to http://download.broadbandmedic.com/VbStuff/KillBox.zip arent working i get an error 400 :evil:
also the link to http://tools.zerosrealm.com/dllfix.exe isnt working either this page cannot be displayed yada yada :evil:
i am a member and i understand its possible to send programs over the daniweb so could u do so to me i can recieve emails from all parties
also u can send it over hotmail as i have around 250mb of space on there :eek:
i really like smileys :cheesy:
also the link to http://tools.zerosrealm.com/dllfix.exe isnt working either this page cannot be displayed yada yada :evil:
i am a member and i understand its possible to send programs over the daniweb so could u do so to me i can recieve emails from all parties
also u can send it over hotmail as i have around 250mb of space on there :eek:
i really like smileys :cheesy:
Hello The Unreal Wolf,
I don't know if you noticed, but this thread is almost a year old; a lot can change in that amount of time.
The Killbox is now called the Pocket Killbox, and can be downloaded here. I can't find a working link to DLLFix anywhere; my guess is that it isn't in use anymore. In any event, programs such as those are dangerous to use without having an expert give you directions that are specific to your particular infection.
If you need help, you should do the following:
Download HijackThis:
http://www.majorgeeks.com/download3155.html
Once downloaded, follow these instructions to install and run the program:
Create a folder outside of any Temp/Temporary folders for HJT and move it there now. A folder such such as C:\HijackThis or C:\Spyware Tools\HijackThis will do.
One of the normal steps in eliminating malicious programs is to entirely delete the contents of all Temp folders. Given that, if HijackThis (and other data that you care about) is living in those Temp folders, it will be erased along with everything else.
Run HijackThis, but do not have HJT fix anything yet; only have it scan your system! Once the scan is complete, the "Scan" button will turn into an option to "Save log...". Save the log in the folder you created for HiajckThis, open the log in Windows Notepad, and cut-n-paste the entire contents of the log in a new thread of your own in this forum.
The log contents will tell us a lot about what "nasties" have crept into your system, and once we analyse the log we can tell you what to do from there.
I don't know if you noticed, but this thread is almost a year old; a lot can change in that amount of time.
The Killbox is now called the Pocket Killbox, and can be downloaded here. I can't find a working link to DLLFix anywhere; my guess is that it isn't in use anymore. In any event, programs such as those are dangerous to use without having an expert give you directions that are specific to your particular infection.
If you need help, you should do the following:
Download HijackThis:
http://www.majorgeeks.com/download3155.html
Once downloaded, follow these instructions to install and run the program:
Create a folder outside of any Temp/Temporary folders for HJT and move it there now. A folder such such as C:\HijackThis or C:\Spyware Tools\HijackThis will do.
One of the normal steps in eliminating malicious programs is to entirely delete the contents of all Temp folders. Given that, if HijackThis (and other data that you care about) is living in those Temp folders, it will be erased along with everything else.
Run HijackThis, but do not have HJT fix anything yet; only have it scan your system! Once the scan is complete, the "Scan" button will turn into an option to "Save log...". Save the log in the folder you created for HiajckThis, open the log in Windows Notepad, and cut-n-paste the entire contents of the log in a new thread of your own in this forum.
The log contents will tell us a lot about what "nasties" have crept into your system, and once we analyse the log we can tell you what to do from there.
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing
Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.
However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
- Ancient Aborigine blessing
Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.
However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
As the member who originally started this thread has not responded for (exactly) 1 year, the thread is consided abandonded and is being locked.
If the original poster would like this thread re-activated, please PM a moderator. All other members should start their own threads for their questions.
If the original poster would like this thread re-activated, please PM a moderator. All other members should start their own threads for their questions.
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing
Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.
However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
- Ancient Aborigine blessing
Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.
However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
![]() |
Similar Threads
- Slow computer + about:blank homepage (Viruses, Spyware and other Nasties)
- About:Blank Homepage (Viruses, Spyware and other Nasties)
- Can't remove "about:blank" homepage. Please help. (Viruses, Spyware and other Nasties)
- Yet another About;Blank homepage problem (Viruses, Spyware and other Nasties)
- Can't remove "about:blank" homepage. Please help. (Viruses, Spyware and other Nasties)
Other Threads in the Viruses, Spyware and other Nasties Forum
- Previous Thread: Please help i am new cannot find server or DNS error
- Next Thread: Can't reach a specific web site
| Thread Tools | Search this Thread |
adware anti-malware anti-virussitesaccessissue antivirus apple audio avg backtoschoolspeech bar blackhat botnet botnets censorship china commercial commercials conficker connect control crosssitescripting cyber cybercrime cyberwarfare domains e-mafia education email europe exam facebook fancheckvirus gaming gtaiv halloween hijack hosting internet iphone kaspersky legal logfiles mail malware mcafee messagelabs microsoft mobile msn nazi news obama onlinethreats paedophile panel parents patch phishing police policeprovirusmba-mblockedinternetaccess president privacy pro problem reliability report research risk rogueantivirus samhain sans scareware school search security seopoisoning sites software spam spyware spywareexternalwindows7adminstratortrojans sqlinjection symantec teen translate trojan unabletoaccessanti-virussites unwanted update usa virus viruses war warning windows worm yahoo zeroday





