I've got enought of the about:blank general tips...as a "not very up to date in computers" lay person, I would love to have a step by step solution to the problem. Which software should I use? then, which file should I delete.
I would really appreciate some help with this.
Thank you
:o

Dani AI

Generated

A short, practical checklist for that builds on what and have started without repeating download instructions:

  • Quick local checks (do first)

    • Is about:blank your homepage or does it appear only when new windows/tabs open?
    • Right‑click the browser shortcut, Properties -> Target: make sure there is no extra URL appended.
    • In Internet Options check the Home page and the LAN/Proxy settings (a proxy set without your knowledge is a red flag).
    • Open the hosts file (C:\Windows\system32\drivers\etc\hosts) and look for unfamiliar entries redirecting sites.
  • If those checks show nothing, next steps for a suspected hijack

    • Reboot to Safe Mode with Networking and run up‑to‑date scanners (as recommends); save the scan logs. Do not wholesale delete everything until logs are reviewed.
    • If a DLL is being injected into IE/explorer (as mentioned is common), use a tool that lists running processes and loaded modules to identify the offending DLL; locked DLLs usually require removal from Safe Mode or by a boot‑time/offline scanner.
    • Create a system restore point or back up the registry before making manual edits.
  • Useful registry locations to inspect (backup first)

    • HKCU\Software\Microsoft\Internet Explorer\Main\Start Page
    • HKCU/HKLM\Software\Microsoft\Windows\CurrentVersion\Run (startup entries)
    • HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable and ProxyServer

When posting back, include: exact OS and browser version, whether about:blank is a homepage or temporary page, the exact symptom sequence, and saved diagnostic logs. That information lets helpers move from guessing to specific, safe removal steps.

Recommended Answers

All 2 Replies

There are several about:blank issues so one cannot be specific until the hijack is sighted. I would first run Adaware & spybot, the run hijackthis & post it here.

Download & instal Adaware from
& update it before scanning.
In settings under 'scanning,' have it set to
'scan within archives,'
'scan active processes,'
'scan registry,'
'deepscan registry'
'scan my IE Favourites for banned URL's,'
'scan my host's file.'
In 'tweaks' under 'scanning engine' set it to 'unload recognised processes during scanning.'
Also in 'tweaks' under 'cleaning engine' set it to 'Automatically try to unregister objects prior to deletion' & 'let Windows remove files in use at next reboot.'
Select 'activate in-depth scan' before starting scan.
When the scan is finished select 'next.'
Remove what it finds by placing a check in the box to the left of the object. Reboot

Download & instal Spybot S&D from Update it before scanning.
After the scan is complete, have spybot fix everything marked RED.
On the page that first opens when you start Spybot there is an option to immunise, you should do this. In the immunise section there is also a link to download Spywareblaster. This program will prevent the install of bad activex controls that it has knowledge of. Download that & you can keep it updated by selecting the same link that you use to download it. Reboot

Download HijackThis from & unzip it into it's own, permanent folder, (Not a temporary folder or the desktop & not directly on your hard drive).
If you have anything disabled in MsConfig, please re-enable it/them.
Start HJT & with all browser windows closed, press the scan button. When the scan is finished the scan button will change to save. Save the log to a text file, copy the entire contents of the text file & paste it into the body of your post. DO NOT FIX ANYTHING YET. Most of what is there is necessary for the running of your system.

Additionally, read this thread:

http://www.daniweb.com/techtalkforums/thread7507.html

It involves using a tool called APM (Advanced Process Manipulation) to yank a DLL file out of a running IE process. Then, you can do the same to explorer.exe, and then remove the affected files. The instructions are step-by-step, and worked excellently on my wife's system.

Additionally, there's CWShredder. The latest version, 1.59.1, removes several about:blank hijacks, including the really nasty "sp.html" one floating around.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.