About Blank Removal Guide

Threat Level:
6/10
Rate this Article:
Comments (0)
Article Views: 69286
Category: Browser Hijackers

AboutBlank Infection is a homepage hijacker that is a new version of the notorious Cool Web Search hijacker. It is very dangerous spyware software, because AboutBlank infection is extremely hard to remove. The reason why it might be hard to delete this infection is that the hijacker files can restore themselves and start up together with Windows again, even if they have been deleted.

Sometimes it might be hard to get rid of AboutBlank Infection because of a Trojan or the so-called “I Love You” worm that changes your browser’s homepage into a blank page. But the main reason why this infection is hard to get rid of is the browser hijacker infections themselves. Technically, browser hijackers are not viruses, so they are hardly ever detected by antivirus programs. Your computer stores your browser’s homepage and these hijackers replaces it into an HTML file that is set to “about:blank”. This page looks like a part of a search engine, and if you click on any of the links that are embedded into that page, the owners of these ads get some profit from it.

This infection installs a browser helper object into your browser, and as a result this BHO slows down your computer and your internet connection. This browser helper object appears in your browser after the infection hides a dll file in the follow registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows \ CurrentVersion\ Windows\\AppInit_DLLs

There are also a few .exe files that are running in your Windows Task Manager that are related to AboutBlank, but the newer versions of this spyware generate the names of these executables at random, in order to avoid being detected by security programs. And since there are a lot of hidden dll files associated with this infection, they can restore AboutBlank even if you have tried to delete it already. It means that this infection needs to be terminated and purged through and through, along with its hidden files and registry key entries.

Apart from hijacking your browser, AboutBlank can also exhibit other symptoms. This infection can easily change your default search settings, display annoying pop-up advertisements and install dangerous Trojan downloaders. With a Trojan infection at hand you consequently can be a subject to a rogue antispyware infection, so you must remove AboutBlank infection before this vicious circle gained any momentum. Acquire a powerful computer safeguard application that will detect and terminate every single file related to AboutBlank and you will be able to utilize your browser to the fullest again.

Download Remover for About Blank *
*SpyHunter scanner, published on this site, is intended to be used only as a detection tool. To use the removal functionality, you will need to purchase the full version of SpyHunter.

About Blank technical info for manual removal:

Files Modified/Created on the system:

# File Name File Size (Bytes) File Hash
1wdm.dll
2cbme.dll
3se.dll
4iesp1.dll
5achpjba.dll
6sethcd.exe
7smbdins.exe
8tsmsetup.exe
9phafxfa.exe
10svhost.exe
11abu.exe20480 bytesMD5: 225b2e7654bf62bb3ee2f5d337af9997

Memory Processes Created:

# Process Name Process Filename Main module size
1sethcd.exesethcd.exe
2smbdins.exesmbdins.exe
3tsmsetup.exetsmsetup.exe
4phafxfa.exephafxfa.exe
5svhost.exesvhost.exe
6abu.exeabu.exe20480 bytes

Registry Modifications:

The following Registry Keys were created:

  • HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{b664647f-efd5-4837-a810-a807139107e5}
  • HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runnetworkservice
  • HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run network service
  • HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser {06abaa2d-34ab-4902-a326-409bd9b9a7a5}
  • b664647f-efd5-4837-a810-a807139107e5
  • 06abaa2d-34ab-4902-a326-409bd9b9a7a5
  • HKEY_CLASSES_ROOT\clsid\{06abaa2d-34ab-4902-a326-409bd9b9a7a5}
  • HKEY_CLASSES_ROOT\clsid\{b664647f-efd5-4837-a810-a807139107e5}
  • ce6a1268-9cc9-4ba3-8657-fe1132906cc4
  • HKEY_CLASSES_ROOT\clsid\{ce6a1268-9cc9-4ba3-8657-fe1132906cc4}
  • HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar {06abaa2d-34ab-4902-a326-409bd9b9a7a5}
  • HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runnetworkservice
  • HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run network service

Reply

Your email address will not be published.

Name
Website
Comment

Enter the numbers in the box to the right *