• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

questions after an "about:blank" fix

redbeard1

Diamond Member
After pulling my hair out for most of the day, I found this link with instructions on how to find and remove the registry entry and the hidden file from the hard drive.

What threw me was that things could be hidden from view in the registry and on the hard drive. I found the registry entry value using the free registry editor, while regedit couldn't see it. Show all hidden files was turned on, yet I could not see the dll file while I was in windows. It was there at a recovery command prompt however.

I talked with a someone who said that the ability to hide certain things was a feature to protect system files. I was not able to talk with him long enough to see if he knew where I could edit whatever policy to change this "feature". I looked all around in the local and group policy and did not find a fix.

So my question is, what would need to be done to see ALL files, no matter what MS says. It is so irritating that the spyware is using windows security against itself. :|

SecuriTeam
 
Further searching has turned up something called superhidden files in windows. In this key is an entry for ShowSuperHidden. Any idea what value would you change it to, to enable them to be seen? My non-infected system is set to: 0x000000001 (1)

HKEY_CURRENT_USER/Software/Microsoft/Windows/CurrentVersion/Policies/Explorer/Advanced

Explains how to change
 
I looked at the registry of the system, and superhidden was enabled. So that still gets back to the question of what can be changed to see even super secret triple probation files.
 
Originally posted by: Schadenfroh
Originally posted by: Confusednewbie1552
what's wrong with about:blank?

an evil hijacker CWS variant

Ah, the horrid CoolWebSearch, may its creators burn in hell. I recently cured an infection of this on someone's system - it was an old variant though. CWSHredder found it and got rid of it easily.

Spyware Info Forum link. Those forums have info on how to get rid of CWS. I'll try to find the link that helped me. I needed to download a registry editor called Registrar Lite, so I could rename a hidden registry entry in order to delete it (it is regenerated if you just delete it), then a program called Killbox to forcibly delete the hidden file (which had a randomly generated name) in the Windows folder.
Relevant thread

Interesting link here - programs that bill themselves as spyware removers, when they are themselves spyware/malware. Quite a lengthy list too.
 
Back
Top