about:blank/http://vv2.s13.topx.cc

G

Guest

If anyone has the coolweb and windows pop up with the
address http://vv2.s13.topx.cc in the bar. It is the file
JIBG.dll- boot into safe mode then search for it and
delete it. It also seems to mutate into JWFZT.dll.
 
R

Ron Kinner

The dll file has many variations.
CoolWebSearch is best removed with the free CwShredder.exe


http://cwshredder.net/bin/CWShredder.exe

AdAware Se (free version) with the VX2 Cleaner Add on will
clean VX2 infections.

http://www.pchell.com/support/aboutblank.shtml

gives a good explanation of where aboutblank hides.
Annoying that neither regedit nor HijackThis can see it.

Two German tools for about:blank removal are:

sphjfix.exe and spoonweg.exe

http://www.trojaner-info.de/cgi-bin/download.cgi?
file=sphjfix

http://mmrealisation.de.vu/

I've had pretty good luck with them in conjunction with
HijackThis. If you can identify one component of the
hijacker then you can search for everything Modified on
the same Date and Time and delete them.

Ron Kinner MVP Servers
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads


Top