Hijacked Homepage & Search Page

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by chuckycharms, Oct 2, 2004.

  1. chuckycharms

    chuckycharms Private E-2

    Hello,

    I am currently having issues with IE6 and would like to request some help. I have followed every step that had been outlined prior to posting. I have Ad-Aware SE Ad-Watch running in automatic mode. When I open IE some service is constantly trying to change my homepage. This is what it is trying to change to:

    mk:mad:MSITStore: C:\spe\start.chm::/start.html#

    Secondly, when typing an address in the address bar, unless I use the fully qualified URL, including http://, it uses the text as a search string for http://www.heretofind.com.

    I am not new to computers, nore spy and ad ware. However, I am not able to pin point the cause, nor do I have time to spend on this.

    Your Help is greatly appreciated,

    Adam
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are sure you have performed the ALL the steps here: READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    then you should read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail, items in the tray, anything you can close... Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder or choose run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. chuckycharms

    chuckycharms Private E-2

    Here is my log. I have ran this prior, and removed all appropriate keys, only to have them reappear after a reboot.

    Thanks for your help.

    I tried to add an attachment, but the manage attachment button does nothing. Would you like me to past it into the message?
     

    Attached Files:

    • hjt.txt
      File size:
      3.4 KB
      Views:
      3
    Last edited by a moderator: Oct 2, 2004
  4. Kodo

    Kodo SNATCHSQUATCH

    did you go through the tutorial?
     
  5. chuckycharms

    chuckycharms Private E-2

    Yes I did, to the "T".
     
  6. Kodo

    Kodo SNATCHSQUATCH

    do a search for a folder on your system called spe. Find it and delete it. Then remove these keys

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.heretofind.com/show.php?id=18&q=%s
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.heretofind.com/show.php?id=18&q=%s
    O13 - DefaultPrefix: http://www.heretofind.com/show.php?id=18&q=
    O13 - WWW Prefix: http://www.heretofind.com/show.php?id=18&q=
    O13 - Home Prefix: http://www.heretofind.com/show.php?id=18&q=
    O13 - Mosaic Prefix: http://www.heretofind.com/show.php?id=18&q=
    O13 - Gopher Prefix: http://www.heretofind.com/show.php?id=18&q=

    you probably should do this while in safe mode.. just incase a file is in use.
     
  7. Kodo

    Kodo SNATCHSQUATCH

    Damnit.. I didn't notice this .. you need to download a new version of HJT.. you're on 1.97.7. The latest is 1.98.2

    Please download it here
    http://www.majorgeeks.com/download3155.html

    and then run it again and post a new log..
     
  8. chuckycharms

    chuckycharms Private E-2

    Heres my log, thanks for the quick responses!! (again the manage attachments button does nothing).
     

    Attached Files:

  9. Kodo

    Kodo SNATCHSQUATCH

    reboot into safe mode
    locate a folder called C:\SPE and delete that sucker!
    then run HiJackThis and remove the following


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.heretofind.com/show.php?id=18&q=%s
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = mk:mad:MSITStore:C:\spe\start.chm::/start.html#
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.heretofind.com/show.php?id=18&q=%s
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = mk:mad:MSITStore:C:\spe\start.chm::/start.html#
    O13 - DefaultPrefix: http://www.heretofind.com/show.php?id=18&q=
    O13 - WWW Prefix: http://www.heretofind.com/show.php?id=18&q=
    O13 - Home Prefix: http://www.heretofind.com/show.php?id=18&q=
    O13 - Mosaic Prefix: http://www.heretofind.com/show.php?id=18&q=
    O13 - Gopher Prefix: http://www.heretofind.com/show.php?id=18&q=


    For my own records as I update my knowlege in how to fight this stuff, can you post the file names of any files found in that directory?
     
  10. chuckycharms

    chuckycharms Private E-2

    Just the one (including hidden files), start.chm

    Thanks!!!!
     
  11. Kodo

    Kodo SNATCHSQUATCH

    everything working ok now?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't know where all the problems stand right now but a some comments I have:

    Both Kodo and I asked if you ran the READ ME tutorial. Your answer was, "Yes I did, to the "T"."

    My answer is no you did not. If you had run the tutorial (ALL STEPS) you would have signs of the Symantec & TrendMicro online scans in your log. Also Kodo would not have had to ask for a new HJT log with the correct version. Please follow directions in the future these tutorials are there for a reason and we expect ALL the steps to be followed. It may not have mattered in this particular case but there have been many cases where someone skips a step that should not have been skipped and we spend a week trying to resolve a problem that would have been fixed within the hour had all directions been followed exactly.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds