Home page changed, can't go to any other sites

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by gal1998, Jul 19, 2004.

  1. gal1998

    gal1998 solo-cob

    Yesterday, computer was working fine. I downloaded Spysweeper, it found a few things and fixed them. (I thought)
    I even downloaded Mozilla Firefox and was trying that out.

    Well, this morning, I boot up and when I connect tried to go to my home page www.majorgeeks.com. Instead, I end up at some myfamily thing. Never could get to majorgeeks. Tried it on Firefox and IE. Same thing. I could go to some other websites, but not many. Most came up no data found.

    Since then I have restored computer to an earlier date. I am running my scans to see what they find. So far, ad-aware found nothing. Even on deep scan. Neither did spybot S &d. I am downloading Spysweeper right now, to see what it finds.
    Might be a long night for me.

    Running XPHome.

    Gal
     
  2. ANHEDONIC

    ANHEDONIC Will Title For Food

    try not to let it overwhelm you... i had a major spyware invasion a few months ago just by clicking on a harmless picture after a google image search... it gave me alot of anxiety and a big headache but after a day or 2 of posting here i was able to get the advice i needed to rid my system of all the nasties... perhaps u should post a hijack this log ?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Post your hosts file. Use this, click Start, Run, and in the Open box enter:
    notepad C:\windows\system32\drivers\etc\hosts

    Copy and paste the info back here.
     
  4. gal1998

    gal1998 solo-cob

    I didthat and this is what it shows.
    Spysweeper only showed Backweb and I did not fix it.

    Right now, I keep getting Soyguard Browser asking me if I want to change my homepage from www.majorgeeks.com\ to www.majorgeeks.com
    # Copyright (c) 1993-1999 Microsoft Corp.
    #
    # This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
    #
    # This file contains the mappings of IP addresses to host names. Each
    # entry should be kept on an individual line. The IP address should
    # be placed in the first column followed by the corresponding host name.
    # The IP address and the host name should be separated by at least one
    # space.
    #
    # Additionally, comments (such as these) may be inserted on individual
    # lines or following the machine name denoted by a '#' symbol.
    #
    # For example:
    #
    # 102.54.94.97 rhino.acme.com # source server
    # 38.25.63.10 x.acme.com # x client host
    127.0.0.1 localhost


    Gal

    I am running ZA and this 127.0.0.1 is always the IP it shows I think.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your hosts file is okay. Time to send us a HijackThis log.
     
  6. gal1998

    gal1998 solo-cob

    I am downloading hijack this as I write this. Will post back as soon as I run it.

    Thanks chaslang.

    Gal
     
  7. gal1998

    gal1998 solo-cob

    Logfile of HijackThis v1.98.0
    Scan saved at 4:30:32 PM, on 7/19/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\alg.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\PROGRA~1\CACHEM~1\CachemanXP.exe
    C:\Program Files\Ahead\InCD\InCDsrv.exe
    C:\windows\system\hpsysdrv.exe
    C:\WINDOWS\System32\hkcmd.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\HP\KBD\KBD.EXE
    C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
    C:\PROGRA~1\AWS\WEATHE~1\Weather.exe
    C:\Program Files\PowerPlugs\Outlook Express Stationery\OLExp\winoeinit.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Spyware Doctor\spydoctor.exe
    C:\Program Files\VisualZone\VisualZone.exe
    C:\Program Files\SpywareGuard\sgmain.exe
    C:\Program Files\SpywareGuard\sgbhp.exe
    C:\Program Files\LeechGet 2004\LeechGet.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us7.hpwis.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us7.hpwis.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.majorgeeks.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rd.yahoo.com/customize/ymsgr/defaults/*http://my.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/customize/ymsgr/defaults/su/*http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/ymsgr/defaults/sb/*http://www.yahoo.com/ext/search/search.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.majorgeeks.com
    O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
    O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded
    O4 - HKLM\..\Run: [LexStart] lexstart.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
    O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
    O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
    O4 - HKCU\..\Run: [OEPowerPlugs] C:\Program Files\PowerPlugs\Outlook Express Stationery\OLExp\winoeinit.exe
    O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\spydoctor.exe" /Q
    O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
    O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
    O4 - Global Startup: VisualZone.lnk = C:\Program Files\VisualZone\VisualZone.exe
    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
    O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
    O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
    O8 - Extra context menu item: Download using LeechGet - file://C:\Program Files\LeechGet 2004\\AddUrl.html
    O8 - Extra context menu item: Download using LeechGet Wizard - file://C:\Program Files\LeechGet 2004\\Wizard.html
    O8 - Extra context menu item: Parse with LeechGet - file://C:\Program Files\LeechGet 2004\\Parser.html
    O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - (no file)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - (no file)
    O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
    O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: ChatSpace Full Java Client 3.1.0.229 - http://streak.fimc.net:8000/Java/cfs31229.cab
    O16 - DPF: ppctlcab - http://www.pestscan.com/scanner/ppctlcab.cab
    O16 - DPF: Video Poker - http://download.games.yahoo.com/games/clients/y/vpt0_x.cab
    O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/games/clients/y/xt0_x.cab
    O16 - DPF: Yahoo! Blackjack - http://download.games.yahoo.com/games/clients/y/jt0_x.cab
    O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/games/clients/y/it1_x.cab
    O16 - DPF: Yahoo! Dominoes - http://download.games.yahoo.com/games/clients/y/dot7_x.cab
    O16 - DPF: Yahoo! Euchre - http://download.games.yahoo.com/games/clients/y/et1_x.cab
    O16 - DPF: Yahoo! Gin - http://download.games.yahoo.com/games/clients/y/nt1_x.cab
    O16 - DPF: Yahoo! Hearts - http://download.games.yahoo.com/games/clients/y/ht1_x.cab
    O16 - DPF: Yahoo! MahJong Solitaire - http://download.games.yahoo.com/games/clients/y/mjst3_x.cab
    O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt1_x.cab
    O16 - DPF: Yahoo! Sheepshead - http://download.games.yahoo.com/games/clients/y/dt0_x.cab
    O16 - DPF: Yahoo! Spades - http://download.games.yahoo.com/games/clients/y/st2_x.cab
    O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.pestscan.com/scanner/axscanner.cab
    O16 - DPF: {4539348E-01D7-11D5-9A39-0080C8D85044} (GINSLOTS90 Class) - http://66.98.132.11/g_bin_eng/slots90_2_0_0_12.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
    O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
    O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dll
    O16 - DPF: {A7196C8E-35A5-4FF0-9E46-E28918B5CAF6} (GINDOMINO Class) - http://66.98.132.156/g_bin_eng/domino_2_0_0_15.cab
    O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundler/CAB/RealArcadeRdxIE.cab
    O16 - DPF: {E23FABEE-12E3-33DA-DA12-195DAC123984} (GINMAHJONG Class) - http://66.98.132.11/g_bin_eng/mahjong_2_0_0_9.cab
    O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?319
    O17 - HKLM\System\CCS\Services\Tcpip\..\{658B5410-6B2D-497A-8174-08A1BF2EE32C}: NameServer = 206.10.62.4 206.10.62.3
    O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll

    Here it is. Not sure I did it correctly, though. Looking at 04

    I will not close it or shut down till I hear back.

    Gal
     
  8. gal1998

    gal1998 solo-cob

    I am wondering about this line?
    O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe

    I do not share files from my printer. Should this be disabled?

    Gal
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Go here and scroll down to see info on what that exe is:
    http://www.answersthatwork.com/Tasklist_pages/tasklist_h.htm

    It's up to you whether you need it or not.

    I'm still looking at the HijackThis log.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See this:
    C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

    This is a bad place to have HijackThis. You need to put it in its own directory where it can save backups. Do not put it on your desktop or in any temp folder where it could be prone to cleanups thus losing backups.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Goto Add/Remove Programs and uninstall WeatherCast stuff.

    Also have HijackThis fix:

    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - (no file)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - (no file)
    O16 - DPF: {4539348E-01D7-11D5-9A39-0080C8D85044} (GINSLOTS90 Class) - http://66.98.132.11/g_bin_eng/slots90_2_0_0_12.cab
    O16 - DPF: {A7196C8E-35A5-4FF0-9E46-E28918B5CAF6} (GINDOMINO Class) - http://66.98.132.156/g_bin_eng/domino_2_0_0_15.cab
    O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsol...ArcadeRdxIE.cab
    O16 - DPF: {E23FABEE-12E3-33DA-DA12-195DAC123984} (GINMAHJONG Class) - http://66.98.132.11/g_bin_eng/mahjong_2_0_0_9.cab

    Please give the exact place you are being hijacked to. All you said was "I end up at some myfamily thing".

    Also, you said, "Right now, I keep getting Soyguard Browser asking me if I want to change my homepage from www.majorgeeks.com\ to www.majorgeeks.com" You meanyt SpywareGuard or SpySweeper, right???? If so, tell it yes and that should end that message.
     
    Last edited: Jul 19, 2004
  12. gal1998

    gal1998 solo-cob

    I did what you asked.

    I cannot tell you what the exact website was it directed me to, as I had to restore computer to even get online.
    I know it started with www.majorgeeks....... but was NOT this website. All I know is it had "myfamily": and wanted me to sign up, etc....was a whole page of "myfamily" things. I wish now I had wrote it down.

    Yes, it is SpyGuard Browser Hijack Protection that keeps popping up,. Even if I am offline.
    Thinking back, I am wondering if that is what started this (when I next booted) If I clicked yes, to get it to stop, maybe that is what is doing this? Now, I just leave it on screen and don't do anything with it.
    Should I try uninstalling Spyguard?

    Thanks for all your patience and help with this.

    Gal
     
  13. gal1998

    gal1998 solo-cob

    Duh me. Uninstalling that won't do me any good. That isn't the problem. Do you want me to click yes to change it, then reboot and see what happens? If it does it again, I can write down address, then restore computer and come back online and tell you?

    Gal
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's SpywareGuard not SpyGuard. Be careful with names. There can be differences and there could be products with similar names (some of which are bad). SpywareGuard is good. Leave it installed. And click yes to let the home page change to www.majorgeeks.com. That should end the popup from SpywareGuard.

    What do you mean "restore computer"? Is that a typo? Did you meant restart?

    Did WeatherCast uninstall okay?

    Post a new HijackThis log.
     
  15. gal1998

    gal1998 solo-cob

    I meant restore. This morning, when this happened, I could not get to majorgeeks at all. Neither in IE or Firefox. I had to restore my computer to Saturday morning.

    Yes, weatherbug uninstalled fine and I fixed the hijack this lines.


    I will go get a new hijackthis now.

    Gal
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well then I take it that if you restored to an old restore point that you no longer have a problem with website access. So there should not be anything to look for. Right.? That's why we have not found anything. I missed the fact that you already did a restore in your first message.
     
  17. gal1998

    gal1998 solo-cob

    So then I am ok? The creepy crawly things won't come back to this restore? I can see them wiggling their way back. Just kidding. Gotta have some humor.

    I am sorry if I didn't have it clear in first message. I tried to give as much info as I could.

    I still haven't clicked yes to change the home page again from Spyware Guard Browser? Should I do that? Only way I will get rid of that. Then, if it starts this all over, I will get the address it sends me to or doesn't it matter?

    Gal
     
  18. gal1998

    gal1998 solo-cob

    I am sorry if it was just plain stupidity on my part not to know that restore would fix my problem....

    Sorry
    Gal
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have said this a few time already. Why do you keep asking? .... "And click yes to let the home page change to www.majorgeeks.com. That should end the popup from SpywareGuard. " It is only warning you about a change to your start page that you really want to make.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds