M@'s Homepage Hijacker

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mahtchew, Aug 18, 2004.

  1. mahtchew

    mahtchew Private E-2

    hello!

    i think i have the homepage hijacker that someone else i was reading about had. it includes plenty of pop-ups and conveniently changes my homepage to some search site (even when i try to change it back). also, everytime i boot up my pc, it comes up with a window that says "atlcy32.exe has failed to load". usually that comes up twice before my system completely boots.

    another problem (or possibly the SAME problem) is that i seem to have all kinds of extra programs/internet web pages running (but not visible), according to my Task Manager. sometimes i find "My Documents" open and running 2 and 3 times with no visible sign of it actually being open except on Task Manager.

    i was going to run a couple of the programs that you all had suggested to the other guy, but i wanted to make sure of what to do before i downloaded anything. the programs that were suggested were BHO Demon & HSREmove. i have SpyBot and Ad-Aware now and have run both with no success. can you please let me know where i can start to fix this problem? i would really appreciate your help!

    thanks!
    M@
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. mahtchew

    mahtchew Private E-2

    Great I will try these processes tonight! Thank you very much!!
     
  4. mahtchew

    mahtchew Private E-2

    Ok, I tried all of the steps in the threads you mentioned. The "about:Buster" seemed to work the best at removing some of the other smaller (less noticable problems), but the homepage hijacker still seems to be in control. Does anyone have any other ideas?
     
  5. mahtchew

    mahtchew Private E-2

    Ummmm ok. I guess that means nobody else has any ideas on a solution to this problem. Thanks alot guys, great website.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You message from 8/23/2004 just got lost in the pack!

    The solution has been here all the way along but we prefer to try the other procedures first. Read this Sticky thread: When all else fails - try Generic Solution to HSA (Only the Best) hijack
     
  7. mahtchew

    mahtchew Private E-2

    I did follow all the directions in that "Generic Solution" thread as well as the other one you posted previously. I will try it once again though as this seems to be the only solution. Thanks for your help.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is but you need to follow it exactly and you need make sure you are locating all the problem files and lines in HijackThis. If you need help, post your HJT log as an attachment but you must not shut down or reboot your PC afterwards or the problem will possibly mutate and change filenames making the log useless.

    Did you look for the NSS and WNS stuff in step 6? Did you find either of them?

    Perhaps you have other problems too that are compound problems making the solution less effective. I have seen many cases like that where we had to fix other problems first inorder to effectively resolve HSA problems.

    And finally new breeds of HSA have been occurring during the last number of months making it necessary to add additional steps (as you can see in my Generic Solution).
     
  9. mahtchew

    mahtchew Private E-2

    Hi, it's me again. I kind of gave up this last time because nothing seemed to work. But now I apparently have the e-mail virus where it sends out e-mails from me to other people with Viruses attached in the form of music files. I guess I need to stop dowloading anything onto my pc as it keeps getting worse. I tried, last night, to run all of the SpyWare programs that I dowloaded off your website. That didn't seem to do much in itself. I'm really afraid of erasing certain things off HijackThis log. Sometime this weekend I will go ahead and run HijackThis and post the log (without turning off my pc). I'd like to think of myself as a novice at computers, but when it comes to program files and extensions and things, I get a little lost.

    As far as the e-mail virus, do you have a seperate solution for that, or will this generic solution help with that also?

    Thank you again for all your help.
     
  10. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    A Hijack This logfiule would be helpful now to identify it. If we do not respond within 24 hours, bump the thread politely so we see it. Mainly 2 of us 2 the majority here and its often hard to keep up, we dont want to miss anyone.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I think since it has been such a long time since you previously started this thread and you now have new problems, you should start over again and do the steps here first (we have also made some changes to this thread since you last ran it):
    http://forums.majorgeeks.com/showthread.php?t=35407

    After that post your HijackThis log as an attachment.
     
  12. mahtchew

    mahtchew Private E-2

    Sorry it's taken so long to respond. I moved a couple weeks ago and it's been crazy. I still have the problem though and will go through all of the steps tonight (hopefully). I plan on posting my HijackThis log as an attachment tomorrow.
    Before I go through all these steps, has there been any updates to these threads posted below? Or when I click on the link to the thread, does it automatically take me to the newest version? It's been a while since posted so I wanted to be sure. Please let me know when you get a chance.

    Thanks again for your help!

    M@
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thread are constantly getting updated. Always recheck the links to make sure you have the current applications and are following the latest instructions. They have changed as recently as Oct. 6,2004
     
  14. mahtchew

    mahtchew Private E-2

    Alrighty, attached is the HijackThis log that I ran yesterday. I did not shut down my computer after running it. Can you please help me to determine which of these are bad? I really appreciate your help!

    Thanx!
    M@
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Next time please save the file to a .txt file (like logxx-xx.txt) not a .doc file.
    Also you must get HijackThis off of your Desktop and into its own folder before continuing.
    Did you read the HijackThis tutorial thread?

    You never completed all the steps of the READ ME FIRST thread. I can tell this because there are no signs of any online scans being performed. You also should have run about:Buster and HSremove since you do have the HSA hijack. You also have several other really bad problems which are going to be difficult to repair. How in the world did you get all this stuff?

    First the easy part, go to Add/Remove Programs and uninstall WebRebates.
    Also look for BullsEye Network, BargainBuddy, WindowsSyncroAd (or SyncroAd or Winsync) in Add/Remove Programs and if found uninstall them too.

    Then run the online scans as requested in the READ ME file. Make sure you run Stinger too because I also see this virus: W32/MyWife.c@MM
    http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=128172

    Then see the Alternative Scans section of the READ ME and run A-squared and RavAntivirus.

    When done with ALL the above post a new HJT log as a .txt file attachment so we can continue to work on this.
     
    Last edited: Oct 15, 2004
  16. mahtchew

    mahtchew Private E-2

    Well I'm glad you're helping me with this problem. I'm not sure HOW I got all this crap! I think it's just kind of compiled over time and I haven't been able to do anything about it.

    I actually DID run a whole bunch of scans prior to running HiJackThis. about:buster, HSRemove, Shredder, SpyBot, SpyAware, etc. (I can't remember what they were all called, but there were almost 10 of them) I downloaded and ran everything that was on the thread. I even checked every single one of them for Updates as you suggested. I don't think they're really helping much. They remove things, but none of the problems I'm seeing are being resolved AT ALL. But I will run them all once again. Tonight I will go through this list of things you suggested, and follow the process once again, step by step, following everything exactly as you wrote it. I should have the new HijackThis log .txt file posted tonight or tomorrow sometime.

    Thank you again for all your help and your patience with me and my problem.

    M@
     
  17. mahtchew

    mahtchew Private E-2

    Oh a few more things. My HijackThis program IS in a seperate folder that I keep ALL of my virus scanners in. Do I need to create a DIFFERENT folder just for HijackThis?

    When I run one of the cleaner programs (I'm not sure which one because I run them all at once), it opens up My Documents, sometimes twice. I'm not sure if that's possibly where the problem lies but thought I'd mention that.

    Also, can you re-post the exact process that you want me to follow? There are several DIFFERENT threads that you have told me to follow exactly within my Homepage Hijacker thread, and I want to be sure I'm following the CORRECT one! It may be helpful to spell it out for me since I'm a beginner. (i.e. "1st process, follow this one first", "If 1st process doesn't work, follow 2nd process", etc.)

    Thanks again!
    M@
     
  18. mahtchew

    mahtchew Private E-2

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You had HijackThis running from here:
    C:\Documents and Settings\Owner.YOUR-M5D4U9R2UV\Desktop\FIX\HijackThis.exe

    That's your Desktop. Put it in its own folder that is not on the Desktop and not a temp folder of anykind. Try C:\HJT or c:\Program Files\HJT or similar.

    DO NOT RUN THE SCANNERS AT THE SAME TIME!!!!

    Follow the steps in the order given in this Sticky thread < READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal >


    Make sure you run ALL steps do not skip the Stinger and online scan steps.


    And make sure (as I said before) you run about:Buster and HSremove. Make sure you use about:Buster's update button and save the log from about:Buster.

    The goto the <Alternative Scans - If still having problems> section of that thread and run (in normal boot mode):

    Bitdefender online scan
    RavAntivirus online scan <-- select Auto Clean then click Scan My PC
    TrojanScan online scan

    a-squared (a²) Free edition free but requires an email address to register


    When done with ALL the above post the log from about:buster and a new HJT log as a .txt file attachment so we can continue to work on this.
     
    Last edited: Oct 15, 2004

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds