Homepage being redirected

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Kiteye, Jul 31, 2004.

  1. Kiteye

    Kiteye Private E-2

    I hope that someone will help me with this, because I don't know what to do! Today, whenever I open my Internet Explorer, my homepage is being redirected. Even when I type in the address for my homepage, I am unable to open it. No other page actually comes up; the page just keeps trying to open, and the bottem of the page says something like "check is in network." I followed the directions under Major Attitude's thread about ridding a system of spyware, but the problem is persisting. Any help anyone has would be much appreciated!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    An exact message would be more useful. Sounds more like a network connection problem than spyware. How did you connect here? Was it on the same PC?
     
  3. Kiteye

    Kiteye Private E-2

    The exact message is:
    opening page http://www.comcast.net/CheckIsInNetwork

    This is the only site that is being affected on my computer. I was thinking it might be spyware because I have a laptop which is able to open the site with no problem, which leads me to believe the problem resides with my home PC. If its not spyware, do you have any thoughts on what the problem might be?

    Thanks very much!
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I assume Comcast is your ISP? What is you home page supposed to be?

    Have you tried simply to Reset Web Settings and then to reset you home page?

    Reset Web Settings by opening Internet Explorer. Then click Tools, Internet Options, Programs, and click the Reset Web Settings button. Then go back to the General tab and set your home page back to what you like (i.e., www.majorgeeks.com).
     
  5. Kiteye

    Kiteye Private E-2

    You are correct, my ISP is Comcast. Comcast.net is supposed to be my homepage.

    I followed your instructions re: resetting the web settings and homepage, but the problem still persists.

    I appreciate your help with this!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This link "http://www.comcast.net/CheckIsInNetwork " sounds like some kind of diagnostic from ComCast but it looks like it could be incomplete.

    Please download HijackThis and unzip it to its own directory. Then run it and save the log file but save it as "All File types" and change the name so that it is a .txt file. Then attach it to your next message as an Attachment using the Manage Attachments button. If you do not see Manage Attachments make sure you are in the Advance mode and then scroll down.
     
  7. Kiteye

    Kiteye Private E-2

    Okay, here is the log file.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis again and put check marks on these lines (but do not select Fix yet):
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:7212
    O2 - BHO: IEWatchObj Class - {9527D42F-D666-11D3-B8DD-00600838CD5F} - C:\WINDOWS\System32\IETie.dll
    O9 - Extra button: (no name) - {578FC4E3-151E-456c-AF8E-B63061EFE228}} - (no file)

    Now shutdown (that means close not minimize) all Internet Explorer sessions and then click fix in HijackThis.

    You need to reboot your computer and then rename this file
    C:\WINDOWS\System32\IETie.dll to IETie.bad

    To rename it navigate to it with Windows Explorer and then Right click on it and select rename.
    Let me know if you have any problems doing this.

    Tell me how things are working now.
     
  9. Kiteye

    Kiteye Private E-2

    Okay, I followed your directions, but the problem still persists.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did all of the steps work okay? No problems doing any of them?
     
  11. Kiteye

    Kiteye Private E-2

    As far as I know, everything went fine. Do you think I should re-try those steps just in case? I'm only semi-computer literate, as I'm sure you can tell. :rolleyes:
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's do this:
    - click Start, Run, and in the Open box enter the following and click OK:
    notepad C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS

    Now in the notepad window hit CTRL-A to select all of the contents.
    Now hit CTRL-C to copy the contents

    Come back here and in a new message, hit CTRL-V to paste in the contents of your hosts file.
     
  13. Kiteye

    Kiteye Private E-2

    Uh-oh, nothing was on the notepad when I ran that.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you get an error message about the file not being found?
     
  15. Kiteye

    Kiteye Private E-2

    no, when the notepad opened, it was just blank.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Do it again:
    - click Start, Run, and in the Open box enter the following and click OK:
    notepad C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS

    but copy the below into your notepad window and save the file:
    # Copyright (c) 1993-1999 Microsoft Corp.
    #
    # This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
    #
    # This file contains the mappings of IP addresses to host names. Each
    # entry should be kept on an individual line. The IP address should
    # be placed in the first column followed by the corresponding host name.
    # The IP address and the host name should be separated by at least one
    # space.
    #
    # Additionally, comments (such as these) may be inserted on individual
    # lines or following the machine name denoted by a '#' symbol.
    #
    # For example:
    #
    # 102.54.94.97 rhino.acme.com # source server
    # 38.25.63.10 x.acme.com # x client host
    127.0.0.1 localhost
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now post a new HijackThis log attachment for me.
     
  18. Kiteye

    Kiteye Private E-2

    Okay, I saved the notepad and ran Hijackthis. Here is the new log.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Close down ALL windows. Run HijackThis and have it fix this line (make sure you do not have Internet Explorer running, in other words you cannot be still connected here when you do this):
    O2 - BHO: IEWatchObj Class - {9527D42F-D666-11D3-B8DD-00600838CD5F} - C:\WINDOWS\System32\IETie.dll (file missing)

    Now give me another HjackThis log.
     
  20. Kiteye

    Kiteye Private E-2

    Okay, I fixed the line as you instructed. Here is the latest Hijack this log.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! But are you still having re-direction problems?

    If so, please download and run CWShredder from here and select Fix (not Scan only).
     
    Last edited: Aug 1, 2004
  22. Kiteye

    Kiteye Private E-2

    Okay, I'm still having re-direction problems, even after running the CWShredder. I'm very tempted to install Netscape, and forget using IE, becuase I'm thinking this problem is tied into IE. A different browser shouldn't have the same problems, should it?
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you want to use a different browser, try Mozilla Firefox.

    Try downloading and running CCleaner (formerly called CrapCleaner) on this PC. Get it here
    Just run it and on the Windows tab (you'll see when you run it) leave the defaults and click Run Cleaner.


    I still wonder about three items:
    1) R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:7212
    Do you have a proxy server? Who is setting this and why does it keep coming back?
    2) GhostSurf - I do not know too much about this program and whether it is good or bad. But if I search for 127.0.0.1:7212 string on the web, it seems to occur in many places where GhostSurf is installed. Can you disable this program or uninstall it and see if you problems go away.
    3) Did you use SpyBot or anything else to cause these two restrictions:
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    If not, you should have HijackThis fix those two lines.
     
  24. Kiteye

    Kiteye Private E-2

    Thanks for the recommendation regarding Mozilla Firefox.

    I ran CCleaner, to no avail.

    In response to your other three questions:

    1) I do not know if I have a proxy server, but my PC is plugged into a router that my place of employment gave me, so I can have my home PC and my work laptop both plugged into a cable modem. I do not know if this info is helpful or not.

    2)I disabled Ghostsurf, but nothing happened.

    3)As far as I know, I did not cause the restrictions, so I'll try what you advise here.

    Thanks again! You have been very patient and helpful.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay fix those two O6 lines with HijackThis and then reboot your PC (this is necessary) and try to fix the R1 line again. By the way download the new version of HijackThis. It just came out today. Get it here: http://www.majorgeeks.com/download3155.html
     
    Last edited: Sep 1, 2004
  26. un_commons

    un_commons Private E-2

    had the same problem, turned out the system clock was somehow set to 9999 as the year...set the clock and comcast started working fine...
     
  27. Computerdude60

    Computerdude60 Private E-2

    I too am seeing the exact same problem. I can go to any site except comcast.net even comcast.com works. I have run all the spyware tools and have removed everything I could find but the problem still continues. Anyone have more ideas? Is Comcast using some strang code on their web page?
     
  28. Computerdude60

    Computerdude60 Private E-2

  29. Computerdude60

    Computerdude60 Private E-2

    I got mine to work by following this advice form the comcast forum.

    I have had the same problem I went into tools then internet options then I hit privacy tab then hit edit type comcast.net then hit allow and it worked for me.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Check your hosts file and doing the other items indicated in this thread. Even check your clock as indicated by un_commons.
     
  31. Covota01

    Covota01 Private E-2

    I also have had the same problem with Comcast.net but no other web site. Interestingly enough ... I ran the windows updates for .NET Framework 1.1 and the problem no longer exits. Incidentally my platform is Windows XP Professional ... hope this will help ...
     
  32. eternityx

    eternityx Private E-2

    I had so many problems with my computer for the past few weeks that I had to reformat my hard drive twice due to spyware and other problems resulting in me setting the highest security settings on my computer. I was resulting in this same event : not being able to access the comcast website and getting this same redirect that you were. I realized that on the bottom toolbar of the IE window was a little red icon with an exclamation point and I clicked on it. It brought me to an internet settings window that allowed me to allow cookies from comcast and thereby fixed my problem. Hope this helps.

    -EX
     
  33. NEWELLIO

    NEWELLIO Private E-2

    I had the same problem. it was because my system clock and date were set incorrectly. I changed it and now everything works fine.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds