Desperate for help - Colleagues have same problem

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by PJ_Davao, Apr 12, 2005.

  1. PJ_Davao

    PJ_Davao Private E-2

    Whenever I try to connect to Microsoft support, or Windows update, my browser goes instead to http://g.msn.com/mh_mshp/98765?http...dows+Update&CM=Navigation&CE=productResources with a "Cannot find Server" on page.
    I couldn't get to the TomCoyote.org site either, getting redirected, so had to download the program on another computer.

    I've run Adaware, Spybot S@D, and am clean. I have AVG7 and Spyware Blaster running.

    Yesterday I scanned with Hijack This, and when I checked it over, didn't see anything suspicious. It was very short.
    I would really appreciate ideas of how I can get this sorted out.

    THanks for your help!
     
  2. PJ_Davao

    PJ_Davao Private E-2

    Additional info - I am running Zone Alarm, and also have a Linux IP Cop machine running as a firewall and filter

    Thanks
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program.
    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot. Did this help?
     
  4. PJ_Davao

    PJ_Davao Private E-2

    Thanks for your super quick reply. Was posting from home, so will try on my office computer shortly and let you know.

    PJ
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ok! But I will not be around much longer tonight!
     
  6. PJ_Davao

    PJ_Davao Private E-2

    I tried the fix, following all of the steps, but still have the same problem. I am able to connect to Windows Updates by going to Start/All Programs/WIndows Updates, but if I use IE to go to the Microsoft site, and try to access Updates, Support or any of the links on their page, it changes my URL to http://g.msn.com/mh_mshp/98765?http...dows+Update&CM=Navigation&CE=productResources.

    What should I try next?

    PJ
     
  7. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    While Chas isnt here at the moment, just to keep things moving along. Lets get a look at a HJT log.


    http://www.majorgeeks.com/images/grenade.gif Download HijackThis 1.99.1

    http://www.majorgeeks.com/images/grenade.gif Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    http://www.majorgeeks.com/images/grenade.gif Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the ZIP file as your backups will not be safely stored.

    http://www.majorgeeks.com/images/grenade.gifBefore running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    http://www.majorgeeks.com/images/grenade.gifRun HijackThis and save your log file.

    http://www.majorgeeks.com/images/grenade.gif Post your log as an ATTACHMENT to your next post. (Do NOT copy/paste the log into your post as it will be removed).

    http://www.majorgeeks.com/images/grenade.gifNeed help with HJT? See this thread: NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting
     
  8. PJ_Davao

    PJ_Davao Private E-2

    Okay. Here is my HJT log.

    Sorry for the delays when you reply so quickly. I keep getting called out of my office.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you require the below ProxyServer setting?
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.0.2

    Other than that I see no problems in your log.

    Perhaps you need to flush your DNS cache by doing the following:

    click Start, Run, and enter ipconfig /flushdns and hit OK.

    Did that help? If not, try using http://207.46.196.46 instead of http://support.microsoft.com

    Does that work?
     
  10. PJ_Davao

    PJ_Davao Private E-2

    Thanks for all your help. Found that reason several of us on the network were having problems was due to an entry in the IPCop Machine. Fixed now.

    Thanks again. Great to know you are there if we need you!!

    PJ
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Happy to hear you got it all worked out.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds