help with homepage hijack

Discussion in 'Malware Help (A Specialist Will Reply)' started by shufi, Jun 28, 2006.

  1. shufi

    shufi Private E-2

    hi!
    yes, i'v been victimized too...
    at first, my homepage was "about:blank" hijacked.
    using several anti spyware programs. (spyware doctor, spysweeper, ad-aware se) - i gladly got reed of it but i found out that it was only replaced by the msn homepage hijack. please help me fix this annoying problem.
    thanks

    Edit: Removed inline log
     
    Last edited by a moderator: Jun 28, 2006
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi and Welcome

    To sucessfully remove any malware please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis


    When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
    • Bitdefender
    • Panda Scan
    • HijackThis



    once done, we can proceed with any futher removal steps.
     
  3. shufi

    shufi Private E-2

    help still needed - home page still hijacked

    hello again,

    after following your instructions step by step (your "read and run me first" process), my homepage is still hijacked.
    at first, it was "about:blank" hijack. then i ran few anti spyware programs (spyware doctor, spybot, adaware se) and the homepage hijack was changed to msn.
    at that point i found your amazing site and followed your instructions fully.
    after finishing all the steps one by one, my homepage is still hijacked, only this time it is "http://v4.windowsupdate.microsoft.com/"

    i need your help solving this problem once and for all
    attached 3 logs:bdscan.txt, activescan.txt, hijackthis.log

    thanks
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: help still needed - home page still hijacked

    Please do not start new threads for the same problem. You must remain in one thread from beginning to end. I have merged you back to your original thread.

    Is your copy of SpywareDoctor a paid version or free trial? If free, uninstall it since it will not fix anything for you.

    What is it that you still have install from Symantec? Seems to be a security center application which you should not use since you have AVG7 installed.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - blank (file missing)
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    c:\program files\eMedia Codec <--- delete the whole folder
    D:\My Downloads\vcodec_ver3.119.exe
    D:\My Downloads\eCodec-v4.345.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  5. shufi

    shufi Private E-2

    hi !

    my spyware doctor is a paid version.

    about symantec: i used in the past symantec security center but i am not using it anymore and i uninstalled the program. i don't know what it is that still showing symantec application use or how to get rid of it.
    i use avg as my antivirus software.

    i followed your instructions and i still have windows update as my homepage, it still can not chang the settings for the homepage.

    the new HJT log is attached.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! So uninstall Windows Defender

    For your Symantec AV issue, do the below.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to SymWMI Service ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    SymWSC

    If you receive any error messages just ignore them and continue.

    Now exit HJT and reboot when it tells you it needs to.
    After reboot make sure the below line is no longer in your HJT log:
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

    Also delete the below folder:
    C:\Program Files\Common Files\Symantec Shared\Security Center

    After uninstalling Windows Defender and after removing the Symantec Security Center Service as directed above, try resetting your home page again, but make sure you either disable Spyware Doctor's active protection or that you allow the change to be made if Spyware Doctor intercept's the change.

    Let me know how this goes.
     
  7. shufi

    shufi Private E-2

    hi!

    sorry to say, still homepage hijacked (by "http://v4.windowsupdate.microsoft.com/").
    i uninstalled windows defender & followed your inst. regarding symantec av
    what do i do next??
    and again - t h a n k s
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not a malware problem. Sounds like a configuration issue or your antispyware tools are blocking the change.

    Did you try changing it before or after fixing the Symantec stuff and uninstalling Windows Defender?

    What happens when you try to change it and how are you trying to change it?

    Did you shutdown Spyware Doctor before changing it?
     
  9. shufi

    shufi Private E-2

    i tryed changing after fixing.....

    and, also tryed changing after shutdown of spyware doctor

    i try to change the homepage through control panel/internet options
    it allows me to change, but the change does not actualy take place.
    if i open "internet options" again or if i run the internet explorer the homepage shown is still "http://v4.windowsupdate.microsoft.com/".
    what shoud i do ???

    any other suggestions? i'm realy getting frustrated
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It still does not sound like a malware issue. It still seems more like to be due to software that is running or a restriction place on your user account (possibly a registry setting). Do you get an error message? Does it actually change on the screen when you edit it or does it immediately block the change? What I want to know is when it changes back!!!

    Try this:

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    If the above does not help, then continue on to the below steps!

    Please download ProcessExplorer
    • Unzip it to its own folder somewhere you can locate it.
    • Now run procexp.exe by double clicking on it.
    • Let's configure some options first:
      • Click View and select Show Lower Pane. And where it says "Lower Pane View" make sure DLL's is checked.
      • Now click on iexplore.exe.
      • Now also under the View menu choose "Select columns" and put a check mark on "Image Path".
    • Now click on File and then Save As. And save the process list.
    • Post it back here as an attachment.
    Now run the below procedure and attach the runkeys.txt log.
     
    Last edited: Jun 30, 2006
  11. shufi

    shufi Private E-2

    well,

    first to your questions:
    I do not get an error message.
    as I mentioned before, when i edit the homepage settings, it does change on the screen (at the internet option window), it does not immediately block the change.
    the actual change does not realy take place.
    the next time i open internet explorer or the next time i open internet options (in the control panel), it shows the unwanted homepage again.

    fixme.reg - did not help

    i attach the logs you requested.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have you tried change the home page on other user accounts and does it work?

    Have you tried changing it after booting in safe mode?

    Try using MSconfig to stop the Startups for Spyware Doctor. You nned to disable them under both the Startup and Services tabs. Then reboot and try to change your start page.

    If that does not help, then while Spyware Doctor is still disable do the following:

    Copy the bold text below to notepad. Save it as fixPOL.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Then get a new runkeys.txt log and then try to change your start page. Then attach a new HJT log. If at this point you still have a problem, leave Spyware Doctor disabled otherwise enable it.
     
    Last edited: Jul 1, 2006
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note the reason I asked about the other user accounts is that I'm wondering if something has changed the ownership setting of the Registry key related to your user account's start page. If that has happened, it explains why nothing is working. We will have to use a special procedure to try and fix it in this case. Basically we need to have your user account take ownership of the registry key again and then make the change.
     
  14. shufi

    shufi Private E-2

    hi,

    when i change the homepage settings in safe mode.
    it works !!
    after i boot back to normal mode, the homepage i specified stays but again i can not chang it.

    there is only one user account

    i tried to disable spyware doctor as you suggested, it does not help.

    i didn't merge fixPOL.reg to the registry yet, i didn't understand the need for these changes.

    what do you think i should do now? to merge the fixPOL.reg or anything else??
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good! I had a mistake in that registry patch anyway which I just fixed. So if you already downloaded it, download it now and overwrite the previous one. These changes are an attempt to change a potential system policy that is blocking you from changing your home page. Run the patch now.
     
  16. shufi

    shufi Private E-2

    ok!
    where is the fixed patch?
    did you overwrite the previous one (message #12)?
     
  17. shufi

    shufi Private E-2

    at last !!!

    while waiting for your response, i continued to try and find the cause for this problem.
    well, i found it.
    the program responsible for the blocking of homepage change was zone alarm latest version - 6.5.722.000.
    i disabled zone alarm and the problem was solved.
    so, i uninstalled za and reinstalled an older version - 6.1.744.001.
    now i can change the homepage.

    thank you very much for your help and support,
    i'd love hearing comments from you about this.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have not used the most current versions of ZoneAlarm yet so I'm not familiar with this. But remember I did say multiple times that your problem was more than likely not malware but rather a setting somewhere. I'm sure that ZoneAlarm has a setting in it someplace where you can choose to enable or disable the feature of locking your home page.

    Is this just the firewall or is it their security suite, or is it the firewall + antispyware?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds