Hijacked Homepage

Discussion in 'Malware Help (A Specialist Will Reply)' started by IceMaiden, Jan 24, 2010.

  1. IceMaiden

    IceMaiden Private E-2

    I was able to run all of the tutorial scans you suggested. Malware Bytes found a registry key infected with a home page hijacker. I don't know if it is fixed or not. My original home page was www.yahoo.com. Then it began showing up as m.www.yahoo.com. I thought this was something that yahoo was changing to. But now it has changed several times to a different yahoo page that says it is one for a mobile device unit. I originally ran the tutorial scans because my mother who shares a printer with me picked up a fake-alert trojan. In looking at the hijack-this log it looked like there might be a lot of things that shouldn't be there. Thank you for your help. :)
     

    Attached Files:

  2. IceMaiden

    IceMaiden Private E-2

    Re: Hijacked Homepage, 2nd attachment

    Hi, I ran my tutorial yesterday and didn't find the "don't run Combo-Fix or attach logs until I had already posted. I have attached my log for MG Tools. but I didn't know how to attach it from MGTools.exe. Please advise if I didn't do it correctly. thank you
     

    Attached Files:

  3. evilfantasy

    evilfantasy Malware Fighter

    Hello IceMaiden.

    Download Disable/Remove Windows Messenger to the desktop to remove Windows Messenger.

    Do not confuse Windows Messenger with MSN Messenger or Windows Live Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Unzip the file on the desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.

    Exit out of MessengerDisable then delete the two files that were put on the desktop.



    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX Checked until you exit all browser sessions including the one you are reading in right now:

    • R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.m.yahoo.com <- You will likely need to reset your Homepage to Yahoo.com by removing this. If you want to keep the m.yahoo homepage then don't place a check mark next to it.

    • R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    • R3 - URLSearchHook: (no name) - *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    • O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - (no file)
    After clicking Fix checked, exit HijackThis.



    You need to update your Java. Updating Sun Java


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Go to the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work through the below link:
     
  4. IceMaiden

    IceMaiden Private E-2

    thank you so much for your help, Evilfantasy. I did everything you said to do. I only had a problem with uninstalling ComboFix and I thought I did it all as suggested. On another computer it uninstalled quickly and told me it was uninstalled. On mine, it
    said I needed to disable AVG and it acted like it was installing rather than uninstalling. I ignored the command to disable AVG mainly because I don't know how to do it and went on to next. After this the logo on desktop disappeared. So, I don't know that it is entirely gone. :(
    Ice Maiden
     
  5. evilfantasy

    evilfantasy Malware Fighter

    Restart the computer and see if the desktop comes back.
     
  6. IceMaiden

    IceMaiden Private E-2

    HI, I'm sorry, if I wasn't clear in my post. The desktop didn't disappear, the icon for Combo-Fix disappeared but it never told me that it was uninstalled like it did on another computer. I was afriad that it was still in there somewhere and I didn't want to leave it since there has been so much trouble lately with Combo-Fix. Thank you.
     
  7. evilfantasy

    evilfantasy Malware Fighter

    That's not a problem. Running the other steps would have removed ComboFix also.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds