hijacked homepage

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by empty_pockets, Aug 1, 2004.

  1. empty_pockets

    empty_pockets Private First Class

    I hope someone can help me with this problem. Seems I've been bitten by a hijacked homepage. I always use a blank hompage and now there's a search page with an annoying popup that wants me to buy spyware removal software. I followed the instructions in Major Attitude's recommendations on Basic Spyware Removal & Hijack This Tutorial. (Went to Safe Mode, ran AVG--no viruses, ran AdAware--no problems, ran Spybot--no problems, and ran AboutBuster as per their homepage instructions. The darn search page with popup is still with me.

    I then turned off all processes in ctrl-alt-del except explorer and systray, turned off all icons in systray, as well as ZoneAlarm, and AVG; then ran Hijack This. I don't know what to do now to get rid of this search page and get back to about:blank page.

    I've attached my Hijack This log. Thanks in advance for ANY help you can give me to try to get rid of this.
     

    Attached Files:

  2. NeoNemesis

    NeoNemesis Moutharrhea

    These are lines I'm seeing...

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\TEMP\sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\WINDOWS\TEMP\sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\WINDOWS\TEMP\sp.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\TEMP\sp.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\WINDOWS\TEMP\sp.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\WINDOWS\TEMP\sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
     
  3. empty_pockets

    empty_pockets Private First Class

    Me too, but what do I do about them? I have Hijack This fix them, then run Hijack This again after a reboot and they're back in there again. Any ideas?
     
  4. NeoNemesis

    NeoNemesis Moutharrhea

    Do it in safe mode.
     
  5. shyni_diamz

    shyni_diamz Private E-2


    Wow...i dunno about this...

    good luck!
     
  6. empty_pockets

    empty_pockets Private First Class

    Thanks. I've already done that.
     
  7. NeoNemesis

    NeoNemesis Moutharrhea

    Are you sure you followed all directions in the about:blank removal thingy? Cuse that should have done it.
     
  8. empty_pockets

    empty_pockets Private First Class

    I followed them to the letter. It's got me stumped too.
     
  9. NeoNemesis

    NeoNemesis Moutharrhea

    Whats?

    O2 - BHO: (no name) - {AD649E11-A443-4F8C-B9C7-5DAB66879BDA} - C:\WINDOWS\SYSTEM\JNNO.DLL

    oh and make sure you are doing this and closing all internet explorer windows
     
  10. empty_pockets

    empty_pockets Private First Class

    Don't know. That's why I'm in this forum. I'm not an expert and don't understand what I should do about this, but I've ckd that line while in Safe Mode and it reappears when I run Hijack This again after rebooting.
     
  11. NeoNemesis

    NeoNemesis Moutharrhea

    I just didn't know if you know like a program that might have that name or something.
     
  12. empty_pockets

    empty_pockets Private First Class

    I don't recognize it as being anything I have installed on my pc.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds