Hompage resets (to res://...), Pop-ups (eg "Only the Best")

Discussion in 'Malware Help (A Specialist Will Reply)' started by sammerz, Jan 14, 2005.

  1. sammerz

    sammerz Private E-2

    Hi there.... been reading some other threads, especially the one entitled: ""Only The Best" Pop up, mshp.dll homepage default? WTF???"

    Anyway mine's a similar problem, and I believe the admins here prefer if i start a new thread with yet a new problem.

    Some problems encountered (most likely known to many out there):
    - homepage always reset to about:blank or to a page prefixed res://
    - pop-up (most commonly entitled "Only the Best") appears everytime you first open an internet browser, open a new browser, and mostly everytime you enter a new web address
    - AVG seems to keep detecting a new *.exe file (trojan or backdoor) attempting to plant itself within the Windows or Windows/system32 repository

    I understand there are a great many antivirus programs out there... please let me know the best free one and the best (cost-to-effectiveness) professional one... I used to have norton - but their insistence on annual updates has taken it's toll, so i'm staying away from that.

    Moving right along, here's my HiJackThis log, please let me know what I should do. Many thanks in advance.

    -------------------------------------------------------------------------
    Edit by chaslang: Unrequested, inline log deleted
    -------------------------------------------------------------------------

    I believe those with prefix R1, R0, O15 do not belong there... tried "fixing" the O15 ones but they keep coming back.
     
    Last edited by a moderator: Jan 14, 2005
  2. sammerz

    sammerz Private E-2

    by the way, I've also tried Pest Control's online scan... it seems to detect a great deal more than AVG, furthermore it found some CWS (the annoying coolwebsearch spyware) files which the CWSshredder fails to find... any recommendations?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have more problems than "Only the Best" aka HSA hijack that must be fixed. But you first must follow forum guidelines. Do not post HJT logs unless we ask for them and do not post them inline.

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal
    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.


    After doing ALL of the above if you still have a problem:

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT

    You also need to do the below:

    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file move.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.)

    Double-click on the move.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to merge say yes.
     
    Last edited: Jan 14, 2005
  4. sammerz

    sammerz Private E-2

    thankyou for that chaslang... sincerest apologies for not following the thread guidelines. I'm currently cleaning the computer now... but i've encountered a problem: i cannot seem to install ccleaner. After going through the "Install to:" directories, and saying yes to "Add Desktop icon" etc, the pre-install program quits before the actual installation. Any idea why?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! I'm not sure what's happening! Are the other programs installing okay?
    Skip CCleaner for now. In place of using it, click Start, Run and enter cleanmgr and click OK! It may take a minute or so but a window will pop up after it does some disk checking. When it does popup, make sure there are check marks on the following items only:
    - Temporary Internet Files
    - Recycle Bin
    - Temporary Files

    Then click OK and let it clean.

    Then continue the rest of the steps of the READ ME.
     
  6. sammerz

    sammerz Private E-2

    After the initial run through threads 35407 and 38772 the "Only the Best" pop-up still persevered, as well as AVG continues to report an exe that keeps finding its way to the windows/ or windows/system32 folder.

    After a second run through there are no problems. None for three days.

    Many thanks to chaslang and Major Attitude for their help.

    If any problems persist will call again (but unlikely by the looks of it).

    Thanking you again

    Regards,

    Sam.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds