IE accesses only certain sites

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jcsturtz, Aug 28, 2004.

  1. jcsturtz

    jcsturtz Private E-2

    Hello:

    I'm having a problem with my web browser (IE) and my computer seems to be running very slow (i.e., loading "my pictures", etc.)

    For some reason, IE will not go to certain sites (e.g., USA Today) but it will go to other site (e.g., Washington Post). When I clicked on my previously bookmarked link, instead of going to the web site, I was being taken to something called "My Way", that looked like a google search page.

    I have been unable to access the Microsoft Website to download SP2. I have read and tried to follow all the recommendations on the READ ME FIRST: Basic Spyware, Trojan and Virius thread.

    Here is my computer specification:

    Dell Pentium III, 975 MHz
    80 GB hard drive
    384 MB RAM
    128 MB Video Card

    Access the internet via cable modem and Road Runner.

    According the READ ME FIRST guideance, here's the result:

    1. Unable to update my copy of Windows... Screen shows the default "Cannont Find Server... This page cannot be displayed..."
    2. Disabled System Restore
    3. Checked for "Network Security Service", not present...
    4. Enabled view of hidden files and extensions...
    5. Tried to access TrendMicro and PandaSoftware but was unable to run the online scan.
    6. Booted in Safe Mode, then
    7. Ran CCleaner
    8. Ran Ad-Aware, with a recent update (day or two old) and then ran the VX2 Plug-in. Nothing came up with Ad-aware or the VX2 plug in. Ran Spybot, and had six DSO items detected. Selected fix, but if I run it again, I seem to get the same DSO items again...
    9. Downloaded and Ran Bugoff, CWShredder, aboutbuster and HSRemove.
    10. Tried to download A2, but I couldn't access the website
    11. Reviewed the thread on the HSA Highjack but it doesn't seem applicable.
    12. Downloaded Hijack This!

    I was told that I should just reformat my hard drive, but I'm hoping there's and easier fix...

    Thanks in advance for your assistance...
     
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Nice job spending the time to try all of our steps.

    Uninstall My Search Bar from "Add/Remove Programs" in the Windows® Control Panel. Look for entries called "My Search Bar", "Search Assistant - My Search" and "My Way Speedbar".

    I would do a scan of your system afterwards with the usual tools to be sure as well as check startup items. If all that works, running Hijack This to check for (hopefully) now obsolete My Way entries would be good.

    Check back with us.
     
  3. jcsturtz

    jcsturtz Private E-2

    I'm sorry that I failed to mention that I had already removed "My Way" using Add/Delete Program. Now, instead of pages being misdirected to My Way, I simply get the "Cannot Find Server, This page cannot be displayed" message.

    After removing My Way, I then found the Major Geeks site and followed the detailed steps in the READ ME FIRST section.

    I've just finished running HiJack This and read the tutorial. Using TonyK and Pacman's list, it looks like almost everthing is ok. There are a few things that didn't come up and some things in the O9 and O18 section that seem fishy.

    I also purchased Spy Sweeper from Best Buy and nothing seems to fix the problme...
     
  4. pegg

    pegg MajorGeek

    I just had something similar happen to me but it didn't seem like a "normal hijack" -- I couldn't get to most IE pages at all (including this one), couldn't download program updates, etc.

    I don't know if this will fix anything but it would be interesting to see what it says: Go into Ad-aware SE Personal (is that what you have?) and click on the "cog" -- top right area, then select "defaults" (left column) and see what the "default home page" and "default search page" are actually set to. Mine were messed up once and then they looked ok but I then went below there and clicked on "Read current settings from system" and it gave me something else.

    Just curious if it tells you anything interesting.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    jc,

    Post your HijackThis log as a .txt file attachment and we will have a look.
     
  6. jcsturtz

    jcsturtz Private E-2

    Here's my most most recent HiJackThis! log... :rolleyes:

    Pegg... I have Ad-aware 6.0, not SE... so I couldn't follow your suggestion...
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You said you followed the READ ME FIRST. If you did, you would be using Ad-aware SE.
    Why didn't you change to the new version?
     
  8. jcsturtz

    jcsturtz Private E-2

    Chaslang:

    I was told that Ad-aware 6.0 and SE were essentially the same thing...
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If they were the same they would not have needed to release a new version. They are much different. The new version even has the ability to scan for ADS (Alternate Data Streams).
    Are you a paid subscriber using Ad-watch?
    If not, switch to Ad-aware SE (make sure you uninstall Ad-aware 6 when prompted).
     
  10. jcsturtz

    jcsturtz Private E-2

    Chaslang:

    I feel that you chastized me inappropriately... The READ ME FIRST guideance, in step 8 (i.e., step two under "Time to Start Scanning...) says to scan using "Ad-aware" not Ad-aware SE...

    In any event, all the other steps have proven fruitless, however running Pest Patrol indicates I have something called CWS.GoolgeMS.3

    As indicated in the READ ME FIRST guideance, I've downloaded and run Hijack This! I've posted my most recent run...

    Any assistance you can provide is appreciated.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are supposed to click on the hot links there. That is why we put them in the tutorial. Click on it and tell me what you get. You do not get Ad-aware! You get the current version of Ad-aware SE. Following the directions is important for you and for the people helping you. We need to know that the proper versions with correct up to date definitions are being run. You would not believe how many times a users swears they are using the current version and that they have clicked the "check for update" buttons and there are no updates. Then when we specifically ask "what version are you running" and they have an old version. That's why there are no updates. The main program is out of date. The same is now true for Ad-aware 6. It no longer has any updates and everyone says, "I am up to date. I clicked update just today". Same goes for SpyBot. We still have people using version 1.2. Also for HijackThis we constantly get people posting logs using v1.97.7 and the correct version is 1.98.2. All they had to do is click on the link in the tutorial they said they read and they would have the correct version. Even you did not follow directions on using HijackThis. Look in your log at these two lines:
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\John Sturtz\Desktop\HijackThis.exe

    You were specifically told in the HJT Tutorial that,

    "All running programs should be closed, including your web browser, email, items in the tray, anything you can close... Close before running Hijack This! Do not to install Hijack This to the Desktop, a temp folder or choose run from the download. Place it in its own folder, for example C:\Program Files\HJT"

    Did you follow directions? Hmmmm? Firefox is a browser and you have HJT on your Desktop!

    So perhaps you may feel like I was chastizing you, but think of what I go thru a 100 times a day having to repeat the same stuff over an over again because many people simply do not take the time to look at the sticky threads. And when they do, they don't follow the instructions anyway. I'm not saying it is everyone. But it is a lot. You have to realize that this gets extremely frustrating for us helpers and we can get grumpy sometimes. But we still continue to provide outstanding help.
     
    Last edited: Sep 2, 2004
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I do not see any problems in you HJT log. Have you checked to see what is in your Internet Explorer, Tools, Security, Restricted Zones. See if any of the sites you are having problems with are listed there. If so, remove them from the list.

    Also, check your hosts file to see if something was inserted there to block the sites. Your hosts file is in c:\windows\system32\drivers\etc\hosts You can quickly bring this up by click Start, run and in the open box enter the following command:
    notepad c:\windows\system32\drivers\etc\hosts

    then click ok.

    The default file should look like the below:
    # Copyright (c) 1993-1999 Microsoft Corp.
    #
    # This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
    #
    # This file contains the mappings of IP addresses to host names. Each
    # entry should be kept on an individual line. The IP address should
    # be placed in the first column followed by the corresponding host name.
    # The IP address and the host name should be separated by at least one
    # space.
    #
    # Additionally, comments (such as these) may be inserted on individual
    # lines or following the machine name denoted by a '#' symbol.
    #
    # For example:
    #
    # 102.54.94.97 rhino.acme.com # source server
    # 38.25.63.10 x.acme.com # x client host
    127.0.0.1 localhost
     
  13. jcsturtz

    jcsturtz Private E-2

    Chaslang:

    Point well made regarding following instructions... I guess that's why I'm just a Private E-2. I thought I was following all the directions explicity, I did close Mozilla before running the Hijack This log by clicking the X on the dialog box...

    Regarding you suggestions:

    1. Under the IE Restricted Zones, there were about 100 sites listed, mostly porn and gambling sites but some web searches also. I removed most of them but every time I clear the list, exit the site and return, the list is repopulated, albeit with fewer items. Now I only seem the have about 20 that continually return and despite repeated attempts to remove them, they continue to return...

    2. I checked the hosts file usign the path you provided and got an identical display as the default file that you listed....

    Are they any other options to explore or should I just reformate my hard drive... :eek:
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Which ones were you removing? I did not want you to remove anything from the restricted zones that should be restricted. If they certain ones are being added back in you should check to see who is adding them back in. Is it PestPatro, NavNT, or SpySweeper? Maybe the ones in there should be restricted. What I was bringing up in my previous message was for you to check the restricted zones to see if any of the sites you want to go to are in there.

    A firewall can case similar issues. Do you have a firewall (hardware or software)? Some routers have firewalls.

    Which browser are you running when you have problems? FireFox or IE? Do they both ave the same problems? If you cannot get a set with IE, did you try it with FireFox? Do they both prevent access to the site?
     
  15. jcsturtz

    jcsturtz Private E-2

    I now understand what you were asking. I was trying to remove all the files listed as restriced but now I understand... No, the web sites I'm unable to access are things like the USA Today, MSNBC, Consumer Reports and of course the Microsoft website to download SP2...

    I do have a firewall enabled. The Tech activeated it when he installed the cable modem.

    I had been using IE when the problems first surfaced. Someone told me to switch to Mozilla to avoid the security loopholes in IE but the damage was already done. Both bowsers give me the same problems regarding access... I can access the same sites with either and I'm unable to connect to the same sites with both...
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to check to see if there is anything setup in your firewall to block those sites.

    So for example you mean if you try to go to:

    http://www.msnbc.msn.com/

    you cannot get there. What do yet get? What is the exact message?

    How about this way:

    http://207.46.150.51

    does that work?

    When did the problem first surface? Had anything new been added to your system (hardware or software)?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds