IE has been hijacked

Discussion in 'Malware Help (A Specialist Will Reply)' started by jonwite, Nov 18, 2005.

  1. jonwite

    jonwite Private E-2

    My system seems to have been hijacked : My home page is set to msn.com but this page from adobe,
    http://www.adobe.com/?lang=en-us&linkentry=tour, is what comes up.

    I have gone through the steps in the "Read Me Process 10-09-05", which did find and delete a number of problems, but nothing has given me back my home page yet. (For instance CCleaner removed 28 objects, Spybot removed 3 problems, CW Shredder removed 1 file).

    I ran the Hijack This! log (I followed the steps on the Hijack This! install page) through the three analyzer pages as suggested but still have been unable to remove the Adobe page.
    I have also followed the steps in the "How to protect your system from malware" article to avoid future infections.

    My system:
    OS Name Microsoft Windows XP Professional
    Version 5.1.2600 Service Pack 2 Build 2600
    OS Manufacturer Microsoft Corporation
    System Name ROC
    System Manufacturer MICRO-STAR INC.
    System Model MS-6728
    System Type X86-based PC
    Processor x86 Family 15 Model 2 Stepping 9 GenuineIntel ~2400 Mhz
    BIOS Version/Date American Megatrends Inc. V3.3, 12/10/2003
    SMBIOS Version 2.3
    Windows Directory C:\WINDOWS
    System Directory C:\WINDOWS\system32
    Boot Device \Device\HarddiskVolume1
    Locale United States
    Hardware Abstraction Layer Version = "5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)"
    User Name ROC\John
    Time Zone Pacific Standard Time
    Total Physical Memory 512.00 MB
    Available Physical Memory 158.89 MB
    Total Virtual Memory 2.00 GB
    Available Virtual Memory 1.96 GB
    Page File Space 1.22 GB
    Page File C:\pagefile.sys
    Drive A:
    Description 3 1/2 Inch Floppy Drive

    Drive C:
    Description Local Fixed Disk
    Compressed No
    File System NTFS
    Size 153.38 GB (164,694,745,088 bytes)
    Free Space 101.19 GB (108,654,272,512 bytes)
    Volume Name BigGig
    Volume Serial Number B498E733

    Drive D:
    Description CD-ROM Disc

    Drive E:
    Description CD-ROM Disc
    Description Disk drive
    Manufacturer (Standard disk drives)
    Model HDS722516VLAT80
    Bytes/Sector 512
    Media Loaded Yes
    Media Type Fixed hard disk media
    Partitions 1
    SCSI Bus 0
    SCSI Logical Unit 0
    SCSI Port 0
    SCSI Target ID 0
    Sectors/Track 63
    Size 153.38 GB (164,694,781,440 bytes)
    Total Cylinders 20,023
    Total Sectors 321,669,495
    Total Tracks 5,105,865
    Tracks/Cylinder 255
    Partition Disk #0, Partition #0
    Partition Size 153.38 GB (164,694,749,184 bytes)
    Partition Starting Offset 32,256 bytes

    Any help in resolving this will be greatly appreciated.

    Thanks,

    John
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. jonwite

    jonwite Private E-2

    OK, I set up and ran HJT as requested. Log is attached
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I see no problems! Which browser is your problem occurring with?

    Try the below:


    Now we need to Reset Web Settings ( Make sure you leave www.majorgeeks.com as your start page for now. ):
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    No post a new HJT log an let me know if you go to Majorgeeks when you click to goto your Home page.
     
  5. jonwite

    jonwite Private E-2

    Hi,

    I am having problems with IE.

    I have been using a quick launch button, and its properties, target, showed the adobe website. I deleted that portion of the target and I now go to msn.com.
    I went thru the steps as you requested.

    I have tried to set the home page to majorgeeks.com many times using both internet options and internet tools and it appears to change but always comes back to msn.com when I restart IE.

    Very frustrating!

    I have attached the HJT log that I just ran.

    Thanks again for your help.

    John
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's probably because some software you have installed (like CounterSpy or McAfee) is locking your settings and not allowing any changes. Most programs like this normally popup and warn you about a change trying to be made and ask for your approval. If you do not approve the change, it reverts back to the previous settting.

    If you are not having any malware issues, I would not be concerned with this because it is standard operating procedure.
     
  7. jonwite

    jonwite Private E-2

    Thanks, you have been very helpful! :)
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds