Reinstalling itself

Discussion in 'Malware Help (A Specialist Will Reply)' started by copperman, Apr 27, 2005.

  1. copperman

    copperman Private E-2

    Problem: when I launch MSIE I get a strange page with search bar. If I click my Home icon it will go to my homepage. This only happens on LAUNCH of MSIE. If I change my homepage in options it's ok.

    Intervention: Ad-aware and spybot find something linked to a cookie which is my homepage. I can delete said files but when I reboot my computer and launch MSIE there is a brief pause and the same bogus search page shows up again. I have done this while turning off the restore setting. McAfee, Symantec, MS antispyware, Avert stinger all say nothing is there. But Ad-aware and spybot will find this.

    Writing this post to see if I need to run Hijack This. I understand it is for advanced users. I do want to try everything first but it seems this bug keeps reinstalling itself upon the initial launch of windows and attaches itself to my homepage address.

    Specs: Windows XP with NTFS formatting, running McAfee Security Center with firewall and Privacy setting on. MSIE version 6 with 128bit encryption

    Thanks. Please let me know if it's time for Hijack This or after my description there is something more I can do.
     
    Last edited: Apr 27, 2005
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the steps below.

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus RemovalMake sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. copperman

    copperman Private E-2

    Please find attached Hijack This log file. The first line says something about excite.com which is my homepage that is having trouble loading when first launching MSIE.

    Thanks.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please install HijackThis properly. You have it where requested not to put it.

    C:\Documents and Settings\Jeffrey Lewis\My Documents\My received files\Hijack This\HijackThis.exe
     
  5. copperman

    copperman Private E-2

    Sorry, try this time. I created a folder under C:/program files/HJT
     

    Attached Files:

    Last edited: Apr 27, 2005
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Remember to exit all browsers ( C:\Program Files\Internet Explorer\iexplore.exe ) before running HijackThis.


    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: IE SP2 AddOn - {4E8F37A5-6C1D-4768-8C32-4607B98C8883} - C:\WINDOWS\System32\spwma.dll

    Nothing belongs in the Trusted Zone unless you cannot get something to work (that you need) with out putting in the TZ entry.
    O15 - Trusted Zone: http://www.apple.com

    If you do not recognize the below items, fix them too.
    O16 - DPF: {00C7C2A0-8B82-11D1-8B57-00A0C98CD92B} (ActiveReports Viewer) - https://www.unet.unos.org/Reports/arviewer.cab
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z.net/content.info.apple.com/iTunes4/WW/win/019-0312.20050111.MmVrT/iTunesSetup.exe
    O16 - DPF: {5AA5A569-F96F-4628-A528-8B3698F558BB} (HS_live Control) - http://install.homestead.com/~site/InstallFiles/SIFiles/lpxlive/HS_live.cab
    O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} (Install Class) - http://updates.lifescapeinc.com/installers/pinstall/pinstall.cab

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\spwma.dll

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  7. copperman

    copperman Private E-2

    I checked the first one and turned off system restore. Then rebooted. Now the MSIE launches normally. No more bogus search bar.

    Thank you for you assistance. Sites and support like this are greatly appreciated.

    Now if I could just find a monitor that would stay in focus.....
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds