I also have a highjacked home page !!!!!!!!!!!!!!!

  • Thread starter Thread starter Guest
  • Start date Start date
Hi youngy :-)

You have a hijacker, malware, spyware or parasites on your system causing
this problem. Thus, in addition to running your updated anti-virus program,
you should do the following to be sure none of these are present on your
system. Although you may have already run one or more of the programs,
please do so again according to the instructions below. Some variants of
malware can replicate themselves over and over if not removed properly.
Please follow all instructions carefully to be sure your system is
thoroughly cleaned:

Dealing with Unwanted Spyware and Parasites:
http://mvps.org/winhelp2002/unwanted.htm
Be sure to run CWShredder, Ad-aware and Spybot.
If these steps do not resolve your problem, please post back to this thread
with the details and any error messages.
(or Spybot - Search and Destroy DSO Exploit Fix 1.3.1 TX)
http://www.majorgeeks.com/download4392.html
Also be sure to use the HijackThis. Please do not post your log to this
newsgroup, but to the HiJackThis Support Forum
http://www.hijackthis.de/forum/forumdisplay.php?f=10&guestlanguageid=4
or the Aumha HiJackThis forums
http://forum.aumha.org/viewforum.php?f=30
to allow the experts there to evaluate your log and advise you of the
necessary steps to clean your system.

Also this program searches for hidden .dlls that recreate the malware.
About Buster:
http://www.majorgeeks.com/download4289.html

CAUTION!!!!! Before you try to remove spyware using any of the programs
below, download a copy of LSPFIX from any of the following sites:
http://www.cexx.org/lspfix.htm
http://www.spychecker.com/program/winsockxpfix.html
(if your OS is Win2k or XP) The process of removing certain malware may kill
your internet connection. If this should occur, this program, LSPFIX, will
enable you to regain your connection.

Also, get a copy of WINSOCKXPFIX available at:
http://www.spychecker.com/program/winsockxpfix.html
and
WinsockXP Fix- WinXP
http://www.spychecker.com/program/winsockxpfix.html
Also, with instructions, at
http://www.iup.edu/house/resnet/winfix.shtm
also
From LavaSoft- all versions of Windows-
http://digital-solutions.co.uk/lavasoft/whndnfix.zip
also ....
(NOTE: It is reported that in XP SP2, the command netsh winsock reset
will fix this problem without the need for these programs.)

or ........

Winsock Fix Utility
http://www.dfwonline.net/files/WinsockFix.zip

Also.........

Courtesy of Jim Byrd -

Download Sysclean.com, from Trend Micro, here:
http://www.trendmicro.com/download/dcs.asp along with the latest pattern
file, here:
http://www.trendmicro.com/download/pattern.asp
Be sure to read the "How-to" info here:
http://www.trendmicro.com/ftp/products/tsc/readme.txt
You might also want to get Art's updater, SYS-UP.Zip, here for future
updating of these: http://home.epix.net/~artnpeg/.
(If you download and use the updater from the beginning, it will
automatically handle downloading the other files. Place them in a dedicated
folder after appropriate unzipping, and then run. This scan may take a long
time, as Sysclean is VERY extensive and thorough

and......

NOTE: If you can not download these programs from the Internet, if your PC
has CD read capabilities, go to another computer with CD-ROM burning
capabilities. Create a folder on the hard drive of the other computer called
HOLD, download the programs to that folder, then burn that folder to a CD.
Copy the HOLD folder to your HD and then install the programs from there
and run them. After you have IE access again, update all programs where
possible to get the latest definitions and run them again in Safe Mode to be
sure there are no lingering items on the system.

also...........

Additional information on how to protect your PC:
The Parasite Fight http://www.aumha.org/a/quickfix.htm
More security tips at http://www.aumha.org/a/parasite.htm
Bugs, Glitches & Stuffups: http://www.mvps.org/inetexplorer/Darnit.htm


If these steps do not resolve your problem, please post back to this thread
with the details and any error messages.

Hope this helps

Jan :)
Smiles are meant to be shared,
that's why they're so contagious.

Please reply to the newsgroup so others may benefit.
Replies are posted only to the newsgroup for the benefit or other readers.

How to make a good newsgroup post:
http://www.dts-l.org/goodpost.htm
 
Please help !!!!....I too have apparently been hijacked. I have run the ad
aware, sysclean, spybot S&D, along with McAffee but I cannot reset my home
page, either in the control panel options or in the IE browswer options
window. It has the same looking "dll"...mine reads
"res://C:\WINDOWS\system32\shdocpe.dll/security.htm". If I try to load a
url from the naviagation bar, it apparently redirects me with a response
like..."http:///?0/020yahoo.com"...(the 0/0 is the percent symbol, but I cant
seem to get that to operate either...).

Is there any way back home?

Thanks in advance,
(e-mail address removed)
 
This has been a FAQ on this newsgroup. See this site for possible help and
more information:
http://inetexplorer.mvps.org/answers.htm#home_page

This may be caused by spyware/malware that's gotten installed on
your system. Use Ad-Aware and/or Spybot Search & Destroy to remove it.

Ad-Aware: http://www.lavasoftusa.com/
Spybot: http://www.safer-networking.org/en/index.html
Good sites on how to install and use Spybot -
http://www.safer-networking.org/en/tutorial/index.html
http://tomcoyote.com/SPYBOT/index1.php

Also download a winsock repair tool, to have just in case cleaning up
anything found breaks it -

Winsock repair tools:
LSPFix- all versions of Windows http://www.cexx.org/lspfix.zip
Winsock2 Fix- Win98, ME
http://www.bu.edu/pcsc/internetaccess/winsock2fix.html
LavaSoft- all versions of Windows-
http://digital-solutions.co.uk/lavasoft/whndnfix.zip

More information here:
http://www.spywareinfo.com/
http://inetexplorer.mvps.org/Darnit.htm
http://www.doxdesk.com/parasite/ - runs a little script when loading page to
check for common parasites

If no joy, in IE go to Tools...Internet Options...Advanced tab, Browsing
section, uncheck "Enable third-party browser extensions", click Apply, click
Okay, reboot. If that solves your problem, then more troubleshooting is
needed to find out exactly which program, or Browser Helper Object (BHO) is
causing this problem. You don't want to leave it at that, as some BHOs are
useful or necessary - like Adobe Acrobat for reading .pdf files or an
essential component of Norton AV. Get BHODemon -
http://www.definitivesolutions.com/bhodemon.htm - read all about BHOs.
Disable all items, and then gradually replace one or two at a time to narrow
down the culprit.

Or if you have IE 6 SP-2 you can do this within the browser:
How to manage Internet Explorer add-ons in Windows XP Service Pack 2
http://support.microsoft.com/default.aspx?scid=kb;en-us;883256

If all the above fails, then the problem could be something new that the
spyware cleaners above don't have in their databases yet. In that case....
HijackThis direct download:
http://www.spywareinfo.com/~merijn/files/hijackthis.zip
Tutorial on how to use HijackThis:
http://www.spywareinfo.com/~merijn/htlogtutorial.html
Then post it's output log to the forum here for analysis and feedback by the
parasite experts:
http://www.spywareinfo.com/forums/
Or the other HijackThis Logs forums listed here:
http://www.spywareinfo.com/~merijn/forums.html

Or try this program to get some of the most nasty malware:
CWShredder direct download:
http://aumha.org/downloads/cwshredder.zip

An alternate resource for all of this and more:
http://www.aumha.org/secure.htm

You may also want to check out StartPage Guard -
http://pjwalczak.com/spguard/index.php
StartPage Guard protects your PC from cyberscam, by monitoring status of
your internet browser StartPage and preventing it from any unauthorized
changes.

And to keep from having to manually edit the registry to unlock your
homepage settings, try this little script by Doug Knox, MS MVP:
http://www.dougknox.com/security/scripts_desc/nosethomepage.htm

More information here: http://www.cexx.org/hphijack.htm
 
Back
Top