|
|
|||||||||
|
|||||||||
| |||||||||
|
|
|
| |||||||||
![]() |
|
|
«
Previous Thread
|
Next Thread
»
|
Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
|
|
Get inside! Sample the range of functionality easily built with JMSL Library for Time Series Data Analysis, Heat Maps, Portfolio Optimization, Monte Carlo Simulation, Stock Price Charting and more. Download Now! |
|
#1
|
|||
|
|||
|
Still having problems with hijacked homepage. Just tried Spybot Search and Destroy.
I'm still having the same old problem. I downloaded Spybot Search & Destroy. The detection was fantastic! After removing the unwanted files......and after re-booting.......the same problem occured. My homepage was again "http://up-search.com/search.html". I really need help now. Please.....Help me.......
|
|
#2
|
|||
|
|||
|
Try using Spy Sweeper <a href="http://www.webroot.com/wb/products/spysweeper/index.php">LINK</a> ...
Not sure what else to do besides that ... Perhaps Norton 2004? |
|
#3
|
|||
|
|||
|
Spy Sweeper
Quote:
Thanks for the help rave41779. My PC is clean and all the unwanted stuff is cleared. My Homepage is not hijacked anymore. Thanks a million times!!! |
|
#4
|
|||
|
|||
|
Hijacked - use Spybot in advanced mode
I have had some sucess using Spybot in advanced mode, go to "tools", then to "browser pages", then change any search.com pages back to your own home page address. Doing this every time you boot up suppresses the problem temporarily - maybe for a week or so, but does not eliminate it.
|
|
#5
|
|||
|
|||
|
hijacker
This has workrd for me with 3 different hijackers. Copy the address of the hijacker. Do a 'search' on that address. A list of 'hits' will come up and in that list is someone who will provide you with the tools necessary to get rid of them - permanently.
|
|
#6
|
|||
|
|||
|
You downloaded Spybot Search & Destroy 1.3? The latest version available. Using Spybot itself is not enough. I have a total of 7 spyware removal tools. Add me at dreamcatcherx@hotmail.com or send me an email and I'll give ya some advice
![]() |
|
#7
|
|||
|
|||
|
Quote:
Thanks iceattitude. So far, after installing Spy Sweeper, all my dirty things were cleared. I only depend now on SpySweeper, SpyBot Search and Destroy 1.3. I don't have Norton or McAfee. I use EZ Antivirus and Firwall for protection. Is this ok? |
|
#8
|
|||
|
|||
|
Spybot software gets rid off most of it but CWShredder resolves the rest and stops the home page reverting back to about:blank etc each time. I downloaded it for free just by doing a search in Google for "about:blank" and "CWShredder".
Hope that helps if anyone has the same problem. Matt |
|
#9
|
|||
|
|||
|
Help with my HijackThis log
Logfile of HijackThis v1.98.2
Scan saved at 3:28:55 PM, on 9/30/2004 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\PROGRA~1\McAfee.com\Agent\mcupdui.exe C:\Windows\Explorer.EXE C:\PROGRA~1\NavNT\vptray.exe C:\Program Files\QuickTime\qttask.exe C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe c:\progra~1\mcafee.com\vso\mcvsescn.exe C:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\Windows\system32\javasg.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Symantec\ACT\SideACT.exe c:\progra~1\mcafee.com\vso\mcvsftsn.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Kevin\Desktop\HijackThis19802.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\Windows\eobvm.dll/sp.html#37049 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\Windows\eobvm.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\Windows\eobvm.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\Windows\eobvm.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\Windows\eobvm.dll/sp.html#37049 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\Windows\eobvm.dll/sp.html#37049 R3 - Default URLSearchHook is missing O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {16A47DFB-0B7B-6D1B-05B7-210FEB83CF1C} - C:\Windows\appck32.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\NavNT\vptray.exe O4 - HKLM\..\Run: [Uninstall0001] "C:\Program Files\Common Files\Totem Shared\Uninstall0001\upd.exe" LASTCALL!adverts.stripsaver.com!StatsStripSaver O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [msxc.exe] C:\Windows\system32\msxc.exe O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe O4 - HKLM\..\Run: [atlyj32.exe] C:\Windows\system32\atlyj32.exe O4 - HKLM\..\Run: [javasg.exe] C:\Windows\system32\javasg.exe O4 - HKLM\..\Run: [CleanUp] C:\PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3 /cleanup O4 - HKLM\..\RunOnce: [mcvsescn.exe] c:\PROGRA~1\mcafee.com\vso\mcvsescn.exe -regserver O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: SideACT!.lnk = C:\Program Files\Symantec\ACT\SideACT.exe O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O16 - DPF: High Stakes Pool by pogo - http://pool2.pogo.com/applet-5.8.1.28/pool2/pool-ob-assets.cab O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt1_x.cab O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://i.a.cnn.net/cnn/resources/cult3d/cult.cab O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/15d4435426d1902b8e14/netzip/RdxIE601.cab O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = CIRS O17 - HKLM\Software\..\Telephony: DomainName = CIRS O17 - HKLM\System\CCS\Services\Tcpip\..\{083D0317-6012-41CC-9E8A-76226D016ACC}: NameServer = 192.168.0.3 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = CIRS O17 - HKLM\System\CS1\Services\Tcpip\..\{083D0317-6012-41CC-9E8A-76226D016ACC}: NameServer = 192.168.0.3 O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = CIRS O17 - HKLM\System\CS2\Services\Tcpip\..\{083D0317-6012-41CC-9E8A-76226D016ACC}: NameServer = 192.168.0.3 |
|
#10
|
|||
|
|||
|
How about those annoying MICROSOFT HIJACKINGS
Does anyone know how to never get any Microsoft Hijackings that send it to their site for some info or crap like that. I know everyone has gotten hijacked by Microsoft to make it the homepage. What is weird about it is that when I check my internet options my homepage was not changed. THey are some tricky basta*d over there at Microsoft. Please help me take control from the GIANT.Thanks ![]() |
![]() |
| Viewing: Dev Shed Forums > System Administration > Antivirus Protection > Still having problems with hijacked homepage. Just tried Spybot Search and Destroy. |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|
|
|