Unsolved

This post is more than 5 years old

2 Posts

13163

December 29th, 2003 23:00

HIjacked Homepage

I'm not sure if I'm posting this question in the right place, so I apologize if I'm not.  I recently had my Internet Explorer homepage "hijacked".  Apparently this is a result of some kind of spyware having been installed on my computer, but nobody has been able to tell me how to get rid of it.  I've tried commercial spyware blocker/sweepers, but nothing has worked. 

Not only did I lose my preferred homepage, but I lost the ability to change it.  When I go to Tools / Internet Options, I get the usual window, WITHOUT the "General" tab.  This is the tab that allows you to set your home page, clear your cache, etc.  Does anyone have any insight for me?  It will be greatly appreciated.  Thanks in advance for your help.

453 Posts

December 30th, 2003 00:00

This should get rid of it.

CoolWebShredder

342 Posts

December 30th, 2003 00:00

Did you try AdAware?

2 Intern

 • 

2K Posts

December 30th, 2003 01:00

Use Regedit to navigate to HKEY
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel
& set  Homepage   to   0
 
As visiting a site probably also set an Auto Startup program to set Homepage use FREE programs below ,
to find & Delete program.
--------------------
You can get FREE program called Startup Control Panel to List Auto Startup Folders & HKEY's &  Add / Remove Auto Startup programs from;
http://www.mlin.net/StartupCPL.shtml
 
After install  use Control Panel switch to Classic View & select "Program" , you can also create Desktop shortcut by right click on Control Panel "Program".
To Temp remove , remove tick & doesn't give Startup message like MSCONFIG.
Is provides a more permanent Delete than MSCONFIG.
---------------------

You can  also get FREE program called Spybot from;
http://spybot.eon.net.au/
If you install with Blind Icons you also get extra Immunize Options
"Lock IE Home Page"
"Lock Hosts file"
"Lock use of Internet Options from IE" > Tools > Internet Options
 
Use Update 1st before Immunize or Check for Problems.
 
*** Also has other Tools , like Edit of Auto Startup Programs.
Select "Tools" , "System startup " , click on a program & remove tick for Temp removal ,
or click on "Delete" button at the top for permanent removal. ***

2 Posts

December 30th, 2003 11:00

First of all, thanks for the replies.  I have tried Adaware and Spybot, but neither have corrected the problem to date.  I tried updating Spybot and running it again this morning, but that didn't do the trick either.  I guess I'll try the coolwebshredder today and see how that goes.  Any ideas as to what I can do next if that doesn't work?  Dell recommended going out and spending $45 on their anti-spyware software, but I can't see how theirs would be any more effective than these free options.  Thanks again.

2 Intern

 • 

3.9K Posts

December 30th, 2003 12:00

My post as below is pegged in the virus board at dell, post a hijackthis log, before doing a cwshredder, that only targets one type of of malware.
----------------------------
Use these to remove Malware (Spyware and Adware).

1) SpyBot Search and Destroy
After installing SpyBot Search & Destroy, first press Online, and search for, put a check mark at, and install all updates.
Next, close all Internet Explorer windows, hit 'Check for Problems', and have SpyBot remove all it finds.

2) Get Ad-Aware
After installing Ad-Aware, and before running the program, first press “check for updates now".
Click "Connect" and install all updated components available. Click 'Finish'.
Press "Scan Now", then 'next', and let Ad-Aware scan your drives.
It will find a number of "bad" files and registry keys. Click 'Next' again.
Check all found items, and click 'next' once more.
It will ask you whether you'd like to remove all checked items. Click OK.

Always reboot the computer between each program - both of these may find things that they need to have a reboot of the machine to clear - please reboot and let them finish .

Failing those solving your problems a post of a hijackthis log for the experts to advise.
HijackThis From Here
Download, run, scan, save log, then in notepad copy the FULL log by copy and paste as a reply to this post and an expert with HijackThis Knowldge, will have a go at giving advice. Please note the list of experts names below, very few forum regulars here have had this training.

DO NOT FIX ANYTHING WITH HIJACKTHIS WITHOUT EXPERT ADVICE
, most of what it finds you need for normal MS Windows tasks.

Known Spyware HijackThis fighters in DellTalk - If you are, and are not on the list please PM Me.
ChrisRLG (Expert in Training LOL)
YoKenny (Accredited Expert at TomCoyotes)
baskar1234 (Teaching Assistant at TomCoyotes)
TomCoyote (of http://tomcoyote.org/forums/index.php)

You could also go to one of the more specalist forums where more experts will be able to help.
http://tomcoyote.org/forums/index.php
http://forums.spywareinfo.com/index.php
http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi (Home of Spybot S&D)
http://boards.cexx.org/index.php
Do read the sites FAQ before posting, and advise your problem and what steps you have already done to try to cure your problem.

I, and the other hijack experts mentioned above, are in all those sites (and more) with the same login names. You might get one of us at those sites also to anwser your log, but other experts will also be available.

1 Rookie

 • 

25 Posts

December 30th, 2003 15:00

Try looking through your Add/Remove Programmes, you might find it there. I've found hotbar and a couple of others sometimes sneak in on me.  Also, see if you can find their website, they may have a 'how to uninstall' faq.

2 Intern

 • 

2K Posts

December 30th, 2003 20:00


@gryjhnhpe wrote:
Use Regedit to navigate to HKEY
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel
& set  Homepage   to   ...........(0)
 
As visiting a site probably also set an Auto Startup program to set Homepage use FREE programs below ,
to find & Delete program.

Has you tried the above .?
If you can't navigate to HKEY just press Windows+R keys together then type
regedit   , press Enter or click OK.
Click "Edit" > "Find..."  , type    homepage
tick all boxes "Look at"  &  "Match whole string only" box.
Click "Find Next" .
Then double click on  Homepage   &  type  "Value data"  of    0 .
 


 

Message Edited by gryjhnhpe on 12-31-2003 09:27 AM

1 Message

February 3rd, 2004 21:00

I have been fighting this same issue for 2 months and nothing worked until I registered and logged on to this forum. I downloaded spyware and Cool Web Shredder and they both worked to locate and resolve my issues. Thanks for your posts. I'm glad I finally logged on to this forum. "Free at last!"

July 7th, 2004 13:00

Hi there

Please help!

Have had my homepage hijacked and have used all the recommended clean up programmes (spybot, adaware, spyware blaster, startpage guard, CWS) but to no avail.  They all clean up well but the computer seems to get re infested quite easily and quickly.  So now have followed instructions with hijack this and below is the resultsand would really appreciate your knowledge on what to get rid of as this is my last hope!

Many thanks!!

Steve.

 

Logfile of HijackThis v1.97.7
Scan saved at 14:49:26, on 07/07/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\mfcmm.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\System32\dslagent.exe
C:\WINDOWS\system32\crgt.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\System32\gsicon.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\BT Broadband\Help\bin\mpbtn.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\helpctr.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Steve Fuller\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\cdfgn.dll/sp.html#35759
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://cdfgn.dll/index.html#35759
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://cdfgn.dll/index.html#35759
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\cdfgn.dll/sp.html#35759
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://cdfgn.dll/index.html#35759
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\cdfgn.dll/sp.html#35759
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = NOT USED (OK)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7656789A-ED76-CC21-B379-9B8792A5DDF6} - C:\WINDOWS\system32\sdkog32.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM32\MSDXM.OCX
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Messenger\ycomp.dll
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [crgt.exe] C:\WINDOWS\system32\crgt.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [GSICONEXE] gsicon.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [zSPGuard] c:\program files\pjw\spguard\spguard.exe /s /r
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: AOL 7.0 Tray Icon.lnk = C:\Program Files\AOL 7.0\aoltray.exe
O4 - Global Startup: BT Broadband Help.lnk = C:\Program Files\BT Broadband\Help\bin\matcli.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O14 - IERESET.INF: START_PAGE_URL=http://www.btinternet.com/
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/bonnie/us/win/QuickTimeInstaller.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{96FAB6F0-1340-43FD-AC58-6A680B5D01CF}: NameServer = 194.74.65.68 194.72.9.38

 

2 Intern

 • 

2K Posts

July 7th, 2004 15:00

This is probably the hardest of the CWS infections to remove. For see info, see this page. Your 04 entry is
O4 - HKLM\..\Run: [crgt.exe] C:\WINDOWS\system32\crgt.exe.

For expert guidance, you will need to visit the Special Interest - Virus Infomation and Removal Board. Lots of problems, and few experts. I believe they are 48-72 hours behind at this time.
No Events found!

Top