This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Homepage Hijacked

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I think my homepage was highjacked, explorer opens up to a search portal and computer runs real slow ever since. Here is the log:

Logfile of HijackThis v1.97.7
Scan saved at 6:10:24 PM, on 2/26/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\TEMPORARY INTERNET FILES\CONTENT.IE5\8IATLM5F\HIJACKTHIS[1].EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://channels.aimtoday.com/search/aimtoolbar.jsp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://v73.us/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://v73.us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://v73.us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://v73.us/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://v73.us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://v73.us/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://v73.us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://v73.us/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://v73.us/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://v73.us/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://v73.us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://v73.us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,First Home Page = http://v73.us
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://v73.us
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_12_0.DLL
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\MWSBAR.DLL
O2 - BHO: (no name) - {E02170AF-AB70-5074-A4D7-DD3F71FDF7F2} - (no file)
O2 - BHO: (no name) - {28791B4A-A806-7F08-FBAA-2F8B97EBBFFA} - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_12_0.DLL
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\PROGRAM FILES\AIM TOOLBAR\AIMBAR.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: &AIM Search - res://C:\PROGRAM FILES\AIM TOOLBAR\AIMBAR.DLL/aimsearch.htm
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200411…meInstaller.exe
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt3_x.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab
O16 - DPF: {0B1CFA78-7DF3-4231-A2E3-22B60B4B1C2E} - http://65.125.226.86/traff/web.cab
Hello javoro2000, Welcome to TomCoyote forum. If you still need help, please follow these directions:

1) Your HijackThis.exe is running from Temporary Internet Files. We need a permanent folder to save backups and logs. Return to C:\Windows and point your mouse at a blank spot and make a NEW FOLDER, call it HJT. Move the HJT.exe into that folder and any logs you see. Delete any instance of HJT not in that folder.

2) Your HJT.exe is very outdated. Before you post the next log, please update to version 1.99.1 like this: Open HJT > Open the Misc Tools section > Scroll to Check for update online > Follow instructions.

3) Follow the instructions in the following link to download, update and FIX not scan with CWShredder. Please let me know what it located in the next post.
http://www.softpedia.com/get/Internet/Popu…WShredder.shtml

4) Scan with HijackThis and check the box in front of each of these line items:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://v73.us/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://v73.us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://v73.us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://v73.us/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://v73.us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://v73.us/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://v73.us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://v73.us/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://v73.us/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://v73.us/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://v73.us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://v73.us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,First Home Page = http://v73.us
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://v73.us
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\MWSBAR.DLL
O2 - BHO: (no name) - {E02170AF-AB70-5074-A4D7-DD3F71FDF7F2} - (no file)
O2 - BHO: (no name) - {28791B4A-A806-7F08-FBAA-2F8B97EBBFFA} - (no file)
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200411…meInstaller.exe
O16 - DPF: {0B1CFA78-7DF3-4231-A2E3-22B60B4B1C2E} - http://65.125.226.86/traff/web.cab

Close all programs but HJT and all browser windows then click on "Fix Checked". Empty the recycle bin and restart the computer. Surf a bit to see how you are running. Post a new log along with any comments you have.
Thanks…pskelley
TomCoyote forum
Slyware Warrior
If you get help here consider a donation:
http://tomcoyote.com/donate.php

Hello javoro2000, Welcome to TomCoyote forum. If you still need help, please follow these directions:

1) Your HijackThis.exe is running from Temporary Internet Files.  We need a permanent folder to save backups and logs.  Return to C:\Windows and point your mouse at a blank spot and make a NEW FOLDER, call it HJT.  Move the HJT.exe into that folder and any logs you see.  Delete any instance of HJT not in that folder.

2) Your HJT.exe is very outdated.  Before you post the next log, please update to version 1.99.1 like this: Open HJT > Open the Misc Tools section > Scroll to Check for update online > Follow instructions.

3) Follow the instructions in the following link to download, update and FIX not scan with CWShredder.  Please let me know what it located in the next post.
http://www.softpedia.com/get/Internet/Popu…WShredder.shtml

4) Scan with HijackThis and check the box in front of each of these line items:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://v73.us/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://v73.us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://v73.us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://v73.us/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://v73.us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://v73.us/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://v73.us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://v73.us/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://v73.us/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://v73.us/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://v73.us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://v73.us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,First Home Page = http://v73.us
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://v73.us
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\MWSBAR.DLL
O2 - BHO: (no name) - {E02170AF-AB70-5074-A4D7-DD3F71FDF7F2} - (no file)
O2 - BHO: (no name) - {28791B4A-A806-7F08-FBAA-2F8B97EBBFFA} - (no file)
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200411…meInstaller.exe
O16 - DPF: {0B1CFA78-7DF3-4231-A2E3-22B60B4B1C2E} - http://65.125.226.86/traff/web.cab

Close all programs but HJT and all browser windows then click on "Fix Checked".  Empty the recycle bin and restart the computer.  Surf a bit to see how you are running.  Post a new log along with any comments you have.
Thanks…pskelley
TomCoyote forum
Slyware Warrior
If you get help here consider a donation:
http://tomcoyote.com/donate.php

137312

Hello javoro2000, Welcome to TomCoyote forum. If you still need help, please follow these directions:

1) Your HijackThis.exe is running from Temporary Internet Files.  We need a permanent folder to save backups and logs.  Return to C:\Windows and point your mouse at a blank spot and make a NEW FOLDER, call it HJT.  Move the HJT.exe into that folder and any logs you see.  Delete any instance of HJT not in that folder.

2) Your HJT.exe is very outdated.  Before you post the next log, please update to version 1.99.1 like this: Open HJT > Open the Misc Tools section > Scroll to Check for update online > Follow instructions.

3) Follow the instructions in the following link to download, update and FIX not scan with CWShredder.  Please let me know what it located in the next post.
http://www.softpedia.com/get/Internet/Popu…WShredder.shtml

4) Scan with HijackThis and check the box in front of each of these line items:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://v73.us/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://v73.us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://v73.us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://v73.us/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://v73.us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://v73.us/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://v73.us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://v73.us/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://v73.us/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://v73.us/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://v73.us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://v73.us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,First Home Page = http://v73.us
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://v73.us
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\MWSBAR.DLL
O2 - BHO: (no name) - {E02170AF-AB70-5074-A4D7-DD3F71FDF7F2} - (no file)
O2 - BHO: (no name) - {28791B4A-A806-7F08-FBAA-2F8B97EBBFFA} - (no file)
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200411…meInstaller.exe
O16 - DPF: {0B1CFA78-7DF3-4231-A2E3-22B60B4B1C2E} - http://65.125.226.86/traff/web.cab

Close all programs but HJT and all browser windows then click on "Fix Checked".  Empty the recycle bin and restart the computer.  Surf a bit to see how you are running.  Post a new log along with any comments you have.
Thanks…pskelley
TomCoyote forum
Slyware Warrior
If you get help here consider a donation:
http://tomcoyote.com/donate.php

137312

Thankyou so much pskelly, worked like a charm, computer runs great. Here is the updated log:

Logfile of HijackThis v1.99.1
Scan saved at 8:52:31 AM, on 3/3/2005
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\MY DOCUMENTS\HIGHJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://channels.aimtoday.com/search/aimtoolbar.jsp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_12_0.DLL
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_12_0.DLL
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\PROGRAM FILES\AIM TOOLBAR\AIMBAR.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: &AIM Search - res://C:\PROGRAM FILES\AIM TOOLBAR\AIMBAR.DLL/aimsearch.htm
O9 - Extra button: (no name) - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM95\AIM.EXE
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0521.DLL
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0521.DLL
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall-beta.trendmicro.com/housecall/xscan60.cab
Hello javoro2000, I was wondering why you quoted my post so many times??…lol.

Follow the instructions in the following link to download, update and FIX not scan with CWShredder.  Please let me know what it located in the next post.

I asked for this information and did not get it? Oh well, I got everything else I asked for. :D

Log is clean, you are good to go. Here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://forums.net-integration.net/index.php?showtopic=3051
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html

Thanks…pskelley
TomCoyote forum
Slyware Warrior
If you get help here consider a donation:
http://tomcoyote.com/donate.php
If you are reading this information…thank a teacher, If you are reading it in English…thank a soldier.
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI