This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Homepage keeps changing Think I've been hijacked

25 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

And I'm a bit nervous about having all those Restricted Sites removed so how long before I can put them back in with SpyBlaster and IESPY AD?

You can add those back now.


I have been choosing Admin thinking that it should cover everything but now I'm wondering if that is right

Admin is best.


Let's get a new restore point in case any of the bad guys are hanging out there.
Note: This will remove all previous Restore Points

Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Restart your computer, turn it back on.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Remove the Check Turn off System Restore.
Click Apply, and then click OK.


Let me know how we're doing now.
Okay, I've done the new System Restore point.


Let me know how we're doing now.

Last night, I still got the BHB message that the homepage had been changed. I haven't had the computer on for very long today but I'm expecting it will happen after a few hours, as usual. :(

I want to run something past you…..I'm probably WAY off the track here (think I'm getting paranoid..hehe), but anything is worth a shot to get rid of this pest.

Okay….bearing in mind that my granddaughter loves to chat on MSN Messenger, I thought I'd have a look and see if she had received any files over Messenger. There was nothing in My Received files but I saw that she had created a new folder called Kerrie's Pics and inside were a stack of jpgs, which I imagine she had saved from various websites. One of them had a strange name, no letters, just symbols like little squares.

I was immediately suspicious because I know that viruses can be transmitted via image files so I copied the name of the file and pasted it into Notepad to make myself a note so I would remember to ask you about it but when I ttied to save the txt file, I got a message telling me that it contained characters in Unicode format (a new word to me, I had never heard of it before) and they would be lost if it was saved as an ANSI encoded text file bla bla. I saved it anyway and when I opened it again later I saw that the strange characters had been replaced with question marks.

Okay… please bear with me…..then I did a Google search to find out what Unicode was and in so doing, I followed various links and discovered that viruses can be transmitted somehow through the use of Unicode. :o So now I'm wondering if this image could possibly contain a virus?


I told you I was paranoid.

Crazy Chris :wacko:
I just did that now and it said it was clean. So I guess I can cross that one off the list. Since my last post here I've had another case of the homepage getting changed, when the computer was still running last night. And, as usual, I couldn't open a browser window from the IE icon on the desktop after the change. But later on, I thought I'd try clicking "Home" from another browser window just to see where I ended up, if anywhere, and I was surprised to find myself sent to MSN.com…..which I'm sure is the default home page that should have been set in place when you had me do the Reset Web Settings the other day. But after I had done that job, I would have expected to find it listed as the home page in IE's Properties/General but instead it showed those couple of symbols followed by 1%2O. Since then I have changed the homepage back to Google but as I've mentioned before, it doesn't seem to stick. However, when I first boot up it still shows as Google (despite that always, every time I use the computer for few hours, I get the message that it's been changed FROM Google to
Backup your Registry…
- Press "CTRL - ALT - DEL" keys all at the same time to start "Task Manager"
- In the Task Manager window click on "File", then from the drop-down menu select "New Task (Run…)"
- In the "Create New Task" window enter\type "regedit" (without quotes)
- Once Regedit opens click on the FILE menu and select Export
- Save the file as backup. Save the file somewhere you will remember and not delete.
IMPORTANT: make sure to set the export range to ALL



I recommend you download RegSeeker. Extract it to it's own folder, open and double click RegSeeker.exe to start the program. Maximize the window and click clean registry. Check all sections and click OK. When the scan is complete, verify the backup box in lower left corner is checked and click the select all button, then select all again. Then right click within the search results and select delete. Run it again and again, deleting everything it finds until it finds nothing. Reboot and make sure your programs are working properly, control panel and add/remove programs windows open, etc (basically just do a quick check of everything). In the event anything was 'broken', you can open RegSeeker, click backups and double click any/all files to put the information back. A reboot may be required for the effects to be seen. Reboot When done.
Okay, I've cleaned out the registry and it took three runs of RegSeeker to get rid of everything, but…. the homepage is STILL getting changed! *SCREAM* I am thinking I might just have to live with this, as nothing seems to work. It doesn't happen until after the ocmputer has been running for a fair few hours so maybe I'll just have to do my online stuff when I first boot up before it gets changed. It's a pain because I use Google a lot for finding things and it's handy to have it as my homepage. Thanks again for your help. You've been fantastic!!! Chris.
Wow! I certainly admire your persistence.

I don't know if this will be any help or not but I've saved two HijackThis scans…..one done just after I got the messaage to say the homepage had been changed (when it was set back to
I ran Hoster, emptied the bin and rebooted, and left the computer running to test whether the homepage would get changed again….and it did. It is back to
I suggest you do this:

Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe


Close ALL windows and browsers except HijackThis and click "Fix checked"

Download DelDomains.inf
http://www.mvps.org/winhelp2002/DelDomains.inf

Right-click and select….. Save Target As….Save

To use: Right-click and select……. Install (no need to restart)
**Note** This will remove all entries in the "Trusted Zone"



Empty Recycle Bin

Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
Sorry for the delay in getting back to you. Here's the new log.


Logfile of HijackThis v1.99.1
Scan saved at 4:41:23 PM, on 29/08/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Vet\VetTray.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Vet\isafe.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Vet\VetMsg.exe
C:\Program Files\Browser Hijack Blaster\bhblaster.exe
C:\HIJACK THIS\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [VetTray] C:\Vet\VetTray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/web_…aploader_v6.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\Vet\isafe.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Vet\VetMsg.exe


I'll have to come back later and tell you how the computer is behaving because I don't get that message about the homepage being changed until after the computer has been running a few hours.

Chris.
Lets run the ewido scan agaig. Be sure you run it in Safe Mode

[*]Reboot into Safe Mode, you can do this by restarting your computer, then contiunally tapping F8 until a menu appears. Use your up arrow key to highlight Safe Mode, then hit enter. Then, run ewido.


[*]Close all open windows/programs/folders. Have nothing else open while ewido performs its scan!


[*]Click on scanner

[*]Click on Settings
  • Under "How to scan" all boxes should be selected
  • Under "Possibly unwanted software" all boxes should be selected
  • Under "What to scan" select scan every file
  • Click OK

[*]Click on Complete system scan

[*]Let the program scan the machine


[*]If ewido finds anything, it will pop up a notification. NOTE: We have been finding some cases of false positives with the new version of Ewido, so we need to step through the fixes one-by-one. If Ewido finds something that you KNOW is legitimate (for example, parts of AVG Antivirus, AOL, pcAnywhere and the game "Risk" have been flagged. In particular, watch for alerts that have the word "Heuristic" in them - if you recognize the file name as "friendly," these may actually be false positives) select "none" as the action. DO NOT check "Perform action with all infections." If you are unsure of an entry, select "none" for the time being. I'll see that in the log you will post later and let you know if ewido needs to be run again.


Once the scan has completed, there will be a button located on the bottom of the screen named Save report.

[*]Click Save report

[*]Save the report to your desktop

[*]Exit ewido
Restart your computer in normal mode and please post a new HijackThis log, as well as the log from the Ewido scan.
Here are the two scans but ewido found nothing this time.

———————————————————
ewido security suite - Scan report
———————————————————

+ Created on: 3:17:18 PM, 1/09/2005
+ Report-Checksum: 7C6F8CB2

+ Scan result:

No infected objects found.

::Report End

____________________________

Logfile of HijackThis v1.99.1
Scan saved at 3:20:36 PM, on 1/09/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Vet\VetTray.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Vet\isafe.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Vet\VetMsg.exe
C:\HIJACK THIS\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [VetTray] C:\Vet\VetTray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/web_…aploader_v6.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\Vet\isafe.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Vet\VetMsg.exe
____________________________

Something I should mention which has only recently come to my attention is that SpyBot won't run properly after I've received the message to say that the homepage has been changed. It freezes a couple of minutes into the running and I have to close it down from the Task Manager. But as soon as I reboot (and my settings have been restored and Google is back to being the homepage) it runs fine.

I used to find, when using my old dinosaur Pent2 computer, that when a program froze it was usually a memory issue….but it can't be in this case because (a) this new computer has a 2800 processor and a gig of RAM and (b ) I can still run the memory hogging game The Sims, and all its 7 expansion packs, straightaway afterwards without a reboot, and no problems there. And SpyBot runs fine at any other time, no matter how long I've been on the computer, even after surfing the net and playing the Sims, provided that I've not had the message to say that the homepage has been changed.

So, to me, it appears that the changing of the homepage somehow throws a spanner into SpyBot's works and cripples it.

Chris.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI