Forum     

Go Back   Digit Technology Discussion Forum > Portables, Peripherals and Electronics > QnA (read only)
Register FAQ Calendar Mark Forums Read

QnA (read only) Mods please help transfer the contents of this forum to proper sections. :)


 
 
LinkBack Thread Tools Search this Thread Display Modes
Old 31-08-2004, 12:31 AM   #1 (permalink)
bsb
Right Off the Assembly Line
 
Join Date: Nov 2003
Posts: 16
Default unwanted home page


Hi!
I am using Windows XP on a P-4. I have got two problems with my browser (IE 6), which started after I opened one spam by mistake. Well, the problem 1 my home page has been changed. Everytime, I switch on, I set to yahoo.com but as soon as I restart, it is same again.

2nd - I have got a few unwanted links as my favourites. I delete them everytime but as soon as I restart they appear again.

Will some one help me to rectify the above problems.

Thanks.

BSB
bsb is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 31-08-2004, 12:59 AM   #2 (permalink)
Alpha Geek
 
mariner's Avatar
 
Join Date: Dec 2003
Location: mumbai
Posts: 522
Default

you have got some spyware.
download ad aware se from www.lavasoft.com.
also download spybot search n destroy from
http://www.safer-networking.org/en/download/index.html

run these applications to get rid of all the spywares.
also get a good firewall. sygate personal firewall is good
mariner is offline  
Old 31-08-2004, 06:06 PM   #3 (permalink)
Apprentice
 
Join Date: Jul 2004
Posts: 69
Default

best apply the available security patches for ie 6 in the net
lajs is offline  
Old 31-08-2004, 07:32 PM   #4 (permalink)
Alpha Geek
 
mariner's Avatar
 
Join Date: Dec 2003
Location: mumbai
Posts: 522
Default

btw adawae se download site is www.lavasoft.de

sorry for the error
mariner is offline  
Old 01-09-2004, 12:36 AM   #5 (permalink)
Coming back to life ..
 
it_waaznt_me's Avatar
 
Join Date: Nov 2003
Location: A bit closer to heaven
Posts: 1,997
Default

Please post your HijackThis Logfile for better assesment of your problem.
__________________
Sleight of hand and twist of fate...
On a bed of nails she makes me wait...
And I wait without you ...
With or without you ..
----
Batty = Too Busy Now !!!
it_waaznt_me is offline  
Old 01-09-2004, 12:01 PM   #6 (permalink)
Jai Suresh
 
lywyre's Avatar
 
Join Date: Aug 2004
Location: Vellore, TN
Posts: 580
Default

Download Autoruns.exe from www.sysinternals.com

Boot into safemode and and run Autoruns.exe: remove unwanted executable from startup.
Remove all unwanted programs in Add/Remove programs.
Delete twain.dll and twain_32.dll in the Windows folder.

Also check there are no unwanted .dll files in your c:\windows\System32 folder. To do this list your files in 'details' view and sort by date. Delete all the .dll and tmp files created after you visited that 'spam site'.

Delete unwanted plugins in the "downloaded programs files". (Delete all except shockwave and java and quicktime).

Emtpy you Temp folder (Type %temp% in the address bar).

Hope this solves you problem.
To avoid further such issues, stop using IE.
lywyre is online now  
Old 02-09-2004, 12:08 AM   #7 (permalink)
Wise Old Owl
 
aadipa's Avatar
 
Join Date: Feb 2004
Location: Palghar, Mumbai
Posts: 1,000
Default

Best way .......
Post ur HijackThis Log file.....
__________________
i generally prefer quality over quantity
1 aadi + 1 aadi = 1 full ;)
aadipa is offline  
Old 02-09-2004, 01:40 AM   #8 (permalink)
bsb
Right Off the Assembly Line
 
Join Date: Nov 2003
Posts: 16
Default unwanted homepage

Hi! Thanks to all who responded.

Well, 'ad aware SE' and ' Spybot SD' could not solve the problem. However, by running these programmes, I came to know that I may have more problems than I can see.

Secondly, I ran 'Hijackthis'. The logfile is reproduced below.
Logfile of HijackThis v1.98.2
Scan saved at 1:28:39 AM, on 9/2/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\spoolsv.exe
C:\Windows\System32\Ati2evxx.exe
C:\Windows\Cpqdiag\Cpqdfwag.exe
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\Windows\System32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\Windows\Explorer.EXE
C:\Program Files\Trend Micro\OfficeScan Client\ofcdog.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\twain_32\ScanWiz5\SDII.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Contract\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,Search = http://up-search.com/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://up-search.com/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer,Search = http://up-search.com/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://up-search.com/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://up-search.com/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://up-search.com/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://up-search.com/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://up-search.com/index.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://up-search.com/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://up-search.com/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://up-search.com/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://up-search.com/index.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://up-search.com/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://up-search.com/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://up-search.com/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://up-search.com/search.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = 10.205.122.80:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 10.205.*.*;<local>
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [winupd] C:\Windows\System32\winupd.exe
O4 - HKLM\..\RunServices: [CPQDFWAG] C:\Windows\Cpqdiag\CpqDfwAg.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microtek Scanner Finder.lnk = C:\WINDOWS\twain_32\ScanWiz5\SDII.exe
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O16 - DPF: {11010101-1001-1111-1000-110112345678} - ms-its:mhtml:file://c:\nosuch.mht!http://69.31.79.101/winsearchie32.ch...searchie32.exe
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = mumbai.ongcl.com
O17 - HKLM\Software\..\Telephony: DomainName = mumbai.ongcl.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{EE93C8B8-C329-4C20-AC17-9A6E663D96C7}: NameServer = 203.94.227.70 203.94.243.70
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = mumbai.ongcl.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = mumbai.ongcl.com


I get a home page www.up-search.com. Although I tried to remove all references to this page through 'highjackthis' but as soon as I restart my computer, it appears again. The links added to 'favourites' folder still exist there.

Hope you will help me to solve my problem without reformatting the hard disk.

Thanks again.
bsb is offline  
Old 02-09-2004, 11:27 PM   #9 (permalink)
Coming back to life ..
 
it_waaznt_me's Avatar
 
Join Date: Nov 2003
Location: A bit closer to heaven
Posts: 1,997
Default Re: unwanted homepage

To proceed with your HijackThis log, Run HijackThis again and put a CheckMark next to these entries and Click on Fix Checked.
Please make sure that all Internet Explorer and Windows Explorer windows are closed.
Quote:
Originally Posted by bsb
R1 - HKCU\Software\Microsoft\Internet Explorer,Search = http://up-search.com/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://up-search.com/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer,Search = http://up-search.com/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://up-search.com/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://up-search.com/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://up-search.com/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://up-search.com/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://up-search.com/index.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://up-search.com/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://up-search.com/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://up-search.com/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://up-search.com/index.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://up-search.com/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://up-search.com/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://up-search.com/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://up-search.com/search.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = 10.205.122.80:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 10.205.*.*;<local>
O4 - HKLM\..\Run: [winupd] C:\Windows\System32\winupd.exe <-- Virus
O16 - DPF: {11010101-1001-1111-1000-110112345678} - ms-its:mhtml:file://c:\nosuch.mht!http://69.31.79.101/winsearchie32.ch...searchie32.exe
__________________
Sleight of hand and twist of fate...
On a bed of nails she makes me wait...
And I wait without you ...
With or without you ..
----
Batty = Too Busy Now !!!
it_waaznt_me is offline  
Old 03-09-2004, 12:17 AM   #10 (permalink)
bsb
Right Off the Assembly Line
 
Join Date: Nov 2003
Posts: 16
Default

at last!!!!

Problem solved. Thanks a lot.

By the way, how serious was it? Do u think the hijacker could have copied down my passwords etc.?
bsb is offline  
 

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


 
Latest Threads
- by abhidev
- by clinton

Advertisement




All times are GMT +5.5. The time now is 06:21 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2