Go Back   PCMech Forums > Help & Discussion > Internet, Web Applications, & The Cloud

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 09-22-2004, 04:30 PM   #1
Member (7 bit)
 
Join Date: Aug 2002
Location: San Angelo, TX
Posts: 85
My home page keeps changing

I set explorer to go to myexcel.com as my home page when I connect or load explorer browser, it doesn't really matter what I set it to and after a few days when I connect, I notice the home page is switched to http://www.findthewebsiteyouneed.com/. I even have the site blocked in the explorer settings. What the heck is going on here? I have win xp explorer 6 and all the recent updates installed.
__________________
Thanks,
Robert Hamblen
www.ihamblen.com
robhamblen is offline   Reply With Quote
Old 09-22-2004, 09:17 PM   #2
Member (9 bit)
 
eldon's Avatar
 
Join Date: Jul 2002
Location: Kentucky
Posts: 288
Have you downloaded and ran spybot search and destroy or adaware?They are 2 free programs that will stop some things like this,also try spywareblaster also.I will look up the ip addresses for all 3 or you can do a google search for them.After downloading them be sure and update them.
__________________
Win XP Home,Pent.4 (1.5 GHZ)40Gig WD Hardrive,512meg DDR ,Nvidia Geforce2 mx/mx400,SoundBlaster Live 5.1,Asus P4B266mobo.Memorex 12x 24x 52x cdrw.
eldon is offline   Reply With Quote
Old 09-22-2004, 09:28 PM   #3
Member (7 bit)
 
Join Date: Aug 2002
Location: San Angelo, TX
Posts: 85
Yes Eldon, I have a free spy ware in my browser and so far I havent had anything show up but then again it might not be good enough to pick it up. Its free with yahoo toolbar. I also scanned for viruses.
robhamblen is offline   Reply With Quote
Old 09-22-2004, 09:32 PM   #4
Member (7 bit)
 
Join Date: Aug 2002
Location: San Angelo, TX
Posts: 85
Hey eldon, I just scanned for tracking cookies and a bunch came up. I just deleted them all but I bet they only take a day or two to be there again.
robhamblen is offline   Reply With Quote
Old 09-22-2004, 11:55 PM   #5
Member (9 bit)
 
delta013's Avatar
 
Join Date: Apr 2002
Location: Somewhere, out there…
Posts: 402
It would still be best to download spybot S&D, it may catch something that Yahoo missed. I would also run a virus scan.

Delta013
delta013 is offline   Reply With Quote
Old 09-23-2004, 04:10 PM   #6
Member (8 bit)
 
Join Date: May 2001
Location: Hamilton, ontario
Posts: 147
Send a message via AIM to compusport
I trust spybot and AdAware far more than Yahoo. they're both free and i'm sure that if you ran them they would pick up far more entries. There is also a free program for protecting your homepage here:

http://www.snapfiles.com/get/startpageguard.html
compusport is offline   Reply With Quote
Old 09-25-2004, 01:53 PM   #7
SGS
Member (8 bit)
 
Join Date: Jul 2004
Posts: 160
robhamblen,

The usual drill for this kind of thing is to download, update and run:

Ad-Aware and Spybot Search & Destroy .

Then run an online virus scan at Trend Micro .

When you're done, download and run HijackThis . Click the scan button. Click the "Save Log" button and copy and paste the log here.
SGS is offline   Reply With Quote
Old 01-09-2005, 09:27 PM   #8
Member (1 bit)
 
Join Date: Jan 2005
Posts: 1
Hello all, i have the same problem, have run both ad-aware and spybot search and destroy but my home page keeps changing all the time. Have also run a virus check and all is good.

I ran HijackThis and here is the log

Logfile of HijackThis v1.99.0
Scan saved at 2:25:04 PM, on 1/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe
C:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe
C:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\windows\ebeuute.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe
C:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\DOCUME~1\John\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://dr-search4u.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://dr-search4u.com/index.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dr-search4u.com/index.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://dr-search4u.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://dr-search4u.com/index.htm
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe"
O4 - HKLM\..\Run: [PCCClient.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe"
O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [agskhrh] c:\windows\kvilrjq.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Easy-PrintToolBox.lnk = C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTS...er/alpine.html
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1096509837673
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O16 - DPF: {E62A47D8-74B1-4A93-963A-E5E43B7CC5C2} (UCSearch.ucUCSearch) - http://www.zuvio.com/opnste/UCSearch.CAB
O23 - Service: Ati HotKey Poller - Unknown - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PC-cillin PersonalFirewall - Trend Micro Inc. - C:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe
O23 - Service: SoundMAX Agent Service - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Trend NT Realtime Service - Trend Micro Inc. - C:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe


any help would be greatly appreciated
JohnA is offline   Reply With Quote
Old 01-09-2005, 10:25 PM   #9
Member (9 bit)
 
Join Date: Dec 2004
Posts: 323
Quote:
Originally Posted by SGS
robhamblen,

The usual drill for this kind of thing is to download, update and run:

Ad-Aware and Spybot Search & Destroy .

Then run an online virus scan at Trend Micro .

When you're done, download and run HijackThis . Click the scan button. Click the "Save Log" button and copy and paste the log here.

Your browser has been hijacked. Do the above steps. Adaware and Spybot don't alway removed items completely. I've had to manually removes items in the past.

I recommend purchasing webroot spysweeper, its well worth the $25. I did a good cleaning with the above steps and installed spysweeper, and use the pop up blocker included with SP2. Have not had any problems in several months.
Spaz06 is offline   Reply With Quote
Old 01-09-2005, 10:55 PM   #10
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 37,773
JohnA: You have hijacked robhamblen's thread. Please start your own. Thank you.

Do not post a HijackThis log until you have thoroughly read the sticky thread in the Security forum. Thank you.

- Moderator -

Last edited by glc; 01-09-2005 at 10:58 PM.
glc is offline   Reply With Quote
Old 01-10-2005, 12:39 AM   #11
Member (9 bit)
 
sataraid0's Avatar
 
Join Date: Aug 2004
Location: Ma.
Posts: 319
Hmmmm, you might also try using spywareblaster, I have used it for about a year now and it seems to work very well. Get very very little spyware on my computer. latest version is 3.2 and you can get it here:

www.javacoolsoftware.com

It was free when I got it and as far as I know still is.

Hope this helps...........regards..................Sterling
sataraid0 is offline   Reply With Quote
Old 01-10-2005, 08:33 AM   #12
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 37,773
Spyware Blaster is not a remover - it's a preventative.
glc is offline   Reply With Quote
Old 01-10-2005, 09:58 AM   #13
Member (9 bit)
 
sataraid0's Avatar
 
Join Date: Aug 2004
Location: Ma.
Posts: 319
That's right..........sooo maybe ifn ya have that ya won't get the problems in the first place.

Regards...........................Sterling
sataraid0 is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 09:13 AM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 PL2