1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Hijacked homepage and search engine

Discussion in 'Virus & Other Malware Removal' started by TomBurlin, Oct 10, 2003.

Thread Status:
Not open for further replies.
Advertisement
  1. TomBurlin

    TomBurlin Thread Starter

    Joined:
    Oct 10, 2003
    Messages:
    7
    My internet homepage has been hijacked. So has google which I used as my search engine. I downloaded and scanned with "Hijackthis". I generated a scan log. I don't know anything about what should or shouldn't be there. Here is the log. I would appreciate it if someone can tell which ones in the list are the culprits. I have a Gateway with Windows ME 4.9.300.
     

    Attached Files:

  2. man1ac

    man1ac

    Joined:
    Oct 7, 2003
    Messages:
    18
    hi tomburlin
    that is just your startuplist log
    please post ur hijackthis log
     
  3. $teve

    $teve

    Joined:
    Oct 9, 2001
    Messages:
    9,396
    You also have a trojan in there.....
    C:\WINDOWS\SYSTEM\MSREXE.EXE

    As man1ac advises,post your full HijackThis logfile.
    In the meantime do this:

    First

    Download AdAware 6 181 from here: http://www.lavasoftusa.com/
    Before you scan with AdAware, check for updates of the reference file by using the "webupdate".
    Then ........

    Make sure the following settings are made and on -------"ON=GREEN"
    From main window :Click "Start" then " Activate in-depth scan"

    then......

    click "Use custom scanning options>Customize" and have these options on: "Scan within archives" ,"Scan active processes","Scan registry", "Deep scan registry" ,"Scan my IE Favorites for banned URL" and "Scan my host-files"

    then.........

    go to settings(the gear on top of AdAware)>Tweak>Scanning engine and tick "Unload recognized processes during scanning" ...........then........"Cleaning engine" and tick "Automaticly try to unregister objects prior to deletion" and "Let windows remove files in use at next reboot"

    then...... click "proceed" to save your settings.

    Now to scan it´s just to click the "Scan" button.

    When scan is finished, mark everything for removal and get rid of it.

    then
    Download Spybot - Search & Destroy from http://security.kolla.de

    After installing, first press Online, and search for, put a check mark at, and install all updates.
    Next, close all Internet Explorer and OE windows, hit 'Check for Problems', and have SpyBot remove all it finds that is marked in RED

    Run an online antivirus check from at least one of the following sites
    http://security.symantec.com/default.asp?
    http://housecall.trendmicro.com/
    http://www.pandasoftware.com/activescan/

    Take a trip here.....Online trojan scanner:
    http://www.anti-trojan.net/en/onlinecheck.aspx
     
  4. TomBurlin

    TomBurlin Thread Starter

    Joined:
    Oct 10, 2003
    Messages:
    7
    I humbly thank you for your help man1ac and $teve. My homepage is back ( "there's no place like home(page)") and I can get to google again so I won't burden you with the Hijackthis log. I hope that I won't be begging for help for a while. Thanks again and goodbye.
     
  5. $teve

    $teve

    Joined:
    Oct 9, 2001
    Messages:
    9,396
    (y) your welcome
     
  6. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/171109

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice