The summer of my (computer's) discontent continues:
I have scads of protection on my PC, but somehow my homepage has been and continues to get hijscked everytime I reset it! The site is www.syssecuritysite.net, and thers is an accompanying pop-up to www.entertainpage.net.
I am running Symantec Anti-Virus and have run a full system scan. I have also scanned using Spysweeper , Spybot Search and Destroy and Ad-Aware , rebooting each time. All picked up nothing and the hijacking continues. Another component of this is an icon that randomly appears in my system tray. It is a yield sign with a pop-up alerting of spyware on my computer.
Has anyone ever experienced this or something like it and/or does anyone have any suggestions?
Doing a little more searching, there seems to be some question about whether you need to do more than just run the SmitFraudFix tool in Safe mode, so maybe you can just do that.
God hates us all, you know it's true, God hates this place. - Slayer 1726 Posts 10/03
Posted - Jul 13 2006 : 7:06AM
Ya I ran in to it a lot when i was a comp tech.... the situation sucks.
First - PLEASE tell me you are using FireFox. I have yet had this happen to anyone using this browser, but that's not to say it can't.... Anyway, this should fix the hijacked homepage problem, but it may not fix that prog from popping up...
Second, the link provided is about the only way to get rid of it. However, be warned Hijackthis can fuck your shit up if you don't follow the instructions the person helping you gives.
Unfortunately I'm leaving for work related stuff come tomorrow and I'll be gone for a good week. I wanna see that Hijackthis log, so I'll check in as often as I can to see it. Maybe I can help, maybe others here can too. That forum looked like a good spot to try as well.
Good luck!
"The universe is hostile, So impersonal. Devour to survive." - Tool
I will give it a shot. I've been ruminating about Firefox for some while...I guess my lack of tchnological knowledge and experience just makes me insecure about changing.
Several sources cite the ZLOB Trojan virus as the cause of this problem. Changing browsers may stop the page hijack but, obviously, it isn't going to remove the virus from your PC.
Take a look at your SmitFraudFix log file. If you follow the thread on the site I sent you to you'll see that after-scan report ends with:If your log file has a similar entry showing an EXE and/or DLL file then you've still got work to do, and you should continue through the rest of the steps outlined by the Tweaks.com moderator.
Well, I had the exact same ending to my report - so I followed all the mods steps. Took quite awhile, and I'm now hung up on the final step.
The mod there mentions that you have to turn off Sytem Restore and turn it back on again or the virus can remain. He directs to http://www.pchell.com/virus/systemrestore.shtml for instructions on how to do this.
However, that site gives directions for turning System Restore on & off if you are running Windows ME or Windows XP.
I am running Windows 2000 Professional. I have tried both ways and neither applies. I cannot find the Sytem Restore Tab (or in the case of ME, cannot find the Performance, File System or Troubleshooting tabs) I have been trying all sorts of variations and I cannot seem to figure out how to turn this off and back on !
Things appear to be okay, but here's the latest HiJack this log. Again, thanks for your assistance!
Logfile of HijackThis v1.99.1 Scan saved at 1:11:02 AM, on 7/17/2006 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Yeah, I just noticed that...I wonder why all of these different programs left it? I ran Ad Aware, Symantec Anti-virus, Spysweeper, SpyBot Search & Destruy, and then later the ATF Cleaner and Ewido!
If you're positive that you have the latest definition files for those programs then running them again won't help. However, if you aren't positive then that's the place to start. Also, it may be necessary to use them in Safe Mode.
If you're comfortable with editing the registry you can follow the instructions here. They seem pretty straight forward.
Note the tool they claim will automagically remove it for you. I have no info about these guys, so use it at your own risk.
Here's another site that claims to be able to remove it. Again, I don't know anything about them.
Hardware, thanks tons, man! I deleted the files manually after doing some research and finding out that the link was to a software that would only detect them, but one had to buy the "full version" to remove them.
Here is my last HiJack this report...it appears okay to my uneducated eyes.
Logfile of HijackThis v1.99.1 Scan saved at 3:36:26 AM, on 7/18/2006 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
If you deleted the files but not the registry entries you may get some error messages at startup. However, the program itself can't run without those files.
BTW, I found out that you got the Seekmo adware courtesy of Logitech. Apparently they bundle (bundled?) it with their mouse driver software. Just goes to show that you should never just 'accept all' when doing a software install, no matter who it's from.
At any rate, this probably explains why none of your spyware/adware programs dealt with it.
JAG, I strongly suggest that you download and use the following two programs: Counter Spy (for spyware & adware, etc.) AVG Anti-Virus (for virus protection)
I'm saying get them and use them in addition to what you already have -- at least to run now that you think you've fixed your problem(s). I'm betting that they will find things that have been missed to date.
AVG offers a totally-free version for personal use only on one computer. 100% Virus Detection by AVG... GRISOFT once again received the VB100% Award by independent malware advisor, Virus Bulletin, in June 2006. AVG Anti-Virus proved itself by detecting all In the Wild viruses, while generating no false positives, during both on-demand and on-access scanning in Virus Bulletin's comparative tests.
Counter Spy offers a free 15-day trial. This is a top-rated adware/spyware program, and is very much worth running it for at least the two free weeks. It will find things other programs have missed :)
Whoa, big fella! You should never run more than one antivirus program on your PC at a time. If Jag wants to replace what he's got that's fine but, if so, he should download the new program, uninstall his current one and only then load the new one (and don't forget to cancel your subscription to the old one!).
In the case of running the AVG Anti-virus, disable your other anti-virus program(s) before running it. You don't have to run every anti-virus program on your computer even though it is installed. Most anti-virus programs will place an icon in the Task Bar "Tray" that you can usually right-click on and turn features on and off.
IF you find that AVG is finding things Symantec has missed (not real hard to do), I think the decision as to which one to keep and use will become obvious... certainly by the time you need to send Symantec more money again.
In the case of my Counter Spy recommendation, you can run these adware/spyware programs as needed without a conflict problem. Note: You already are doing this now, as you stated you are using Spybot Search and Destroy and Ad-Aware. Counter Spy is even better. The 15-day free trial may find things that Spybot Search and Destroy and Ad-Aware missed.