Hijacked Homepage - and can't change it!

Hijacked Homepage - and can't change it!

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Hijacked Homepage - and can't change it! Peteroid 08-14-2005
Posted by Peteroid on August 14, 2005, 6:08 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
***I figure this is a MS Security issue, hence why I posted this here. If
this is the wrong place, please point to to the correct place. Thanks! ***

I was surfing the web when all of a sudden viruses (viri, but it looks
funny) are detected. I tried to elliminate with AVG (which detected them),
but not all were apparently removed.

First, I have a two-screen system, and one of these screen was changed to an
ad for 'RazeSpyware'. I was only able to remove this by downloading their
demo and running it.

Then I openned my browser, and it comes up with a page telling me I have a
security risk instead of my MSN.com home page. This page has info about my
system on it, such as keywords, and links to a company called
"Evidence-Eliminator.com".

I've tried to change my homepage, but it always comes back to this hijacked
page if I hit the homepage icon or open up a new browser. It seems to be
getting this from my own machine, as this appears in the address field:

res://C:\WINDOWS\system32\shdocvn.dll/errorAPI.htm#ID=PX8594;

I've tried changing the homepage both by drag-and-drop and by going into the
'Tools : Internet Options". I've applied and just exited, in all cases the
homepage reverts back to their 'ad'.

I've run my (already owned) anti-spyware and anti-virus software sweepers,
they report nothing is wrong. And, whatever they did, it cleared all
previous 'restore points', so couldn't even solve it that way.

"Evidence-Eliminator.com" is England based. Isn't this blackmail? Buy our
software (which will likely return control of my homepage to me) or we won't
let you change your homepage?

FYI:

Operating System: Win XP Pro 5.1
Browser: MS IE 6.0.2900.2180.xpsp_gdr.050301-1519
Update Versions: ; SP2;

I have most recent MS updates installed.

Basically I'm looking for a way to return my homepage control. Any ideas?
And don't you think MicroSoft should have a word with these guys (my
homepage was MSN.com)? They also almost slander MS in regards to what they
say.

And to show how awful "Evidence-Eliminator.com" is, this is their disclaimer
(at bottom of my 'new homepage'):

"The information is provided 'as is' without warranty of any kind. But, if
you don't follow our recommendations & don't use 'required software', we
will disclaim all warranties, either expressed or implied, including the
warranties of merchantability and fitness for a particular purpose. In no
event shall we be liable for any damage whatsoever including direct,
indirect, incidental, consenquential, loss of business profits or special
damages, even if we have been advised of the possibility of such damage."

The 'required software' in the above is a link to buy their software.

Again, I didn't go to them, they hijacked my homepage via a virus of some
kind while surfing totally unrelated content.

Help!!!

[==Peteroid==]



Posted by Malke on August 14, 2005, 7:50 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Peteroid wrote:

(snippage) - See comments inline:

> I was surfing the web when all of a sudden viruses (viri, but it looks
> funny) are detected. I tried to elliminate with AVG (which detected
> them), but not all were apparently removed.

"Viruses" is the correct term. It doesn't sound like you got hit with
viruses. It sounds like you may have had some malware on your system
already and then you got more malware. However, it will not hurt for
you to update your AVG and do a thorough scan in Safe Mode.
>
> First, I have a two-screen system, and one of these screen was changed
> to an ad for 'RazeSpyware'. I was only able to remove this by
> downloading their demo and running it.

Big mistake - you got swindled.
>
> Then I openned my browser, and it comes up with a page telling me I
> have a security risk instead of my MSN.com home page. This page has
> info about my system on it, such as keywords, and links to a company
> called "Evidence-Eliminator.com".

More swindling.
>
> I've tried to change my homepage, but it always comes back to this
> hijacked page if I hit the homepage icon or open up a new browser. It
> seems to be getting this from my own machine, as this appears in the
> address field:
>
> res://C:\WINDOWS\system32\shdocvn.dll/errorAPI.htm#ID=PX8594;

I don't know what other antispyware tools you used, but you should check
to see if any of them are "rogue" - programs that purport to fix
spyware but are really evil themselves. Look them up on MVP Eric Howes'
fine site here:

http://www.spywarewarrior.com/rogue_anti-spyware.htm

Start by trying to uninstall any suspect programs from Add/Remove
Programs, understanding that if malware programs have an uninstall
routine it is generally a lie. Then go to the link below and follow the
malware removal steps systematically. It is key that you do everything
with updated tools in Safe Mode. You will probably need to get all
tools and updates from a different, known-clean computer with an
Internet connection and either a cd burner or have a usb thumbdrive
with a large enough capacity to transfer the files.

http://www.elephantboycomputers.com/page2.html#Removing_Malware

Malke
--
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
MS-MVP Windows - Shell/User

Posted by Steven L Umbach on August 14, 2005, 8:03 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
The type of problem you describe is usually not remedied with a virus
detection and removal program. Try using one or more of the parasite
detection and removal programs such as AdAware SE, SpyBot Search and
Destroy, or Microsoft AntiSpyware. You may also have to use tools like
BhoDemon, CWShredder, or Hijack This depending on exactly what the problem
is. Whatever you try be sure that the application is current with
definitions before you scan and you may need to also scan in Safe Mode.
Though opinions vary on Microsoft AntiSpyware I have found it to work well
and have seen it remove cases of hijacked home pages. See the links below
for more details. --- Steve

http://www.microsoft.com/athome/security/spyware/software/default.mspx ---
Microsoft AntiSpyware
http://www.download.com/3000-2144-10045910.html --- AdAware SE.
http://mvps.org/winhelp2002/unwanted.htm --- dealing with parasites tips.
http://www.microsoft.com/athome/security/spyware/default.mspx --- MS link
on Spyware.

> ***I figure this is a MS Security issue, hence why I posted this here. If
> this is the wrong place, please point to to the correct place. Thanks! ***
>
> I was surfing the web when all of a sudden viruses (viri, but it looks
> funny) are detected. I tried to elliminate with AVG (which detected them),
> but not all were apparently removed.
>
> First, I have a two-screen system, and one of these screen was changed to
> an ad for 'RazeSpyware'. I was only able to remove this by downloading
> their demo and running it.
>
> Then I openned my browser, and it comes up with a page telling me I have a
> security risk instead of my MSN.com home page. This page has info about my
> system on it, such as keywords, and links to a company called
> "Evidence-Eliminator.com".
>
> I've tried to change my homepage, but it always comes back to this
> hijacked page if I hit the homepage icon or open up a new browser. It
> seems to be getting this from my own machine, as this appears in the
> address field:
>
> res://C:\WINDOWS\system32\shdocvn.dll/errorAPI.htm#ID=PX8594;
>
> I've tried changing the homepage both by drag-and-drop and by going into
> the 'Tools : Internet Options". I've applied and just exited, in all cases
> the homepage reverts back to their 'ad'.
>
> I've run my (already owned) anti-spyware and anti-virus software sweepers,
> they report nothing is wrong. And, whatever they did, it cleared all
> previous 'restore points', so couldn't even solve it that way.
>
> "Evidence-Eliminator.com" is England based. Isn't this blackmail? Buy our
> software (which will likely return control of my homepage to me) or we
> won't let you change your homepage?
>
> FYI:
>
> Operating System: Win XP Pro 5.1
> Browser: MS IE 6.0.2900.2180.xpsp_gdr.050301-1519
> Update Versions: ; SP2;
>
> I have most recent MS updates installed.
>
> Basically I'm looking for a way to return my homepage control. Any ideas?
> And don't you think MicroSoft should have a word with these guys (my
> homepage was MSN.com)? They also almost slander MS in regards to what they
> say.
>
> And to show how awful "Evidence-Eliminator.com" is, this is their
> disclaimer (at bottom of my 'new homepage'):
>
> "The information is provided 'as is' without warranty of any kind. But, if
> you don't follow our recommendations & don't use 'required software', we
> will disclaim all warranties, either expressed or implied, including the
> warranties of merchantability and fitness for a particular purpose. In no
> event shall we be liable for any damage whatsoever including direct,
> indirect, incidental, consenquential, loss of business profits or special
> damages, even if we have been advised of the possibility of such damage."
>
> The 'required software' in the above is a link to buy their software.
>
> Again, I didn't go to them, they hijacked my homepage via a virus of some
> kind while surfing totally unrelated content.
>
> Help!!!
>
> [==Peteroid==]
>



Similar ThreadsPosted
How to get rid of an unwanted homepage? August 18, 2007, 3:20 pm
Error message instead of Homepage..... December 31, 2005, 6:31 am
hijacked desktop December 12, 2005, 5:24 pm
Browser being hijacked? February 21, 2007, 7:03 am
why has my .net account hijacked my computer? November 10, 2005, 12:21 pm
Hijacked Hotmail Account April 1, 2006, 6:12 pm
Bravesentry.com has hijacked my home pc! May 16, 2008, 11:57 am
A Program called SpywareQuake has hijacked my computer April 3, 2006, 4:11 pm
hotmail hijacked to phishing site live.com April 22, 2006, 2:29 pm
DC reg change September 7, 2005, 1:05 pm

The site map in XML format XML site map

Contact Us | Privacy Policy