Homepage Hijacks

KMA

Registered User
Forum Member
May 25, 2003
745
2
0
If your Home page changes unexpectedly, you have a "HomePage hijack", and will see this page each time you invoke your browser. What the hijacker has done is to change the registry key:

In the Root key HKEY_CURRENT_USER, the key Software\Microsoft\Internet Explorer\Main has a value "Start Page" that has likely been reset to something.

In the Root key HKEY_LOCAL_MACHINE, the key Software\Microsoft\Internet Explorer\Main has a value "Start Page" that has likely been reset to something like http://yourbookmarks.ws/


Fixing this seems simple, but some pests make repair a bit more difficult. For instance, CWS sets the first of these entries to:

http://www.coolwwwsearc %68%2e%63%6f%6d/%7a/%61/%78%31%2e%63%67%69?%36%35%36%33%38%37 This is "encrypted"; its decryption works out to http://www.searchv.com/



Disabling Scripting:

IE supports "scripting", a useful but dangerous capability that you will want to disable if you ever visit unknown sites. The scripts that can be run will be Javascript or VBScript, often embedded in a web page you visit. Such scripts can execute ActiveX controls, which can do anything in your machine that any software can do.


To be stop scripting the easy way, do this:
From IE's top menu bar, select the Tools menu. On this menu, choose "Internet Options". It will display a popup dialog box. Click on the Security tab, you will see the internet options box has popped up.


Each zone has four security levels available, ranging from Low Security to High. IE is configured for Low Security when it is first installed. Medium or High is what you need.

High (most secure) Exclude content that could damage your computer.
Medium (more secure) Warn before running potentially damaging content.
Medium-Low (Same as Medium) No warning before running potentially damaging content.
Low Minimal safeguard and warning before running potentially damaging content.

For the Internet Setting, move the slider to "Medium" This will ensure that you are prompted before signed ActiveX controls are run, and unsigned ActiveX controls will not run.

But it will still allow active scripting. So click on the "Custom Level" button, and follow these instructions:


Configure IE so that it does not run Active scripts automatically:
On the Tools menu, click Internet Options, click the Security tab, click the Internet Web content zone, and then click Custom Level.

In the Settings box, scroll down to the Scripting section, and click Disable under Active scripting and Scripting of Java applets.

Click OK, and then click OK again.

Configure IE so that it does not automatically use items that show active content, such as vertical marquees or animations:

On the Tools menu, click Internet Options, click the Security tab, click the Internet Web content zone, and then click Custom Level.

In the Settings box, click Disable under Download signed ActiveX controls, Download unsigned ActiveX controls, Initialize and script ActiveX controls not marked as safe, Run ActiveX controls and plugins, and Script ActiveX controls marked safe for scripting.

Click OK, and then click OK again.

Verify that IE's internal Java Just-In-Time (JIT) compiler is disabled:

On the Tools menu, click Internet Options, click the Advanced tab, and then click to clear the JIT compiler for virtual machine enabled (requires restart) check box under Java VM.

Click OK.

Configure IE so that it does not run Java programs automatically.

On the Tools menu, click Internet Options, click the Security tab, click the Internet Web content zone, and then click Custom Level.

In the Settings box, click Disable Java under Java Permissions, click OK and then click OK again.
 

Eddie Haskell

Matt 02-12-11
Forum Member
Feb 13, 2001
4,595
41
0
26
Cincinnati
aclu.org
Thanks darlin.

KMA, I have a question. When I click my internet explorer icon on my desktop, I have to wait about 10 seconds for my home page to pop up. This just started recently. Any suggestions on how to lessen the time?

Thanks,
Ed
 

CryBoy

Registered User
Forum Member
Nov 12, 2000
2,853
27
48
Arlington, TX
Thanks, KMA

Thanks, KMA

I did everything you suggested above. :)

Now I have another question. I am in the market for a new computer and have a computer teacher friend that builds computers at home for his friends and family. He likes DMA and not Pentium 4. Which option is better in your opinion? Build a computer yoursefl or buy one from Dell?

I have another friend that is a computer programmer and used to build computers at home as a hobby. He recommends buying from Dell because Dell has tested all their parts to make sure things run smoothly. His argument is no home-based builder can test all the possible errors that might occur when snapping together different parts from different makers.

Appreciate all that you do here in the forum.
 

KMA

Registered User
Forum Member
May 25, 2003
745
2
0
Eddie Haskell try:


tools
internet options
clear history
delete cookies
delete files




Uou my have some spyware on your comp, it'd be a good idea to run ad-aware.
 

KMA

Registered User
Forum Member
May 25, 2003
745
2
0
CryBoy,

I would go with the home computer as long as I can have full access to the computer box, should I want to do upgrades or modifications I don't need to send it in to the manufacturer.
An example would be like adding more ram or a cd burner later or even a bigger harddrive. Most parts do test well together as they need to be within microsoft standards, they set the rules basicly.
 

wareagle

World Traveler
Forum Member
Feb 27, 2001
5,712
40
48
47
MEMPHIS, TN
www.dunavant.com
KMA, i am having problems similar to those you have mentioned.

Every time i change my homepage on IE, it goes back every time to "about blank" This blank homepage never quits... Also i get icons on my desktop for "fast loans" and "online pharmacy" whenever i browse the internet. I delete them and they ALWAYS return with a different icon pic, but same name. I have deleted all cookies numerously, but it doesnt work. I am pretty sure it is some form of a virus. Can you help?
 

parlayinn

Registered User
Forum Member
Mar 15, 2001
824
1
0
if i disable all that stuff, does that mean there will be stuff i won't see when i browse the web that i would want to see?
 

macavoy

Registered User
Forum Member
Sep 4, 1999
302
0
0
Mesa, Arizona
can someone post a link to ad aware. My computer has been way slowed this weekend, not just my internet connction. Somethings got me.
 

KMA

Registered User
Forum Member
May 25, 2003
745
2
0
Wareagle,

You need sypbot search and destroy, and ad-aware to delete spyware from your system, then go back into your browser settings and reset your homepage. That should do it for you.
 

KMA

Registered User
Forum Member
May 25, 2003
745
2
0
System Recovery or system restore.
Click on Start
Programs
Accessories
System Tools and look for system restore.



Or, you could also change the date on the calendar and reset it to a date BEFORE you had the hijack.
 

Sportsaholic

Jack's Mentor
Forum Member
Jan 18, 2000
32,345
314
0
62
Crustacean Nation
KMA said:
Eddie Haskell try:


tools
internet options
clear history
delete cookies
delete files




Uou my have some spyware on your comp, it'd be a good idea to run ad-aware.

KMA, I used to be able to do this................now the screen to delete cookies/files is gone :shrug: now it takes me to internet properties.........................


Thanks
 

KMA

Registered User
Forum Member
May 25, 2003
745
2
0
Sportsaholic, are yah using IE???


Try goin to:
start
programs
accessories
systemtools
system information
and on the popup window select on the menu bar tools and select from that drop down Internet Explorer Repair Tool.
 
Last edited:

wareagle

World Traveler
Forum Member
Feb 27, 2001
5,712
40
48
47
MEMPHIS, TN
www.dunavant.com
KMA, well i did what you suggested and bought spyhunter. I was pleased to see after i ran the program that there where over 200 "parasites" on my computer, but only six of which where "severe". So i delete all from my computer, and it gets WORSE. Same problems as before: icons popping up on desktop, my homepage keeps changing to "about blank", and now mysterious porn websites start showing up on my favorites lists? I keep deleting and they keep returning. The problem is in the cookies, when i run the spyware it comes up with the same four everytime: doubleclick, centrport, bluestreak, and adtmt. I am about to throw this computer out the window. Any suggestions?
 

CryBoy

Registered User
Forum Member
Nov 12, 2000
2,853
27
48
Arlington, TX
wareagle

wareagle

I had almost the exact same problem and this is what I did (suggestion from KMA): Ran SpyBot then Ad-aware . I am not sure if that stopped the problem because I uninstalled internet explorer completely and then reinstalled.

I had ZoneAlarm before all take over. Guess that didn't help too much.

You might want to try Smart Protector . They give you a 15-day free trial period. It's enough clean out all your cookies.

Good luck.
 

KMA

Registered User
Forum Member
May 25, 2003
745
2
0
Wareagle,

Spybot Search and Destroy.
Ad-Aware.

Get a good popup blocker, that's how this crap starts.
 

wersty

Registered User
Forum Member
Jun 21, 2001
695
4
18
73
Jupiter, Florida
start bar

start bar

something has hit my home computer, running windows me and home page is gone and have no task bar on bottom of screen and can't find start in order to get to to systems accessories to try and fix--every time i try to get on internet unit just shuts down--help if possible-----in laymans terms--:rolleyes:
 
Last edited:

Franky Wright

Registered User
Forum Member
May 28, 2002
3,363
16
0
57
Heaven, oh!!, this isn't it?!
Help KMA!!!.........

Help KMA!!!.........

Well its happened to me........
I remembered this thread, and did a search(this feature worked great, thanks Jack), and found it.
I have upgraded to an almost new computer running XP, and now I have that damn "about blank", which has taken over my home web page.

KMA, I did everything you said in this thread, except the spybot search and destroy, I cant find that thing any where? I ended up scaning what I thought was it, turned out to be PAL Spyware Remover, which found 3 items, then wanted to charge me $30 to remove it.

I used to have spybot......know where I can find it again?

Thanks for all your help here!

Franky
P.S. what is a Neuroscience degree? LOL, sounds enticing, LOL!
 
Bet on MyBookie
Top