Hijacked homepage

D

David H. Lipman

From: "Ibrahim" <[email protected]>

| Hello all
| My Homepage has been hijacked actually I don't know how this happened, I've
| just finished formating my PC
| the homepage now is http://www.freewebs.com/archbase/index.htm I cannot
| change it, everytime i restart my PC it goes back to this address.
| Please help
|

This post diod NOT need to be Cross-Posted to so many groups.
Nor did you have to post it twice in a five minute period !



If you are using any version of Sun Java that is prior to JRE Version 5.0,
then you are strongly urged to remove any/all versions that are prior to JRE/JSE
Version 5.0. There are vulnerabilities in them and they are actively being exploited.
It is possible that is how you got infected with malware.

Therefore, it is highly suggested that if there are any prior versions of Sun Java
to Version 5 on the PC that they be removed and Sun Java JRE/JSE Version 5.0 Update 7
be installed ASAP.

Simple check, look under...
C:\Program Files\Java

The only folder under that folder should be the latest version...

C:\Program Files\Java\jre1.5.0_07


http://www.java.com/en/download/manual.jsp



For non-viral malware...

Please download, install and update the following software...

* Ad-aware SE v1.06
http://www.lavasoft.de/
http://www.lavasoftusa.com/
http://www.lavasoft.de/ms/index.htm

* SpyBot Search and Destroy v1.4
http://security.kolla.de/
http://www.safer-networking.org/microsoft.en.html

* SuperAntiSpyware
http://www.superantispyware.com/superantispywarefreevspro.html

After the software is updated, I suggest scanning the system in Safe Mode.

I also suggest downloading, installing and updating BHODemon for any Browser Helper Objects
that may be on the PC.

* BHODemon

http://www.majorgeeks.com/downloadget.php?id=3550&file=11&evp=245a87539eea8ed6904332b4b8b8442d

For viral malware...

* Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.

You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
file. http://www.ik-cs.com/multi-av.htm

Additional Instructions:
http://pcdid.com/Multi_AV.htm


* * * Please report back your results * * *
 
K

Kerry Brown

If you formatted your pc and installed a version of XP prior to SP2 then
that is why you are infected. With versions of XP prior to SP2 if you are
connected to the Internet during the install you will be infected before the
install is finished. You need a firewall active before you connect to the
Internet. This means physically unplugging the cable to your modem.
 
J

Jay

Ibrahim said:
Hello all
My Homepage has been hijacked actually I don't know how this happened,
I've
just finished formating my PC
the homepage now is http://www.freewebs.com/archbase/index.htm I cannot
change it, everytime i restart my PC it goes back to this address.
Please help

You have mass-cross posted (3 times), you have repeated the question after a
few minutes and now you post again despite already having had your question
answered.
Do you check your threads or just keep reposting in the hope that someone
will email you?

Jay
 
G

Guest

Ping - David H Lipman or Anyone else that knows

Is it ok to delete;

J2SE Runtime Enviroment 5.0
J2SE Runtime Enviroment 5.0 update 4
J2SE Runtime Enviroment 5.0 update 6

if I have

J2SE Runtime Enviroment 5.0 update 7

Are the updates cumulative, that is update 7 includes all
updates1-6 in it, so its ok to delete old updates 1 - 6.



David H. Lipman said:
From: "Ibrahim" <[email protected]>

| Hello all
| My Homepage has been hijacked actually I don't know how this happened, I've
| just finished formating my PC
| the homepage now is http://www.freewebs.com/archbase/index.htm I cannot
| change it, everytime i restart my PC it goes back to this address.
| Please help
|

This post diod NOT need to be Cross-Posted to so many groups.
Nor did you have to post it twice in a five minute period !



If you are using any version of Sun Java that is prior to JRE Version 5.0,
then you are strongly urged to remove any/all versions that are prior to JRE/JSE
Version 5.0. There are vulnerabilities in them and they are actively being exploited.
It is possible that is how you got infected with malware.

Therefore, it is highly suggested that if there are any prior versions of Sun Java
to Version 5 on the PC that they be removed and Sun Java JRE/JSE Version 5.0 Update 7
be installed ASAP.

Simple check, look under...
C:\Program Files\Java

The only folder under that folder should be the latest version...

C:\Program Files\Java\jre1.5.0_07


http://www.java.com/en/download/manual.jsp



For non-viral malware...

Please download, install and update the following software...

* Ad-aware SE v1.06
http://www.lavasoft.de/
http://www.lavasoftusa.com/
http://www.lavasoft.de/ms/index.htm

* SpyBot Search and Destroy v1.4
http://security.kolla.de/
http://www.safer-networking.org/microsoft.en.html

* SuperAntiSpyware
http://www.superantispyware.com/superantispywarefreevspro.html

After the software is updated, I suggest scanning the system in Safe Mode.

I also suggest downloading, installing and updating BHODemon for any Browser Helper Objects
that may be on the PC.

* BHODemon

http://www.majorgeeks.com/downloadget.php?id=3550&file=11&evp=245a87539eea8ed6904332b4b8b8442d

For viral malware...

* Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.

You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
file. http://www.ik-cs.com/multi-av.htm

Additional Instructions:
http://pcdid.com/Multi_AV.htm


* * * Please report back your results * * *
 
D

DL

These are somewhat missdescribed as updates, they are actually
v5.0
v5.0.4
v5.0.6
and finally v5.0.7
They are not deleted during the installation of the latest version simply to
give compatibilty, should you run something not compatible with a later
version.
They can be removed.

Grumpy said:
Ping - David H Lipman or Anyone else that knows

Is it ok to delete;

J2SE Runtime Enviroment 5.0
J2SE Runtime Enviroment 5.0 update 4
J2SE Runtime Enviroment 5.0 update 6

if I have

J2SE Runtime Enviroment 5.0 update 7

Are the updates cumulative, that is update 7 includes all
updates1-6 in it, so its ok to delete old updates 1 - 6.



David H. Lipman said:
From: "Ibrahim" <[email protected]>

| Hello all
| My Homepage has been hijacked actually I don't know how this happened, I've
| just finished formating my PC
| the homepage now is http://www.freewebs.com/archbase/index.htm I cannot
| change it, everytime i restart my PC it goes back to this address.
| Please help
|

This post diod NOT need to be Cross-Posted to so many groups.
Nor did you have to post it twice in a five minute period !



If you are using any version of Sun Java that is prior to JRE Version 5.0,
then you are strongly urged to remove any/all versions that are prior to JRE/JSE
Version 5.0. There are vulnerabilities in them and they are actively being exploited.
It is possible that is how you got infected with malware.

Therefore, it is highly suggested that if there are any prior versions of Sun Java
to Version 5 on the PC that they be removed and Sun Java JRE/JSE Version 5.0 Update 7
be installed ASAP.

Simple check, look under...
C:\Program Files\Java

The only folder under that folder should be the latest version...

C:\Program Files\Java\jre1.5.0_07


http://www.java.com/en/download/manual.jsp



For non-viral malware...

Please download, install and update the following software...

* Ad-aware SE v1.06
http://www.lavasoft.de/
http://www.lavasoftusa.com/
http://www.lavasoft.de/ms/index.htm

* SpyBot Search and Destroy v1.4
http://security.kolla.de/
http://www.safer-networking.org/microsoft.en.html

* SuperAntiSpyware
http://www.superantispyware.com/superantispywarefreevspro.html

After the software is updated, I suggest scanning the system in Safe Mode.

I also suggest downloading, installing and updating BHODemon for any Browser Helper Objects
that may be on the PC.

* BHODemon

http://www.majorgeeks.com/downloadget.php?id=3550&file=11&evp=245a87539eea8ed6904332b4b8b8442d

For viral malware...

* Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.

You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
file. http://www.ik-cs.com/multi-av.htm

Additional Instructions:
http://pcdid.com/Multi_AV.htm


* * * Please report back your results * * *
 
D

David H. Lipman

From: "Grumpy" <[email protected]>

| Ping - David H Lipman or Anyone else that knows
|
| Is it ok to delete;
|
| J2SE Runtime Enviroment 5.0
| J2SE Runtime Enviroment 5.0 update 4
| J2SE Runtime Enviroment 5.0 update 6
|
| if I have
|
| J2SE Runtime Enviroment 5.0 update 7
|
| Are the updates cumulative, that is update 7 includes all
| updates1-6 in it, so its ok to delete old updates 1 - 6.
|
|

Keep: J2SE Runtime Enviroment 5.0 update 7

Remove all others from the Control Panel applet; "Add/Remove Programs"
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top