My operating system is Me.

I know I got it from a videogame emulating site because both times I went to the site I got the virus, I got rid of it once by using scanreg/restore under a command prompt or maybe I didn't get rid of it completely :-| ...

Now when I try to restore it only lets me go back a couple of days...why is that?

Also, I've tried Ad-Aware and Spy Bot but maybe I'm doing something wrong. Is this a common virus, the controlling the homepage thing?

Help, thanks in advance.

Dani AI

Generated

Short diagnosis and a safe plan of attack for a persistent IE homepage hijack on Windows Me (based on what described and pointing out that you should read the other thread).

Most homepage hijacks are small programs or browser components that set the Start Page value in the registry and reapply it on each boot. They can also install a helper object that prevents changes in Internet Explorer. If restore only offers very recent points, the OS backup/restore mechanism has a limited rotation and some malware also deletes older snapshots, so you may be getting reinfected from remaining startup objects or damaged system files.

Step-by-step practical checklist

  1. Work offline. Boot to Safe Mode (F8) and disconnect the network so the malware can’t re-download components.
  2. Backup personal files (documents, bookmarks). Export the registry before editing.
  3. Look for the homepage value and the launcher entries in the registry (for example, the Start Page setting under the Internet Explorer key) and export any suspicious keys before removing them. Search the registry for the hijacked URL — that often shows what sets it.
  4. Inspect startup locations (Startup folder, Run/RunOnce entries) and remove unknown entries. Check browser helper objects in the registry and remove only GUIDs you can identify as malicious — always back up first.
  5. Run a thorough scan from a clean environment: use a current, reputable offline rescue scanner or bootable rescue media (resident AVs can be disabled by the malware). Also run a disk check to rule out file-system damage.

When to cut losses
If security utilities report they are damaged or the infection keeps returning after removing startup entries, the system is very likely compromised at multiple points. The safest route then is to backup data and perform a clean reinstall of the OS, followed by current updates and a modern browser/antivirus.

Recommended Answers

All 2 Replies

Before going any further, please read this thread.
http://www.daniweb.com/techtalkforums/thread5690.html

If none of these suggestions help, then ask for assistance. It's more rewarding to help yourself than have someone do all of the work for you! :)

I actually fixed it once but I got the same problem from a similar website. I've fixed many issues already, before I couldn't even log in or even have my PC on for a certain amount of time, click on anything, etc...I would get a Close/Ignore prompt.

I've been messing around with it all day.

I will say this...

When I try to use Spy Blaster, which is an update for Spy Bot to block viruses, I get this error now (after using it once)...

This program has been damaged, possibly by a bad sector of the hard drive or a virus. Please reinstall it.

I don't know that much about security issues, I'm taking my first class at the Cisco Academy which started about two weeks ago.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.