Link to home
Start Free TrialLog in
Avatar of jerryvoss
jerryvoss

asked on

SafetyDefender

Each time I click on IE, safetydefender.com opens instead of my home page. The content says that I am under the control of a remote computer and the only way to fix this is to click a link that will sell me the removal tools,ie. Spyware and Malware removal software.

I have tried smitrem and smitfraudfix, but even though they say they are cleaning my machine, when I reboot and open IE, I still am at the safetydefender website.

Has anyone else encountered this and overcome it?
SOLUTION
Avatar of r-k
r-k

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of jerryvoss
jerryvoss

ASKER

Thank you, r-k

http://www.hijackthis.de/logfiles/4e922e2fda7987abd7d332297775bb9a.html

I hope this is the right way to post the link.

Jerry
That is the ight way, thanks.

I would suggest running HJT again and asking it fix the following entries:

 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
 O2 - BHO: Nothing - {edbf1bc8-39ab-48eb-a0a9-c75078eb7c8e} - C:\WINNT\system32\hpB1F9.tmp
 
Then reboot and re-run HJT to see if these entries are really gone. If so, the problem should be mostly solved and you should be able to reset you home page.
After rebooting, I ran HJT again.  Two of the entries are gone, and the BHO has changed, but is still there.

When I opened IE, it didn't open to "safetydefender.com,"  instead, there is an empty page with the address "about:blank" and when I try to reset my home page it returns to about:blank as soon as I leave the page.

I resubmitted the logfile from the latest scan. It is: http://www.hijackthis.de/logfiles/36da920c430d1c9d4e19b164242d18d1.html

How do I get rid of about:blank?

Thank you for your help.

Jerry
SOLUTION
Avatar of Naga Bhanu Kiran Kota
Naga Bhanu Kiran Kota
Flag of India image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Oh yeah, remove the entries that r-k suggested if they're still present after running the tool, :)

Ooops, the rougescanfix canned speech is a little outdated but the fix itself is also updated with removing the the re-spawner "C:\WINNT\system32\dcomcfg.exe"
Thank you all for your help.  I won't be able to try them until later in the day.

Jerry

Hi There, Check Out this link , Someone has the same problem    ;)

http://forums.techguy.org/security/461472-windows-xp-hijack-log-eliminate.html
Thank you all for your help!

After I ran the newer version of SmitFraudFix in Safe Mode, I got a message saying: "Cannot inport cleanup.reg:  Error accessing the registry" but when the text file came up at the end, it reported that the registry was cleaned.

I restarted the computer in normal mode, and IE opened up to MSN, and then I reset it to my normal home page.  I've opened and closed the browser several times, and it seems to be back to normal.  Again, thank you all very much!

Jerry
Glad to hear your problem's resolved.

Thanks, :)