Page 1 of 1

Internet exsploorer home page problem

PostPosted: Sun Jun 27, 2004 7:14 pm
by venney
Hey every 1, i need help. my home page keeps returning back 2 blank. i keep changing it back to www.yahoo.com but every single time i open my exsploorer it doesnt go to yahoo.com it goes tot eh balnk search thing. ive tryed adding yahoo.com to my favourates, then going thru my pc, finding it, moving the ikon 2 my desktop, chanigng it to internet exsploorer n chanignign the ikon so it looks like it but then i cant remove the origonal from my desktop. please can some one help me. ive used about 3 different programs to remove spy ware. is it maby a virus? i dont know why it has done it. please help! thank u. :)

PostPosted: Sun Jun 27, 2004 7:24 pm
by Ranger Bob
What operating system are you running and version of IE? Are you running any malware protection software applications such as Adaware, SpyBot, SpywareBlaster, or other software that might protect your homepage?

PostPosted: Sun Jun 27, 2004 7:31 pm
by venney
ok u r soo completle rite.lol i have all 3 of them softwares. ive allways had adaware installed and thats been fine but i installed the other 2 yesterday. im running xp and ie erm... the latest 1 i think. should i uninstall the 2 new programs? will that set it normal? pleaser write back :)

PostPosted: Sun Jun 27, 2004 8:34 pm
by Ranger Bob
Does IE allow you to change the homepage or is it grayed out?

PostPosted: Sun Jun 27, 2004 8:43 pm
by venney
i can change it, as in u normally woudl from yahoo to lycos, and the first time sometimes i open the ie after changing it back to yahoo it works, but then the next time i open it, it goes back to the blank. i think i may uninstall spykiller as thinking bout it i only installed it like 2 days ago n now its messed up. and u did say that. its not a big loss 2 me. i still have adaware. what do u think i should do? please help :)

PostPosted: Sun Jun 27, 2004 9:20 pm
by Ranger Bob
I don't know anything about SpyKiller so if it has the ability to lock the webpage then this might be your problem. If not then I would advise that you go to the below link and read brads instructions on running HijackThis and do exactly everything that he says and then post the log as a reply to this thread. If I knew you are not running Windows XP I would recommend that you run CWShredder but since I don't know that I will hold off on that until I see the HJT log.

modules.php?name=Forums&file=viewtopic&t=2253

PostPosted: Sun Jun 27, 2004 10:14 pm
by venney
ok heres my log from hijackthis

Logfile of HijackThis v1.97.7
Scan saved at 22:10:26, on 27/06/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\Firewall\PavFires.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\pavsrv51.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\AVENGINE.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Panda Software\Panda Antivirus Platinum\apvxdwin.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\Dit.exe
C:\WINDOWS\System32\GSICON.EXE
C:\WINDOWS\System32\dslagent.exe
C:\Program Files\Logitech\ImageStudio\LogiTray.exe
C:\WINDOWS\System32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\POPUPS~1.EXE
C:\WINDOWS\DitExp.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\pavProxy.exe
C:\Program Files\Logitech\ImageStudio\LowLight.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\BitTorrent\btdownloadgui.exe
C:\Program Files\BitTorrent\btdownloadgui.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\ALCFDRTM.EXE
C:\Documents and Settings\Lawrence\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R3 - URLSearchHook: {1A03F196-9617-4CA0-842B-A83CEECB022B} - - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {09F54714-AFA6-93A2-957C-B725AB1A7A3F} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {6D6773DE-4814-4E35-BE28-21261EAD56F3} - C:\WINDOWS\System32\icapnlh.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: SuperBar - {87377221-FAB9-454C-9148-EB4E105AB3F5} - C:\Program Files\_SUPERBAR\_SUPERBAR.dll (file missing)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [] C:\WINDOWS\Options\OEMReset.exe /Audit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [VOBRegCheck] C:\WINDOWS\System32\VOBREGCheck.exe -CheckReg
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [FOUR STORE] C:\PROGRA~1\BLEHWI~1\default frag.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files\Panda Software\Panda Antivirus Platinum\Inicio.exe"
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus Platinum\APVXDWIN.EXE" /s
O4 - HKCU\..\Run: [PopUpStopperProfessional] "C:\PROGRA~1\PANICW~1\POP-UP~1\POPUPS~1.EXE"
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: CoolMP3 (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} (Microsoft Office Template and Media Control) - http://office.microsoft.com/templates/ieawsdc.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shoc ... w-intl.cab
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) - http://download.microsoft.com/download/ ... 3327421984
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {2DBEFB64-B6C4-4A2C-BE6A-16FF065B99C6} (cuadruple Class) - http://www.dialerzona.com/cuadruple.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) - https://webresponse.one.microsoft.com/o ... winrep.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/share ... insctl.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/10638657fbb079c9ec ... xIE601.cab
O16 - DPF: {88C51E90-8E9C-4C96-8A45-574D88B63FAF} - http://acceso.masminutos.com/laaplicacion.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... Client.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/C ... 2074421296
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shoc ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{013A7D65-1582-4014-AE65-D077E2EE15BC}: NameServer = 194.72.9.38 194.74.65.69
O17 - HKLM\System\CS1\Services\Tcpip\..\{013A7D65-1582-4014-AE65-D077E2EE15BC}: NameServer = 194.74.65.69 194.72.9.38
O17 - HKLM\System\CS3\Services\Tcpip\..\{013A7D65-1582-4014-AE65-D077E2EE15BC}: NameServer = 194.72.9.38 194.74.65.69

please help me, ive uninstalled the softwarte i had, like spybot n spysweep n i still have the same problem. i really need 2 sort it out its really annoying me. thank u
Write back :)

PostPosted: Sun Jun 27, 2004 11:22 pm
by Ranger Bob
You might want to take a look at the link below. SUPERBAR is an adware program which you may or may not want on your PC.

http://www.pestpatrol.com/PestInfo/S/SuperBar.asp

Are you running either two AV or firewall programs? Did you run both Adaware and SpyBot before taking this HijackThis scan? You don't want to uninstall SpyBot. Go ahead and download CWShredder from the link I provided on brads instructions but don't run it until you have replied that you have run both Adaware and SpyBot and you still have the problem.

PostPosted: Sun Jun 27, 2004 11:45 pm
by venney
ok i cant find the "CWShredder" link on ether this page or brads page. plz can i have it again. also yes and ive done it again, i scanned with both ad aware and spybot and nouthing new was found,e very thing i found on there i cleared. i wanna get rid of that superbar and i wanna do n e thing to fix this stupid blank thing coming up. also i wasnt aware i had 2 firewalls running. i only want 1. how do i stop the other. i want the panda anti virus 1 running. plz give me instructions on wat 2 do with "CWShredder" as well plz. thank u. write back please
:)

PostPosted: Mon Jun 28, 2004 12:45 am
by Ranger Bob
Sorry about that. I thought brad had the link of CWShredder in his instruction. Her is the download link for it:

http://www.spywareinfo.com/~merijn/files/cwshredder.zip

Once you download the file, unzip it into a folder and run the program. Click on the fix button in the program not the scan button.

The link I provided above on Superbar has the instructions for the removal of Superbar on it.

I was only asking about two AV or firewall programs to find out if you happen to have two installed or not.

Once you have run CWShredder run a new HJT scan and post it back to the thread.

PostPosted: Mon Jun 28, 2004 2:48 pm
by brad
This is why I don't post the Link to CWS:
Running CWShredder when there are no known CWS Variants can cause some Trojan files to become fragmented and thus harder to remove.

First:

**(Always create a Folder for HiJackThis anywhere but your Temp/Temporary Internet Folders. This is where it will save the backup files needed if there's a problem.)**

Unless you paid for Spykiller, I'd do the following
Then follow these instructions for the entrees that remain in HJT:

Press Ctrl/Alt/Del and "End Task" or "End Process" on each of the following: (They may or may not be there)

spykiller.exe

Turn off System Restore. (Turn it back on after this is repaired and you've rebooted.) Close all other open Windows and have HiJackThis Fix:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R3 - URLSearchHook: {1A03F196-9617-4CA0-842B-A83CEECB022B} - - (no file)
O2 - BHO: (no name) - {09F54714-AFA6-93A2-957C-B725AB1A7A3F} - (no file)
O2 - BHO: (no name) - {6D6773DE-4814-4E35-BE28-21261EAD56F3} - C:\WINDOWS\System32\icapnlh.dll
O3 - Toolbar: SuperBar - {87377221-FAB9-454C-9148-EB4E105AB3F5} - C:\Program Files\_SUPERBAR\_SUPERBAR.dll (file missing)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [] C:\WINDOWS\Options\OEMReset.exe /Audit
O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
O16 - DPF: {2DBEFB64-B6C4-4A2C-BE6A-16FF065B99C6} (cuadruple Class) - http://www.dialerzona.com/cuadruple.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/10638657fbb079c9ec ... xIE601.cab


Go to Control Panel / Add/Remove Programs and remove the following if they are there:

Spykiller
SUPERBAR


Now delete these Folders or Files that are Highlighted: (You may need enable "Show all Files" and disable "Hide System Files" in Windows Explorer / Tools / Folder Options / View Tab) (You may have to boot to "Safe Mode" in order to delete some Files/Folders)

C:\WINDOWS\System32\icapnlh.dll
C:\Program Files\SpyKiller
C:\Program Files\_SUPERBAR

Now, empty all your TEMP Folders (WinXp has up to 4 of them) / Temporary Internet Files Folder and then empty your "Recycle Bin" and reboot.

brad

PostPosted: Tue Jun 29, 2004 1:52 am
by venney
ok, thnak u both, but for the moment brad that seems very complicated. what im doing right now is ive downlaoded a trail of pestpatrol n im scanning so i can rmeove the superbar. n damn its finding alot of things. also after this has done im going 2 downlaod CWShredder and
run a new HJT scan and post it on here and hopefully 1 of you 2 or even both can help me from there. i do really apprichate all this. if this doesnt fix my ie problem what do u recon we could do? or shal we cross that bridge if we get to it? thanks again! write back, or wait for my to do my post of the report of the scan. thanks. :)

PostPosted: Tue Jun 29, 2004 11:29 am
by venney
ok good news! pest partol fixed my problem! now it is fine. thank you very much, you guys r alot better than ringin 1 of these pricey phone lines! thanks a bunch, if i need help im looking 2 u! thank u again :)