Cannot change MSN Home Page

Discussion in 'Malware Help (A Specialist Will Reply)' started by sab2624, Dec 26, 2005.

  1. sab2624

    sab2624 Private E-2

    Hello,

    I believe I have some spyware infecting my system, but have spent all day trying to fix without any luck.

    Problem: Every time I try to change my default home page to something new, it changes back to MSN after a reboot. My default setting used to work at one time.

    Steps I have taken:

    1) Tried changing the setting in IE using web default reset and deleting old history, files, etc. No luck.

    2) Followed the tutorial step by step. Scans did not find anything while in safe mode. Ran all scans including sCWhredder and Kill2me without luck.

    3) Interesting issues I did find. Ran the Hijack This scan. There is an entry under R0 that does not look correct, but it does not refer to a website. Also, while checking under configuration in Hijack the default home page came up as about:blank.

    4) Did run About Buster without any luck.

    Any help would be appreciated.
     

    Attached Files:

  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download L2MeFix Tool and save it where you will be able to find it.

    Please print out these instructions now or save locally so that you can operate with All Browser Windows CLOSED.

    Exit Browsers now before continuing

    Please move the L2MeFix Tool to your Desktop and DoubleClick l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix Folder on your Desktop. DoubleClick l2mfix.bat and Type 1 and ENTER to select Option #1 for Run Find Log . Allow it as much time as it needs to run until NotePad opens with a log. Save this log. You will need to post this log back here later when you come back.
    Next DoubleClick l2mfix.bat and type 2 and ENTER to select option #2 for Run Fix. Then, press any key to Reboot your machine.

    Your computer will go crazy for a bit, but just let it run. It should eventually spit out a log in Notepad. Please also attach this log to your next message.

    Now open your browser and come back here and post the above two logs as attachments to your message. Also indicate your current status.


    NOTE: Please do not run any other options or files in the l2mfix Folder!
     
  3. sab2624

    sab2624 Private E-2

    Ok....ran L2MeFixTool with the following reports attached.
     
  4. sab2624

    sab2624 Private E-2

    Sorry files attached.
     

    Attached Files:

  5. sab2624

    sab2624 Private E-2

    Just discovered another interesting behavior. Windows XP does not retain the default printer that I set after a reboot. Basically my home page and default printer get reset after a restart. Do not know if they are related.
     
  6. sab2624

    sab2624 Private E-2

    Well I have solved the issue.

    I have discovered that my IBM Thinkpad has a profile setup under "IBM Acess Connections" (wireless access) with defaults set for Start Pages and Printers. Unless I do not select to turn off those defaults they override IE settings. Once I turned them off everything came back to normal.:) Thanks.
     
  7. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Glad you got your problem fixed, there were a few issues you I noticed in your log if you would like to procede with the cleaning.

    Let me know!
     
  8. sab2624

    sab2624 Private E-2

    Yes, please advise if there are some other items I should clean and how. Thanks.
     
  9. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Attach a fresh HJT log.
     
  10. sab2624

    sab2624 Private E-2

    Here is the fresh log.
     

    Attached Files:

  11. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Scan with HijackThis and Check the Boxes for the following:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/4h/player.virtools.com/downloads/player/Inst all3.0/Installer.exe

    Make sure All Browser Windows are Closed when you Click FIX.

    NEXT:
    Run CCleaner to clean up cookies and temp files.

    Run full scans with Ad-Aware SE & Spybot S&D and have both programs fix what they find.
    Note: Remember to get all updates before doing the scans.


    After you complete the above your log will be clean, reboot and let me know how things are running.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds