Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
IE Startup Page Always Modified...HiJackThis Log Attached
   
BullGuard Antivirus Forum > Virus Removal > Removal Help > IE Startup Page Always Modified...HiJackThis Log Attached  
Forum Quick Jump
 
New Topic Post reply to : IE Startup Page Always Modified...HiJackThis Log Attached Printable version of : IE Startup Page Always Modified...HiJackThis Log Attached
[ << Previous Thread | Next Thread >> ]

krywar
New Member


Date Joined Sep 2004
Total Posts : 1
 
   Posted 9-28-2004 3:42 (GMT +1)    Quote: IE Startup Page Always Modified...HiJackThis Log AttachedAlert an admin about: IE Startup Page Always Modified...HiJackThis Log Attached
   The Internet Explorer startup page is always changed to a page not specified by me.  Changing the IE settings help for the current work day but upon restart of the computer, the page is set back again.  Spybot and Adaware have both been used to no avail.  Any help would be greatly appreciated.  I have attached the HiJackThis log.Thanks for your time.
 
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\appea.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\NavNT\vptray.exe
C:\WINDOWS\ieko32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Nikon\NkView6\NkvMon.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\yvlpc.dll/sp.html#22776
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\yvlpc.dll/sp.html#22776
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://yvlpc.dll/index.html#22776
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://yvlpc.dll/index.html#22776
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\yvlpc.dll/sp.html#22776
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\yvlpc.dll/sp.html#22776
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\yvlpc.dll/sp.html#22776
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://yvlpc.dll/index.html#22776
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\yvlpc.dll/sp.html#22776
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.uchase.com/directory.php?a=1006
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\yvlpc.dll/sp.html#22776
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {32FBCE5B-436D-3987-125B-379933C8F470} - C:\WINDOWS\atlcl.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [ieko32.exe] C:\WINDOWS\ieko32.exe
O4 - HKLM\..\RunOnce: [appuz.exe] C:\WINDOWS\system32\appuz.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &iSearch The Web - res://C:\WINDOWS\System32\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 14350
 
   Posted 9-28-2004 5:08 (GMT +1)    Quote: IE Startup Page Always Modified...HiJackThis Log AttachedAlert an admin about: IE Startup Page Always Modified...HiJackThis Log Attached
Hey krywarcool
 
Please download AboutBuster: http://tools.zerosrealm.com/AboutBuster.zip
Just unzip to Desktop.
Scanner  http://www.mwti.net/antivirus/free_utilities.asp
Choose one of the first seven links.

 
Leave the programs.
 
 
 
 
Please print out the remainder of these directions, as you'll have to proceed in Safe Mode.  Now, disconnect to the net.
 
Go to Taskmanager ctrl+alt+del Processes, find:
ieko32.exe
appuz.exe
Rightclick on them-end proces
 
Start-run, type:regedit
Find- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
check for a key called-HOMEOldsp, if present- delete it.
And if you have some files in searchpage/searchbar which end with …\sp delete them
Go to Edit in registry and type - HOMEOldsp. Click-Find Next, delete it-if present.
Use F3 for search more, if you find more- delete them.
Same procedure with-About:blank
Close Registry.
 
Reboot to Safe Mode - F8

Scan with HijackThis , close all other windows and browsers, and place a checkmark next to these items, and fix:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\yvlpc.dll/sp.html#22776
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\yvlpc.dll/sp.html#22776
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://yvlpc.dll/index.html#22776
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://yvlpc.dll/index.html#22776
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\yvlpc.dll/sp.html#22776
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\yvlpc.dll/sp.html#22776
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\yvlpc.dll/sp.html#22776
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://yvlpc.dll/index.html#22776
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\yvlpc.dll/sp.html#22776
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.uchase.com/directory.php?a=1006
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\yvlpc.dll/sp.html#22776
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {32FBCE5B-436D-3987-125B-379933C8F470} - C:\WINDOWS\atlcl.dll
O4 - HKLM\..\Run: [ieko32.exe] C:\WINDOWS\ieko32.exe
O4 - HKLM\..\RunOnce: [appuz.exe] C:\WINDOWS\system32\appuz.exe
 
 
find and delete these files:
C:\WINDOWS\system32\yvlpc.dl<<If present
C:\WINDOWS\atlcl.dll<<If present
C:\WINDOWS\ieko32.exe
C:\WINDOWS\system32\appuz.exe
 
Double click the AboutBuster.exe file. Click OK, then click Start, then click OK.
 This will scan your computer for the bad files and delete them. Save the report it creates (copy and paste it into notepad  and save as a .txt file).
 
Run Ccleaner, put a checkmark to Temporary internet files, cookies, History, Empty Recycle bin, Temporary files, Old Prefetch Data
 
 
Run Adware
we need to configure Ad-aware SE for a full scan. Some of them should be enabled by default, while others you will need to set yourself (see below).
Click on the Gear icon (second from the left) to access the preferences/settings window
   In the General window make sure the following are selected:
 Automatically save logfile
 Automatically quarantine objects prior to removal
 Safe Mode (always request confirmation)
Click on the Scanning button on the left and select :
 Scan within archives
 Scan active processes
 Scan registry
-Deep-scan registry
 Scan my IE Favorites for banned URLs
 Scan my Hosts file
Under Select drives & folders to scan, choose:
 Select all of your hard drives that are not selected already
Click on the Advanced button on the left and select:
 Include additional object information
Include negligible objects information
Include environment information
Click the Tweak button and select:
Under the Scanning Engine:
    Unload recognized processes & modules during scan
Under the Cleaning Engine:Let Windows remove files in use at next reboot
Click on Proceed to save the settings.
Click Start and on the next screen choose:
 Use custom scanning options

Click Next and Ad-aware will scan your hard drive(s) with the options you have selected.
Save the log file when it asks and then click Finish.
When finished, mark everything for removal and get rid of it. (Right-click on any of the entries and choose Select All from the drop down menu and click Next).
 
 
Now run the Scanner, you downloaded from Microworld.
Activate all in settings
 
Reboot, this should be your first reboot! If you need updates: : http://v5.windowsupdate.microsoft.com/v5consumer/default.aspx?ln=en

Update Hijackthis, or download a new version: http://www.softpedia.com/public/cat/10/17/10-17-69.shtml


 post new log, with AboutBuster log
---------------------------------------------------------------------------
 

 



     Touch
 
Proud member of:
Back to Top
 
New Topic Post reply to : IE Startup Page Always Modified...HiJackThis Log Attached Printable version of : IE Startup Page Always Modified...HiJackThis Log Attached
 
Forum Information
Currently it is Friday, January 09, 2009 10:24 PM (GMT +1)
There are a total of 66.008 posts in 16.187 threads.
In the last 3 days there were 19 new threads and 110 reply posts. View Active Threads
Who's Online
This forum has 27804 registered members. Please welcome our newest member, revmrf.
62 Guest(s), 1 Registered Member(s) are currently online.  Details
LapinBlanc
5 Latest Threads
Google redirect virus help (6)09-01-2009 20:36:39 (phinfan)
Connection to server timeout (0)09-01-2009 20:35:36 (revmrf)
Hijackthis (2)09-01-2009 19:41:14 (fingers101)
Need help with removing viruses ∼tmpa and ∼tmpc!!! (4)09-01-2009 19:26:11 (Strummer89)
Virus help needed (10)09-01-2009 19:23:22 (msmat999)