Hello. My concern is simular to a concern that has aleady been posted here. This involves I can't change the homepage for IE7; it keeps redirecting to
www.msn.com. [Reference Info in this forum:02.19.2007 at 09:14PM PST, ID: 22400171.] I am having the simular issue. My Internet Explorer 7's homepage has been either hijacked or some setting in some program is prohibiting me in changing the homepage. These are the softwares that I have used to try to combat/correct this: Norton Internet Secuirty 2007, Ad-Aware Pro SE, CounterSpy v.2, Spybot v.1.5, SuperAntiSpyware. The 2 latter ones are free versions. I run a nightly anti-spyware scan with CounterSpy v.2 and also have it running constant active protection on my system. I recall a couple of days ago seeing in my quarantine list 2 Trojan Horses that had something to do with changing homepages. I did not write down the names of these Trojans, but assumed that CounterSpy got them! Done deal! Since yesterday, is when I get this homepage changing.I have ran Norton Internet Security 2007 (which also is active on my system at all times). I did not get any viruses or malware postings. it was all clean. I have run Ad-Aware found several things. They all had a Trac Rating (per Ad-aware) of 3 or posed no threat. I deleted them ALL anyways. CounterSpy also found spyware and I deleted them as well. It had 308 detections to be removed. I removed them as well. I downloaded & ran Spybot 1.5 last night and it found cookie trackers and other little things. Nothing serious.They were deleted too. SuperAntiSpyware (free version), found 12 cookie trackers and 2 ClickSpring spywares. I see that since I have performed these scans, the homepage is still getting changed. Cannot stop the IE 7 page homepage from being
www.msn.com. In Internet Options I change to
http://start.verizon.net or anything else, and it redirects to
www.msn.com after a slight hang as it is loading with following link:
http://go.microsoft.com/fwlink/?LinkId=69157. I have used BHODemon 2.0 and I disable all the BHO items in the listing giving control over to this application. Still I get MSN as the homepage at times. If I go directly into IE 7 and disable add-ons there and also use BHO Demon, sometimes I get my desired homepage. I notice this even more so after I reboot. When it is working fine, and I as soon as I click on Registry Repair Wizard to run it, I get a message from both Sybot & SuperAntiSpyware that my homepage is being changed to MSN and a request to either accept or decline since they have homepage protection with IE7 (somehow by clicking on Registry Repair Wizard 2007triggers the homepage to change???) If I click decline, both applications keep popping up a window asking me again. If I click accept for both applictions, it stops. However, I get MSN as my unwanted homepage.
I have tried changing the registry: HKEY_CURRENT_USER\Software
\Microsoft
\Internet Explorer\Main and changing the Start Page value to: http//:start.verizon.net. I immediately get the confirmation from both applications regarding a homepage change. I accept. Then when I go to open IE7, it still "About:blank". Then I think I am getting somewhere. So I go back inot the homepage settings in IE7 and it says
http://start.verizon.net, even though it says About:blank in the address bar. Keep changing it to
http://start.verizon.net though IE7 settings, closing the browser and after a couple of tries of opening and closing IE7, my homepage
http://start.verizon.net shows. In the midst of all this, both Spybot & SuperAntiSpyware ask me about my homepage change. I accept. Now all is good. This is true sometines. Sometimes I get Verizon home page that I want. Sometimes I do not get About:blank and I get MSN. Once I click to open the interactive seem Registry Repair Wizard 2007, I get a message from Spybot & SuperAntiSpyware that my homepage is being changed back to MSN again. I click accept to avoid the continual popups of asking me. Now I am back to MSN.
I have said a lot here to comprehend in first contact. If you have any more questions please reply. Please help me with a solution. I have Windows XP SP2. I am communicating with Opera web browser. There seems to be no effect in Opera with this problem. Everything else on my computer "seems" to be working okay. Please reply ASAP. I have added the report from HijackThis here for your inspection:
Logfile of HijackThis v1.99.1
Scan saved at 10:59:25 AM, on 10/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\Ati2ev
xx.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\Ati2ev
xx.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.ex
e
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\Symantec\LiveUpdate\
ALUSchedul
erSvc.exe
C:\Program Files\Intel\IDU\awServ.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI\Catalyst Media Center\Kernel\TV\CLCapSvc.
exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\ATI\Catalyst Media Center\Kernel\CLML_NTServi
ce\CLMLSer
ver.exe
C:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\Program Files\Raxco\PerfectDiskRx\
PD9Engine.
exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSSv
c.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Raxco\PerfectDiskRx\
PerfectDis
kRx.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSTr
ay.exe
C:\PROGRA~1\Yahoo!\YOP\yop
.exe
C:\Program Files\Common Files\InstallShield\Update
Service\IS
USPM.exe
C:\WINDOWS\system32\svchos
t.exe
C:\Program Files\VisualTaskTips\Visua
lTaskTips.
exe
C:\WINDOWS\system32\ctfmon
.exe
C:\Program Files\DigiPortal Software\ChoiceMail\Choice
Mail.exe
C:\Program Files\DigiPortal Software\ChoiceMail\Choice
Mail.exe
C:\Program Files\Raxco\PerfectDiskRx\
PDCleaner.
exe
C:\Program Files\Raxco\PerfectDiskRx\
PDState.ex
e
C:\Program Files\DigiPortal Software\ChoiceMail\CMServ
er.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\DigiPortal Software\ChoiceMail\CMServ
er.exe
C:\Program Files\Raxco\PerfectDiskRx\
PD9Agent.e
xe
C:\Program Files\SUPERAntiSpyware\SUP
ERAntiSpyw
are.exe
C:\WINDOWS\system32\driver
s\WDelMgr2
0.exe
C:\Program Files\Webroot\Washer\Washe
rSvc.exe
C:\Program Files\Logitech\SetPoint\Se
tPoint.exe
C:\Program Files\ATI\Catalyst Media Center\Kernel\TV\CLSched.e
xe
C:\WINDOWS\system32\Search
Indexer.ex
e
C:\PROGRA~1\Yahoo!\browser
\ycommon.e
xe
C:\Program Files\Common Files\Logitech\KhalShared\
KHALMNPR.E
XE
C:\Program Files\Opera\Opera.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.ex
e
C:\Documents and Settings\e-MAIL\Applicatio
n Data\Opera\Opera\profile\c
ache4\temp
orary_down
load\hijac
kthis_sfx.
exe
C:\Program Files\HijackThis\HijackThi
s.exe
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,CustomizeS
earch =
R1 - HKCU\Software\Microsoft\In
ternet Connection Wizard,ShellNext =
http://go.microsoft.com/fwlink/?LinkId=74005R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Window Title = Microsoft Internet Explorer
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7
695ECA0567
0} - C:\Program Files\Yahoo!\Companion\Ins
talls\cpn\
yt.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D
42A53123C7
5} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.
5\NppBho.d
ll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-2
06D7942484
F} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2
FC0DE4A789
7} - C:\PROGRA~1\Yahoo!\Common\
yiesrvc.dl
l
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0
BBC1D38A37
E} - C:\PROGRA~1\MICROS~2\Offic
e12\GRA8E1
~1.DLL
O2 - BHO: TwcToolbarBhoApp Class - {AA1F9DDB-E605-4ba6-81D4-E
427DEE012A
D} - C:\WINDOWS\system32\TwcToo
lbarBho.dl
l
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-C
E66B5AD205
D} - C:\Program Files\Google\GoogleToolbar
Notifier\2
.0.301.716
4\swg.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A
6CCDF9CBF6
D} - C:\Program Files\Yahoo!\browser\YSide
barIEBHO.d
ll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
2.dll
O3 - Toolbar: The Weather Channel Toolbar - {2E5E800E-6AC0-411E-940A-3
69530A35E4
3} - C:\WINDOWS\system32\TwcToo
lbarIe7.dl
l
O3 - Toolbar: Copernic Agent - {F2E259E8-0FC8-438C-A6E0-3
42DD80FA53
E} - C:\Program Files\Copernic Agent\CopernicAgentExt.dll
O3 - Toolbar: Copernic Desktop Search 2 - {968631B6-4729-440D-9BF4-2
51F5593EC9
A} - C:\Program Files\Copernic Desktop Search 2\DesktopSearchBand2526.dl
l
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-F
BEE9C7B26D
F} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.
5\UIBHO.dl
l
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} - C:\Program Files\Yahoo!\Companion\Ins
talls\cpn\
yt.dll
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [PerfectDiskRx] C:\Program Files\Raxco\PerfectDiskRx\
PerfectDis
kRx.exe /tray /startrun
O4 - HKLM\..\Run: [SBCSTray] C:\Program Files\Sunbelt Software\CounterSpy\SBCSTr
ay.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCt
r\Binaries
\MSConfig.
exe /auto
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop
.exe /autostart
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\Update
Service\IS
USPM.exe" -scheduler
O4 - HKCU\..\Run: [TransBar] C:\Program Files\AKSoftware\TransBar\
TransBar.e
xe /s
O4 - HKCU\..\Run: [VisualTaskTips] C:\Program Files\VisualTaskTips\Visua
lTaskTips.
exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKCU\..\Run: [ChoiceMail] "C:\Program Files\DigiPortal Software\ChoiceMail\Choice
Mail.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUP
ERAntiSpyw
are.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\Se
tPoint.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.5.0_11\bin
\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.5.0_11\bin
\ssv.dll
O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-5
1FB2220DF8
0} - C:\Program Files\Desktop Sidebar\sbhelp.dll
O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-5
1FB2220DF8
0} - C:\Program Files\Desktop Sidebar\sbhelp.dll
O9 - Extra button: (no name) - {193B17B0-7C9F-4D5B-AEAB-8
D3605EFC08
4} - C:\PROGRA~1\COPERN~1\COPER
N~1.EXE
O9 - Extra 'Tools' menuitem: Launch Copernic Agent - {193B17B0-7C9F-4D5B-AEAB-8
D3605EFC08
4} - C:\PROGRA~1\COPERN~1\COPER
N~1.EXE
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5
663EE0C6C4
9} - C:\PROGRA~1\MICROS~2\Offic
e12\ONBttn
IE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5
663EE0C6C4
9} - C:\PROGRA~1\MICROS~2\Offic
e12\ONBttn
IE.dll
O9 - Extra button: The Weather Channel - {2E5E800E-6AC0-411E-940A-3
69530A35E4
3} - (no file)
O9 - Extra 'Tools' menuitem: The Weather Channel - {2E5E800E-6AC0-411E-940A-3
69530A35E4
3} - (no file)
O9 - Extra button: Verizon Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2
FC0DE4A789
7} - C:\PROGRA~1\Yahoo!\Common\
yiesrvc.dl
l
O9 - Extra button: Copernic Agent - {688DC797-DC11-46A7-9F1B-4
45F4F58CE6
E} - C:\PROGRA~1\COPERN~1\COPER
N~1.EXE
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MICROS~2\Offic
e12\REFIEB
AR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-5
8CAB36FD2A
2} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-5
8CAB36FD2A
2} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Add to Local Website Archive - {17388483-9699-44B5-85AC-E
B37D24FFC7
5} - C:\Program Files\Local Website Archive\wsarc_add.exe (file missing) (HKCU)
O9 - Extra button: Start Local Website Archive - {C918245D-A801-4B98-BCB9-1
1DAB0F6C9B
A} - C:\Program Files\Local Website Archive\wsarc.exe (file missing) (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: vzTCPConfig -
http://www2.verizon.net/help/dsl_settings/include/vzTCPConfig.CABO16 - DPF: {01113300-3E00-11D2-8470-0
060089874E
D} (Support.com Configuration Class) -
https://activatemydsl.verizon.net/sdcCommon/download/DSL/tgctlcm.cabO16 - DPF: {0742B9EF-8C83-41CA-BFBA-8
30A59E2353
3} (Microsoft Data Collection Control) -
https://support.microsoft.com/OAS/ActiveX/MSDcode.cabO16 - DPF: {30528230-99f7-4bb4-88d8-f
a1d4f56a2a
b} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsth
elper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-D
C1FA91D2FC
3} (MUWebControl Class) -
http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1190929927343O16 - DPF: {E5ABEB00-B357-4884-9949-7
7B2C71A7EE
3} (BoardCtl Class) -
http://www.intel.com/design/motherbd/boardid/BoardID.cabO18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3
CB6248B04C
D} - C:\PROGRA~1\MICROS~2\Offic
e12\GR99D3
~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-0
0C04F8EC29
4} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-0
0B0D022E94
5} - C:\PROGRA~1\COMMON~1\MICRO
S~1\OFFICE
12\MSOXMLM
F.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SAS
WINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLog
on.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-9
4D524869DB
5} - C:\WINDOWS\system32\WPDShS
erviceObj.
dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2ev
xx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sg
ag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\
ALUSchedul
erSvc.exe
O23 - Service: AdminWorks Agent X6 (AWService) - OSA Technologies Inc., An Avocent Company - C:\Program Files\Intel\IDU\awServ.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\ATI\Catalyst Media Center\Kernel\TV\CLCapSvc.
exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\ATI\Catalyst Media Center\Kernel\TV\CLSched.e
xe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.e
xe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\ATI\Catalyst Media Center\Kernel\CLML_NTServi
ce\CLMLSer
ver.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEU
P~1\LUCOMS
~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-
4c61-B58F-
2F227FCA9A
08}\PIFSvc
.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-
4c61-B58F-
2F227FCA9A
08}\PifEng
.dll (file missing)
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe
O23 - Service: PD9Engine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDiskRx\
PD9Engine.
exe
O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSv
c.exe
O23 - Service: Choice Mail (svcChoiceMail) - DigiPortal Software, Inc. - C:\Program Files\DigiPortal Software\ChoiceMail\\CMSer
ver.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.ex
e
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.ex
e
O23 - Service: WDelMgr20 - Unknown owner - C:\WINDOWS\system32\driver
s\WDelMgr2
0.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\Washe
rSvc.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER
~1.EXE
Start Free Trial