Hi
I have that bloody Blank Trusted start Page,
when I'm starting IE even if i have reseted the default home page

running Adaware and Spybot scans and letting them fix what they find.
And now after Reboot and scan with Hijackthis
here is the log:

Logfile of HijackThis v1.98.2
Scan saved at 21:36:36, on 09/11/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Mixer.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\User\Desktop\HijackThis.exe

O1 - Hosts: auto.search.msn.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: RenFile.lnk = C:\Program Files\Fuji Axia\iX-10 driver for XP(Eng)\RenFile.bat
O8 - Extra context menu item: &יצ ל- Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O18 - Protocol: start - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\DGJMPSVY.dll
O18 - Filter: text/html - {63B95211-7D77-11D2-9F80-00104B107C96} - C:\WINDOWS\System32\DGJMPSVY.dll
O18 - Filter: text/plain - {63B95211-7D77-11D2-9F80-00104B107C96} - C:\WINDOWS\System32\DGJMPSVY.dll

thanx in advance
Shay Ya

Dani AI

Generated

Good call from to treat the HijackThis results seriously and to work in Safe Mode. The log shows a classic browser-start hijack scenario; that single-step removal is useful, but several common persistence points often remain. The following checklist fills those gaps and helps prevent reinfection.

Before making changes, create a System Restore point and back up the hosts file and any registry keys that will be edited (export from Regedit). A safe sequence is: stop suspicious processes, use Autoruns (Sysinternals) to locate and disable unknown startup/persistence entries (BHOs, protocol handlers, AppInit_DLLs, services, scheduled tasks), then delete files from disk while in Safe Mode, and finally remove the corresponding registry entries. If inexperienced with the registry, rely on Autoruns or an experienced helper rather than manual key deletion.

Use updated scanners to catch components missed by one tool: a current anti-malware scanner (Malwarebytes or equivalent) plus a rootkit scanner (RootkitRevealer/GMER) are recommended. Check IE specific settings as well: disable any unknown add-ons, ensure no proxy is set in LAN Settings, and reset Internet Explorer to defaults if the homepage still redirects. Also inspect Scheduled Tasks and both HKCU/HKLM Run and RunOnce keys for re-installers.

After cleaning, flush network caches and reset socket providers to remove network hooks. For example, run the Windows network reset and then reboot:

netsh winsock reset
ipconfig /flushdns

Finally, re-enable System Restore and create a fresh restore point. Keep OS and browser patched and consider moving off legacy IE6 to a supported browser to reduce future risk. The steps above complement ’s removal advice by covering persistence, rootkits, and restore-point recontamination.

Scan with hijackthis and tick the boxes next to all the following entries, then close all browser and explorer windows, and hit the "Fix checked" button.

O1 - Hosts: auto.search.msn.com

O18 - Protocol: start - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\DGJMPSVY.dll
O18 - Filter: text/html - {63B95211-7D77-11D2-9F80-00104B107C96} - C:\WINDOWS\System32\DGJMPSVY.dll
O18 - Filter: text/plain - {63B95211-7D77-11D2-9F80-00104B107C96} - C:\WINDOWS\System32\DGJMPSVY.dll

Reboot into safe mode following the instructions & navigate to & delete the following if found:

C:\WINDOWS\System32\DGJMPSVY.dll-file

Reboot normally after doing the above, rescan with hijackthis, then post that log here please.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.