A friend of mine is having some problems with Internet Explorer after getting rid of spyware with cwshredder and spybot S&D. She opens up IE and it shows her homepage (www.google.ca), but then switches to . In the same way, if she types in another page, it'll show momentarily, then switch to . She's got Firefox and Windows Explorer hasn't been affected, so she's not really suffering in the use of her machine, but she's contemplating reformatting because she hasn't got a clue as to what's going on with her machine.

Any ideas?

Dani AI

Generated

The symptom you describe — IE loads the expected page for a moment, then immediately jumps to http:/// — points to something running inside Internet Explorer after the initial load. That fits 's observation that Firefox and Explorer are fine: this is most likely an IE add-on, toolbar/BHO, a per-user startup/registry stub, or a proxy/hosts redirect left behind by whatever spyware was removed. 's comment about extra slashes is a red herring; the problem is an active redirect, not URL syntax.

Next steps (in order):

  • Try IE from a clean environment first. Boot Windows into Safe Mode with Networking and open IE. If the redirect stops, a third-party add-on or service is the culprit.
  • Check Internet Options → Connections → LAN Settings to ensure no proxy is set. Also inspect the user Internet Settings proxy values in the registry (ProxyEnable/ProxyServer) if comfortable.
  • Inspect the hosts file at %windir%\system32\drivers\etc\hosts for unexpected entries.
  • Follow 's suggestion to run HijackThis and post the full log. When posting, include OS and IE version. Focus attention on entries that show: unknown Browser Helper Objects / toolbars, unusual Run/RunOnce startup entries, items that point to temp folders or oddly named EXEs/DLLs, and any proxy/service entries. Do not delete things until someone confirms them — post the log first.

If you can use additional tools, enumerate startup items with msconfig or Autoruns and check what DLLs are loaded into iexplore.exe with Process Explorer; unfamiliar DLLs loaded by IE are prime suspects. Back up the registry and create a restore point before removing entries. If the cleanup fails, a system restore to a pre-infection point or a full reinstall is the last resort.

Posting a clean HijackThis log plus the results of Safe Mode and whether a proxy was set will let others point to the exact offending entries.

Recommended Answers

All 2 Replies

All I know is that the World Wide Web Consortium technically says that there should be three backslashes after any case of file:whatever. I don't know the specifics but Unix machines used to (or still do, i dunno i'm no guru) use three backslashes, while windows platforms depended on the browser to interpret what they meant. I know this doesn't at all answer your question of why websites momentarily show up. Tell your friend to try going to
http:///www.google.ca thats all i can guess.

Please download the utility program HijackThis, run it, and post the log file it generates for us to review.

Instructions for downloading and using HijackThis can be found in our member caperjack's post in this thread:

http://www.daniweb.com/techtalkforums/thread15641.html

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.