I cannot get rid of as my homepage whatever I try, I am not sure what to do to get rid.

Please help,

my log is

Scan saved at 15:59:49, on 09/05/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Bionic Cow\Local Settings\Temp\Temporary Directory 1 for hijackthis[1].zip\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O1 - Hosts: 1159680172 auto.search.msn.com
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.
O19 - User stylesheet: C:\WINDOWS\stsheets.dat
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

Dani AI

Generated

opened this thread with a persistent homepage problem and supplied a HijackThis scan; correctly pointed toward updating and running HJT from a proper location. The suggestions below build on that baseline with a focused diagnostic workflow and safety notes useful when a homepage keeps coming back.

Start with an offline, controlled cleanup sequence: boot to Safe Mode, stop the browser, and run two different on-demand scanners (signature and heuristic types) to remove obvious components. Use Autoruns (Sysinternals) or HijackThis output to inspect every auto-start area — Run keys, Startup folder, Scheduled Tasks, services, Browser Helper Objects/Toolbars and AppInit-style injections. Use Process Explorer or a file-search for the exact homepage string to locate the file or service that contains or resets the URL. Once the offending file or autorun entry is identified, remove or quarantine the file, then clean the autorun entry and clear browser caches before resetting the homepage.

If the change persists after removal, investigate persistence mechanisms: a scheduled task, a tiny service, or System Restore can reapply the change. Temporarily disable System Restore, delete old restore points, then repeat the cleanup so nothing resurrects the hijacker. Also confirm shortcuts (IE and desktop shortcuts) have no extra parameters appended. If a suspicious service or DLL is involved, stop it, export the registry key before editing, and only remove entries after confirming file origins.

Safety first: export the registry and save a copy of the current HijackThis log before making fixes. Do not delete unknown system files or services without verification. A clear, current HijackThis/Autoruns dump (run from a permanent folder) plus a short symptom note is the most useful diagnostic artifact for helpers when further analysis is required.

First of all, you need to go to Windows Update and get SP1a for both XP and IE.

Next, before fixing anything with hijackthis, you should move it from the Temp folder it is in now, to it's own permanent folder, like c:\HJT\hijackthis.exe.

After you've moved it, enable anything you may have disabled in msconfig, close any open browser windows, scan with HJT, and post a new log please.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.