Everytime I start Internet Explorer I receive this homepage res://dkahp.dll/index.html#37049

This will set off a chain of events by causing .EXE's to run and adding them to my registry. I have attempted to delete / modify registry settings & files, but the problem comes back everytime I start Internet Explorer.

This also effect customized settings with toolbars in both Internet Explorer & My Computer.

When I click on certain links on random sites with words like "forum", "spybot" I get redirected to the following site

I have tried running spybot, which I have updated recently, and receive nothing to fix.

CWShredder came up clean as well.

I have tried the Free online virus scans from http://housecall.trendmicro.com/housecall/start_corp.asp, but receive a general protection fault when downloading the certificate.

I downloaded the other recommended free virus scanner from http://www.grisoft.com/us/us_dwnl7.php, but I receive an error stating "shell.exe" not found during setup.

The EXE's in this hijackthis file will startup when I start IE and if I delete & remove the registry settings other EXE's will take it's place.

The first time I ran hijackthis.exe I tried to fix the seleted items that are in bold text.

I do not have the means to buy new software at the moment and I'm at a loss on what to do next. Any advise would be greatly appreciated.

Thank you in advance

Logfile of HijackThis v1.97.7
Scan saved at 12:46:15 PM, on 6/19/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\taskmgr.exe
C:\WINDOWS\system32\msqi.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Documents and Settings\cc\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\dkahp.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://dkahp.dll/index.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://dkahp.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\dkahp.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://dkahp.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\dkahp.dll/sp.html#37049

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Caveman's IE shit
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {3E92881C-5DEB-061D-127B-BAA4818F8349} - C:\WINDOWS\system32\ntaz.dll
O2 - BHO: (no name) - {F7F808F0-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem218.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [FastUser] C:\Program Files\Support Tools\PowerToys\fast.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [FreeRAM XP] "G:\Programs\FreeRam XP Pro\FreeRAM XP Pro 1.22.exe" -win
O4 - HKLM\..\RunOnce: [msqi.exe] C:\WINDOWS\system32\msqi.exe
O4 - HKLM\..\RunOnce: [crnc.exe] C:\WINDOWS\crnc.exe
O4 - HKLM\..\RunOnce: [apihb32.exe] C:\WINDOWS\system32\apihb32.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Download A&ll by ReGet Deluxe - C:\Program Files\Common Files\ReGet Shared\CC_All.htm
O8 - Extra context menu item: Download by Re&Get Deluxe - C:\Program Files\Common Files\ReGet Shared\CC_Link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O12 - Plugin for .bcf: C:\Program Files\Internet Explorer\Plugins\NPBelv32.dll
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
O16 - DPF: {1E89F686-B78D-4C85-9EFC-3474516E3FE2} -
O16 - DPF: {29C13B62-B9F7-4CD3-8CEF-0A58A1A99441} (MSN Chat Control 4.1) -
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} -
O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) -
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.
O16 - DPF: {8E28B3A9-FE83-45D1-B657-D5426B81A121} (CustomerCtrl Class) -
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} (CTAdjust Class) -

Dani AI

Generated

This thread documents a classic Internet Explorer "res://"-style homepage hijack where a malicious DLL is registered as an IE resource and repeatedly restores itself at browser start. reports a successful cleanup using a dedicated DLL‑fix approach; the useful takeaway is that these infections often combine a loaded BHO/resource DLL with persistent startup entries, so a one‑off file delete usually fails unless the loader and startup hooks are cleaned too.

A reliable cleanup workflow that works for these cases:

  • Create a full backup or system restore point before making changes. Capture current logs (HijackThis, Autoruns) for record keeping.
  • Boot into Safe Mode (or use rescue media) to prevent the loader from reinjecting itself.
  • Run updated anti‑malware scanners designed for current threats (for example, an updated offline scanner or a reputable on‑demand tool) and remove any findings.
  • Use Sysinternals Autoruns to locate and disable items that load DLLs into Internet Explorer or restart at boot. Use Process Explorer to inspect iexplore.exe for unusual loaded modules, then delete the file when it is not in use.
  • After removing files, use Autoruns or the Registry only if comfortable; always export keys before edits. Finish by clearing temporary files and resetting Internet Explorer settings.

If the infection persists or multiple startup hooks reappear, use a bootable rescue disk to scan from outside the OS or consider a clean OS reinstall. Credentials changed while the machine was compromised should be reset only from a known clean device. Exercise caution with unvetted removal tools; prefer well‑known scanners or established manual removal steps. The approach that fixed — removing the malicious DLL plus all its startup hooks — is the reliable pattern for this family of hijacks.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.