Ron Wolpa 0 Newbie Poster

aug 21 2004

IE6 has been hijacked ;

http://homepage.com/ is the start page now ;
(Start page entry is :
http://%68%6F%6D%65%70%61%67%65%2E%63%6F%6D%00@%77%77%77%2E%65%2D%66%69%6E%64%65%72%2E%63%63/%68%70/ )

I tried to run CWShredder v1.59.1 and hijackthis v1.98.2 ;

CWShredder´s Restoring Internet Explorer Pages item suceeds to clear 18 items ; The 1st time I open IE6 after using CWShredder , it opens a blank page , then I close to test it and open a 2nd time , so the hijacking page is back as start page ;

I ran hijackthis v1.98.2 , but without success :

browser helper object C:\DPE.dll has been found , I check it to be fixed , but
it gets back ;
At the end of this post I will paste hijackthis LOG ;

It is interesting to note that I have the useless SpywareBlaster Version 3.2 which would be a protection against hijacking (by the looks of it I will remove it......feeling cross about that) ;

Well friends I count on you for some help ;

Cheers
RW
.....................................................................................................
Logfile of HijackThis v1.98.2
Scan saved at 21:17:24, on 21/08/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\LOADQM.EXE
C:\ADMUNCHER\ADMUNCH.EXE
C:\WINDOWS\SYSTEM\FPPDIS2A.EXE
C:\VITALAGENT8\VITALAGENT\PROGRAM\VTLAGENT.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\MSXMIDI.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\ARQUIVOS …

Ron Wolpa 0 Newbie Poster

As per microsoft instructions at : (http://www.microsoft.com/windowsxp/using/mobility/learnmore/offlineviewing.mspx)
"To save all of the files needed to display this page, including graphics, frames, and style sheets, click Web Page, complete. This option saves each file in its original format."

............. I haven´t got this option : Web Page, complete , on the "Save as" drop down menu it comes up only html (*htm,*html) which saves plain html but not the pictures , css , sounds , etc , or text file ;
Since the browser was hijacked months ago it hasn´t been the same ;
I think something has been changed in the register ;
Do I reinstall IE6 ?

Ron Wolpa 0 Newbie Poster

Are you choosing - Web Page, Complete(*htm,*html) - under Save As.

august 5th 2004
Hi JR8
I choose *htm,*html (and not txt) , It saves the htm but it does not create any folder ;
Any hint ???
RW

Ron Wolpa 0 Newbie Poster

aug 4th 2004

ref: I E 6 - "file/save as" menu does not save pages correctly on my local disk

on last May I was obliged to reformat the HD and reinstall everything ;

since then I noticed that I cannot save correctly the web pages on my local disk ;

as I employ "file/save as" to save pages , only the html file is saved but the folders - for the images ,css,jclasses,flash swfs files ,etc - are not created ;

as far as I can remember I´ve never had this trouble before and I´ve never configured anything for the browser to "capture" pages properly ;

Can someone gimme a hint on how to solve that ???

Cheers

RW

Ron Wolpa 0 Newbie Poster

22:52 11/06/04

Hi Caperjack

1-) No , no , it hasn´t worked ;

I did exactly as you told me : I checked each one of the entries following your instructions ,
Hijackthis was ran and supposedly fixed that mess , the BHO C:\DPE.DLL was found & deleted
on the "DOS" safety mode ( out of the Windows 98) ;

as soon as I rebooted the system the infection remains the same please take a look at the log
below ;

OBS: once back to the Windows I had a hunch and tried to "dir" for C:\DPE.DLL on
PROMPT DOS , and found the d am n e d file there ;

Which is the file responsible for the " re-infection" ???
So what to do next to get rid of www.e-finder.cc/..........????


2-) Hello Crunchie , as a matter of fact I installed the player Winamp (it is not the virus you
mention on your post )
in the root as I usually do , because I don´t like to have all the programs centralized in
program files folder ;

________________________________________________________________________

Logfile of HijackThis v1.97.7
Scan saved at 23:29:14, on 11/06/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\LOADQM.EXE
C:\ADMUNCHER\ADMUNCH.EXE
C:\WINDOWS\SYSTEM\FPPDIS2A.EXE

Ron Wolpa 0 Newbie Poster

Hello Caperjack
Thank you very much for your answer !
Exactly as per your instructions bellow is the log of Hijackthis (I prefer to wait and not to take a chance and delete by myself ) :

Logfile of HijackThis v1.97.7
Scan saved at 00:21:52, on 09/06/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\LOADQM.EXE
C:\ADMUNCHER\ADMUNCH.EXE
C:\WINDOWS\SYSTEM\FPPDIS2A.EXE
C:\SPYBOT\TEATIMER.EXE
C:\VITALAGENT8\VITALAGENT\PROGRAM\VTLAGENT.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\ARQUIVOS DE PROGRAMAS\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\CHATBROWSER4\CB_4001.EXE
C:\ARQUIVOS DE PROGRAMAS\INTERNET EXPLORER\IEXPLORE.EXE
C:\!_DOWNLOAD\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://homepage.com%00@www.e-finder.cc/search/ (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://homepage.com%00@www.e-finder.cc/search/ (obfuscated)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.com%00@www.e-finder.cc/hp/ (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://homepage.com%00@www.e-finder.cc/search/ (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://homepage.com%00@www.e-finder.cc/search/ (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://homepage.com%00@www.e-finder.cc/search/ (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.com%00@www.e-finder.cc/hp/ (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://homepage.com%00@www.e-finder.cc/search/ (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://homepage.com%00@www.e-finder.cc/search/ (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://homepage.com%00@www.e-finder.cc/search/ (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://homepage.com%00@www.e-finder.cc/search/ (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

Ron Wolpa 0 Newbie Poster

_________________________________________________________________

IE6 has been hijacked

spybot version 1.3 was ran but it has not fixed the problem ;

every time I run IE start page switches to :

http://%68%6F%6D%65%70%61%67%65%2E%63%6F%6D%00
@%77%77%77%2E%65%2D%66%69%6E%64%65%72%2E%63%63/%68%70/

is there any other program I can install to scan to clear the register / system ?

going mad with that

RW

_________________________________________________________________

Ron Wolpa 0 Newbie Poster

"Links" folder , how to get rid of it ?

It´s useless to delete it from favorites menu , every time the sistem is booted , the Links folder is recreated ;
Is there a way to get rid of it :?:

(perhaps to edit an entry in the register ?)

Cheers

RW

Ron Wolpa 0 Newbie Poster

Hi
I am quite fed up with spyware , this time : http://prosearching.com/searchbar.html
(Id wish to have a valid email to call a bit of names to such [Moderator's edit: Please keep it clean, we ask that our members not use profanity in these forums- thanks]


is there any safe tutorial on how to get rid of IE hijacking (cwshredder has got 2 links where there are explanations on how to uninstall java virtual machine and others items which allow hijacking )

In this meantime , perhaps any of you could assist me to clear my system out of this rubbish (what the h e l l is that : C:\ARQUIVOS DE PROGRAMAS\MIX MAIL LOVE\POLLBAIT.EXE)


Here youve got the Logfile :


HijackThis v1.97.7
Scan saved at 1:00:59, on 23/04/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
D:\12GHOSTS\12SRVC.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
D:\ADMUNCHER\ADMUNCH.EXE
C:\ARQUIVOS DE PROGRAMAS\MIX MAIL LOVE\POLLBAIT.EXE
C:\ARQUIVOS DE PROGRAMAS\MYVITALAGENT8\VITALAGENT\PROGRAM\VTLAGENT.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\ARQUIVOS DE PROGRAMAS\MSN MESSENGER\MSNMSGR.EXE
D:\CHATBROWSER4.0\CB_4001.EXE
C:\ARQUIVOS DE PROGRAMAS\SYSAI\SYSAI.EXE
D:\!DOWNLOAD\!_HIJACK_CLEAN\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://prosearching.com/searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://prosearching.com/searchbar.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://prosearching.com/searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title …

Ron Wolpa 0 Newbie Poster

Hi Tall Cool1

1st of all thank you for your answer ;


I contacted search-for support which stated they distribute the pesky IeFeastSl , an adware that can be unistalled ; ok , I followed their advice and uninstalled that s...t from the sytem , but the search-for window opens up at every time I search an entry at Google ;
I run CwShredder and bellow you get the log (shall I hit Fix ?)


CWShredder v1.53.1 scan only report

Windows 98 (4.10.2222 A)
Windows dir: C:\WINDOWS
Windows system dir: C:\WINDOWS\system
AppData folder: C:\WINDOWS\Application Data
Username: rw

Infected Registry value:
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL
Infected data: C:\WINDOWS\system32\blank.html
Hosts file not present
Found CWS.Control (if filesize is over 50k) file: C:\WINDOWS\control.exe (2147 bytes, A)
Found CWS.Smartsearch.2 file: c:\y.exe (3072 bytes, A, running)
Found file: C:\WINDOWS\my.css (1252 bytes, A)
Registry value: DefaultPrefix (should be http://) [] http://
Registry value: WWW Prefix (should be http://) [www] http://
Registry value: Mosaic Prefix (should be http://) [mosaic] http://
Registry value: Home Prefix (should be http://) [home] http://
Found Win.ini file: C:\WINDOWS\win.ini (8595 bytes, A)
Found line in Win.ini: load=
Found System.ini file: C:\WINDOWS\system.ini (2091 bytes, A)
Found line in System.ini: shell=Explorer.exe

- END OF REPORT -

Ron Wolpa 0 Newbie Poster

I have had problems with changed start page by this annoying res://mshp.dll/index.html#10213 ;
Besides that every time I run Google.com a pop up ad comes up just after submiting any entry a new browser windows opens with this pesky search company :
(http://search-company.com/search.php?qq=kee+bird&pin=10213)

Despite I have employed Hijackthis to clear out the system , the d a m n thing goes on happening ;
can someone help me to get rid of the trouble ?


Hijackthis log after the clearing :

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\ARQUIVOS DE PROGRAMAS\MYVITALAGENT8\VITALAGENT\PROGRAM\VTLAGENT.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
D:\ADMUNCHER\ADMUNCH.EXE
C:\ARQUIVOS DE PROGRAMAS\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\ARQUIVOS DE PROGRAMAS\INTERNET EXPLORER\IEXPLORE.EXE
C:\ARQUIVOS DE PROGRAMAS\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\NOTEPAD.EXE
C:\AHDW\AHD3.EXE
D:\!DOWNLOAD\HIJACKTHIS\HIJACKTHIS.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uol.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\system32\blank.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Multi Media Marketing
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://home.uol.com/
O2 - BHO: (no name) - {2E9CAFF6-30C7-4208-8807-E79D4EC6F806} - C:\PROGRAM FILES\SUBMIT\SUBMITHOOK.DLL
O2 - BHO: (no name) - {FCADDC14-BD46-408A-9842-CDBE1C6D37EB} - D:\IEDOCTOR\ADFLR.DLL
O2 - BHO: . - {587DBF2D-9145-4c9e-92C2-1F953DA73773} - C:\WINDOWS\APPLICATION DATA\WINVX\WINVX.DLL
O2 - BHO: (no name) - {FD9BC004-8331-4457-B830-4759FF704C22} - C:\WINDOWS\APPLICATION DATA\WINVX\MSIESH.DLL
O2 - BHO: ShowSearch module - {E2DDF680-9905-4dee-8C64-0A5DE7FE133C} - C:\WINDOWS\APPLICATION DATA\WINVX\MSSEARCH.DLL
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\ACROBATREADER\READER\ACTIVEX\ACROIEHELPER.OCX
O3 - Toolbar: @msdxmLC.dll,-1@1046,&Radio - …

Ron Wolpa 0 Newbie Poster

since the IE6 browser was hijacked and subsequently cleared up by means Hijackthis ,
I have noticed that dialogue boxes , check boxes and radio buttons work very slowly ;
this message had to be typed in a text editor because it would have taken a while
to do it on the forum box ;
When I click on a form check box or radio button the same happens ;
is there some way to get the thing back to the normal ?

Ron Wolpa 0 Newbie Poster

ie6setup.exe and q828750.exe were downloaded from Microsoft IE6 download area ;

ie6setup.exe starts a 12 megabytes download and after the file is totally downloaded is autoexecuted starting up the instalation , the system reboots , and so the message comes up : it was not possible to install all the files , try to run again ;
Useless to run it again , the same message ;
q828750.exe , service pack 2 , cant be ran because IE6 has not been upgraded by serv. pack 1 ;

The question is : is there something wrong on my side or other people has ever experienced the same ? (or the problem is on the almighty Microsoft ?)

I remember I had IE5.5 , and when tried to upgrade to IE6 , the files downloaded by means MIcrosoft site were uselles as well ;
I could only upgrade to IE6 succesfully because I installed from a magazine CD that offered the upgrade ;

Cheers

RW

Ron Wolpa 0 Newbie Poster

Hi Steam

Its done , I ran hijackthis and fixed the entries as per your advice ;
Its too early to tell if the start page and weird pop ups problem is fixed , but I suppose so ;
At least the start page dialogue box and buttons at internet options /general / start page is back to normal operation (since the 1st time IE was hijacked they were invalid )
Thank you once again for your support ;
RW

Ron Wolpa 0 Newbie Poster

Not only have I had problems with changing start page but with weird pop up screens coming up with ads of skunk marijuana,
bogus universities degrees , pornography , mp3 songs for free , etc , etc ...
I think for some people it would be funny to open the page of a serious company like Boeing and get a pop up ad of marijuana ;
disgusting ;
Below I paste the log of hijackthis:

Logfile of HijackThis v1.97.7
Scan saved at 02:24:56, on 30/12/03
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSINFO.EXE
C:\ARQUIVOS DE PROGRAMAS\MYVITALAGENT8\VITALAGENT\PROGRAM\VTLAGENT.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\ARQUIVOS DE PROGRAMAS\ICQ\ICQ.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\ARQUIVOS DE PROGRAMAS\INTERNET EXPLORER\IEXPLORE.EXE
C:\ARQUIVOS DE PROGRAMAS\MSN MESSENGER\MSNMSGR.EXE
D:\!DOWNLOAD\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.theadultgate.com/find/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.........../
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lookfor.cc/index.php?p=37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.lookfor.cc/sp.php?p=37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.lookfor.cc/index.php?p=37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.lookfor.cc/sp.php?p=37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Ron Wolpa
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://........../
F1 - win.ini: run=C:\WINDOWS\svcinit.exe
O2 - BHO: . - {587DBF2D-9145-4c9e-92C2-1F953DA73773} - C:\WINDOWS\APPLICATION DATA\IEFEATSL\IEFEATSL.DLL
O2 - BHO: (no name) …

Ron Wolpa 0 Newbie Poster

Hi Guys !
Following your advice I downloaded hijackthis , runned and found
a very large list of .exe files and register entries ; basic what this program does is to seek for suspicious entries that autoload when
the op. system starts up ; alright so Hijackthis supposedly found some entries on my register :

1- H_key_currentuser/software/Microsoft/internet/SearchUrl/http...
the url of a porno site ;

2-H_key_currentuser/software/Microsoft/internet/Main/ .....
search and start page , both www.lookfor....

Before to click hijackthis to do anything I opened the register and
have not found such entries in the way it stated it was ;
I had edited minutes before the start page (because it had happened again , start page was changed ) and deleted the entry H_key_currentuser/software/Microsoft/internet/Main/ search
which was pointing to the lookfor , once again ;
This hold me back in relation to hijackthis , I am not confident its
realiable , as it found items it was no longer there ;
I thank you anyway for your attetion ;
Ron Wolpa

Ron Wolpa 0 Newbie Poster

IE6 has been constantly hijacked ;
this damn site :
http://www.lookfor.cc/index.php?p=37049 , replaces the start page , obliging me to edit the register HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\start page ;

It has happened almost every night since the 1st time a week ago ;

An updated Spybot search and destroy has scanned the system and some cookies have been cleared up but it has not solved the annoying problem ;

Is there something else I can do to eliminate whatever is in the system ?

I am very very fed up with that bastard www.lookfor...

Thank you so much

RW

Ron Wolpa 0 Newbie Poster

In october I had my IE6 hijacked , the system was scanned by spybot and cleared up ; however a sequel was left : the Internet Options/General Tab/ Start page is disabled ;

In order to change the damn porno start page I had to edit the register: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main;
Today it has happened once again , the start up changed to a
damn porno page (how the scoundrels may think they will get customers with this strategy ????)

But this time , I scanned with spy bot , cleared up system , and
have edited the register , but the start page remains the same
porno stuff ;

How can I get rid of that , how can I change start page and eventually recover the general page button to change start page address ??
Thank you for your reply ;

Cheers
ron_wolpa@hotmail.com

Ron Wolpa 0 Newbie Poster

Some days ago my IE6 was hijacked.
Spybot scanned and cleared the system , lefting as start page a blank;
However the buttons that configure the start page kept disabled ;
By editing manually the register (HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main)
I was able to change start page.
Ive turned register upside down and have not discovered a way to recover the start buttons normal operation.
Does anybody know the right key , if there is one ??
Cheers

RW

Ron Wolpa 0 Newbie Poster

Hey TallCool
I have done exactly as you suggested, spybot has cleared the damn file , placed by ALEXA , that damn and hateful page ;
However it has not solved totally the problem , the IE6 buttons to define the startup page keep uncheckable ;
Is there a way to fix it ? (a .dll or another else file must be corrupted I suspect, but dont know what )
Thank you very much for your support
Cheers
Ron Wolpa

Ron Wolpa 0 Newbie Poster

october 12th 2003

october 12 2003

Dear friends

Be careful with sites like (You may become victims of fiend minds) :

[ Links removed by admin because they pointed to X-rated sites ]

Unfortunately links above are now the start up page on my I E 6 ;
I had never visited the damn pages before this unwanted change ;
such change is unwanted and would be unauthorized if I had chance ;

I simply cannot change it as start up page option is now disabled (buttons disabled and into the address box is one of those damn URLs every time I open up my browser ) ;

I never authorized the installation of any kind of plug in (or , nav bar , program , etc ) that pops up and usually is offered as "free stuff" ;

Simply I dont know how it happened , it makes me think of invasion , spyware ;

Every time I open up the browser Ive got one of the damn pages and besides that many other pages with pornography ;

Ive tried to uninstall (to get back to version 5.5 as a matter of fact , its not possible to uninstall) and reinstall version 6 , but it does not matter what I do , start up page keeps the same ;
Ive searched for strange folder , for any suspect key into the register , but without …

)BIG"B"Affleck commented: nice 1 +0