|
|
|
Click My Computer and IE 6 Starts.
|
Original Message
|
Name: seanproblems
Date: November 8, 2004 at 08:20:27 Pacific
Subject: Click My Computer and IE 6 Starts. OS: Windows 98SECPU/Ram: PII 233 MHz MMX |
Comment: When I click onto My Computer Internet Explorer starts and it trys to goto "http://213.159.117.130/di/w/di.html" and then no page opens but then trys to open "http://67.18.129.75/iex/doit.cgi?s=1753350144&xdat=&url=http://67.18.129.75:8" I just stop it at that point. I have look on the forum and I have tried the following to fix the problem. Downloaded and ran "CWShredder" it is complete and clean. Downloaded and ran "Lavasoft Ad-Aware SE Personal" it cleaned alot but the repeat ones come up everytime I restart and click on My Computer. All three are; Vendor "TX4.BrowserAd" Category "Malware" One: Regkey "HKEY_CLASSES_ROOT:interface\{31ca5c07-7f5f-4502-8c77-99091558addo}\" Two: RegValue "HKEY_CLASSES_ROOT:interface\{31ca5c07-7f5f-4502-8c77-99091558addo}\" Three: Regkey "HKEY_CLASSES_ROOT:typelib\{223a26d8-9f91-42f6-8ed3-0946637de020}\ The other problem is that my homepage is hijacked. I go into IE6/Tools/General and reset the homepage to blank and click apply then click OK. I go back to IE6/Tools/General and it is back to "http://hot-search.biz/indez.html" I have tried to lock the blank as my homepage but the "http://hot-search.biz/index.html" gets locked because the blank page can never stay. Please Help Me, Thanks in advance. Séan.
Report Offensive Message For Removal
|
|
Response Number 1
|
Name: Mark.UK
Date: November 8, 2004 at 08:58:56 Pacific
|
Reply: (edit)There are 2 more programs you should run to clean your system, Spybot Search & Destroy and Hijack This. Spybot available here: http://www.safer-networking.org/en/download/index.html and Hijack This: http://www.majorgeeks.com/download3155.html once you have ran HJT post your log here and press analyse: http://www.hijackthis.de/index.php?langselect=english Any problems post back here. M
Report Offensive Follow Up For Removal
|
|
Response Number 3
|
Name: seanproblems
Date: November 9, 2004 at 06:53:57 Pacific
|
Reply: (edit)Hi Mark.UK, I download and ran Spybot Search & Destroy; it searched and it destroyed stuff but I still have the problem. I also downloaded HijackThis (there where five download buttons for it I choose the USA Fl one)but when I click on the Zip file it said "no packages available for uninstall". So I havn't been able to run that. Hi OtheHill, I tried a few times to start up in Safe mode but I was unable to. I think it is because I have a second hard drive and it has a program that runs before Windows start which allows the computer to recognize the larger hard drive. I still have the same problems. Thanks for tring to help me, I hope one of you might have some more ideas! Sean.
Report Offensive Follow Up For Removal
|
|
Response Number 5
|
Name: seanproblems
Date: November 9, 2004 at 13:52:02 Pacific
|
Reply: (edit)Hi OtheHill, I was able to start in Safe mode by using the System Configuration Utility and Enable Startup Menu. I ran Lavasoft Ad-Aware SE Personal and Spybot Search & Destroy. In the Control panel I changed the Homepage to about:blank and it stayed. I then lokced in the registry. I was still locked. I restarted in regular mode and clicked on My Computer and the Internet Explorer 6 started again. Also the Homepage was back to "http://hot-search.biz/index.html" and it was locked! I removed the lock from the registry. I will try to perform a Clean-Boot tonight. I found out how to do this from Microsoft's Website. Thanks again, Sean.
Report Offensive Follow Up For Removal
|
|
Response Number 6
|
Name: seanproblems
Date: November 11, 2004 at 07:37:38 Pacific
|
Reply: (edit)Thanks, I have fixed it. I have run the following. Spybot Search & Destroy CW Shredder Ad-Aware SE Personal LSP Fix Hijack This I had to run all five of this once I restarted my computer, and without click on My Computer or it would reinstall or change settings. Thanks Again! Sean.
Report Offensive Follow Up For Removal
|
Use following form to reply to current message:
|
|

|