Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
The IE home page is locked up with following nonsense web search page:
res://lajet.dll/index.html#27859
No matter how I change the home page at Internet Option, scanned and checked with CWshreder, adware,..., I can't set my home page to what I want.
Anyone can help me to solve this problem?
Thanks in advance.

Have you tried Spybot Search & Destroy?
If that doesn't help then get Hijack This from the same maker as CWshreder and post your log file on the Security/virus forum.
The experts there will be able to help.

i have the same problem. Everytime i open my browser my homepage changes to about:blank, i keep changing it to the one i usually have(www.yahoo.com) and i make sure i click "apply" but the next time i open my e.i it goes back to about:blank. So i ran the spysweeper and it detected that my homepage has changed, and it restored to yahoo.com but it still keeps on changing everytime i open the i.e window.
I tried the hijack this and this is the output i got:R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\PHUNKM~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\PHUNKM~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\PHUNKM~1\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\PHUNKM~1\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\PHUNKM~1\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\PHUNKM~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {1C78AB3F-A857-482e-80C0-3A1E5238A565} - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {A241DDE5-BD83-90A8-8F58-DE19B005EBF9} - (no file)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O2 - BHO: (no name) - {FFA8C7C8-3A96-43FB-BB22-E7830C7D382A} - C:\WINDOWS\System32\flm.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {2118063F-6BFE-B748-0732-8B5D02B3F1B6} - (no file)
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe /startup
O4 - HKLM\..\Run: [frsk] C:\WINDOWS\frsk.exe
O4 - HKLM\..\Run: [QD FastAndSafe] C:\Program Files\Norton SystemWorks\Norton CleanSweep\QDCSFS.exe /scheduler
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [MessengerPlus3] C:\Program Files\Messenger\Messenger Plus! 3\MsgPlus.exe
O4 - HKLM\..\Run: [Global Build] C:\PROGRA~1\FLAWDO~1\Ford Admin Close.exe
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &iSearch The Web - res://C:\WINDOWS\System32\toolbar.dll/SEARCH.HTML
O9 - Extra button: ICQ 4.0 (HKLM)
O9 - Extra 'Tools' menuitem: ICQ Lite (HKLM)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/autocomplete.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O19 - User stylesheet: C:\WINDOWS\sstyle.css (file missing)I deleted
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\PHUNKM~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\PHUNKM~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\PHUNKM~1\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\PHUNKM~1\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\PHUNKM~1\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\PHUNKM~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blankbut it doesnt seem to reslove the problem.
IF ANY HELP -I WOULD APPRICIATE IT SO MUCH!!!!!

Hottie.
Post it in your own thread in the security/virus forum. Be sure to have run both adaware and spybot S&D and cleaned up anything they find first.

oh im sorry, im new to this, and first time posting. I didnt want to make another "Same thread" so i figured i'd just post it under the same topic, sorry about that, wont do it again.
Richard - i have done all that and still having the same problem. It deletes everything and plus the unnecessarry files but when i reboot, and run the scan again, the same files pop-up.

Download CWShredder and run it. Make sure that you do a check for updates on all the programs before running them again. Also try spywareblaster after you get everything working, it runs constantly in the background and prevents most future problems. I run it and still run Spybot and Ad Aware manually to see if some thing slipped by spywareblaster.
Good luckRichard

Done everything you stated Richard but nothing seems to work for me.
I appriciate you trying to help me bro.

My home page is still hijacked by this annoyance melware/spyware:
res://lajet.dll/index.html#27859
This brings my IE brower to a web page called Home Search Assistant)
I tried the following:
(1)
Run clean boot and then use the Adware, Spybot, CWShreddr to scan and fix the possible problems.
(2)
Deleted this hidden file (lajet.dll) from its location - c:\windows\system32
(3)
Run the regedit to delete its values in following registry keys:
HKEY_CURRENT_USER\..\Internet Explorer\Main
HKEY_LOCAL_MACHINE\..\Internet Explorer\Main
HKEY_USERS\Default\...\MainThe first opened browser is ok.
However, the lajet.dll comes back again when I clicked on IE for the 2nd browser. The annoyed start page is occurred again.HELP! I need someone's help to tell me where I can find this melware/spyware and how I can remove it from my pc.

I had the same problem Hottie describes for over a week, and tried all kinds of suggested things (turned off System Restore, scanned with AdAware, SpyBot, CWShredder, ran HijackThis and deleted all the relevant entries, etc.). It would appear to fix my problem for awhile, but then the problem would ALWAYS come back, sometimes in an hour or sometimes a day later.
I finally found a solution that WORKED at this URL: http://www.securiteam.com/securityreviews/...5RP0L0UD5U.html
The manual steps outlined there eliminate 2 dlls: one that keeps appearing with a random name in the 02-BHO section of the HijackThis listing, and then another hidden dll in the registry that was not in the HijackThis listing.
Follow the steps outlined in that link and it should fix the problem. I've been free of the virus for 2 days now.
Good luck.

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |