Changing IE Home Page and Other Errors

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

I am trying to fix my son's computer while he is on spring break. I think
problems started in early to mid-January. There are two issues that appear
to be caused by a virus or adware program. Currently running XP-SP2, and
Norton Internet 2005.

Problem-1
Can't use navigation tools - keep getting sysfader error when attempting to
use Windows Explore, or try to use the Control Panel Icon or the My Computer
Icon. Can navigate in Safe-Mode.

Problem-2
Internet Epxlorer is resetting the home page to either BLANK , or is
randomly setting to some other keyword search.

Diagnostics performed
System Restore to January 9 date (oldest available) -- still have problem
performed undo of last restore.

Express hardware check -- okay

Error logs -- Multiple MSiInstaller warnings
Multiple Userenv warnings
Multiple DCOM errors on system log
 
Hi Keith :-)

The problem is probably due to some kind of scumware on the system. Try the
following and see if it helps. Even if you have already run some programs,
run them again according to the instructions in the information below to
thoroughly clean you system. Some variants of malware can replicate itself
and return repeatedly if not cleaned properly. It is best to read through
all the information before you start to know before hand what you need to do
and how. Follow all instructions to letter as much as possible.

WARNING>>>> Backup all documents and files before removing any spyware!!

First, Go to Start | Run and type CMD
In the command window type
netsh winsock reset

Then download and install BHODemon from
http://www.definitivesolutions.com/bhodemon.htm
Your problem may be caused by a bad BHO.

If this does not resolve the problem, the do the following. Run all programs
in Safe Mode:

Dealing with Unwanted Spyware and Parasites:
http://mvps.org/winhelp2002/unwanted.htm
What You Should Know About Spyware
http://www.microsoft.com/athome/security/spyware/devioussoftware.mspx
What you can do about spyware and other unwanted software
http://www.microsoft.com/athome/security/spyware/spywarewhat.mspx
Most importantly, be sure to run CWShredder here
http://www.majorgeeks.com/download3019.html
Also this program searches for hidden .dlls that recreate the malware.
About Buster:
http://www.majorgeeks.com/download4289.html
Then visit these two sites to test for parasites and help basic cleaning:
On-Line Check
http://aumha.org/a/noads.htm
and
Quick-Fix Protocol.
http://aumha.org/a/quickfix.php
Basically, throw everything here at your "infection".

Also download and install HiJackThis -

How to download and install HiJackThis:
http://www.bleepingcomputer.com/forums/topict309.html

Please DO NOT post your log to this newsgroup. It is important that you go
to one of the HiJackThis Support Forums below and allow the experts there
to analyze it for youPlease DO NOT post your log to this newsgroup. It is
important that you go to one of the HiJackThis Support Forums below and
allow the experts there to analyze it for you.::
AumHa HiJackThis Forum
http://forum.aumha.org/viewforum.php?f=30
or Bleeping Computer Forum
http://www.bleepingcomputer.com/forums/forum22.html
to allow the experts there to evaluate your log and advise you of any
necessary steps to clean your system.
(Note: You will have to Register before posting on these Forums. Please
follow all posting instructions carefully to avoid having your log deleted
or ignored.

CAUTION!!!!! Before you try to remove spyware using any of the programs
below, download a copy of LSPFIX from any of the following sites:
http://www.cexx.org/lspfix.htm
http://www.spychecker.com/program/winsockxpfix.html
(if your OS is Win2k or XP) The process of removing certain malware may kill
your internet connection. If this should occur, this program, LSPFIX, will
enable you to regain your connection.

You should also get a copy of WINSOCKXPFIX available at:
http://www.spychecker.com/program/winsockxpfix.html
and
WinsockXP Fix- WinXP
http://www.spychecker.com/program/winsockxpfix.html
with instructions, at
http://www.iup.edu/house/resnet/winfix.shtm
also... From LavaSoft- all versions of Windows-
http://digital-solutions.co.uk/lavasoft/whndnfix.zip
(NOTE: It is reported that in XP SP2, the command netsh winsock reset
will fix this problem without the need for these programs.)
or Winsock Fix Utility
http://www.dfwonline.net/files/WinsockFix.zip

Hope this helps :-)

Jan :)
Smiles are meant to be shared,
that's why they're so contagious.

Replies are posted only to the newsgroup for the benefit or other readers.
How to make a good newsgroup post:
http://www.dts-l.org/goodpost.htm



">I am trying to fix my son's computer while he is on spring break. I think
 
Thanks for the response. I successfully reset the netsh winsock. However,
between my first posting and your reply, I did another Norton's scan and
deleted a bunch of adware files. Now I cannot access the internet and keep
getting the message that IE-6 has encountered a problem and must shutdown.
Any suggestions on how to get back online or download files from another
computer?

Keith
 
Thaks Jan for the help:
I finally got back online and was able to download the BHODemon software.
It found an unknown BHO. Once I disabled it all of the problems went away.

Thanks for the help.
Keith
 
Hi Keith :-)

Removing some types of scumware can leave damaged Winsock keys in the
Registry. Some types of warez use the Layered Service Providers (LSP),
which are little bits of software that can be added or inserted into the
Winsocks. Outward bound data from your computer to a legitimate destination
on the Internet can be intercepted by an LSP and sent somewhere other than
where it is supposed to go.

In order to correct the mis-direction, you should download and run the
programs below that apply to your OS, which should resolve the connection
problem. If you are unable to download these programs from the affected
machine, you can download them from another machine and copy them to a
floppy disk or CD, copy them to the hard drive of your machine, then install
and run them.

LSPFix
http://www.spychecker.com/program/winsockxpfix.html
(if your OS is Win2k or XP) The process of removing certain malware may kill
your internet connection. If this should occur, this program, LSPFIX, will
enable you to regain your connection.

and..

Winsock Fix Utility
http://www.dfwonline.net/files/WinsockFix.zip
WinsockXP Fix for XP
http://www.spychecker.com/program/winsockxpfix.html
Also, with instructions, at
http://www.iup.edu/house/resnet/winfix.shtm

also...

Additional LPS Information:
http://searchwin2000.techtarget.com/sDefinition/0,,sid1_gci213375,00.html
http://searchwin2000.techtarget.com/sDefinition/0,,sid1_gci213376,00.html
http://computercops.biz/LSPs.html
(scroll down the list to the lsp.dll files here)

Hope this helps :-)

Jan :)
Smiles are meant to be shared,
that's why they're so contagious.

Replies are posted only to the newsgroup for the benefit or other readers.
How to make a good newsgroup post:
http://www.dts-l.org/goodpost.htm
 
Hi Keith :-)
Thaks Jan for the help:
I finally got back online and was able to download the BHODemon software.
It found an unknown BHO. Once I disabled it all of the problems went
away.

Thanks for the help.
Keith

You're very welcome! Glad to hear you were able to resolve your problem.
Good job!

Thank you for posting back and letting us know what worked for you, and for
the benefit of other readers who might have a similar problem. :-)

Jan :)
Smiles are meant to be shared,
that's why they're so contagious.
 
Back
Top