google a problem too?

hello,
you have helped me clean-up a mess in my computer.
thank you so very much!

but now

geez...

now google has taken over my homepage. I thought google would be safe. is it a problem also?

here's a hjt log

is there something I can get rid of to stop google from stealing my homepage?

are there certain files I can look for if somebody else steals my homepage again?


I appreciate your help


Logfile of HijackThis v1.99.0
Scan saved at 2:47:17 PM, on 3/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Program Files\Yahoo!\Messenger\YPager.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\ME\Desktop\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.excite.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1104048626937
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Trend Micro Central Control Component - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

Comments

  • Buckeye_SamBuckeye_Sam Columbus, Ohio
    edited March 2005
    You can easily change your homepage in IE by clicking Tools -> Internet Options. Under the General tab you should see where you can enter in whatever page you want as your home page. The reason it has defaulted to Google is that you have the Google toolbar installed.

    Usually you can see where your homepage has been changed by looking at the R0 and R1 lines on the hijackthis log.
  • edited March 2005
    yes, I change it all the time, but when I reboot, it comes up google again

    why does it change back? where is that located?

    the R0 and R1 linesw show excite as my main page however google comes up on reboot.
  • edited March 2005
    hi Sam,

    can you help me with this one ?

    every once in awhile when I turn on the computer, I get this screen


    problem detected and windows was shut down

    problem with file IPVNMON.sys

    PAGE_FAULT_IN_NONPAGED_ AREA

    TECNICAL INFORMATION
    STOP: 0X00000050 (0XE1CC0000,0X00000000,0XF9089C66,0X00000001)

    ivpnmon.SYS - ADDRESS F9089C66 BASE AT F9080000,DATESTAMP 3ee7a27a


    do you have any idea what any of that means?

    or where the problem is?


    thanks

    Paul
  • Buckeye_SamBuckeye_Sam Columbus, Ohio
    edited March 2005
    Do you have Spyware Blaster installed?



    Your error seems to be related to hardware or perhaps a driver issue.
    http://www.microsoft.com/resources/documentation/Windows/XP/all/reskit/en-us/Default.asp?url=/resources/documentation/Windows/XP/all/reskit/en-us/prmd_stp_ccgm.asp

    Right click on My Computer and select Properties. Then click on the Hardware tab. Select Device Manager. Look for anything with a yellow "!" next to it.
  • edited March 2005
    Do you have Spyware Blaster installed?

    Yes I do






    Right click on My Computer and select Properties. Then click on the Hardware tab. Select Device Manager. Look for anything with a yellow "!" next to it.


    I did that and found none with a mark by it
  • Buckeye_SamBuckeye_Sam Columbus, Ohio
    edited March 2005
    I'm not sure what else to tell you on that then. It doesn't appear to be related to a virus or spyware.


    Regarding your Google problem - do you have Spyware Blaster installed?
  • edited March 2005
    I'm not sure what else to tell you on that then. It doesn't appear to be related to a virus or spyware.


    Regarding your Google problem - do you have Spyware Blaster installed?


    yes I do
  • Buckeye_SamBuckeye_Sam Columbus, Ohio
    edited March 2005
    Try this.

    Open Spyware Blaster. Go to Tools -> Browser pages and see what's listed there. If it's Google, just change it to whatever you want.
  • edited March 2005
    ok, there were actually several listed.

    I changed all the ones google.

    why are there so many listed?
    why can't you delete some of those listed?
  • Buckeye_SamBuckeye_Sam Columbus, Ohio
    edited March 2005
    Did changing them with Spyware Blaster solve your problem?

    Each line represents a registry entry for a start up page. In order to get rid of them you have to edit the registry, which is not recommended.
This discussion has been closed.