Unsolved

This post is more than 5 years old

71 Posts

8382

April 12th, 2004 00:00

Home Page keeps resetting to nothing!!!! please help!

I have a problem that whenever I load up internet explorer, it automatically loads up " http://%68%6F%6D%65%70%61%67%65%2E%63%6F%6D%00@%77%77%77%2e%65%2d%66%69%6e%64%65%72%2e%63%63/%68%70/ "  I dont know what this is, or how this happened.  I also cannot run windows update, I get a message saying "Windows Update has encountered an error and cannot display the requested page."  I have run Ad-aware and Spybot and cleaned out everything I can find, but that still did not help my problem.  I have even scanned my whole computer for viruses.  Thank you so much if you can help.

Thanks again.

2 Intern

 • 

409 Posts

April 12th, 2004 01:00

I think I would try to repair Internet Explorer.  This link will tell you how.

http://www.theeldergeek.com/repair_ie6.htm

71 Posts

April 12th, 2004 01:00

No, I did that, but it did not work.  Thanks a lot though.  Any other suggestions for fixing this problem?  Thank you.

123 Posts

April 12th, 2004 02:00

It might be due to a browser plugin that you inadvertently downloaded

start--run--inetcpl.cpl [Enter]
under "temporary internet files" click "settings"
click "view objects" delete everything except "update class" [this is the ms win updater]

at the same time delete all your cookies, temporary internet files, and files in
%userprofile%\temp and or %userprofile%\tmp

NOTE: while deleting these files in the temp directory you may not be able to delete them all
you will have to do CTRL+A to select all and then deselect the file which cannot be deleted and continue this process until only files left are the ones that cannot be deleted.

then set your desired homepage and that should hopefull solve the problem.

==rohini

71 Posts

April 12th, 2004 02:00

No, did this not help.  I noticed something though.  When I click on 'use current' in internet options.  The address reads "res://C:\WINDOWS\System32\shdoclc.dll/syntax.htm"  This might have something to do with it.  I have attached a screen shot of the home page.

4.4K Posts

April 12th, 2004 04:00

MOTO2000,

I checked that link with the FireFox browser, and was able to resolve it to www . e-finder . cc.

(edit) DNSStuff.com has a tool for interpreting obfuscated URLs. Here are the results for the URL you posted.

You probably don't recognize that name. It's strong evidence that your browser has been "hijacked". I found several posts searching Google corroborating that.

First check your machine with AdAware and SpyBot, as described in the first link listed below. If neither of those two steps resolves the problem, obtain a copy of HijackThis, again following the instructions in the first link below. Then submit your HijackThis log for analysis.

Jim

Message Edited by jimw on 04-11-2004 10:44 PM

18 Posts

April 12th, 2004 12:00

MOTO...I think you might have a virus.  I got MSBlaster last week and Im still trying to clean things up.  I had a lot of the same errors you are experiencing.  My IE Explorer also loaded that web page, http://%68...bla bla bla...and could not be reset....

 

I still havent worked out all the kinks but I just re-formatted my harddrive and re-installed windows..

 

 

71 Posts

April 12th, 2004 23:00

thanks jimw, and everyone for helping, i scanned with hijackthis and submitted my log in the help page.  I hope to get a reply and find the problem.  As soon as this problem happened, I noticed that windows update would not function properly, could this hijacking interfer with windows update?  Here is a screen shot of the error message I recieved.

4.4K Posts

April 12th, 2004 23:00

I noticed that windows update would not function properly, could this hijacking interfer with windows update? Here is a screen shot of the error message I recieved.

I suspect it could, but the HijackThis experts would know for sure.

Jim

71 Posts

April 16th, 2004 01:00

Wow, I figured out the problem, it is a virus after all.  I scanned my entire computer but found nothing.  The thing is, the virus is new, it was just discovered a couple of days ago. here is the description about it:  http://securityresponse.symantec.com/avcenter/venc/data/trojan.popdis.html  I found the file, but the problem is, is that I cannot delete it, I get a message saying that the file is in use.  The file name is "dp.dll"

123 Posts

April 16th, 2004 01:00

hi,
You can end the process run by that dll or you can try this tool, that will delete the marked files on boot.
http://www.snapfiles.com/get/moveonboot.html

==rohini

71 Posts

April 16th, 2004 02:00

sweet, thanks a lot, that worked, great program.
No Events found!

Top