Click to See Complete Forum and Search --> : No Home page for Yahoo.UK


Fitter
April 11th, 2004, 05:41 PM
Hi to all,

Could i please ask the following question regarding my dual boot XP Home and 98SE computer?
What it is, is that on both systems i cannot access the search engine i normally use http://uk.yahoo.com/ in Internet Explorer 6.0.
But i can access it if i use my ISP browser from AOL, (i have to use AOL where i live because of the cheaper phone calls from the cable company against the normal main company) and this is driving me mad regarding why it won't work.
I have scanned both systems with Ad-Aware, SpyBot, AVG, a2 and i have stopped SpywareBlaster and SpywareGuard.
But still i cannot open yahoo UK in IE 6.0.

I used Hijack This and the results are as follows:

98SE result:

Logfile of HijackThis v1.97.7
Scan saved at 13:15:56, on 11/04/04
Platform: Windows 98 SE (Win9x 4.10.2222B)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGSERV9.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\SYSTEM\MDM.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\WINDOWS\ptsnoop.exe
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKUFIND.EXE
C:\PROGRAM FILES\CACHEMAN\CACHEMAN.EXE
C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE
C:\WINDOWS\SYSTEM\CTFMON.EXE
C:\PROGRAM FILES\SPYWAREGUARD\SGMAIN.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\SPYWAREGUARD\SGBHP.EXE
C:\PROGRAM FILES\AOL 7.0\WAOL.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\RAINLENDAR.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\NEW FOLDER\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com/
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\PROGRAM FILES\SPYWAREGUARD\DLPROTECT.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\GRISOFT\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [PTSNOOP] ptsnoop.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKLM\..\RunServices: [Machine Debug Manager] C:\WINDOWS\SYSTEM\MDM.EXE
O4 - HKCU\..\Run: [Cacheman] C:\PROGRA~1\CACHEMAN\Cacheman.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE"
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O8 - Extra context menu item: &Copy Location - C:\WINDOWS\WEB\graburl.htm
O9 - Extra button: Wallpaper (HKLM)
O9 - Extra 'Tools' menuitem: &Toolbar Wallpaper (HKLM)
O9 - Extra button: Offline (HKLM)
O9 - Extra 'Tools' menuitem: Add to Tr&usted Zone (HKLM)
O9 - Extra 'Tools' menuitem: Add to R&estricted Zone (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: MSN Messenger Service (HKLM)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/...ash/swflash.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.c...8084.7274421296

This is the result for XP Home:

Logfile of HijackThis v1.97.7
Scan saved at 13:22:36, on 11/04/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\PROGRA~1\Grisoft\AVG6\avgserv.exe
D:\Program Files\Norton Internet Security\NISUM.EXE
D:\WINDOWS\System32\nvsvc32.exe
D:\WINDOWS\system32\pctspk.exe
D:\WINDOWS\wanmpsvc.exe
D:\Program Files\Norton Internet Security\NISSERV.EXE
D:\Program Files\Norton Internet Security\SymProxySvc.exe
D:\WINDOWS\Explorer.EXE
D:\PROGRA~1\NORTON~1\navapw32.exe
D:\Program Files\Norton Internet Security\IAMAPP.EXE
D:\Program Files\Grisoft\AVG6\avgcc32.exe
D:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
D:\WINDOWS\tppaldr.exe
D:\WINDOWS\System32\NVATray.exe
D:\WINDOWS\tppnttry.exe
D:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
D:\Program Files\Rainlendar\Rainlendar.exe
D:\Program Files\SpywareGuard\sgmain.exe
D:\Program Files\Norton Internet Security\ATRACK.EXE
D:\Program Files\SpywareGuard\sgbhp.exe
K:\Software\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com/
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - D:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NAV Agent] D:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [iamapp] D:\Program Files\Norton Internet Security\IAMAPP.EXE
O4 - HKLM\..\Run: [AVG_CC] D:\Program Files\Grisoft\AVG6\avgcc32.exe /startup
O4 - HKLM\..\Run: [Microsoft Works Update Detection] D:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [TPP Auto Loader] D:\WINDOWS\tppaldr.exe
O4 - HKLM\..\Run: [NVIDIA nForce APU1 Utilities] NVATray.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "D:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - Startup: Rainlendar.lnk = D:\Program Files\Rainlendar\Rainlendar.exe
O4 - Startup: SpywareGuard.lnk = D:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: &Copy Location - D:\WINDOWS\WEB\graburl.htm
O9 - Extra 'Tools' menuitem: Add to R&estricted Zone (HKLM)
O9 - Extra 'Tools' menuitem: Add to Tr&usted Zone (HKLM)
O9 - Extra button: Wallpaper (HKLM)
O9 - Extra 'Tools' menuitem: &Toolbar Wallpaper (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Offline (HKLM)
O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} (PatchInstaller.Installer) - file://J:\content\include\XPPatchInstaller.CAB
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeu...ontent/opuc.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.c...8080.4356712963

I have also used CWShredder on both systems, and it found nothing. And both of my HOSTS files in XP and 98SE show the following:

# Copyright (c) 1998 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP stack for Windows98
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost


Can anyone please help me?
I must admit i have asked this on another forum, but have received no answers so far to help me.

Many thanks in advance.

Welshjim
April 11th, 2004, 06:16 PM
Fitter--I do not know if this is the cause or not. But your HiJackThis logs are not showing any R1 entries. Those show the URL's for the Search entries. Lacking them, it suggests you have not set up any search engine in IE6.
And your HOSTS file is actually the HOSTS.sam file. This comes with Windows and is only an example of what a real HOSTS file can look like. HOSTS.sam does nothing. (.sam is the file extension for "sample" files.)

Fitter
April 12th, 2004, 11:38 AM
Hi Welshjim,

Thanks for the reply.
And from what you say i can now see, that there is no Internet search engine setup.
But in XP when i click on the Search button in IE 6.0, i get a Search screen come up on the left saying about choosing a catagory for the Search.
And also "Find a webpage containing:", "Brought to you by MSN Search".

This now really has me confused, because if i go into this to try to change the default search engine, i can only choose MSN Search.
And regarding the Hosts file, i did a search in both XP and 98SE and all i can find are the files in the post above.
Even if i re-install the SpywareBlaster backups, i am still in the same state.

One last thing i am bothered about is if i put into the IE 6.0 address bar the following http://uk.yahoo.com/, all i get is a white blank page everytime in both XP and 98SE.

Fitter
April 12th, 2004, 12:13 PM
Hi again,

Regarding using Hijack This, i did a new list in XP and this time it came back with the following:

Logfile of HijackThis v1.94.0
Scan saved at 17:09:47, on 12/04/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://uk.yahoo.co.uk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=D:\WINDOWS\System32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=%SystemRoot%\system32\blank.htm
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - D:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NAV Agent] D:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [iamapp] D:\Program Files\Norton Internet Security\IAMAPP.EXE
O4 - HKLM\..\Run: [AVG_CC] D:\Program Files\Grisoft\AVG6\avgcc32.exe /startup
O4 - HKLM\..\Run: [TPP Auto Loader] D:\WINDOWS\tppaldr.exe
O4 - HKLM\..\Run: [NVIDIA nForce APU1 Utilities] NVATray.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "D:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O8 - Extra context menu item: &Copy Location - D:\WINDOWS\WEB\graburl.htm
O9 - Extra 'Tools' menuitem: Add to R&estricted Zone (HKLM)
O9 - Extra 'Tools' menuitem: Add to Tr&usted Zone (HKLM)
O9 - Extra button: Wallpaper (HKLM)
O9 - Extra 'Tools' menuitem: &Toolbar Wallpaper (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Offline (HKLM)
O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} (PatchInstaller.Installer) - file://J:\content\include\XPPatchInstaller.CAB
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38080.4356712963


I then deleted the bottom two R0 entries from the above with Hijack This, and then restarted my computer in XP.
This then set the default page in IE 6.0 to http://uk.yahoo.co.uk/.
But, still i got a blank page when IE 6.0 started up after i restarted the computer.
And then in Hijack This i found in the section 'Configuration', that my Default Start Page is set to 'Blank'.
I then copied and pasted the http://uk.yahoo.co.uk/ address into it, and closed Hijack This.
Tried IE 6.0, but still it came up a white blank page, and the 'Configuration' setting in Hijack This was again set to a 'Blank' for 'Default Start Page'.

Fitter
April 12th, 2004, 01:30 PM
Hi again,

I don't know if this matters, but the first XP Hijack This logfile above was done with Hijack This running from the XP partition in Windows Explorer. And the second Hijack This logfile below, was run from my Backup 1 partition.

My computer is set up as:

C: - Windows 98SE
D:\ - Windows XP Home
E:\ - Backup 1 (individual file backups)
F:\ - Backup 2 (Empty)
G:\ - Ghost 1 (Ghost image of E:\)
H:\ - Ghost 2 (Ghost images of C:\ & D:\)

Welshjim
April 12th, 2004, 03:43 PM
Fitter--I do not use partitions, so am ignorant as to how HiJackThis would treat them. However I will just ramble a bit in case it might help. Please forgive me if I say things you know.
1) Search page. When I click the Search button on my IE6 Toolbar, the panel on the left opens to Google, which I have set as my search engine. The message you are getting suggests that you are getting an MSNsearch window, perhaps by default. I changed that to Google a long time ago, so am a little hazy about the procedure. But I think I clicked on the "Customize" button just under the X on the Search panel, then on the window that opened I clicked "Autosearch settings", way down at the bottom left. That allowed me to set Google as my Search page. I think you are limited to the choices offered, but perhaps there is a setting in the Registry to permit you to add others.
2) Home page. You say you get a blank, white page. If IE still thinks your Home Page is about:blank, that could be normal. The main question is "Can you use the Address line on that page to access other sites?". Or is this page not functional as an IE window?. I have my home page set as about:blank since it loads faster than a website home page would. And you can change the color of the blank page by clicking IE Tools|Internet options|General tab|Colors. The General tab is also where you should be able to change your Home Page by entering a URL in that line. Don't forget to click Apply|OK. Note you do not change the Home Page by changing the HiJackThis log. All you can do is delete a Home page setting by deleting a HJT entry.
3) If none of the above has helped (and I have seen your comment that entering http://uk.yahoo.co.uk/ into the Address line of your IE window does not work), you might want to run the Internet Explorer Repair Tool. (Again I do not know how having partitions affects this.)
http://help.att.net/docs/howto/other/win/how_ie5_w95-3x_repair-tool.htm?np=1&area=customer_browser&customercontent=customer_browser&platform=none
More info:
For IE used on Windows OS's before XP
http://support.microsoft.com/default.aspx?scid=KB;EN-US;194177&
For XP (although the first link above also has some of this info)
http://support.microsoft.com/default.aspx?scid=kb;en-us;318378

Fitter
April 14th, 2004, 04:27 PM
Hi to all,

Can this post be classed as Solved please?
As i am afraid that i took the easy way out...:confused:

C:\ Format

D:\ Format

Re-Install C:\

Re-Install D:\

Many thanks for all fo the help that was offered to me.