Startup App Locations (Issue with Malware)

TechieSooner

Supreme [H]ardness
Joined
Nov 7, 2007
Messages
7,601
I've got someone's XP machine here...
The problem is the homepage keeps changing. If I set to, say, yahoo.com, reboot into safe mode- works fine.

If I reboot normally, it gets changed.

If I disable all services/startup items via msconfig and reboot, it gets changed (all services/startup items except for the Buffalo wireless entries- as this is a wireless machine).

If I run the Spybot Search and Destroy Tea Timer, it will block the app from changing the page. My issue with this is it doesn't tell me WHAT is blocking it (even viewing the log- it just says it blocked a change to the homepage, not WHAT tried to change it).


My question I guess, if msconfig doesn't disable this, what on earth could be changing this homepage?
 
I would get rid of Spybot S&D for one, I know it used to be king, but the times have passed it by.

- Toss on SuperAntiSpyware (free version is only on demand, $20 for a lifetime license is realtime protection)

- Get winpatrol for free. It'll tell you EXACTLY what is starting up with your system, and allow you to block startup programs as soon as they request access.

- Since this is XP, get Threatfire. Any good system needs an excellent HIPS, and threatfire is one of the best, and free.

- Use Dr Web's CureIt! program. It's a free download, doesn't install, and is one of the more powerful antivirus removal options out there.
 
I don't think this is malware per-say. It's just redirecting to the ISP's homepage...

It's like some sort of remnants of their software (but nothing I can find in Add/Remove programs or ANYWHERE of this program).
 
Autoruns will show you everything thats starting up on your system and gives you the ability to delete what you dont want starting.
 
Autoruns will show you everything thats starting up on your system and gives you the ability to delete what you dont want starting.

Looks almost exactly like that WinPatrol, will try running this as well though (So far- I'm not seeing anything super obvious).
 
Back
Top