PDA

View Full Version : IE6 Start Page Partial Hijack



gestan1
2007-03-29, 22:21
My system WinXPHome

IE6 currently opens at http://www.microsoft.com/isapi/redir.dll?Prd=ie&Pver=5.0&Ar=ie5update&O1=b1, which is not my set home page www.tiscali.co.uk. But whenever I click on 'Home' the Tiscali page opens correctly.

I have used HijackThis to view my system and have deleted an R0 & R1 lines and in IE6 have set the same Tiscali home page, but the above still happens.

However, I notice that very briefly as IE6 starts every time a small box/window with a Spybot Resident icon title (labelled: "Resident") appears very briefly near the system tray with the message:

"Registry Change Denied - resident denied the change of first home page
(category Browser page) based upon you black list."


I suggest that this problem may be as a result of some setting/changes in my
Spybot SD program>Tools>Resident page which has the following lines:

"22/02/2007 22:00:33 Allowed value "First Home Page" (new data:
"http://www.microsoft.com/isapi/redir.dll?Prd=ie&Pver=5.0&Ar=ie5update&O1=b1")
added in Browser page!" .............[This seems to be the problem line???],

and several lines of:

"29/03/2007 14:05:00 Denied value "First Home Page" (new data: "") deleted
in Browser page!"


Question: How to stop this IE6 problem happening, and how to find and amend the 'black list' in Spybot??

Note - This problem does not affect my Firefox browser.

Hoping for a solution soon. Thanks. :sad:

md usa spybot fan
2007-03-29, 23:28
Microsoft sometimes sets the "First Home Page" for updating IE6. Did you update on 2007-02-22 @ 22:00:33?

"First Home Page" should only be deplayed/used once and then is deleted.

The problem you are having is not because of:


"22/02/2007 22:00:33 Allowed value "First Home Page" (new data:
"http://www.microsoft.com/isapi/redir.dll?Prd=ie&Pver=5.0&Ar=ie5update&O1=b1")
added in Browser page!"
The problem is that you are not allowing that entry to be deleted:


"29/03/2007 14:05:00 Denied value "First Home Page" (new data: "") deleted
in Browser page!"
Because you are continually blocking the "First Home Page" deletion because originally you did a "Deny change" with the "Remember this decision" option.


"Registry Change Denied - resident denied the change of first home page
(category Browser page) based upon you black list."

You have to allow the deletion of the "First Home Page" entry.

Right click on the TeaTimer system tray icon and select Settings. This will bring up TeaTimer's "White & Black List". There are four (4) Buttons across the top of the "White & Black List":

Allowed processes
Blocked processes
Allowed registry changes
Blocked registry changes

Note: If you don't see all four buttons, try expanding the window to the right.
Go into "Blocked registry changes" and delete the entry blocking that registry change. You can delete entries by clicking on the scripted black "X" to the right of the entry that you want to delete and then clicking the "OK" button when you're done. This will in effect make TeaTimer forget what you told it to remember so that during future changes to these items TeaTimer will issue a pop-up dialog rather then just a notification pop-up.

The next time you start IE6 you should get the pop-up for the registry change again. Answer with "Allow change" and do not use the "Remember this decision" option.

gestan1
2007-03-30, 20:56
Many thanks for your quick response. The solution worked great - first time IE6 started it opened at the previous fault start page but the second and subsequent time of restarting IE6 it correctly opens to my home page.

Just a comment: You said right click on the 'Tea Timer' icon in the system tray, but when the mouse is over the icon a small window reads "Spybot-SD Resident" not "Tea Timer", and it also states "1172 processes blacklisted". When I click 'Settings' the Spybot window shows the 4 buttons, but trying each one does not show the 1172 blacklisted items. Where are these listed in Spybot and can they be amended if ever required? :bigthumb:

md usa spybot fan
2007-03-30, 22:37
gestan1:

TeaTimer performs two distinct functions:
Processes Monitor.
Registry Monitor.
The Process Monitor piece of TeaTimer monitors processes that are called or initiated in the system. If the process being called or initiated matches a list of known malicious processes in Spypot’s detection files, the process is terminated and an alert is issued in the form of a pop-up dialog to notify you and allow you to make choices as to how to handle the same process during future detections. TeaTimer terminates the application before asking because threats like toll dialers are time critical - they have to be terminated before they can connect.

I believe that the 1172 blacklisted items are the number of processes that TeaTimer looks for. The blacklisted items are not listed anywhere nor is the list alterable.