• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1772
  • Last Modified:

User home page keeps resetting to assistmypc

I have a user that has the google toolbar installed.  For some reason I can't find, her homepage is constantly resetting to http://assistmypc.googlepages.com/index.html.  I have tried changing it back, and it goes right back to it.  She has never used this service(?) and has no remote control apps on her system. Has anyone else seen this or how to get rid of it?
0
oncalltech
Asked:
oncalltech
1 Solution
 
Michael_MCDSTCommented:
Emtpy all cookies, history and reset IE to default. then disable any/all 3rd party addons for IE and finally uninstall google Toolbar and any other toobar for the browser. Once done go in and reset IE to default once again and test if issue persists
 
0
 
David-HowardCommented:
I recommend downloading and updating Malwarebytes.
You can get it free from www.Malwarebytes.org
Prior to running Malwarebytes (or any other anti-virus/malware suite),
disable System Restore. Directions can be found here:
http://support.microsoft.com/kb/310405
Once malwarebytes is downloaded, perform an update, reboot into Safe Mode (F8 at startup) and run a scan.
You should do this with your current antivirus product as well.
You may also need to download and run HiJackThis from
http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
Once you run the utility save the log file.
You can post it for free analysis here or at
www.hijackthis.de
You are primarily looking for items marked with red X's.
You can get a brief overview of Hijackthis here:
http://www.bleepingcomputer.com/tutorials/tutorial42.html
If the above steps fail to remove the threat,
you may need to download and run Combofix.
The free download and directions can be located here.
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
As noted in the directions, prior to running Combofix or any other anti-malware/anti-virus application please stop your anti-virus and anti-malware programs. Combofix should be saved to and run from your desktop.
You should rename the anti-malware suites to a different name prior to downloading as some threats can prevent them from running with their default names.

When you have finished running your scans and the threats have been removed enable System Restore.
0
 
Michael-BestCommented:
Got CONLICKER Worm?
If YOU cant go here:
http://onecare.live.com/site/en-US/center/cleanup.htm
And run scans
you Got Worm:Win32/Conficker.B
Microsoft is offering $250,000 to a (Worm:Win32/Conficker.B) FIX
Hope its ME
0
 
Michael-BestCommented:
Run the: "FULL SERVICE SCAN"
http://onecare.live.com/site/en-us/default.htm
0
 
bRvOCommented:
Spybot Search and destroy will detect and remove the Browser Hijacker even if it isn't malicious

www.safer-networking.org

0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Improved Protection from Phishing Attacks

WatchGuard DNSWatch reduces malware infections by detecting and blocking malicious DNS requests, improving your ability to protect employees from phishing attacks. Learn more about our newest service included in Total Security Suite today!

Tackle projects and never again get stuck behind a technical roadblock.
Join Now