MyTechSupport.ca :: Your Computer Technical Resource Headquarters! MyTechSupport.ca :: Your Computer Technical Resource Headquarters!
HOME FORUMS RESOURCES & TOOLS ARTICLES ONLINE STORE ABOUT US
Computer Support Forums arrow Internet & Network Support arrow Internet & Email arrow Topic: An error has occured in IE
November 13, 2019, 02:51:04 PM
 

Home Forum Rules Help Search Mobile Version Login Register

Welcome, Guest. Please login or register.
Did you miss your activation email?
November 13, 2019, 02:51:04 PM

Login with username, password and session length
 Featured Sites:
News
Article Writers We are looking for quality, informational articles to add to our Computer Articles
Please contact us if you are interested in submitting some....
  0 Members and 1 Guest are viewing this topic.
Pages: [1] Go Down Print
Author Topic: An error has occured in IE  (Read 4605 times)
Kirby6
Jr. Member
**

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 26


Bookmark and Share

View Profile
« on: September 26, 2004, 03:57:30 PM »

PLEASE SUPPLY RELEVANT INFORMATION:
Operating System Version: Win '98
Problem Application Name & Version:
Problem Hardware Make & Model:
Error Messages: An error has ocurred in IE, IE will now close



I have  a USB wireless adapter hooked to this machine to form a small 2 system wireless network. I have an SMC wireless router and this wireless network was running fine until I ran ad-aware one day and now I get this error message. I have checked to make sure I'm getting a signal and it's at 60%. I went to start, then run and put in "cmd" to check my ipconfig and it came up "can't find file cmd or one of it's components. Make sure path and file name are correct and that all required libraries are available"  Any ideas?
Logged

 
benditup
Hero Member
*****

Karma: +2/-0
Offline Offline

Gender: Male
Posts: 2105


Bookmark and Share

View Profile
« Reply #1 on: September 26, 2004, 05:41:51 PM »

Hi Kirby, In Windows 98
Go to START>>>RUN>>>>type in command

Or try going to
START>>>RUN>>>type in winipcfg

You may want to try a different location for your Wireless base station

As for IE closing, I noticed you posted a Hijackthis log for your XP machine
You may also want to post a hijackthis log for your 98 machine
Post it in the security and viruses forum
Logged

 
Kirby6
Jr. Member
**

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 26


Bookmark and Share

View Profile
« Reply #2 on: September 26, 2004, 10:04:18 PM »

I typed in start, run, command and then ipconfig and here's what it pulled up...

1. Ethernet adapter
    IP address...............:0.0.0.0
    Subnet mask..............:0.0.0.0
    Gateway default..........:

2. Ethernet adapter
    IP address...............:0.0.0.0
    Subnet mask..............:0.0.0.0
    Gateway default..........:
3. Ethernet adapter
    IP address...............:0.0.0.0
    Subnet mask..............:0.0.0.0
    Gateway default..........:

4. Ethernet adapter:
   
   IP address.............192.168.2.123


Logged

 
Kirby6
Jr. Member
**

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 26


Bookmark and Share

View Profile
« Reply #3 on: September 26, 2004, 10:07:19 PM »

woops, he's the rest of my post....
  Subnet mask..........255.0.0.0
  Default Gateway......192.168.2.1
Logged

 
benditup
Hero Member
*****

Karma: +2/-0
Offline Offline

Gender: Male
Posts: 2105


Bookmark and Share

View Profile
« Reply #4 on: September 26, 2004, 10:38:08 PM »

If your having Networking problems you may want to try posting in the Networking forum

 
quote:
I ran ad-aware one day and now I get this error message


Can you open up Ad-Aware---Open Quarantine list
Highlight and restore what you removed
RESTART your computer and then post a Hijackthis log from your computer
Logged

 
Kirby6
Jr. Member
**

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 26


Bookmark and Share

View Profile
« Reply #5 on: September 26, 2004, 11:46:07 PM »

I don't have hijack this downloaded on this system. How do I download it if I can't get IE to pull up?
Logged

 
benditup
Hero Member
*****

Karma: +2/-0
Offline Offline

Gender: Male
Posts: 2105


Bookmark and Share

View Profile
« Reply #6 on: September 28, 2004, 11:23:39 PM »

Hijackthis is a small download, you could download it from one machine onto a floppy or Cd and transfer it to the other machine
Reverse the process, put the log on a floppy and post it from the machine online
Logged

 
Kirby6
Jr. Member
**

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 26


Bookmark and Share

View Profile
« Reply #7 on: September 29, 2004, 02:05:34 AM »

Here's my hijack this post from this machine...

Logfile of HijackThis v1.98.2
Scan saved at 8:49:25 PM, on 09/28/2004
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\WILD FILE\GOBACK\GBPOLL.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\WINDOWS\SYSTEM\JAVAYE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\STARTER.EXE
C:\WINDOWS\GWHOTKEY.EXE
C:\PAPRPORT\PPORTLDR.EXE
C:\PROGRAM FILES\ADAPTEC\DIRECTCD\DIRECTCD.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\PHOTOSMART\PHOTO IMAGING\HPI_MONITOR.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\WINDOWS\SYSTEM\ADDDP.EXE
C:\PROGRAM FILES\ADAPTEC\EASY CD CREATOR 4\CREATECD\CREATECD.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\DATE MANAGER\DATEMANAGER.EXE
C:\PROGRAM FILES\WILD FILE\GOBACK\GBMENU.EXE
C:\PROGRAM FILES\PRECISIONTIME\PRECISIONTIME.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
E:\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://cashsearch.biz/redir.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://cashsearch.biz/redir.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://cashsearch.biz/redir.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://drvvv.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://drvvv.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://cashsearch.biz/redir.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://cashsearch.biz/redir.php
R3 - Default URLSearchHook is missing
F1 - win.ini: run=hpfsched
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: ICOO Loader BHO - {B9D90B27-AD4A-413a-88CB-3E6DDC10DC2D} - C:\WINDOWS\MSOPT.DLL (file missing)
O2 - BHO: Class - {0122C0D8-8680-D482-B1B7-A6C961A3A2E3} - C:\WINDOWS\SYSTEM\WINXU32.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [Multi-function Keyboard] GWHotKey.exe
O4 - HKLM\..\Run: [PaperPort] c:\paprport\pportldr.exe
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\ADAPTEC\DIRECTCD\DIRECTCD.EXE
O4 - HKLM\..\Run: [CXMon] "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [WebInstall2] C:\WINDOWS\TEMP\INS2294.TMP /R /A
O4 - HKLM\..\Run: [WinTime] C:\WINDOWS\system32\wintime.exe
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Aplune Service] svchosd.exe
O4 - HKLM\..\Run: [ADDDP.EXE] C:\WINDOWS\SYSTEM\ADDDP.EXE
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
O4 - HKLM\..\Run: [CreateCD] C:\PROGRA~1\ADAPTEC\EASYCD~1\CREATECD\CREATECD.EXE -r
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [GoBack Polling Service] C:\Program Files\Wild File\GoBack\GBPoll.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [JAVAYE.EXE] C:\WINDOWS\SYSTEM\JAVAYE.EXE
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [eZulaMain] C:\Program Files\eZula\eZulaMain.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: date manager.lnk = C:\Program Files\Date Manager\DateManager.exe
O4 - Startup: GoBack.lnk = C:\Program Files\Wild File\GoBack\GBMenu.exe
O4 - Startup: precisiontime.lnk = C:\Program Files\PrecisionTime\PrecisionTime.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM95\AIM.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O12 - Plugin for .wav: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .mov: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .mpeg: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll
O12 - Plugin for .mid: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin2.dll
O12 - Plugin for .mpg: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll
O12 - Plugin for .mp3: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll
O16 - DPF: {351CF0CE-B05A-11D2-ABD9-00104B685417} (PWImageControl Class) - http://ebay.sj.ipixmedia.com/code//PWActiveXImgCtl.cab
O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - http://216.249.24.143/code/PWActiveXImgCtl.CAB
O16 - DPF: {11111111-1111-1111-1111-111111111157} - ms-its:mhtml:file://c:\nosuch.mht!http://cashsearch.biz/legal/x.chm::/load.exe
O18 - Protocol: icoo - {4A8DADD4-5A25-4D41-8599-CB7458766220} - C:\WINDOWS\MSOPT.DLL (file missing)
O21 - SSODL: System - {A79D1F40-B8A0-11D8-8736-000B6B10F194} - C:\WINDOWS\system32\system32.dll (file missing)

Logged

 
benditup
Hero Member
*****

Karma: +2/-0
Offline Offline

Gender: Male
Posts: 2105


Bookmark and Share

View Profile
« Reply #8 on: September 29, 2004, 03:03:37 AM »

Hi again Kirby
I take it this is the computer that can't get online
I need you to do a few things....

Access your Add/Remove Programs and Remove
New.net Application or New.net Domains
RESTART your computer
If you can't find either do the procedure from their website to remove
it....Preferrably procedure #4
http://www.newdotnet.com/removal.html

After Restart could you download and save to Desktop, or transfer from another computer
CWShredder 1.59.1

Set Windows to Show Hidden Files and Folders

RESTART your computer into SAFE MODE

Find and delete these files or folders if they exist
C:\WINDOWS\SYSTEM\ADDDP.EXE <--this file
C:\WINDOWS\system32\wintime.exe <--file
C:\WINDOWS\SYSTEM\JAVAYE.EXE <--file
svchosd.exe <--file, do a Search for it...

C:\Program Files\eZula <--folder

Navigate to these temp folders and delete the WHOLE contents or whatever you can
C:\WINDOWS\TEMP <--delete the contents
C:\WINDOWS\TEMPORARY INTERNET FILES <--delete contents

Stay in Safe Mode
Do another Scan with Hijackthis and put a check next to these entries
and then FIX CHECKED when ALL other windows are closed

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://cashsearch.biz/redir.php

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://cashsearch.biz/redir.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://cashsearch.biz/redir.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://drvvv.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://drvvv.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://cashsearch.biz/redir.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://cashsearch.biz/redir.php
R3 - Default URLSearchHook is missing

O2 - BHO: ICOO Loader BHO - {B9D90B27-AD4A-413a-88CB-3E6DDC10DC2D} - C:\WINDOWS\MSOPT.DLL (file missing)
O2 - BHO: Class - {0122C0D8-8680-D482-B1B7-A6C961A3A2E3} - C:\WINDOWS\SYSTEM\WINXU32.DLL

O4 - HKLM\..\Run: [WebInstall2] C:\WINDOWS\TEMP\INS2294.TMP /R /A
O4 - HKLM\..\Run: [WinTime] C:\WINDOWS\system32\wintime.exe

O4 - HKLM\..\Run: [Aplune Service] svchosd.exe
O4 - HKLM\..\Run: [ADDDP.EXE] C:\WINDOWS\SYSTEM\ADDDP.EXE

O4 - HKLM\..\RunServices: [JAVAYE.EXE] C:\WINDOWS\SYSTEM\JAVAYE.EXE

O4 - HKCU\..\Run: [eZulaMain] C:\Program Files\eZula\eZulaMain.exe

O16 - DPF: {11111111-1111-1111-1111-111111111157} - ms-its:mhtml:file://c:\nosuch.mht!http://cashsearch.biz/legal/x.chm::/load.exe
O18 - Protocol: icoo - {4A8DADD4-5A25-4D41-8599-CB7458766220} - C:\WINDOWS\MSOPT.DLL (file missing)
O21 - SSODL: System - {A79D1F40-B8A0-11D8-8736-000B6B10F194} - C:\WINDOWS\system32\system32.dll (file missing)


After you have FIX CHECKED and close Hijackthis
Open up JUST CWShredder and let it FIX all Problems

RESTART back in Normal Mode
Do Another Scan with Hijackthis and post a Fresh log
If you still can't get online, could you download
LSP fix

Open it up and let me know what you see in the left box, also let me know if you see anything in the Remove box...
Logged

 
Kirby6
Jr. Member
**

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 26


Bookmark and Share

View Profile
« Reply #9 on: September 30, 2004, 01:58:11 AM »

Everything worked pretty good.  I loaded the LSPfix after I still couldn't get online.
On the left it said:

Keep
rhr20.dll    DNS Name space provider
msafd.dll(Protocol handler)
rsvpsp.dll(Protocol handler)  

On the right in said..Remove
newdotnet6...Protocol handler

Here's the new hijack this post

Logfile of HijackThis v1.98.2
Scan saved at 8:38:23 PM, on 09/29/2004
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\WILD FILE\GOBACK\GBPOLL.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\STARTER.EXE
C:\WINDOWS\GWHOTKEY.EXE
C:\PAPRPORT\PPORTLDR.EXE
C:\PROGRAM FILES\ADAPTEC\DIRECTCD\DIRECTCD.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\PHOTOSMART\PHOTO IMAGING\HPI_MONITOR.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\PROGRAM FILES\ADAPTEC\EASY CD CREATOR 4\CREATECD\CREATECD.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\DATE MANAGER\DATEMANAGER.EXE
C:\PROGRAM FILES\WILD FILE\GOBACK\GBMENU.EXE
C:\PROGRAM FILES\PRECISIONTIME\PRECISIONTIME.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
D:\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R3 - Default URLSearchHook is missing
F1 - win.ini: run=hpfsched
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Class - {9E2E66D6-C138-8BD6-0873-1991E8C894C9} - C:\WINDOWS\SYSTEM\MFCSW.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [Multi-function Keyboard] GWHotKey.exe
O4 - HKLM\..\Run: [PaperPort] c:\paprport\pportldr.exe
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\ADAPTEC\DIRECTCD\DIRECTCD.EXE
O4 - HKLM\..\Run: [CXMon] "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [CreateCD] C:\PROGRA~1\ADAPTEC\EASYCD~1\CREATECD\CREATECD.EXE -r
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [GoBack Polling Service] C:\Program Files\Wild File\GoBack\GBPoll.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: date manager.lnk = C:\Program Files\Date Manager\DateManager.exe
O4 - Startup: GoBack.lnk = C:\Program Files\Wild File\GoBack\GBMenu.exe
O4 - Startup: precisiontime.lnk = C:\Program Files\PrecisionTime\PrecisionTime.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM95\AIM.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O12 - Plugin for .wav: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .mov: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .mpeg: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll
O12 - Plugin for .mid: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin2.dll
O12 - Plugin for .mpg: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll
O12 - Plugin for .mp3: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll
O16 - DPF: {351CF0CE-B05A-11D2-ABD9-00104B685417} (PWImageControl Class) - http://ebay.sj.ipixmedia.com/code//PWActiveXImgCtl.cab
O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - http://216.249.24.143/code/PWActiveXImgCtl.CAB



Do I maybe need to reload IE?





Logged

 
benditup
Hero Member
*****

Karma: +2/-0
Offline Offline

Gender: Male
Posts: 2105


Bookmark and Share

View Profile
« Reply #10 on: September 30, 2004, 03:39:15 AM »

Let's try this

Do another Scan with Hijackthis and put a check next to these entries
and then FIX CHECKED when ALL other windows are closed, including this one

R3 - Default URLSearchHook is missing
O2 - BHO: Class - {9E2E66D6-C138-8BD6-0873-1991E8C894C9} - C:\WINDOWS\SYSTEM\MFCSW.DLL

Optionally, Fix the next one too, it is NOT needed on Startup, Programs work fine without them
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

After you have Fix checked and Closed hijackthis

Open LSP fix
Ensure that newdotnet6...Protocol handler
is the only entry in the Remove pane
And then Click FINISH on the bottom right

RESTART your computer
Open LSP fix and make sure that newdotnet is gone
Post back with a Fresh Hijackthis log

Logged

 
Kirby6
Jr. Member
**

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 26


Bookmark and Share

View Profile
« Reply #11 on: September 30, 2004, 10:50:53 PM »

You are awesome again...LSP fix has nothing on the right hand side and I have internet. Here's my new hijack this post. Thanks again. I will certainly contribute to you guys.

Logfile of HijackThis v1.98.2
Scan saved at 5:35:24 PM, on 09/30/2004
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:WINDOWSSYSTEMKERNEL32.DLL
C:WINDOWSSYSTEMMSGSRV32.EXE
C:WINDOWSSYSTEMMPREXE.EXE
C:WINDOWSSYSTEMmmtask.tsk
C:WINDOWSSYSTEMMSTASK.EXE
C:PROGRAM FILESWILD FILEGOBACKGBPOLL.EXE
C:PROGRAM FILESCOMMON FILESSYMANTEC SHAREDCCEVTMGR.EXE
C:PROGRAM FILESCOMMON FILESSYMANTEC SHAREDCCSETMGR.EXE
C:WINDOWs*xPLORER.EXE
C:WINDOWSSYSTEMSYSTRAY.EXE
C:WINDOWSSTARTER.EXE
C:WINDOWSGWHOTKEY.EXE
C:PAPRPORTPPORTLDR.EXE
C:PROGRAM FILESADAPTECDIRECTCDDIRECTCD.EXE
C:PROGRAM FILESHEWLETT-PACKARDPHOTOSMARTPHOTO IMAGINGHPI_MONITOR.EXE
C:WINDOWSSYSTEMSTIMON.EXE
C:PROGRAM FILESREALREALPLAYERREALPLAY.EXE
C:PROGRAM FILESCOMMON FILESSYMANTEC SHAREDCCPD-LCSYMLCSVC.EXE
C:PROGRAM FILESCOMMON FILESSYMANTEC SHAREDCCAPP.EXE
C:PROGRAM FILESADAPTECEASY CD CREATOR 4CREATECDCREATECD.EXE
C:WINDOWSRunDLL.exe
C:PROGRAM FILESDATE MANAGERDATEMANAGER.EXE
C:PROGRAM FILESWILD FILEGOBACKGBMENU.EXE
C:PROGRAM FILESPRECISIONTIMEPRECISIONTIME.EXE
C:WINDOWSSYSTEMWMIEXE.EXE
D:HIJACKTHIS.EXE

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.yahoo.com/
F1 - win.ini: run=hpfsched
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:Program FilesNorton AntiVirusNavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSYSTEMMSDXM.OCX
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:Program FilesNorton AntiVirusNavShExt.dll
O4 - HKLM..Run: [SystemTray] SysTray.Exe
O4 - HKLM..Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM..Run: [EnsoniqMixer] starter.exe
O4 - HKLM..Run: [Multi-function Keyboard] GWHotKey.exe
O4 - HKLM..Run: [PaperPort] c:paprportpportldr.exe
O4 - HKLM..Run: [Adaptec DirectCD] C:PROGRA~1ADAPTECDIRECTCDDIRECTCD.EXE
O4 - HKLM..Run: [CXMon] "C:Program FilesHewlett-PackardPhotoSmartPhoto ImagingHpi_Monitor.exe"
O4 - HKLM..Run: [StillImageMonitor] C:WINDOWSSYSTEMSTIMON.EXE
O4 - HKLM..Run: [RealTray] C:Program FilesRealRealPlayerRealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM..Run: [Symantec Core LC] C:Program FilesCommon FilesSymantec SharedCCPD-LCsymlcsvc.exe start
O4 - HKLM..Run: [ccApp] "C:Program FilesCommon FilesSymantec SharedccApp.exe"
O4 - HKLM..Run: [CreateCD] C:PROGRA~1ADAPTECEASYCD~1CREATECDCREATECD.EXE -r
O4 - HKLM..RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM..RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM..RunServices: [GoBack Polling Service] C:Program FilesWild FileGoBackGBPoll.exe
O4 - HKLM..RunServices: [ScriptBlocking] "C:Program FilesCommon FilesSymantec SharedScript BlockingSBServ.exe" -reg
O4 - HKLM..RunServices: [ccEvtMgr] "C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe"
O4 - HKLM..RunServices: [ccSetMgr] "C:Program FilesCommon FilesSymantec SharedccSetMgr.exe"
O4 - HKCU..Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU..Run: [MoneyAgent] "C:Program FilesMicrosoft MoneySystemMoney Express.exe"
O4 - Startup: date manager.lnk = C:Program FilesDate ManagerDateManager.exe
O4 - Startup: GoBack.lnk = C:Program FilesWild FileGoBackGBMenu.exe
O4 - Startup: precisiontime.lnk = C:Program FilesPrecisionTimePrecisionTime.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:WINDOWSSYSTEMShdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:PROGRAM FILESAIM95AIM.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINDOWSweb\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINDOWSweb\related.htm
O12 - Plugin for .wav: C:PROGRA~1INTERN~1PLUGINS\npqtplugin.dll
O12 - Plugin for .mov: C:PROGRA~1INTERN~1PLUGINS\npqtplugin.dll
O12 - Plugin for .mpeg: C:PROGRA~1INTERN~1PLUGINS\npqtplugin3.dll
O12 - Plugin for .mid: C:PROGRA~1INTERN~1PLUGINS\npqtplugin2.dll
O12 - Plugin for .mpg: C:PROGRA~1INTERN~1PLUGINS\npqtplugin3.dll
O12 - Plugin for .mp3: C:PROGRA~1INTERN~1PLUGINS\npqtplugin3.dll
O16 - DPF: {351CF0CE-B05A-11D2-ABD9-00104B685417} (PWImageControl Class) - http://ebay.sj.ipixmedia.com/code//PWActiveXImgCtl.cab
O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - http://216.249.24.143/code/PWActiveXImgCtl.CAB

Logged

 
benditup
Hero Member
*****

Karma: +2/-0
Offline Offline

Gender: Male
Posts: 2105


Bookmark and Share

View Profile
« Reply #12 on: October 01, 2004, 02:46:29 AM »

Your log looks a lot better Kirby, can you please ask to close your other topic in the Networking forum

Ad-Aware is a great program, don't be worried about using it
The latest version is Ad-Aware SE Personal 1.05

If your not using this version, please uninstall yours from Add/Remove Programs and install the latest version
After installation-CHECK FOR UPDATES
Do a Full system scan----Remove All Critical objects
RESTART your computer to finish the cleaning process

ou should install these 2 apps., they add extra security while
silently protecting you, without running in the background

SpywareBlaster by JavaCool---will block bad ActiveX and malevolent cookies
Install---Check for Updates---Enable all protection
http://www.javacoolsoftware.com/spywareblaster.html

IE-Spyad---IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
Here is a tutorial and download link
TUTORIAL==http://www.bleepingcomputer.com/forums/index.php?showtutorial=53
Download link==https://netfiles.uiuc.edu/ehowes/www/resource.htm#IESPYAD
Scroll down and click on IE-SPYAD.EXE Free!

With both, Check for updates every couple of weeks

I'll lock this topic in a day or so, as your problems seem to be resolved, if you need it reopened please PM a MOD and supply a link to this thread
Logged

 
Pages: [1] Go Up Print 
 
Jump to:  

Powered by MySQL Powered by PHP

Powered by SMF 1.1.21 | SMF © 2015, Simple Machines

Valid XHTML 1.0! Valid CSS!

Disclaimer
This site is NOT responsible for any damage that the information on this site may cause to your system. Everything you try, whether inspired by the response given from this site or not, is entirely at your own risk. All product names and company names used herein are for identification purpose only and may be trademarks or registered trademarks of their respective owners. We are in no way affiliated or representing any of the companies on this site unless specified.
Back to Top
Stop Spam Harvesters, Join Project Honey Pot Fight Back Against Spammers! Get Firefox! Get Thunderbird! View Sylvain Amyots profile on LinkedIn
Back to Top
Google visited last this page November 26, 2018, 06:46:03 AM