For your 'script error' try this: With IE open, click on Tools, click on Internet Options, and then click on the Advanced tab. You should see a heading that says Browsing, and under that, one that says Disable script debugging. If there is not a checkmark at this, put one there.
For your HJT, close all windows, scan with hjt, and have it fix the following entries:
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {029CA12C-89C1-46a7-A3C7-82F2F98635CB} - (no file)
O9 - Extra button: Help - {1EDF7E86-71C9-4A9C-BD7A-36BE465AEAFF} - http://www.btopenworld.com/helpbb (file missing) (HKCU)
O18 - Protocol: aim - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - %SystemRoot%\system32\mshtml.dll (file missing)
O18 - Protocol: shell - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - %SystemRoot%\system32\mshtml.dll (file missing)
This will just clean up your log a bit. Post another log as I'm sure there are more things that should be addressed by one of the pro's. When you post the new log, include whether or not you still get the script error.
dlh6213
Posting Maven
3,117 posts since Jul 2004
Reputation Points: 63
Solved Threads: 214
Hi, since you hadn't posted in awhile I thought you got the problems fixed. I can only think of one other thing for you to try right now, hopefully someone will check your HJT and see if there's something there.
Get sysclean from here:
http://www.trendmicro.com/download/dcs.asp
For the Trend Micro Sysclean Package to be effective, you must download and place the latest pattern file in the same folder as the Trend Micro Sysclean Package. This file can be found in the Update Center on the left side, at the bottom of the list. Allow it to clean up any bad files it finds; it may take awhile.
After that, make sure all browser windows are closed, scan with HJT, and post a new log.
dlh6213
Posting Maven
3,117 posts since Jul 2004
Reputation Points: 63
Solved Threads: 214
This is how I have my ActiveX settings; use this as a guide to set your own to see if it helps any:
To get access to the ActiveX controls in Internet Explorer, Open IE, click on Tools, click on Internet Options, click on the Security tab, click on the Custom Level button (near the bottom). Scroll down a bit to ActiveX controls and plug-ins; here you will have several options. Keep in mind that if you Enable all the options, you are leaving your system open to unwanted intrusions.
Here is how I have my settings:
Download signed ActiveX controls -- Prompt
Download unsigned ActiveX controls -- Disable
Initialize and script ActiveX controls not marked as safe -- Disable
Run ActiveX controls and plug-ins -- Enable
Script ActiveX controls marked safe for scripting -- Enable
The more of these you have Disabled, the safer you system is, but there will be sites that you can't access. Prompting is the next best thing, but constantly clicking OK can be tedious and usually you don't know whether it should be allowed or not. The described combination works best for me, but not be best for you -- it is just shown as a reference.
Anyone have any advice on the HJT log? (Or other suggestions for the script and activex errors)
dlh6213
Posting Maven
3,117 posts since Jul 2004
Reputation Points: 63
Solved Threads: 214
I don't see anything bad in your log and since no one else has responded I'm guessing they don't either. This may not be malware related, perhaps if you post a thread in the Windows XP forum someone there will have some ideas. You might want to include a link to this thread as well. Sorry.
dlh6213
Posting Maven
3,117 posts since Jul 2004
Reputation Points: 63
Solved Threads: 214
The popup you're getting makes it apparent you have adware on your system, but I can't help you get rid of it. This is not a solution, but it should at least prevent the popups: try a browser other then Internet Explorer, like Firefox or Opera. Note: you will still need to keep IE in order to get Windows Updates and to access certain other sites.
For your other problems, a refresh install of Windows may resolve them.
(Suggestions compliments of Catweazle)
dlh6213
Posting Maven
3,117 posts since Jul 2004
Reputation Points: 63
Solved Threads: 214
Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked':
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O4 - HKLM\..\Run: [ExplorerTask] F:\WINNT\ServicePackFiles\i386\explorer.exe
O4 - HKLM\..\Run: [sysinfo] F:\WINNT\sysinfo.exe
Reboot into safe mode following the instructions here & navigate to & delete the following if found:
F:\WINNT\ServicePackFiles\i386\explorer.exe-file Not the legitimate file in C:\WINNT\Driver Cache\i386
F:\WINNT\sysinfo.exe-file
Reboot normally after doing the above, rescan with hijackthis making certain that all instances of Internet Explorer are closed, then post that log here please.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
Just fix these two and your log looks good.
O18 - Protocol: aim - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - %SystemRoot%\system32\mshtml.dll (file missing)
O18 - Protocol: shell - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - %SystemRoot%\system32\mshtml.dll (file missing)
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985