943,761 Members | Top Members by Rank

Ad:
You are currently viewing page 1 of this multi-page discussion thread
Jul 2nd, 2004
0

IE doesn't work, here is my Hijackthis log...

Expand Post »
Hi everyone,

My ie is not working, but it works on other accounts on my xp operating software. Also, IE seems to work if I attempt to visit a "secure" site, but every other site comes up, "the page cannot be displayed...." I also can check my email through outlook. I also seem to have trouble accessing my itunes program, but again, it works on the other account. I downloaded all the latest spyware programs and popups are not usually a problem. Perhaps you can help??? Thanks!

Logfile of HijackThis v1.97.7
Scan saved at 6:34:46 PM, on 7/2/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\gearsec.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\documents and settings\rob\local settings\temp\ONhcKo.exe
C:\Program Files\Softex\OmniPass\scureapp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Softex\OmniPass\Help.exe
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
C:\Documents and Settings\Rob\My Documents\New Folder\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.theforce.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.attwireless.att.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8080
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://us.rd.yahoo.com/p/cpq/desk/*h....cpq.yahoo.com
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ONhcKo] C:\documents and settings\rob\local settings\temp\ONhcKo.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [OmniPass] C:\Program Files\Softex\OmniPass\scureapp.exe
O4 - HKLM\..\Run: [SysUpd] C:\WINDOWS\sysupd.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O14 - IERESET.INF: START_PAGE_URL=http://www.attwireless.att.net
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
Similar Threads
Reputation Points: 10
Solved Threads: 0
Newbie Poster
nuorder is offline Offline
8 posts
since Jun 2004
Jul 2nd, 2004
0

Re: IE doesn't work, here is my Hijackthis log...

Read the links in the following Google search for more info on the " O4 - HKLM\..\Run: [SysUpd] C:\WINDOWS\sysupd.exe" problem:

http://www.google.com/search?hl=en&i...=Google+Search

Have HJT fix the following entries:

O4 - HKLM\..\Run: [SysUpd] C:\WINDOWS\sysupd.exe
O4 - HKLM\..\Run: [ONhcKo] C:\documents and settings\rob\local settings\temp\ONhcKo.exe

Reboot into safe mode and:


- Delete C:\WINDOWS\sysupd.exe

- Delete the entire contents of C:\documents and settings\rob\local settings\temp\ (do this for any other user accounts you might have as well)

- In your Internet Options control panel:
Delete all cookies
Delete all Temporary Internet filess, including "offline content"

- Empty your Recycle Bin

- reboot
DMR
Team Colleague
Reputation Points: 221
Solved Threads: 369
Wombat At Large
DMR is offline Offline
6,439 posts
since Dec 2003
Jul 3rd, 2004
0

Re: IE doesn't work, here is my Hijackthis log...

Does it matter in which order I do those things; or should I do them exactly in the order listed???

Also, how do you reboot in "safe" mode?

Huge thanks, if this works...and if it doesn't still "Huge thanks" for helping out!
Reputation Points: 10
Solved Threads: 0
Newbie Poster
nuorder is offline Offline
8 posts
since Jun 2004
Jul 3rd, 2004
0

Re: IE doesn't work, here is my Hijackthis log...

ok...I just went through everything and it didn't help my problem. What gives? I did a new hijack this log...perhaps there is something we missed?

Logfile of HijackThis v1.97.7
Scan saved at 10:00:37 AM, on 7/3/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\gearsec.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Softex\OmniPass\scureapp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
C:\Program Files\Softex\OmniPass\Help.exe
C:\Program Files\AT&T\WnClient\Programs\wnConnect.exe
C:\PROGRA~1\AT&T\WnClient\Programs\WNCSMS~1.EXE
C:\Documents and Settings\Rob\My Documents\New Folder\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.theforce.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.attwireless.att.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8080
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://us.rd.yahoo.com/p/cpq/desk/*h....cpq.yahoo.com
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [OmniPass] C:\Program Files\Softex\OmniPass\scureapp.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O14 - IERESET.INF: START_PAGE_URL=http://www.attwireless.att.net
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{639A02E8-A8D6-49BD-8371-D592FCD59329}: NameServer = 12.102.244.4 204.127.129.4
Reputation Points: 10
Solved Threads: 0
Newbie Poster
nuorder is offline Offline
8 posts
since Jun 2004
Jul 3rd, 2004
0

Re: IE doesn't work, here is my Hijackthis log...

I don't see anything suspicious in your new log; is there a chance the problem is not malware-related? It could be something going on with your network/Internet connection, a problem on your ISP's end, etc.

You could try downloading a different browser (Netscape, Opera, or Firefox) to see if the problem is specific to IE or not.
DMR
Team Colleague
Reputation Points: 221
Solved Threads: 369
Wombat At Large
DMR is offline Offline
6,439 posts
since Dec 2003
Jul 3rd, 2004
0

Re: IE doesn't work, here is my Hijackthis log...

I don't know if it has anything to do with my isp, because I can access the net on the same computer, but through a different user name...Also, it is not totally specific to IE. When I try to access my itunes.com music store, it comes up empty as well; with an error message. Also, when I try to go online with the messed up account, I still am able to access my email through outlook. This is driving me absolutely crazy!!!!
Reputation Points: 10
Solved Threads: 0
Newbie Poster
nuorder is offline Offline
8 posts
since Jun 2004
Jul 3rd, 2004
0

Re: IE doesn't work, here is my Hijackthis log...

Quote originally posted by nuorder ...
When I try to access my itunes.com music store, it comes up empty as well; with an error message.
What is the exact error?
DMR
Team Colleague
Reputation Points: 221
Solved Threads: 369
Wombat At Large
DMR is offline Offline
6,439 posts
since Dec 2003
Jul 3rd, 2004
0

Re: IE doesn't work, here is my Hijackthis log...

This needs to go. O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE will be in either C:\Windows or C:\Windows\system32 folder. Make sure all programs are set to run in Msconfig, reboot then rescan with HJT (Get the latest version first) & post back.
Start/Run & type in *Msconfig* go to startup tab & *check* all boxes.
Moderator
Featured Poster
Reputation Points: 1142
Solved Threads: 982
Most Valuable Poster
crunchie is offline Offline
12,163 posts
since Feb 2004
Jul 3rd, 2004
0

Re: IE doesn't work, here is my Hijackthis log...

Just wondering....should I have HJT fix the problem first and then I search and destroy the file/program..??? Because when I first did the HJT and was told what to delete...I had HJT fix it and then when I went to look for the bugs they were were they were supposed to be. Anyway, should I do a fix first or delete the bug first??? Thanks again for all the help...you guys should be given an award!
Reputation Points: 10
Solved Threads: 0
Newbie Poster
nuorder is offline Offline
8 posts
since Jun 2004
Jul 4th, 2004
0

Re: IE doesn't work, here is my Hijackthis log...

The " O4 - HKLM\..\Run:" entries that you see in the HJT log are programs that have inserted themselves into your system's registry in such a way that they are automagically started each time you boot your computer. To find/view/edit/delete these entries:

Choose "run" under your Start menu and type "regedit" (omit the quotes) in the resulting dialog box; this will open the registry editor. In the registry editor, navigate to HKEY_LOCAL_MACHINE/Software/Microsoft/Windows/CurrentVersion/Run. Do not make any deletes/changes here unless you know what you're doing or have been given specific instructions! Many of these "autostarted" programs will be legit, but "malware" programs can insert themselves there as well.

When you ask HJT to fix "04" entries, it will only remove the registry values which start these programs, but it will not delete the offending programs themselves- hence the need to "fix" the entries with HJT and then reboot. In other words, HJT will remove the "autostart" registry entries so that the program will not start the next time you boot, which should (because the program has not been "asked" to run at startup) allow you to delete it.
DMR
Team Colleague
Reputation Points: 221
Solved Threads: 369
Wombat At Large
DMR is offline Offline
6,439 posts
since Dec 2003

This thread is more than three months old

No one has posted to this discussion for at least three months. Please let old threads die and do not reply to them unless you feel you have something new and valuable to contribute that absolutely must be added to make the discussion complete. Otherwise, please start a new thread in this forum instead.
Message:
Previous Thread in Viruses, Spyware and other Nasties Forum Timeline: Removed 2020 Search - problems still there: Hijackthis log included
Next Thread in Viruses, Spyware and other Nasties Forum Timeline: quik search bar....wtf?!





About Us | Contact Us | Advertise | Acceptable Use Policy
Forum Index | Build Custom RSS Feed


Follow us on Twitter


© 2011 DaniWeb® LLC