Hello,

This is my first post in the forum and any help will be greatly appreciated.

My problem is that I cannot find the cursor and hence cannot enter any text in IE text-box...texts such as password or search phase. however this functionality works fine in nN 4.7. therefore I am writing this post from a different computer.

I recently downloaded ad-aware and spybot from the links in the posts in this forum, and have sucessfully removed some spyware. I also downloaded the iE 6.0 SP 1 from Microsoft, but that too is having the same problem. I use microsoft windows 2000 5.00.2195 on a Toshiba tecra 8000 laptop. I am getting this problem since the past few days and it is consistent (not intermittent).

Will appreciate any response. My HLogfile of HijackThis JT log is pasted below:

v1.97.7
Scan saved at 6:19:18 PM, on 6/12/2004
Platform: Windows 2000  (WinNT 5.00.2195)
MSIE: Unable to get Internet Explorer version!


Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\msdtc.exe
C:\WINNT\System32\llssrv.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\Explorer.exe
C:\WINNT\system32\Dfssvc.exe
C:\WINNT\EXPLORER.EXE
C:\Program Files\HP DLA\dlatray.exe
C:\WINNT\system32\dla\tfswctrl.exe
C:\Program Files\HP CD-DVD\Umbrella\hpcdtray.exe
C:\Program Files\Common
Files\Real\Update_OB\realsched.exe
C:\docume~1\me\applic~1\svchost.exe
C:\Program Files\OLYMPUS\CAMEDIA Master
4.1\CM_camera.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Internet Explorer\IEXPLORE .exe
C:\Program Files\Internet Explorer\IEXPLORE .exe
C:\explorer.exe
C:\PROGRA~2\WINZIP\winzip32.exe
C:\HJT\HijackThis.exe


R1 - HKCU\Software\Microsoft\Internet
Explorer\SearchURL,(Default) =
O2 - BHO: (no name) -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program
Files\Adobe\Acrobat
5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) -
{53707962-6F74-2D53-2644-206D7942484F} - C:\Program
Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) -
{A579FC44-3619-4D65-A6F8-58C19525141F} -
c:\winnt\system32\ilemba.dll (file missing)
O3 - Toolbar: &Radio -
{8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [HP DLA] "C:\Program Files\HP
DLA\dlatray.exe" /t
O4 - HKLM\..\Run: [dla]
C:\WINNT\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [HP CD-DVD] C:\Program Files\HP
CD-DVD\Umbrella\hpcdtray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKCU\..\Run: [System Update4]
c:\docume~1\me\applic~1\svchost.exe
O4 - HKCU\..\Run: [WTSS] C:\WINNT\System32\wapisu.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program
Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: CAMEDIA Master.lnk = C:\Program
Files\OLYMPUS\CAMEDIA Master 4.1\CM_camera.exe
O4 - Global Startup: WinZip Quick Pick.lnk =
C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links
(HKLM)
O9 - Extra button: Real.com (HKLM)
O12 - Plugin for .mpeg: C:\Program Files\Internet
Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .spop: C:\Program Files\Internet
Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE}
(TDServer Control) -http://www.anandabazar.com/wfplayer/tdserver.cab
O16 - DPF: {11120607-1001-1111-1000-110199901123} -
ms-its:mhtml:file://C:\foo.mht!
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
(Shockwave ActiveX Control) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
(Shockwave Flash Object) -http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

Dani AI

Generated

Symptom pattern (only Internet Explorer text boxes refuse input while other browsers work) strongly suggests a misbehaving IE extension/toolbar (BHO) or an injected/malicious process that hooks IE and grabs keyboard/focus. 's HijackThis approach is the right direction, but work from Safe Mode so cleaners and manual removals can act on locked files. Safe‑mode boots make it much easier to remove autostart items and hostile DLLs. (support.microsoft.com)

Quick isolation step: run Internet Explorer with extensions disabled to see whether an add‑on is responsible. Run this command (from Run or a shortcut):

iexplore.exe -extoff

If typing works in No‑Addons mode, systematically disable BHOs/toolbars instead of immediately deleting registry keys — use Autoruns to uncheck items and test until the problem disappears. Autoruns lets one safely disable and later undo changes if needed. (thewindowsclub.com)

If No‑Addons mode doesn't help, inspect running processes and file paths. Use Sysinternals Process Explorer to right‑click suspect processes, choose “Open File Location” and view Properties / Digital Signatures; legitimate system binaries are signed and live in the system folder, copies elsewhere (user profile/AppData or C:) are a common malware indicator. For stubborn persistence: disable the autostart entry in Autoruns, reboot to Safe Mode and then remove the file; if deletion fails, use offline rescue media or an alternate OS to remove it. (en.wikipedia.org)

After successful cleanup, run a full up‑to‑date anti‑malware scan and reset any account credentials used while the machine was compromised — incident‑response guidance calls for resetting passwords after containment. If IE still misbehaves after removing add‑ons/malware, rebuild the user profile or repair/reinstall IE/Windows as a last step. (scribd.com)

Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' :

O2 - BHO: (no name) -
{A579FC44-3619-4D65-A6F8-58C19525141F} -
c:\winnt\system32\ilemba.dll (file missing)

O4 - HKCU\..\Run: [System Update4]
c:\docume~1\me\applic~1\svchost.exe
O4 - HKCU\..\Run: [WTSS] C:\WINNT\System32\wapisu.exe

Reboot into safe mode following the instructions & navigate to & delete the following if found:

c:\docume~1\me\applic~1\svchost.exe< file (this file should only reside in the system32 folder)
C:\WINNT\System32\wapisu.exe< file

Reboot normally after doing the above then post a fresh log plz.

Please go to this file, right click on it & select properties. Please post all info you can get from it. Date created, product version. manufacturer, etc.
C:\Explorer.exe

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.