This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

IE redirects result in IE error msgs and shut downs

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

No, I can't get it to work from there either. Everything just vanishes. I can, however, do a RUN> COMMAND.COM and get the DOS window. Is that of any use at all?
Click Start> Run> type in command.com tap enter key
Copy/Paste: ipconfig /flushdns
Tap Enter
If you are typing this in, note the space between the g /f
It needs to be there.

Next type in: ipconfig /release
Tap Enter

Next type in: ipconfig /renew
Tap Enter


Now lets check some settings on your system.
Enter your Control Panel and double-click on Network Connections

Then right click on your Default Connection
Usually Local Area Connection for Cable and DSL
Left click on Properties
Double-Click on the Internet Protocol (TCP/IP) item
Select the radio dial that says Obtain DNS Servers Automatically
Note: Do this for all Network Connections
Press OK twice to get out of the properties screen and reboot if it asks
It looks like you have an external modem. Try unplugging the Power from the modem and wait about 5 minutes. Plug the power back in and try the internet. If still a no go, try using the reset button on the modem.
Hi LD, Yes, I'm using an external DSL Speedstream modem. I unplugged it for a few hours and tried it again but nothing has changed. There is no reset buttons (or pinholes or anything else) on these modems. I thought maybe my ethernet card might not be making a good connection so I removed it from the tower, dusted it, and replaced it. Then I re-loaded the drivers from the CD that shipped with the card. My first try to get somewhere from Google resulted in this error: The instruction at "0x77f580db" referenced memory at "0x682f3c3e". The memory could not be "written". Click OK to terminate the program. Fired up IE again and Googled "beef recipes"… cuz I wanted something simple to go with. One of the top results was for Cooks.com so I chose that one. The browser was redirected to elle.com (a woman's magazine) but before the page could load, IE encountered a problem and needed to close. Cranked it up again and tried again to access Cooks.com from Google results. Was redirected to Chatelaine magazines pages… but again, before it could load IE encountered a problem and had to close. It seems strange to me that the redirects all seem to point to women's magazines… not porn or anything nasty. And I've never visited those magazine sites before… Anyway, things aren't getting any better and I'm beginning to think it's time to just give up and give this tower to my brother to use as an anchor for his boat. ;) What do you think?
It's your call but I hate to give up.

1. launch Notepad (Start>All Programs>Accessories), and copy/paste all the Quoted REGEDIT below to it. Don't forget to include REGEDIT4.
Save in: Desktop
File Name: fixme.reg
Save as Type: All files
Click: Save

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""



2. Save this text as fixme.reg. Make sure the "Save as type:" is "All Files (*.*)" and save it to your desktop. Include the word REGEDIT4

3. Double-click on fixme.reg. When it asks you to merge the information to the registry click Yes.

4.Empty Recycle Bin

Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
I created the fixme.reg file, double clicked on it and all my icons and the task bar disappeared for a few seconds and then my desktop slowly rebuilt itself (the same thing that happens when I try a Run>CMD or a Run>REGEDIT)… but nothing asked me to do anything or confirm anything. I did copy everything in your quote box… including the REGEDIT4 heading… and saved it as type - All Files. But… when I right-click on this new fixme.reg icon (a blue cube that's exploding in front of a white document icon) the first option on the resulting menu is Merge in bold type. Should I opt for that?
I chose Merge from the menu I got by right-clicking on the fixme.reg icon. The desktop once again cleared itself of everything and then rebuilt itself.

I then went on Google and searched (once again) for beef recipes. One of the results was allrecipes.com. I clicked on that and got a notice that I was being redirected. When I hit the Back button on Google I got a window that said,

"Are you sure you want to navigate away from this page?

>>>>>>>>>>>>> WAIT WAIT WAIT <<<<<<<<<<<<<<<<<<<<<<<

A live agent wants to talk with you about a special offer!"

I closed down Google… and then fired it back up. Performed the same search. This time when I opted to go to allrecipes.com, the browser actually took me there. But as soon as the page started to load I got the "IE has encountered a problem and needs to close."

I went to empty the recycle bin after choosing Merge from the right-click menu but the bin was empty and the option to empty is was greyed out.

New HiJackThis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:44:39 PM, on 24/04/2009
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
D:\Program Files\Common Files\Symantec Shared\ccApp.exe
D:\Program Files\Max Registry Cleaner\MaxRCSystemTray.exe
D:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
D:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
D:\Program Files\WinZip\WZQKPICK.EXE
D:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
D:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\System32\devldr32.exe
D:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
D:\Program Files\Norton AntiVirus\navapsvc.exe
D:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
D:\Program Files\Spyware Terminator\sp_rsser.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\Tablet.exe
D:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
D:\WINDOWS\explorer.exe
D:\Documents and Settings\Helen\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - D:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - D:\Program Files\WS_FTP Pro\wsbho2k0.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - D:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [ccApp] "D:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [RCAutoLiveUpdate] D:\Program Files\Max Registry Cleaner\MaxLiveUpdateRC.exe -AUTO
O4 - HKLM\..\Run: [RCSystemTray] D:\Program Files\Max Registry Cleaner\MaxRCSystemTray.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "D:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "D:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [SpywareTerminator] "D:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: WinZip Quick Pick.lnk = D:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: D:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - D:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O20 - AppInit_DLLs:
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - D:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: LiveUpdate - Symantec Corporation - D:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - D:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - D:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - D:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - D:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - D:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - D:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: Symantec Core LC - Unknown owner - D:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TabletService - Wacom Technology, Corp. - D:\WINDOWS\System32\Tablet.exe

–
End of file - 6813 bytes
Lets try one more time.

NOTE: worksnow is actually Combofix renamed so user is able download and run Combofix

Download worksnow from HERE:


* IMPORTANT !!! Save worksnow to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on worksnow & follow the prompts.

    Note: worksnow will run without the Recovery Console installed.

    Note: Combofix will run without the Recovery Console installed.

  • As part of it's process, combofix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
"copy/paste" a new HijackThis log file into this thread as well.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.


Also please describe how your computer behaves at the moment.
Ho chi mama… :smack: Gettin' a tad freaked out here. As stated before, I cannot get to this forum using the PC… I'm on a borrowed laptop here. I downloaded 'worksnow.exe' on this laptop and transferred it to my flash drive. Took the flash drive over to the PC and Norton AV went ballistic. I hadn't even opted to move the file onto the desktop… just plugged in the drive and Norton jumped up with this: Virus Alert… High Risk Norton AntiVirus has detected a virus on your computer. Object Name: G:\worksnow.exe Virus Name: Trojan Horse Action Taken: Unable to repair this file Action Taken: Access to the file was denied. I know you said to disable all anti-virus and firewalls before 'running' the .exe file… but I never got a chance. I clicked OK to appease Norton but the same window kept leaping onto the screen. I kept clicking OK but it wouldn't stop appearing. It must have popped up at least 10 times. So I formatted the flash drive to get rid of worksnow.exe and disabled Norton. Brought the flash drive back to this laptop and copied the worksnow.exe back onto it. Took it back to the PC and transferred it from the flash drive to the desktop there. Double-clicked on the file an a very tiny window popped up with the title Combofix.exe and there was a status bar that counted down the installation (I guess) and when it was finished the hour glass next to the cursor flashed a couple of times and… that was it. Nothing else happened… I didn't get any screens to prompt me to go further or make a Recovery Console or anything else. Nothing. I don't know what to think…. it's all so bizarre… :unsure:
I assure you worksnow isn't a Trojan Horse nor any of the other Tools we use. If only these anti-virus programs would stop real infections from infecting a computer websites like WTT wouldn't be needed. I'm not sure where we should go from here. Maybe a re-install of Windows.
I don't doubt you or the tools you provide for an instant, LD. I actually said out loud to Norton AV, "Now you leap up and want to protect my computer? Where were you when I needed you to prevent the infection in the first place?"

The laptop uses AVG and it seems to be a cleaner, less bloated and faster AV program than Norton. Having said that, however, when AVG scanned the downloaded worksnow.exe it, too, found fault. Here's what it reported:

C:\Documents and Settings\Just Me\Desktop\worksnow.exe Trojan horse Agent2.AXL

C:\Documents and Settings\Just Me\Desktop\worksnow.exe\32788R22FWJFW\Tail.com Trojan horse Agent2.AXL


I guess I'll salvage some programs and pictures and stuff from the PC and admit that, finally, the fat lady has sung…

Thank you ever so much for your time, patience and expertise, LD. This is an amazing forum and I truly appreciate all the help!

Hugs,

Helen

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI