This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Internet Explorer trouble

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I'm having trouble with Internet Explorer. When I try to open Internet Explorer through a shortcut or by double clicking the exe file itself, an hourglass comes up for a second, but no window shows up. The iexplore.exe process is runs, but there's no visible sign of it. I've read about this problem and tried several methods to fix it like installing IE 8 and running sfc scannow, none of which have worked. The problem started after I got a virus infection and I removed it using Malware Bytes antimalware. I'm using firefox, but I want my IE back, please help. Here is the HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:05:27 PM, on 4/29/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\Roxio\Media Experience\DMXLauncher.exe
C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\explorer.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [TotalRecorderScheduler] "C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [DMXLauncher] "C:\Program Files\Roxio\Media Experience\DMXLauncher.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: *.antimalwareguard.com (HKLM)
O15 - Trusted Zone: *.gomyhit.com (HKLM)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.2.100.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/gamedownlo…Plugin11USA.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/gamedownlo…GPlugin9USA.cab
O16 - DPF: {DD583921-A9E9-4FBF-9266-8DC2AB5EA0AF} (HGPlugin10USA Class) - http://gamedownload.ijjimax.com/gamedownlo…Plugin10USA.cab
O20 - AppInit_DLLs: xmlnhj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Common Files\Sonic Shared\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Common Files\Sonic Shared\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 10015 bytes
Hi there and welcome - I need to see a bit more of your system but lets do a quick and dirty fix to start

Right-Click Here and Save As to download DelDomains.inf to your desktop.
To use: RIGHT-CLICK DelDomains.inf on your desktop and select: Install (no need to restart)
Note: This will remove all entries in the "Trusted Zone" and "Ranges" also.

Then lets see what you have

Download Rooter.exe to your desktop
  • Doubleclick it to start the tool.
  • A Notepad file containing the report will open, also found at %systemdrive%(usually C:)\Rooter.txt. Copy and paste it with your OTLI log.

THEN

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
Rooter.txt: Microsoft Windows XP Home Edition (5.1.2600) Service Pack 2 A:\ [Removable] (Total:0 Mo/Free:0 Mo) C:\ [Fixed] - NTFS - (Total:131061 Mo/Free:1840 Mo) D:\ [CD-Rom] (Total:24 Mo/Free:0 Mo) E:\ [Fixed] - NTFS - (Total:107411 Mo/Free:2604 Mo) Thu 04/30/2009|15:42 ———————-\\ Processes.. –Locked– [System Process] ———- System ———- \SystemRoot\System32\smss.exe ———- \??\C:\WINDOWS\system32\csrss.exe ———- \??\C:\WINDOWS\system32\winlogon.exe ———- C:\WINDOWS\system32\services.exe ———- C:\WINDOWS\system32\lsass.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\WINDOWS\system32\spoolsv.exe ———- C:\WINDOWS\Explorer.EXE ———- C:\WINDOWS\SOUNDMAN.EXE –Locked– CCAPP.EXE ———- C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe ———- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe ———- C:\Program Files\Roxio\Media Experience\DMXLauncher.exe ———- C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe ———- C:\Program Files\Microsoft IntelliPoint\ipoint.exe ———- C:\WINDOWS\system32\RUNDLL32.EXE ———- C:\Program Files\iTunes\iTunesHelper.exe ———- C:\Program Files\AIM6\aim6.exe ———- C:\WINDOWS\system32\ctfmon.exe ———- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe –Locked– AluSchedulerSvc.exe ———- C:\Program Files\Bonjour\mDNSResponder.exe –Locked– CCSETMGR.EXE ———- C:\Program Files\Common Files\LightScribe\LSSrvc.exe ———- C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe –Locked– NAVAPSVC.EXE –Locked– NPFMNTOR.EXE ———- C:\WINDOWS\System32\nvsvc32.exe ———- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe –Locked– SNDSrvc.exe –Locked– SPBBCSvc.exe ———- C:\WINDOWS\System32\svchost.exe –Locked– symlcsvc.exe ———- C:\WINDOWS\System32\wdfmgr.exe ———- C:\Program Files\Viewpoint\Common\ViewpointService.exe –Locked– CCEVTMGR.EXE ———- C:\WINDOWS\system32\wscntfy.exe ———- C:\Program Files\iPod\bin\iPodService.exe ———- C:\WINDOWS\System32\alg.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe ———- C:\Program Files\AIM6\aolsoftware.exe ———- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe ———- C:\Program Files\Windows Media Player\wmplayer.exe ———- C:\PROGRA~1\MOZILL~1\FIREFOX.EXE ———- C:\Program Files\Messenger\msmsgs.exe ———- C:\WINDOWS\system32\cmd.exe ———- C:\Rooter$\RK.exe ———————-\\ Search.. ———————-\\ ROOTKIT !! HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_TDSSSERV HKLM\SYSTEM\ControlSet003\Enum\Root\LEGACY_TDSSSERV HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TDSSSERV 1 - "C:\Rooter$\Rooter_1.txt" - Thu 04/30/2009|15:43 ———————-\\ Scan completed at 15:43 When I try to run OTListIt2 I get the following error message: Access violation at address 004045B4 in module 'OTListIt2.exe'. Read of address 00000000.
OK that has shown me the problem area

Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1
Link 2
Link 3

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–

Double click on Combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt along with a OTListit log so we can continue cleaning the system.
I'm still getting the error message I described above when I try to run OTListIT2, but ComboFix finished here's the log(IE still doesn't work):

ComboFix 09-04-30.05 - Owner 04/30/2009 19:03.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1983.1534 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\998.exe
c:\windows\system32\CID
c:\windows\system32\drivers\senekawbwevlvm.sys
c:\windows\system32\SvcNm
c:\windows\system32\url1
c:\windows\system32\url2
c:\windows\system32\url3
c:\windows\system32\win32hlp.cnf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_TDSSSERV
——-\Service_tdssserv


((((((((((((((((((((((((( Files Created from 2009-04-01 to 2009-05-01 )))))))))))))))))))))))))))))))
.

2009-04-30 20:42 . 2009-04-30 20:43 ——– d—–w C:\Rooter$
2009-04-29 19:51 . 2009-04-29 19:51 ——– d—–w c:\program files\Trend Micro
2009-04-29 02:04 . 2009-04-29 02:04 ——– d—–w c:\documents and settings\Owner\Local Settings\Application Data\tcbackup
2009-04-28 22:53 . 2009-04-28 22:53 ——– d—–w c:\documents and settings\NetworkService\Application Data\Xfire
2009-04-28 22:32 . 2009-04-28 22:32 ——– d-sh–w c:\documents and settings\LocalService\IETldCache
2009-04-28 22:32 . 2009-04-28 22:32 ——– d-sh–w c:\documents and settings\Owner\IETldCache
2009-04-28 22:26 . 2009-04-28 22:27 ——– dc-h–w c:\windows\ie8
2009-04-27 00:31 . 2009-04-27 00:31 ——– d—–w c:\windows\system32\LogFiles
2009-04-26 22:06 . 2009-04-26 22:06 ——– d–h–w c:\windows\$hf_mig$
2009-04-26 22:05 . 2008-02-26 11:59 294912 -c—-w c:\windows\system32\dllcache\msctf.dll
2009-04-26 21:13 . 2009-04-26 21:13 ——– d—–w c:\program files\iPod
2009-04-26 21:13 . 2009-04-26 21:14 ——– d—–w c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-26 21:13 . 2009-04-26 21:14 ——– d—–w c:\program files\iTunes
2009-04-26 21:13 . 2009-04-26 21:13 ——– d—–w c:\program files\Bonjour
2009-04-26 21:12 . 2009-04-26 21:12 ——– d—–w c:\program files\QuickTime
2009-04-26 21:11 . 2009-04-26 21:11 ——– d—–w c:\program files\Apple Software Update
2009-04-26 21:11 . 2009-03-26 20:23 36864 —-a-w c:\windows\system32\drivers\usbaapl.sys
2009-04-26 21:11 . 2009-03-26 20:23 1900544 —-a-w c:\windows\system32\usbaaplrc.dll
2009-04-26 21:11 . 2009-04-26 21:14 ——– dc—-w c:\windows\system32\DRVSTORE
2009-04-26 21:10 . 2009-04-26 21:13 ——– d—–w c:\program files\Common Files\Apple
2009-04-26 20:41 . 2004-08-04 05:56 2897920 ——w c:\windows\system32\xpsp2res.dll
2009-04-26 18:38 . 2001-08-18 03:36 5632 —-a-w c:\windows\system32\ptpusb.dll
2009-04-26 18:38 . 2002-08-29 11:41 150528 —-a-w c:\windows\system32\ptpusd.dll
2009-04-26 18:38 . 2004-08-04 03:58 15104 —-a-w c:\windows\system32\drivers\usbscan.sys
2009-04-26 18:34 . 2009-04-26 18:34 ——– d—–w c:\documents and settings\Owner\Local Settings\Application Data\Apple
2009-04-26 18:33 . 2009-04-26 21:52 ——– d—–w c:\documents and settings\Owner\Application Data\Apple Computer
2009-04-14 18:17 . 2009-04-14 18:17 41808 —-a-w c:\windows\system32\xfcodec.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-30 22:01 . 2007-03-16 02:36 ——– d—–w c:\program files\Common Files\Symantec Shared
2009-04-29 16:14 . 2008-08-11 20:15 ——– d—–w c:\program files\Xfire
2009-04-26 20:47 . 2007-02-21 15:10 76487 —-a-w c:\windows\PCHEALTH\HELPCTR\OfflineCache\index.dat
2009-04-26 18:53 . 2007-02-21 15:20 ——– d–h–w c:\program files\InstallShield Installation Information
2009-04-04 19:36 . 2007-03-10 18:27 ——– d—–w c:\program files\Starcraft
2009-03-22 00:27 . 2009-03-22 00:19 ——– d—–w c:\program files\TallStick
2009-03-19 21:32 . 2006-09-19 19:44 23400 —-a-w c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-08 09:34 . 2004-02-06 22:05 914944 —-a-w c:\windows\system32\wininet.dll
2009-03-08 09:34 . 2007-04-03 17:25 43008 —-a-w c:\windows\system32\licmgr10.dll
2009-03-08 09:33 . 2007-02-24 01:28 18944 —-a-w c:\windows\system32\corpol.dll
2009-03-08 09:33 . 2007-04-03 17:26 420352 —-a-w c:\windows\system32\vbscript.dll
2009-03-08 09:32 . 2007-02-24 01:28 72704 —-a-w c:\windows\system32\admparse.dll
2009-03-08 09:32 . 2007-04-03 17:24 71680 —-a-w c:\windows\system32\iesetup.dll
2009-03-08 09:31 . 2007-04-03 17:24 34816 —-a-w c:\windows\system32\imgutil.dll
2009-03-08 09:31 . 2007-04-03 17:25 48128 —-a-w c:\windows\system32\mshtmler.dll
2009-03-08 09:31 . 2007-02-24 01:28 45568 —-a-w c:\windows\system32\mshta.exe
2009-03-08 09:22 . 2001-08-18 12:00 156160 —-a-w c:\windows\system32\msls31.dll
2009-02-11 15:19 . 2009-02-16 14:19 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-11 15:19 . 2009-02-16 14:19 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-02-01 03:30 . 2008-12-20 21:17 131072 —-a-w c:\windows\system32\SpoonUninstall.exe
2009-01-31 02:18 . 2007-04-28 01:12 21840 —-atw c:\windows\system32\SIntfNT.dll
2009-01-31 02:18 . 2007-04-28 01:12 17212 —-atw c:\windows\system32\SIntf32.dll
2009-01-31 02:18 . 2007-04-28 01:12 12067 —-atw c:\windows\system32\SIntf16.dll
2007-03-11 23:39 . 2007-03-11 23:38 1388544 —-a-w c:\program files\mozilla firefox\plugins\MSVBVM60.DLL
2008-09-10 18:49 . 2008-09-10 18:49 5817064 —-a-w c:\program files\mozilla firefox\plugins\ScorchPDFWrapper.dll
2008-09-10 18:49 . 2008-09-10 18:49 5817064 —-a-w c:\program files\opera\program\plugins\ScorchPDFWrapper.dll
2008-01-16 01:06 . 2007-02-22 04:19 67696 —-a-w c:\program files\mozilla firefox\components\jar50.dll
2008-01-16 01:06 . 2007-02-22 04:19 54376 —-a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-01-16 01:06 . 2007-02-22 04:19 34952 —-a-w c:\program files\mozilla firefox\components\myspell.dll
2008-01-16 01:06 . 2007-02-22 04:19 46720 —-a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-01-16 01:06 . 2007-02-22 04:19 172144 —-a-w c:\program files\mozilla firefox\components\xpinstal.dll
2007-03-04 22:08 . 2007-03-04 22:08 8 –sh–r c:\windows\system32\DACF22BEF1.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-10-31 50480]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2007-12-05 8523776]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-01-17 58728]
"Symantec NetDriver Monitor"="c:\progra~1\SYMNET~1\SNDMon.exe" [2007-08-09 100056]
"TotalRecorderScheduler"="c:\program files\HighCriteria\TotalRecorder\TotRecSched.exe" [2006-05-12 86016]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-08-10 221184]
"DMXLauncher"="c:\program files\Roxio\Media Experience\DMXLauncher.exe" [2006-08-14 102400]
"RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-07-31 1116920]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2006-07-07 600896]
"NvMediaCenter"="c:\windows\System32\NvMcTray.dll" [2007-12-05 81920]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2006-01-11 577536]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-12-05 1626112]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Microsoft Works Calendar Reminders.lnk - c:\program files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [1999-9-4 53317]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"mixer"= DrvTrNTm.dll
"wave"= DrvTrNTm.dll
"midi1"= xgusb.cpl
"midi2"= xgusb.cpl

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"stllssvr"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R1 c2scsi;c2scsi; [x]
R3 asbp2poa;asbp2poa; [x]
R3 FoxAwdWINFLASH;FoxAwdWINFLASH;c:\program files\Fox LiveUpdate\FoxAwdWINFLASH.SYS [2005-10-29 4380]
R3 PsSdk41;PsSdk41;c:\windows\System32\Drivers\pssdk41.sys [2008-08-24 36928]
S1 vcdrom;Virtual CD-ROM Device Driver;c:\windows\system32\drivers\VCdRom.sys [2001-12-19 8576]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-04-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2009-04-25 c:\windows\Tasks\Norton AntiVirus - Scan my computer - Rami.job
- c:\progra~1\NORTON~1\Navw32.exe [2007-03-30 17:54]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\jryrmfjq.default\
FF - prefs.js: browser.startup.homepage - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-30 19:08
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\x2èwÿÿÿÿ_çwÿcÔw*]
"AB141C35E9F4BF344B9FC010BB17F68A"=""
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(396)
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Symantec Shared\CCSETMGR.EXE
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Norton AntiVirus\NAVAPSVC.EXE
c:\program files\Norton AntiVirus\IWP\NPFMNTOR.EXE
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
c:\program files\Common Files\Symantec Shared\SNDSrvc.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Common Files\Symantec Shared\CCEVTMGR.EXE
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\AIM6\aolsoftware.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
c:\program files\Messenger\msmsgs.exe
.
**************************************************************************
.
Completion time: 2009-05-01 19:10 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-01 00:10

Pre-Run: 44,827,549,696 bytes free
Post-Run: 45,070,024,704 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

214
Hi again I will now use another OT tool this one can be run in safe mode if it will not run in normal

To ensure that I get all the information this log will need to be attached (instructions at the end) if it is to large to attach then upload to Mediafire and post the sharing link.

Download OTScanit2 to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt on your desktop.
  • Close ALL OTHER PROGRAMS.
  • Open the OTScanit folder and double-click on OTScanit.exe to start the program.
  • Check the box that says Scan All Users
  • Check the Radio button for Rootkit check YES
  • Under Additional Scans check the following:
    • File - Lop Check
    • File - Purity Scan
    • Evnt - EventViewer Errors/Warnings (last 10)
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Please attach the log in your next post.

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post
Run this fix and then I will do an AV scan

Start OTScanit. Copy/Paste the information in the quotebox below into the pane where it says "Paste fix here" and then click the Run Fix button.

[Unregister Dlls]
[Files/Folders - Modified Within 30 Days]
NY -> 4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp
NY -> 10 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
NY -> iwgeokxb-RFARHA.dll -> %UserProfile%\Local Settings\Temp\iwgeokxb-RFARHA.dll
[File - Lop Check]
NY -> com.doubleperfect.ggpo.0753AD3679DBFCA1E7F470171B7D0DB8B404A7EA.1 -> C:\Documents and Settings\Ramzi\Application Data\com.doubleperfect.ggpo.0753AD3679DBFCA1E7F470171B7D0DB8B404A7EA.1
[Empty Temp Folders]

The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here.

I will review the information when it comes back in.

Download Dr.Web CureIt to the desktop:
  • Doubleclick the drweb-cureit icon to start the program.
  • press start
  • Allow the program to run the initial express scan
  • This will scan the files currently running in memory. If something is found, click the YES button when it asks you if you want to cure it. This is only a short scan.
    Note: A pop up may appear during this phase suggesting you purchase their program - click the X at the top right corner of this pop-up to close it.
  • Once the short scan has finished, check the Complete scan box on the left side, even if nothing was found on the initial scan.
  • Then click the small green arrow button on the right under the Dr.Web Antivirus picture to start the complete scan. (This scan will take several hours)
  • During this complete scan - if Dr.Web finds an infection a window will pop up requesting your attention. Select the Cure button.
    • Note:(If the file cannot be cured, Dr.Web will automatically delete the file)
  • Once the scan is complete, on the menu bar, click file and choose report list.
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Note:this report will need to be renamed to Dr.Web.txt in order to post it on the forum.
  • Close Dr.Web Cureit.
  • Please post the Dr.Web.txt report in your next reply

Also let me know of any problems you encountered performing the steps above or any continuing problems you are still having with the computer.
Internet Explorer is still behaving in the same way, here are the logs. Other than the problem with IE, everything is normal. OTScanIt log: [Files/Folders - Modified Within 30 Days] C:\WINDOWS\msdownld.tmp folder deleted successfully. C:\WINDOWS\NV13881828.TMP folder deleted successfully. C:\WINDOWS\NV1836244.TMP folder deleted successfully. C:\WINDOWS\NV20122024.TMP folder deleted successfully. File C:\Documents and Settings\Ramzi\Local Settings\Temp\iwgeokxb-RFARHA.dll not found! [File - Lop Check] C:\Documents and Settings\Ramzi\Application Data\com.doubleperfect.ggpo.0753AD3679DBFCA1E7F470171B7D0DB8B404A7EA.1\Local Store\#SharedObjects\ggpo.swf folder moved successfully. C:\Documents and Settings\Ramzi\Application Data\com.doubleperfect.ggpo.0753AD3679DBFCA1E7F470171B7D0DB8B404A7EA.1\Local Store\#SharedObjects folder moved successfully. C:\Documents and Settings\Ramzi\Application Data\com.doubleperfect.ggpo.0753AD3679DBFCA1E7F470171B7D0DB8B404A7EA.1\Local Store folder moved successfully. C:\Documents and Settings\Ramzi\Application Data\com.doubleperfect.ggpo.0753AD3679DBFCA1E7F470171B7D0DB8B404A7EA.1 folder moved successfully. [Empty Temp Folders] File delete failed. C:\Documents and Settings\Ramzi\Local Settings\Temp\~ROMFN_0000038C scheduled to be deleted on reboot. User's Temp folder emptied. User's Internet Explorer cache folder emptied. File delete failed. C:\Documents and Settings\Ramzi\Local Settings\Temporary Internet Files\Content.IE5\QOPHUJ56\AIM_UAC_v2[1].adp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Ramzi\Local Settings\Temporary Internet Files\Content.IE5\QOPHUJ56\tcodebl[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Ramzi\Local Settings\Temporary Internet Files\Content.IE5\QOPHUJ56\tcodewads[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Ramzi\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. User's Temporary Internet Files folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Network Service Temp folder emptied. File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Network Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\JET530C.tmp scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. File delete failed. C:\Documents and Settings\Ramzi\Local Settings\Application Data\Mozilla\Firefox\Profiles\jryrmfjq.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Ramzi\Local Settings\Application Data\Mozilla\Firefox\Profiles\jryrmfjq.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Ramzi\Local Settings\Application Data\Mozilla\Firefox\Profiles\jryrmfjq.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Ramzi\Local Settings\Application Data\Mozilla\Firefox\Profiles\jryrmfjq.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Ramzi\Local Settings\Application Data\Mozilla\Firefox\Profiles\jryrmfjq.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. RecycleBin -> emptied. < End of fix log > OTScanIt2 by OldTimer - Version 1.0.14.0 fix logfile created on 05022009_140625 Files moved on Reboot… File C:\Documents and Settings\Ramzi\Local Settings\Temp\~ROMFN_0000038C not found! C:\Documents and Settings\Ramzi\Local Settings\Temporary Internet Files\Content.IE5\QOPHUJ56\AIM_UAC_v2[1].adp moved successfully. C:\Documents and Settings\Ramzi\Local Settings\Temporary Internet Files\Content.IE5\QOPHUJ56\tcodebl[1].htm moved successfully. C:\Documents and Settings\Ramzi\Local Settings\Temporary Internet Files\Content.IE5\QOPHUJ56\tcodewads[1].htm moved successfully. C:\WINDOWS\temp\JET530C.tmp moved successfully. C:\Documents and Settings\Ramzi\Local Settings\Application Data\Mozilla\Firefox\Profiles\jryrmfjq.default\Cache\_CACHE_001_ moved successfully. C:\Documents and Settings\Ramzi\Local Settings\Application Data\Mozilla\Firefox\Profiles\jryrmfjq.default\Cache\_CACHE_002_ moved successfully. C:\Documents and Settings\Ramzi\Local Settings\Application Data\Mozilla\Firefox\Profiles\jryrmfjq.default\Cache\_CACHE_003_ moved successfully. C:\Documents and Settings\Ramzi\Local Settings\Application Data\Mozilla\Firefox\Profiles\jryrmfjq.default\Cache\_CACHE_MAP_ moved successfully. C:\Documents and Settings\Ramzi\Local Settings\Application Data\Mozilla\Firefox\Profiles\jryrmfjq.default\XUL.mfl moved successfully. Registry entries deleted on Reboot… Dr Web CureIt log: aim553599.exe\data038;C:\Documents and Settings\Rami\Desktop\extras\Installations\aim553599.exe;Adware.Aws;; aim553599.exe;C:\Documents and Settings\Rami\Desktop\extras\Installations;Archive contains infected objects;; mousehook.dll;C:\Documents and Settings\Rami\Local Settings\Temp;Trojan.Click.24603;Deleted.; ntdll64.dll;C:\Documents and Settings\Rami\Local Settings\Temp;Trojan.DownLoad.29917;Deleted.; 1[1].exe;C:\Documents and Settings\Rami\Local Settings\Temporary Internet Files\Content.IE5\TVBPT1P4;Trojan.Virtumod.1556;Deleted.; Auto Xbins 2008 by Ground Zero.exe;C:\Documents and Settings\Ramzi\Desktop;Probably BACKDOOR.IRC.Trojan;Invalid path to file ; DXwnd.exe;C:\Documents and Settings\Ramzi\Desktop\DxWnd;Trojan.PWS.Akak.13;Deleted.; WxBug.EXE;C:\Program Files\AIM\Sysfiles;Adware.Aws;; 137B0DAF.dat;C:\Program Files\Norton AntiVirus\Quarantine;Trojan.Proxy.1739;Deleted.; 15617D98.dat;C:\Program Files\Norton AntiVirus\Quarantine;Trojan.Proxy.1739;Deleted.; 47231EFE.exe;C:\Program Files\Norton AntiVirus\Quarantine;Trojan.Fakealert;Deleted.; 4D841FF9.exe;C:\Program Files\Norton AntiVirus\Quarantine;Tool.ASEye.2;; 4D8749F5.exe;C:\Program Files\Norton AntiVirus\Quarantine;Tool.ASEye.2;; 538423CF;C:\Program Files\Norton AntiVirus\Quarantine;Trojan.Fakealert.401;Deleted.; 57A97FEE.exe;C:\Program Files\Norton AntiVirus\Quarantine;Trojan.NtRootKit.115;Deleted.; 5A6D16E2.ini;C:\Program Files\Norton AntiVirus\Quarantine;Trojan.NtRootKit.115;Deleted.; 610F5F95.sys;C:\Program Files\Norton AntiVirus\Quarantine;Trojan.KeyLogger.91;Deleted.; 70CF30F1.tmp;C:\Program Files\Norton AntiVirus\Quarantine;Trojan.Virtumod.211;Deleted.; 749A35B3.exe;C:\Program Files\Norton AntiVirus\Quarantine;Win32.HLLW.Tazebama;Deleted.; 74A109AC.exe;C:\Program Files\Norton AntiVirus\Quarantine;Win32.HLLW.Texmer.38;; 74A85DA5.exe;C:\Program Files\Norton AntiVirus\Quarantine;Win32.HLLW.Tazebama;Deleted.; 998.exe.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Fakealert.3952;Deleted.; A0027261.exe;C:\System Volume Information\_restore{6BE83B00-32A7-4C4B-8CF7-DD681592CE23}\RP106;Trojan.Fakealert.3952;Deleted.; A0027277.EXE;C:\System Volume Information\_restore{6BE83B00-32A7-4C4B-8CF7-DD681592CE23}\RP106;Program.PsExec.170;Incurable.Deleted.; A0027316.bat;C:\System Volume Information\_restore{6BE83B00-32A7-4C4B-8CF7-DD681592CE23}\RP106;Probably BATCH.Virus;Incurable.Deleted.; A0027417.exe;C:\System Volume Information\_restore{6BE83B00-32A7-4C4B-8CF7-DD681592CE23}\RP107;Trojan.PWS.Akak.13;Deleted.; A0027418.exe;C:\System Volume Information\_restore{6BE83B00-32A7-4C4B-8CF7-DD681592CE23}\RP107;Probably BACKDOOR.IRC.Trojan;Incurable.Deleted.; A0027426.exe;C:\System Volume Information\_restore{6BE83B00-32A7-4C4B-8CF7-DD681592CE23}\RP107;Trojan.Fakealert;Deleted.; A0027427.exe;C:\System Volume Information\_restore{6BE83B00-32A7-4C4B-8CF7-DD681592CE23}\RP107;Trojan.NtRootKit.115;Deleted.; A0027428.ini;C:\System Volume Information\_restore{6BE83B00-32A7-4C4B-8CF7-DD681592CE23}\RP107;Trojan.NtRootKit.115;Deleted.; A0027429.sys;C:\System Volume Information\_restore{6BE83B00-32A7-4C4B-8CF7-DD681592CE23}\RP107;Trojan.KeyLogger.91;Deleted.; A0027430.exe;C:\System Volume Information\_restore{6BE83B00-32A7-4C4B-8CF7-DD681592CE23}\RP107;Win32.HLLW.Tazebama;Deleted.; A0027431.exe;C:\System Volume Information\_restore{6BE83B00-32A7-4C4B-8CF7-DD681592CE23}\RP107;Win32.HLLW.Tazebama;Deleted.; A0015276.exe;C:\System Volume Information\_restore{6BE83B00-32A7-4C4B-8CF7-DD681592CE23}\RP78;Trojan.DownLoad.28002;Incurable.Deleted.; A0015277.exe;C:\System Volume Information\_restore{6BE83B00-32A7-4C4B-8CF7-DD681592CE23}\RP78;Trojan.DownLoad.28002;Incurable.Deleted.;
OK lets look at the system settings

Lets check some settings on your system:
  • Enter your Control Panel and double-click on Network Connections
  • Then right click on your Default Connection
    • Usually Local Area Connection for Cable and DSL, or AOL Connection.
  • Left click on Properties
  • Double-Click on the Internet Protocol (TCP/IP) item
  • Select the radio dial that says Obtain DNS Servers Automatically
  • Press OK twice to get out of the properties screen
  • Restart the computer
Go to Start->Run->Type CMD and click Ok. The MSDOS Window will be displayed. At the command prompt, type the following and press Enter after each line:

ipconfig /flushdns (The space between g and / is needed)
regsvr32 netshell.dll
regsvr32 netcfgx.dll
regsvr32 netman.dll

Exit

Restart the computer.

THEN

Go to Control Panel and select Internet Options
Select the Connections TAB
Select LAN settings button
Ensure there is no tick in the Proxy Server box
Select OK and restart Internet explorer
Okay, I checked the settings and followed the steps, and Internet Explorer is still the same. :wacko: As a side note I am planning on reformatting my computer soon because I haven't reformatted this one in 3 years and have gotten several virus infections over those years. Your help was greatly appreciated.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI