This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

4 IE instances opening and boot problems

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

When I boot my laptop it opens up 4 instances of IE. When I close them I can continue working. Periodically Avast will find a problem and tell me to run a full scan, when I do this it says it's found lots of problems and moves them to the chest but the problem keeps happening. Every so it won't boot and I have to go into safe modae and run an avast scan to get it going again.

Any help is greatly appreciated.

Here's my Hijack this file:


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 08:42:50, on 25/06/2011
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18975)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\system32\igfxsrvc.exe
C:\Users\family\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Windows\WindowsMobile\wmdSync.exe
C:\Windows\PixArt\PAC207\Monitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\system32\igfxext.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Users\family\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Users\family\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Users\family\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\family\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sky.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sky.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…p;m=aspire_5735
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…p;m=aspire_5735
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided By Sky Broadband
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: dTPodcastBHO - {65134FDF-F8A5-4B3D-91D9-CDF273CFD578} - C:\Program Files\Common Files\doubleTwist\IEPodcastPlugin.dll
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: QuickNet - {EA5CA8B6-9B9C-4994-A7A1-947B6C631BE7} - C:\Program Files\RegTweaker\key.dll (file missing)
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: FireShot - {6E6E744E-4D20-4ce3-9A7A-26DFFFE22F68} - C:\Program Files\FireShot for IE\FSAddin-0.86.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
O4 - HKLM\..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
O4 - HKLM\..\Run: [PAC207_Monitor] C:\Windows\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [Google Update] "C:\Users\family\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [{3E3A6437-1901-3CF4-F2C3-A4BC0370CF71}] C:\Users\family\AppData\Roaming\Izun\tote.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O9 - Extra button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.sky.com (file missing)
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O15 - Trusted Zone: *.line6.net
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\599\G2AWinLogon.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\599\g2aservice.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

–
End of file - 10229 bytes

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, dandydan

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to.

—————————————————————————————————

Could you provide the log generated by Avast?

—————————————————————————————————
Hi Conspire, Great news thank you very much. Unfortunately I now can't boot the laptop at all. When I power up I get the initial Acer screen and I can get to the setup screen if I press F2. After the Acer screen it just goes black. I'm not sure what to do now.
We will perform a repair install on your OS to check if it's OS problem. Do you have the recovery disc with you? If you have it, go ahead and press F2 then change the boot priority(under "Boot" header) to IDE CD-ROM or something similar. Once you've done that, insert the recovery disc and press F10 to restart immediately after that. You will then see a message saying "Press any key to boot from CD", select repair install and go from there.
I don't have a recovery disc :-( I was thinking of running a live ubuntu disc to enable me to access the windows files and take off the data I want, then just completely reinstalling but while I can get the live disc up and onto the welcome screen where you can choose to try it or install it, if I choose try it it just hangs.
That's one way to retrieve your data. I'm sorry that I couldn't do much to help you out at this point. Let me know if you have any questions and also the end result.
I can now boot into Ubuntu using the live cd and can access the windows files. I've taken everything I nee. Is there anyway I can fix this now via the file access I have through Ubuntu?
Phew, managed to find the log from the last boot scan! I may be able to find more info for you 06/13/2011 18:21 Scan of all local drives File C:\Users\family\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\11Z0516S\swflash[1].cab|>FP_AX_CAB_INSTALLER.exe Error 42127 {CAB archive is corrupted.} File C:\Users\family\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\A796YB9R\swflash[1].cab|>FP_AX_CAB_INSTALLER.exe Error 42127 {CAB archive is corrupted.} File C:\Users\family\AppData\Local\Mozilla\Firefox\Profiles\pa0mvsp2.default\Cache\6\4A\EB280d01|>{gzip} is infected by JS:Downloader-ARD [Trj], Deleted File C:\Users\family\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24\5a76f7d8-33ccbeba|>Keyworq.class is infected by Other:Malware-gen, Deleted File C:\Users\family\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24\5a76f7d8-33ccbeba|>Uutecwv.class is infected by Java:Djewers-N [Trj], Deleted File C:\Users\family\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25\5c82fb99-47492ae1|>dev\s\AdgredY.class is infected by Java:Agent-AW [Expl], Deleted File C:\Users\family\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25\5c82fb99-47492ae1|>dev\s\DyesyasZ.class is infected by Java:Djewers-C [Trj], Deleted File C:\Users\family\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25\5c82fb99-47492ae1|>dev\s\LoaderX.class is infected by Other:Malware-gen, Deleted File C:\Users\family\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36\431f9624-45a1d9e4|>folder\Glocker.class is infected by Java:Agent-EC [Expl], Deleted File C:\Users\family\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36\431f9624-45a1d9e4|>folder\peternova.class is infected by Java:OpenConnection-T [Trj], Deleted File C:\Users\family\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\2b46d1a6-1cfb827c|>________vload.class is infected by Java:Jade-C [Heur], Deleted File C:\Users\family\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4\4b83f3c4-201d3f94|>yahoo\ConfMgr.class is infected by Other:Malware-gen, Deleted File C:\Users\family\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4\4b83f3c4-201d3f94|>yahoo\InfoCtrl.class is infected by Other:Malware-gen, Deleted File C:\Users\family\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4\4b83f3c4-201d3f94|>yahoo\PlayMgr.class is infected by Java:Jade-C [Heur], Deleted File C:\Users\family\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41\58de70e9-6b1a7bce|>________vload.class is infected by Java:Jade-C [Heur], Deleted File C:\Users\family\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42\420aa02a-5ad224be|>dev\s\AdgredY.class is infected by Java:Agent-AW [Expl], Deleted File C:\Users\family\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42\420aa02a-5ad224be|>dev\s\DyesyasZ.class is infected by Java:Djewers-C [Trj], Deleted File C:\Users\family\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42\420aa02a-5ad224be|>dev\s\LoaderX.class is infected by Other:Malware-gen, Deleted File C:\Users\family\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\6d1b776b-51dc1adc|>JavaUpdateApplication.class is infected by Java:Agent-BY [Expl], Deleted File C:\Users\family\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\6d1b776b-51dc1adc|>JavaUpdateManager.class is infected by Java:Agent-BO [Trj], Deleted File C:\Users\family\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45\2adf7bad-1f310987|>sklif\Hieeyfc.class is infected by Java:Agent-BV [Trj], Deleted File C:\Users\family\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45\2adf7bad-1f310987|>sklif\Hirwfee.class is infected by Java:Djewers-L [Trj], Deleted File C:\Users\family\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45\2adf7bad-1f310987|>sklif\Hiydcxed.class is infected by Java:Djewers-M [Trj], Deleted File C:\Users\family\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\2ab71af0-596487ca|>vmain.class is infected by Other:Malware-gen, Deleted File C:\Users\family\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\299b3ab2-34133488|>________vload.class is infected by Java:Agent-AP [Trj], Deleted File C:\Users\family\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\6ede21f2-564395fe|>dev\s\AdgredY.class is infected by Java:Agent-AW [Expl], Deleted File C:\Users\family\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\6ede21f2-564395fe|>dev\s\DyesyasZ.class is infected by Java:Djewers-C [Trj], Deleted File C:\Users\family\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\6ede21f2-564395fe|>dev\s\LoaderX.class is infected by Other:Malware-gen, Deleted File C:\Users\family\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59\5c9c7f7b-6e6b62a3|>vmain.class is infected by Other:Malware-gen, Deleted File C:\Users\family\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\5b42f9bf-4f8fb853|>________vload.class is infected by Java:Agent-AP [Trj], Deleted File C:\Users\family\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7\3233e207-2a692e66|>CustomClass.class is infected by Java:Jade-B [Heur], Deleted File C:\Users\family\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7\3233e207-2a692e66|>evilPolicy.class is infected by Other:Malware-gen, Deleted File C:\Users\family\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7\3233e207-2a692e66|>SiteError.class is infected by Java:CVE-2010-0094-A [Expl], Deleted File C:\Users\family\Documents\Downloads\Vince Neil – Tattoos & Tequila Download Package.zip|>Tattoos & Tequila Download Package\Videos\480P\Tattoos & Tequila.m4v Error 42125 {ZIP archive is corrupted.}
Can you enter into Safe Mode?

Reboot your computer in Safe Mode
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
Tutorial if you need it How to boot into Safemode

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI