Help needed. IE6 has mind of its own!!!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by cablgy2k, Feb 7, 2005.

  1. cablgy2k

    cablgy2k Private E-2

    I have this same issue on 3 PC's now. It's driving me crazy!!
    I have used the steps outlined in Basic removal and protection thread. AdawareSE removed a couple tracking cookies, and Spybot removed an Alexa realted item and something called Avenue A. Other that this, nothing else was found. I have the latest NortonAV as well as Personal Firewall.

    I have performed a hijackthis scan and saved the logfile (as per spec in the hijackthis thread).

    Any help would be GREATLY appreciated! The last time I had this issue I would up formatting the CPU and starting all over. This was just last week!!! How aggrevating!!

    FYI: windows XP Pro, SP2, IE6, NortonAV smbiz9.0, Norton Personal FW. All were added upon reformatting this cpu. Everything was working fine for about a week after the re-format/re-install.

    Thanks again!
    CABLGY2K
     
  2. TheOldThug

    TheOldThug First Sergeant

    Welcome :eek:

    Sounds like you have tried to do the tutorial. If you have done everything and are still having problems.

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, INCLUDING YOUR WEB BROWSER, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder for example C:\Program Files\HJT
     
  3. Publius

    Publius Sergeant

    If you have been through the tutorial, then attach your HijackThis log as an attachment as outlined in the following thread:

    NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    You already know this if you have read the above thread, but be sure to run HijackThis from its own directory (ex c:\Program Files\HJT\) and not from the Desktop, any folder under Documents and Settings (Win2k, WinXP), a temp folder or choose to run it directly from the downloaded ZIP file.

    Good luck
     
  4. Publius

    Publius Sergeant

    Sorry, Thug, didn't mean to post on top of you.
     
  5. TheOldThug

    TheOldThug First Sergeant

    No problem Pub.
     
  6. cablgy2k

    cablgy2k Private E-2

    Ok... here we go!

    on another note... I have shuttled my CPU to my office and there I have no issues connecting to the Inet. I am becoming ever more suspicious of my router. Is there any way for the router itself to become infected with viruses, spyware, etc?

    I am really confused though, because after the reformat/re-install on my wife's PC (hijackthis.log attached) we had zero problems for almost a week before the same symptoms appeared!

    Well... it's anybody's guess from here. Thanks again for the help!

    Cablgy2K
     

    Attached Files:

  7. TheOldThug

    TheOldThug First Sergeant

    Cablgy

    What is your specific problem Are you getting popups, can't connect, etc. Your log looks pretty clean except for a couple of lines:

    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

    This is the one I question. Are u using viewpoint for something?
    O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - https://components..com/MTSInstalle...ttp://www.viewpoint.com/pub/products/vmp.html

    Chas or PP will look at this and see if I missed something. In the mean time answer my above questions.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This line can be fixed too but it is not the reason for your inability to connect:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm

    What exactly is your connection problem? Can you connect to any sites? Have you tried IP addresses rather than URL's?

    What kind of router at home?
     
  9. cablgy2k

    cablgy2k Private E-2

    I'm not getting any Pop-ups. Just a lot of no connects. MSN.com is set as my homepage and upon opening IE6, it will always open this page. Once I try to navigate to a different page, this is when my problems start. If I stop the browser from reaching my homepage when I open IE6, then type in a different URL, sometimes it will make it through, most times it will not. It is VERY strange. I have tried IP instead of URL with no luck there either. I don't believe I am actually using Viewpoint for anything, so that can be deleted if necessary.

    I am using a D-link wireless router (DI-614+)
    Is there anything that's out there that would affect what the router will allow or block as far as traffic goes? I read in a few posts about Norton Firewalls causing issues with navigating through IE. I also circumvented this protection to see if there was something to it, alas I had no luck!

    Anyway, Thanks again for you help! I'm glad to hear that my first PC looks somewhat clean. At this point, I will go through the basics on the other 2 machines and see what happens...

    Cablgy2K
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Go to D-Link and get the latest updates for your router firmware. There have been issues lately that started out of nowhere and the firmware updates have fixed them in about 5 cases I have worked on.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds