Internet Options...

Discussion in 'Software' started by currentclassics, Oct 10, 2005.

  1. currentclassics

    currentclassics Private E-2

    ...under "Tools" on our "standard buttons" seems to be corrupted in some peculiar way.

    We are using Windows98, second edition and IE 6.00.28000.1106. Looking under "Internet Options" and then the "Security" tab, when I view the "Internet" custom level settings, all the check boxes are missing from the left, and if I attempt to reset them utilizing the slide bar high-to-low selector, it resets itself to "medium" again as soon as I close it. Also, under the "Advanced" tab, all the check boxes are ALSO missing there.

    We have all Spyware, etc, that we have installed here disabled.

    We are unable to access any url that requires encryption (I think)...Ebay, our credit card companies and many many many others, including the Microsoft Windows help pages.

    We have had various viruses removed from the computer in the past, using infromation we were grateful to find here. I could find none on here now utilizing the step-by-step process you advise here. My husband did tell me he found "something funny" under "Tools" on our standard buttons bar recently.. he said it was "some search helper thing" and he deleted it. I can find no trace of any remnants of it, but discovered all the problems I have related subsequent to this.

    I would appreciate any advice or help...this is our business PC and I am incapacitated.
    Thank you.
     
  2. Matacumbie

    Matacumbie Rocky Top

    Try a repair for Internet Explorer first:

    Click Start > Programs > Accessories > System Tools > System Information > Click on Tools and select the Repair Internet Explorer Repair Tool.

    Tick the Repair Internet Explorer box > OK > Yes. You will have to restart when it is finished.

    Check and see if that got some of your settings back under Internet Options. If not, follow the steps below to restore your Advanced Tab.

    Click Start > Run and type this command

    regsvr32 /n /i inetcpl.cpl

    Be sure to pay attention to the spaces when entering the command. You may have to restart after this also but check and make sure.

    Let us know where this gets you.

    Steve
     
  3. currentclassics

    currentclassics Private E-2

    Thanks a MILLION, I am going to give it a try as quick as we open in the AM,
    truly appreciate your help and will let you know how it goes.

    Dee & Bill
     
  4. Matacumbie

    Matacumbie Rocky Top

    OK. Also, maybe in your reply later you can include some info on what anti-virus and firewall you are using. Did you change recently, if so, what did you have before and what do you have now? Have you added any new spyware features or programs lately?

    And, I would also go thru the steps in the link below just to rule a few things out.

    http://forums.majorgeeks.com/showthread.php?t=35407

    Steve
     
  5. currentclassics

    currentclassics Private E-2

    Steve....
    Neither the IE repair or running the regsvr32 /n /i inetcpl.cpl worked.
    We use V-Com's System Suite for a firewall and anti-virus.
    I am going to go through the steps in your link now. Thank you, again, I'll let you know.
     
  6. currentclassics

    currentclassics Private E-2

    I have used the System Suite firewall & anti-virus exclusively for a few years.
    About a year ago, I downloaded all the MajorGeek recommended (at THAT time) spyware/virus removal tools appropriate for Win98 and used them to remove several Trojans. I noted that one of them...Spyware Blaster ...is not in the steps found in the thread you have furnished a link to above, but I disabled mine several days ago when I began having trouble.

    Today, I went through all the steps from your link. I could not utilize any of the on-line virus scans except Bitedefender. I crashed twice midway through the Rav scan and the Trend & Trojan scan's would not work because of I can't change the disallow active-x's. I believe that System Suite is using the same anti-virus as Trend, anyway.


    __________________________________________________________________
    BitDefender Online Scanner



    Scan report generated at: Tue, Oct 11, 2005 - 13:50:36





    Scan path: A:\;C:\;D:\;







    Statistics

    Time
    00:28:33

    Files
    53001

    Folders
    1155

    Boot Sectors
    2

    Archives
    550

    Packed Files
    6773




    Results

    Identified Viruses
    2

    Infected Files
    7

    Suspect Files
    0

    Warnings
    0

    Disinfected
    0

    Deleted Files
    6




    Engines Info

    Virus Definitions
    220499

    Engine build
    AVCORE v1.0 (build 2292) (i386) (Mar 3 2005 11:57:29)

    Scan plugins
    13

    Archive plugins
    38

    Unpack plugins
    4

    E-mail plugins
    6

    System plugins
    1




    Scan Settings

    First Action
    Disinfect

    Second Action
    Delete

    Heuristics
    Yes

    Enable Warnings
    Yes

    Scanned Extensions
    exe;com;dll;ocx;scr;bin;dat;386;vxd;sys;wdm;cla;class;ovl;ole;hlp;doc;dot;xls;ppt;wbk;wiz;pot;ppa;xla;xlt;vbs;vbe;mdb;rtf;htm;hta;html;xml;xtp;php;asp;js;shs;chm;lnk;pif;prc;url;smm;pfd;msi;ini;csc;cmd;bas;

    Exclude Extensions


    Scan Emails
    Yes

    Scan Archives
    Yes

    Scan Packed
    Yes

    Scan Files
    Yes

    Scan Boot
    Yes




    Scanned File
    Status

    C:\WINDOWS\SYSTEM\datadx.dll
    Infected with: Trojan.Downloader.Qoologic.P

    C:\WINDOWS\SYSTEM\datadx.dll
    Deleted

    C:\WINDOWS\TEMP\f101553.exe
    Infected with: Trojan.Downloader.Qoologic.N

    C:\WINDOWS\TEMP\f101553.exe
    Disinfection failed

    C:\WINDOWS\TEMP\f101553.exe
    Deleted

    C:\WINDOWS\TEMP\f95928.exe
    Infected with: Trojan.Downloader.Qoologic.N

    C:\WINDOWS\TEMP\f95928.exe
    Disinfection failed

    C:\WINDOWS\TEMP\f95928.exe
    Deleted

    C:\WINDOWS\TEMP\f56643.exe
    Infected with: Trojan.Downloader.Qoologic.N

    C:\WINDOWS\TEMP\f56643.exe
    Disinfection failed

    C:\WINDOWS\TEMP\f56643.exe
    Deleted

    C:\WINDOWS\Start Menu\Programs\StartUp\naip.exe
    Infected with: Trojan.Downloader.Qoologic.N

    C:\WINDOWS\Start Menu\Programs\StartUp\naip.exe
    Disinfection failed

    C:\WINDOWS\Start Menu\Programs\StartUp\naip.exe
    Deleted

    C:\WINDOWS\pukbq.dat
    Infected with: Trojan.Downloader.Qoologic.N

    C:\WINDOWS\pukbq.dat
    Disinfection failed

    C:\WINDOWS\pukbq.dat
    Deleted

    C:\WINDOWS\jnbaaa.exe
    Infected with: Trojan.Downloader.Qoologic.N

    C:\WINDOWS\jnbaaa.exe
    Disinfection failed

    C:\WINDOWS\jnbaaa.exe
    Delete failed

    __________________________________

    My Ad-Aware log:ArchiveData(auto-quarantine- 2005-10-11 14-38-46.bckp)
    Referencefile : SE1R69 05.10.2005
    ======================================================

    MRU LIST
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
    obj[0]=MRU FileReference : C:\WINDOWS\Application Data\microsoft\office\recent\INVENTORY LIST.LNK
    obj[1]=MRU FileReference : C:\WINDOWS\Application Data\microsoft\office\recent\My Documents.LNK
    obj[2]=MRU FileReference : C:\WINDOWS\Application Data\microsoft\office\recent\Current Classics-Invoice.LNK
    obj[3]=MRU FileReference : C:\WINDOWS\Application Data\microsoft\office\recent\08-01-05 city minutes.doc.url
    obj[4]=MRU FileReference : C:\WINDOWS\Application Data\microsoft\office\recent\collection#2.LNK
    obj[5]=MRU FileReference : C:\WINDOWS\Application Data\microsoft\office\recent\collection#1.LNK
    obj[6]=MRU FileReference : C:\WINDOWS\Application Data\microsoft\office\recent\final_oct1_editor.LNK
    obj[7]=MRU FileReference : C:\WINDOWS\Application Data\microsoft\office\recent\bankstatement.LNK
    obj[8]=MRU FileReference : C:\WINDOWS\Application Data\microsoft\office\recent\Desktop.LNK
    obj[9]=MRU FileReference : C:\WINDOWS\Application Data\microsoft\office\recent\cadstationary.LNK
    obj[10]=MRU FileReference : C:\WINDOWS\Application Data\microsoft\office\recent\Copy of cadstationary.LNK
    obj[11]=MRU FileReference : C:\WINDOWS\Application Data\microsoft\office\recent\cadfindistri.LNK
    obj[12]=MRU FileReference : C:\WINDOWS\Application Data\microsoft\office\recent\bill-beach.LNK
    obj[13]=MRU FileReference : C:\WINDOWS\Application Data\microsoft\office\recent\Concorde 1.LNK
    obj[14]=MRU FileReference : C:\WINDOWS\Application Data\microsoft\office\recent\my_pictures.LNK
    obj[15]=MRU FileReference : C:\WINDOWS\Application Data\microsoft\office\recent\07-05-05 city minutes.doc.url
    obj[16]=MRU FileReference : C:\WINDOWS\Application Data\microsoft\office\recent\10daynoticeletter.LNK
    obj[17]=MRU FileReference : C:\WINDOWS\Application Data\microsoft\office\recent\oct1editor.LNK
    obj[18]=MRU FileReference : C:\WINDOWS\Application Data\microsoft\office\recent\TIF ALMANAC 6 02.doc.url
    obj[19]=MRU FileReference : C:\WINDOWS\Application Data\microsoft\office\recent\Error Affadavit.LNK
    obj[20]=MRU FileReference : C:\WINDOWS\Application Data\microsoft\office\recent\01-03-05 city minutes.doc.url
    obj[21]=MRU FileReference : C:\WINDOWS\Application Data\microsoft\office\recent\01-18-05 city minutes.doc.url
    obj[22]=MRU FileReference : C:\WINDOWS\Application Data\microsoft\office\recent\02-07-05 city minutes.doc.url
    obj[23]=MRU FileReference : C:\WINDOWS\Application Data\microsoft\office\recent\Chapter 07 - City Finance and Business .doc.url
    obj[24]=MRU FileReference : C:\WINDOWS\Application Data\microsoft\office\recent\Chapter 10 - General & Miscellaneous .doc.url
    obj[25]=MRU FileReference : C:\WINDOWS\Application Data\microsoft\office\recent\Chapter 01 - Agencies, Officers and Employees .doc.url
    obj[26]=MRU FileReference : C:\WINDOWS\Application Data\microsoft\office\recent\08-15-05 city agenda.doc.url
    obj[27]=MRU FileReference : C:\WINDOWS\Application Data\microsoft\office\recent\08-01-05 city agenda.doc.url
    obj[28]=MRU FileReference : C:\WINDOWS\Application Data\microsoft\office\recent\07-18-05 city minutes.doc.url
    obj[29]=MRU FileReference : C:\WINDOWS\Application Data\microsoft\office\recent\final oct1 editor.LNK
    obj[30]=MRU FileReference : C:\WINDOWS\Application Data\microsoft\office\recent\06-20-05 city minutes.doc.url
    obj[32]=MRU RegReference : .DEFAULT\software\jasc\animation shop 3\fileopendialog
    obj[33]=MRU RegReference : .DEFAULT\software\jasc\animation shop 3\recent file list
    obj[34]=MRU RegReference : .DEFAULT\software\microsoft\office\9.0\common\open find\microsoft word\settings\open\file name mru value
    obj[35]=MRU RegReference : .DEFAULT\software\microsoft\office\9.0\common\open find\microsoft word\settings\save as\file name mru value
    obj[36]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\doc find spec mru
    obj[37]=MRU RegReference : .DEFAULT\software\microsoft\windows media\wmsdk\general computername

    ALEXA
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
    obj[7]=Regkey : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}
    obj[8]=RegValue : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} "MenuStatusBar"
    obj[9]=RegValue : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} "Script"
    obj[10]=RegValue : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} "clsid"
    obj[11]=RegValue : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} "Icon"
    obj[12]=RegValue : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} "HotIcon"
    obj[13]=RegValue : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} "ButtonText"
    obj[14]=RegValue : .DEFAULT\software\microsoft\internet explorer\extensions\cmdmapping "{c95fe080-8f5d-11d2-a20b-00aa003c157a}"

    WIN32.TROJANDOWNLOADER.QOOLOGIC
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
    obj[15]=RegValue : Software\Microsoft\Windows\CurrentVersion\Run "winsync"
    obj[16]=File : c:\windows\jnbaaa.exe
    obj[17]=File : c:\WINDOWS\Start Menu\Programs\StartUp\naip.exe
    obj[18]=File : c:\WINDOWS\DLLArchive\80045267_dshjfjk.dll
    obj[19]=File : c:\WINDOWS\DLLArchive\80045267_jaaod.dll
    obj[20]=File : c:\WINDOWS\jaaod.dll
    obj[21]=File : c:\WINDOWS\pukbq.dat
    obj[22]=File : c:\WINDOWS\dshjfjk.dll
    obj[23]=File : c:\WINDOWS\bamrcrd.exe

    ______________________________________________________

    My Spybot Search & Destroy Log:


    --- Report generated: 2005-10-11 14:48 ---

    New.Net: Program directory (Directory, fixed)
    C:\Program Files\Firstlook\

    New.Net: Uninstaller (File, fixed)
    C:\WINDOWS\NDNuninstall4_50.exe

    New.Net: Uninstaller (File, fixed)
    C:\WINDOWS\NDNuninstall5_20.exe


    --- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---

    2005-07-25 unins000.exe (51.41.0.0)
    2005-05-31 blindman.exe (1.0.0.1)
    2005-05-31 SpybotSD.exe (1.4.0.3)
    2005-05-31 TeaTimer.exe (1.4.0.2)
    2005-05-31 Update.exe (1.4.0.0)
    2005-05-31 advcheck.dll (1.0.2.0)
    2005-05-31 aports.dll (2.1.0.0)
    2005-05-31 borlndmm.dll (7.0.4.453)
    2005-05-31 delphimm.dll (7.0.4.453)
    2005-05-31 SDHelper.dll (1.4.0.0)
    2005-05-31 Tools.dll (2.0.0.2)
    2005-05-31 UnzDll.dll (1.73.1.1)
    2005-05-31 ZipDll.dll (1.73.2.0)
    2005-04-26 Includes\Cookies.sbi (*)
    2005-07-22 Includes\Dialer.sbi (*)
    2005-07-22 Includes\Hijackers.sbi (*)
    2005-07-22 Includes\Malware.sbi (*)
    2005-06-23 Includes\Keyloggers.sbi (*)
    2005-04-27 Includes\Revision.sbi (*)
    2005-07-22 Includes\Security.sbi (*)
    2005-07-19 Includes\Spybots.sbi (*)
    2005-07-22 Includes\Trojans.sbi (*)
    2005-02-17 Includes\Tracks.uti
    2005-07-22 Includes\PUPS.sbi (*)

    _______________________________________________________

    The good news is my browser is now going to my bank account, Ebay, Paypal, etc.....the bad news is my Internet Options>Security>CustomLevel> choices are still missing selection boxes, along with the Internet Options>Advanced > choices. After I did all that I have related here in this post, I did go and retry your initial advice...no luck.

    Any ideas would be most appreciated and THANK YOU for what we have fixed so far,

    Dee
     
  7. Matacumbie

    Matacumbie Rocky Top

    Dee,

    Looks and sounds like you are making progress. Please start a thread in the Spyware Forum here, http://forums.majorgeeks.com/forumdisplay.php?f=35

    And refer them to this (your) thread here in Software, http://forums.majorgeeks.com/showthread.php?p=666144#post666144

    You probably still have some malware issues that I am not qualified to fix and the guy's there are experts, they will make sure your system is clean and may solve the Internet Options issue. If not, we can get that fixed.

    Be sure to tell them you have completed all the steps (what you could) and would like some help.

    Good luck and good job. :)

    Steve
     
  8. currentclassics

    currentclassics Private E-2

    Thank you so much for your help, Steve.

    Dee
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds