Ready to Chuck this pc from a height!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by nickson2, Apr 23, 2004.

  1. nickson2

    nickson2 Master Sergeant

    ok, here it is.... IE 6 wont let me view secure websites, Msn Messenger 6.1 wont let me sign in (says "we were unable to sign you in to the .NET Messenger Service, possible because of a problem with your Internet connection. Please try again later. 0x81000370") but i can get online to view webpages (apart from secure websites, like webmail, hotmail, banking etc). I took advise from earlier post all to no avail. Im getting Grey quickly and aged about 30 yrs in the last two days.......ive no firewalls etc installed (ive uninstalled them)
    Please, Please, PLease help me :(
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. nickson2

    nickson2 Master Sergeant

    ok, my pc is

    Processor: Cyrix 6x86MX (PR166-266)225MHz
    L2 Cache: 512KB
    Memory: 128MB
    Mainboard: ALADDINS
    O/S Windows Xp Pro
    I/E Version 6.0
    Bios Manufacturer: Award Software International, Inc.

    The pc is old and im only using it as a stand in while i await the return of my other pc after its been fixed.
    I have used Ad Ware, and also done a virus scan and theres nothing been discovered.
    Done that Hijack this, and it comes up with
    Logfile of HijackThis v1.97.7
    Scan saved at 22:11:02, on 23/04/2004
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Norton Internet Security\NISUM.EXE
    C:\Program Files\Norton Internet Security\NISSERV.EXE
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\Program Team Cash\Mags64.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\Program Files\Microsoft Office\Office\Osa.exe
    C:\Program Files\Microsoft Office\Office\Findfast.exe
    C:\Program Files\blueyonder IST\bin\mpbtn.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\unzipped\hijackthis\HijackThis.exe
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.blueyonder.co.uk/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by blueyonder
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O3 - Toolbar: Mini Jeeves - {4E7D0B40-F575-4A29-9710-4675EAF4686A} - C:\WINDOWS\System32\minijvAB.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
    O4 - HKLM\..\Run: [Chin Balm] C:\PROGRA~1\Program Team Cash\Mags64.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKLM\..\RunOnce: [DELDIR0.EXE] "C:\DOCUME~1\EARTHL~1\LOCALS~1\Temp\DELDIR0.EXE" "C:\Program Files\McAfee\McAfee Shared Components\Guardian\"
    O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
    O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
    O4 - Global Startup: blueyonder Instant Support Tool.lnk = C:\Program Files\blueyonder IST\bin\matcli.exe
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
    O9 - Extra button: Freeserve (HKCU)
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: Win32 Classes -
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    O16 - DPF: {4C2C81B4-91DA-494D-8DBF-A7846BA07073} (Mini Jeeves Installer Control) - http://www.ask.co.uk/toolbar/download/MiniJv-inst.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37705.5374189815
    O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.blueyonder.co.uk/assets/tool/files/MotivePreQual.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

    Hope this is sufficient.... im up creek without a paddle....help me please.
    forever in your debt
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have you install, UPDATED, and run both Ad-aware and SpyBot S&D?
    Also do you know what this Blueyonder item is that appears all over the place in the HiJaak log?
     
  5. highly_volatile

    highly_volatile Private First Class

    Blueyonder is a ISP
     
  6. nickson2

    nickson2 Master Sergeant

    I have done Ad Ware( found 1 new item, so i deleted it) & am in the process of Spybot S & D(never used it before...across the bottom it says."running bot check.... whats this dialer things it keeps pickin up on?
    The blueyonder is my ISP
     
  7. nickson2

    nickson2 Master Sergeant

    found 133 problems
     
  8. nickson2

    nickson2 Master Sergeant

    still cant access secure web pages, or msn messenger, webmail, hotmail. etc.
     
  9. Kodo

    Kodo SNATCHSQUATCH

    if you can't login to msn etc.. sounds like you have cookies or sessions blocked.. sorry I didn't get a chance to hit back in your other thread. In the future, only one thread is necessary to save confusion between posts..
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you clean them up? Also, see Kodo's message below this sounds like your problem!
     
  11. BoredOutOfMyMind

    BoredOutOfMyMind Picabo, ICU

    My Brother in law said there was a MS server down for Hotmail, possibly this was related. Can you sign into other sites? ;)
     
  12. ASUS

    ASUS MajorGeek

    Doesent Microsoft reccomend 300MHZ or Higher for XP??
    Short on memory too!

    Not to Knock Ad-Aware, But I've had problems running it, seems it crashed os on one of my rigs, and another had problems accessing internet on another.
    I prefer AVG, but that my opinion ( remember Opinions are like B holes everyone has one or atleast everyone I know!)

    What version of spybot are you running, seems the beta version isnt that great,resourse hog, and some other issues with it
    Im running Spybot S&D 1.2, works great

    So at end of your rope, seems though been loading and unloading lots of programs and stuff, some programs just dont remove all that great, maybe your problem is kinda compounding.

    Mabe should consider might be time for alittle formating and a reinstall of your OS

    Good luck!
     
  13. nickson2

    nickson2 Master Sergeant

    ive got shut of the problems detected by spybot...ive tried to check to see if cookies are enabled but cant find it. as for xp, its not my pc its on loan so formatting is out of the question and its been ok running xp so far, and getting on secure websites. ive even tried restore, but it says your pc cannot be restored. still in need of advice
     
  14. alanc

    alanc MajorGeek

    In IE, go to Tools > Internet Options > Privacy > click 'Default', then click 'Advanced' and UNcheck 'Override Automatic Cookie Handling', click OK, OK.
     
  15. alanc

    alanc MajorGeek

  16. nickson2

    nickson2 Master Sergeant

    just been and done it but it was already done still no secure website access tho :(
     
  17. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds