Can someone please help me?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Kate, Sep 19, 2004.

  1. Kate

    Kate Private E-2

    Hi...
    I don't even know where to start..so I will at the biggest problem.Everytime I try to connect to the internet I receive the message"explorer caused an error in <unknown> explorer will now close if the problem comtinues restart your computer"
    restarting does nothing.I followed the post "read me before asking for support" I did all that...but afterwords
    my computer was stuck on the windows screen...so I went into safe mode and undid some of the changes because I was not sure if they caused another problem.
    anyway I am running windows ME and have a Dell Dimension4100.
    I ran hijack this and here is my log...
    sorry if I am posting this in the wrong place!

    If anyone could help me I would appreciate it.
    thanks!
     
    Last edited by a moderator: Sep 19, 2004
  2. NeoNemesis

    NeoNemesis Moutharrhea

    That has got to be the longest hijack this log i have ever seen. *amazed*
     
  3. Wavetar

    Wavetar Sergeant

    Wow, I agree. Normally, I'm one to try & troubleshoot & fix things...but in this case I would strongly recommend saving anything worth saving to a CD or something & doing a clean wipe & install. This is especially true if you've already tried to follow the steps in the "read me before asking for support" thread & couldn't boot normally.

    Dell should have included a 'restore' CD that'll make the wipe & re-install automatic & painless.
     
  4. NeoNemesis

    NeoNemesis Moutharrhea

    This also has to be the longest running thread with a hijack this log in it that hasn't been deleted by either ma or one of the other mods. amazing. just... amazing. :)
     
  5. Matacumbie

    Matacumbie Rocky Top

    Kate,

    Before doing anything drastic try this. Forget the Hijackthis log for now and just post what you did and undid after reading "read me before asking for support".

    Be sure and post your spyware related questions and issues in the Spyware Specific forum here, http://forums.majorgeeks.com/forumdisplay.php?f=35

    I doubt it is anything that can't be fixed with a little time and support from MG.

    Steve
     
  6. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Hi, we delete log files here :) Why? Because it is posted wrong and not needed yet. You need to run the Spyware, Virus removal tutorial:

    http://forums.majorgeeks.com/showthread.php?t=35407

    When, and if, we ask for a log file, you need to follow the directions here:

    http://forums.majorgeeks.com/showthread.php?t=38752

    Be sure to go to add remove programs, you have Wild Tangent, Weather Bug and many other items installed considered spyware. You also have 2 Hijacks on your browser as seen in these lines:

    R1 - HKCU\Software\Microsoft\Internet Explorer,Default_Search_URL = http://www.searchnow.ws/search/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch.com/ie.aspx?tb_id=92
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\adndj.dll/sp.html#96676
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.search-explorer.net/search_page.php
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\adndj.dll/sp.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=92
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\adndj.dll/sp.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\adndj.dll/sp.html#96676
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\adndj.dll/sp.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.searchxp.com/search.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=92
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =


    Please run the tutorial and start a new thread in the spyware forum so Chaslang or myself can get you cleaned up :)
     
  7. Kate

    Kate Private E-2

    Thanks Steve & M.A.!
    Sorry about the log....
    *sigh*...back to the drawing board,Okay
    I will...and I will post it in the spyware forum...

    Kate
     
  8. Matacumbie

    Matacumbie Rocky Top

    No problem, we will get it worked out. Steve
     
  9. Kate

    Kate Private E-2

    Re: can someone please help me

    Steve & M.A....
    Ok...first I could not scan at Trend Micro Free or Symantec
    because I do not have the option "safe mode with network support" so I was in just safe mode and the only way I have be able to get on the internet is thru Real Player,which I tried in safe mode but it would not work.
    I performed a "full" system scan in Ad-ware SE...
    I have 1446 items in quarantine between the last two scans (do I leave them in there?)
    then I ran Spybot...under problems it had:
    egroup...no info available (I didn't know what it was or what to do so I left it)
    possible hijacker ~ I deleted it
    DSO Exploit...it said it was microsoft security issue~ is this
    a patch I downloaded? I didn't know so I left it.
    ICOO loader~ no info on it...again I didn't know what it was so I left it
    Roings~ no info ...again I didn't know what to do with this either...so I left it...
    Rapid Blaster~ I deleted

    Please advise me on the others I left if you know what they are or if it is safe for me to remove them.

    I ran CWShredder and my windows media player was
    infected with a CWS trojan and it was deleted so I will have to reinstall it...it also fixed 2 internet explorer problems.

    I tried to run Buster but I got the explorer error but instead on in <unknown> this time it was in "user.exe"
    I still could have run it tho but it said to do so at your own risk...kinda scared me off, so I didn't....

    I rebooted in regular mode and got past the windows screen to the blue screen...and there it sat,so I rebooted again and scan disk just sat there so I closed it and everything came up.
    The first thing I tried was clicking my IE shortcut...and here I am!!! I am holding my breath waiting for the error to pop up again but so far so good... :)

    I am going to hit it, as it is late but THANK YOU!!
    I will come back tomorrow to see if you can tell me about the other things I was too chicken to delete, and hopefully
    it will be just as easy to get on tomorrow ;)

    Kate
     
  10. Kate

    Kate Private E-2

    Re: can someone please help me

    Ok...*sigh* well I decided to exit IE and then try again...I get my home page, which is cool because I have not seen it for a while
    but up pops the explorer unknow error again...I found I can move the error box and not click it I can still be on the net...
    Do you think it is a windows problem?

    Kate
     
  11. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Re: can someone please help me

    Kate,
    It is not uncommon to not have a safe mode. Please use your own virus scanner and Stinger and scan the system completely from safe mode. I assume you ran everything else from safe mode. If so, please attach a Hijack This log file in the spyware forum and make note that I requested it or Chaslang will give you the speach about doing the tutorial first :) Follow the Hijack this tutorial for posting it, its important you put it in its own directory and attach it as a text file.
     
  12. 44039

    44039 Private First Class

    How are you posting if IE keeps crashing (just curious)?

    I believe you've got an OS (Windows) problem. You could spend hours trying to correct it, which may work, or not. I would recommend backing all of your data up, reformating, and re-installing windows. This will take you a lot less time than trying to "fix" the issue. Plus, your system will run like "new" again.
    A personal recommendation would be to spend the money and up grade to 2000 or XP (if your system will support it).
    In the mean time, you could load another browser, and use instead of IE. I recommend FireFox. Mozilla and Netscape are good too!
     
  13. Kate

    Kate Private E-2

    Hi M.A....
    I do have a safe mode...but not with networking. It just gives me either safe mode or step-by-step confirmation option.Yes I did run everything else from safe mode. I hope I am understanding correctly that I should post my log file in a new thread on this forum so I will do so now.

    Kate
     
  14. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Please do upload it.

    Please attach it as a file. To do this save the log file and select manage attachments in a new thread to upload it. It is very important that you close all running programs including your web browser, email, items in the tray before running Hijack This!

    Finally, do not install Hijack This to the Desktop, a temp folder or choose run from the download. Place it in its own folder, for example C:\Program Files\HJT

    I, or Chaslang, will get on it ASAP.
     
  15. Kate

    Kate Private E-2

    44039,
    I am able to access the internet through my Real Player.I still get errors but I can move the error box out of the way and keep going.Right now I am staring at "Stimom has caused an error in kernel 32.dll" well at least its not the explorer one...something new and different lol
    Thank you for the suggestions! I am hoping I do not have to go that route because I have no idea how to accomplish it, though xp would be nice.
    I actually did reinstall ME last week because someone one messed around with my pc and everytime I clicked on the I.E. icon I launched into My Doc...same thing with notepad.After weeks of trying to figure out what they did I figured it would be easier to just reinstall it. I did notice something strange on my first log file it said I had IE 5.5 but I had upgraded to 6.0
    maybe the DL didn't finish I am not sure....I wish I was not so ignorant when it comes to computers...I would have much better
    odds if it were a car...speaking of which I have a date with a brake line...but again thanks for the suggestions =)

    Kate
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Kate,

    You need to get us that HijackThis log.
     
  17. Kate

    Kate Private E-2

    Hi Chaselang,
    I did...I posted it in a new thread because I thought that is what you wanted...its titled "requested hijack log"

    Kate
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem. I may merge these together though for a history of what has been happening. So don't be surprise if one of the threads is missing later.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds