Cleaned System-Can't get online

Discussion in 'Malware Help (A Specialist Will Reply)' started by ChuckS, Mar 16, 2005.

  1. ChuckS

    ChuckS Private E-2

    I followed the instructions in the “READ ME FIRST BEFORE…” ran a fully updated Norton AV 2005, Windows 2K, Spybot SD 131TX, Adaware SE Pro, Spyware Blaster, CWshredder, Stinger, Ccleaner, and About Buster, and that appears to have removed whatever nasty little daemon I had. However, now every time I try to start IE in my normal login I get the following error message –

    “IEXPLORE has generated errors and will be closed by Windows. You will need to restart the program.” I also cannot log into the Internet with Netscape or Outlook Express. However I can open IE and have access to the web with Netscape and Outlook Express in “Safe” mode.

    [font=&quot]After spending many hours trying to find the source of my frustration I, once again, turn to Majorgeeks.com for help. As always any help is greatly appreciated. [/font]
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Make sure you have HijackThis 1.99.1 and follow the guidelines on where to install it and how to post a log as an ATTACHMENT.
    All instructions are covered in the sticky thread
    NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting


    Now post a Hijack This log as an ATTACHMENT to your message (Do NOT copy/paste the log into your post). Please close unnecessary running programs before you run HijackThis. You must close each of the following: your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc.

    DO NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. ChuckS

    ChuckS Private E-2

    Thanks bjgarrick,

    I completed the HijackThis cleaning and everything seems to be much better, but I still get the same error message when I attempt to launch IE in my normal login [both Netscape and Outlook Express are working well]. Any suggestions? I have a log file from HTS but I don't know how to attach it to this reply (better safe than sorry) so if you need to view it please let me know how I can safely attach it.

    Thanks

    ~chuck
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Do not fix anything wil Hijack This unless requested as not everything HJT finds is bad. Always ask before removing something if you second guess it.

    Please attach a current HJT log from normal boot mode using the Manage Attachments button at the bottom of this box.
     
  5. ChuckS

    ChuckS Private E-2

    I followed the instructions and the HJT tutorial and only removed the entries that were obvious from PacMan's Startup list etc..

    Here are the before and after HJT logs.

    ~chuck
     

    Attached Files:

  6. ChuckS

    ChuckS Private E-2

    Also, although I seem to be able to get online and with the exception of not being able to open IE everything seems to be back to normal, I checked the Task manager and my CPU is running consistently around 45%. But I can't find the process that's running.

    I guess I'm not as healthy as I thought.

    ~chuck
     
  7. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.


    O2 - BHO: Windows Proxy support DLL - {2DC9D850-144D-11E1-B3C9-10805E499D93} - C:\WINNT\system32\winprox.dll

    O23 - Service: Chyron License Manager (ChyronLM) - Unknown owner - C:\WINNT\System32\chyron_lm.exe (file missing)


    Again, make sure All Browser Windows are Closed when you Click FIX.


    NOW:
    Please boot into Safe Mode with the Viewing of Hidden Files & Folders Enabled and navigate to and DELETE the following if they should remain:

    C:\WINNT\system32\winprox.dll


    NEXT:
    Run CCleaner and Spybot S&D and have Spybot fix what it finds.
    Note: Dont forget to update Spybot S&D by selecting "Search For Updates"


    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.


    Reboot to Normal Windows , Scan with HijackThis and attach the new log.
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now.

    Good Luck!:)
     
  8. ChuckS

    ChuckS Private E-2

    :( I did all of this and the system is running the same. IE won't launch but Netscape and Outlook Express seem to be running well. CPU usage is still steady at 43%.

    Things that make you go hmmm...

    ~chuck
     

    Attached Files:

  9. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Are you familiar with Silicon Grail?

    What does IE do when you try to open it, any errors?
     
  10. ChuckS

    ChuckS Private E-2

    Silicon Grail was a software development company that uses FlexLM for floating licenses. I have had it for several years - that's not to say that it couldn't be the problem but I doubt it is.

    ~chuck
     
  11. ChuckS

    ChuckS Private E-2

    I get the same error message: “IEXPLORE has generated errors and will be closed by Windows. You will need to restart the program.”

    ~chuck
     
  12. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, right click your Internet Explorer icon on your desktop and select properties. Click on the Content Tab, check to see if Content Advisor is enabled.
     
  13. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Let me know about the Content Advisor. What version of Norton do you have installed?

    Also, Open Norton AntiVirus and see if everything loads fine. Does it say error next to email scanning?
     
  14. ChuckS

    ChuckS Private E-2

    When I right click on the IE icon and go to properties I don't get a content tab, I didn't see a Content Advisor option.

    I am running Norton Anti Virus 2005 [just upgraded a couple of days ago]

    ~chuck
     
  15. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Check the attached image, yours doesnt look like this?
     

    Attached Files:

  16. ChuckS

    ChuckS Private E-2

    I can't seem to get to that menu by right clicking on the IE icon. I did manage to get to it thru the control pannel and it looks exactly like that.
     
  17. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Okay Good!

    Now, lets start by trying the below.

    Download IEFix 1.4

    Once download is complete, extract to desktop and run the utility.

    See if this fixes the error first, if not let me know!
     
  18. ChuckS

    ChuckS Private E-2

    I tried th IEFix, unfortunately it asked me for a file that I need from the W2KPro disk - so I will have to look for those.

    It's hard to remember life without computers, but we can dream...

    ~chuck
     
  19. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  20. Matacumbie

    Matacumbie Rocky Top

    BJ,

    I noticed Norton Internet Security in the HJT log, not that familiar with NAV 2005 but does it include NIS? If not, could be something to check also.

    Norton CleanSweep can also cause this error message, http://support.microsoft.com/?scid=kb;EN-US;Q303728

    Hope this might help.

    Steve
     
  21. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Thanks Steve, I seen that article..NAV05 is just the AV doesnt come with anything but the AV, however NIS does include it all.

    Will check this if nothing else works.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds