Having some problems with IE

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by phatdoughnut, Aug 7, 2004.

  1. phatdoughnut

    phatdoughnut Private E-2

    Hello im new here my name is Juan

    And i did some searches before posting and didnt come up with anything, i also did the basic tutorial to help remove most viruses, and got rid of alot of crap.
    The problem i am having is with IE. Something keeps redirecting me to ramdom and or past searches ive done. It keeps using websites www.liquidie.com and www.superlogy.com Im no computer geek, but can get around well enough with some help. now i started to do the "only the best" tutorial and downloaded hijackthis.

    i am having problems with step 5. It sais system cannot find the path specified.

    thanks alot, and i will post a log if and when you guys ask me too..

    Juan
     
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Hi,
    I think the page was updated, so step 5 is not step 5 now... Possibly because I do not see a step 5 that could cause a can not find path specified error.

    Lets cover a couple bases here:
    What is the step instructions giving you that error?
    Can you use Hijack This to remove what you do not need yourself per the tutorial?

    Let me know.
     
  3. phatdoughnut

    phatdoughnut Private E-2

    this is step 5

    5) Now we are going to use notepad to erase the contents of the DLL file shown in the R0 & R1 lines of your HijaakThis log. To do this click Start, Run, and enter the following command "notepad c:\path\xxxxx.dll" (without the quotes) and click OK.

    i guess i shoulda been a lil more specific do i need to have hijack this open? to have


    Edit by chaslang: HijackThis logs must be posted as attachments! I reposted it for you put you cut off some of the most important info at the begining of your log. Do not cut anything out!
     

    Attached Files:

    Last edited by a moderator: Aug 7, 2004
  4. phatdoughnut

    phatdoughnut Private E-2

    okay maybe you can help me reading it now...
     
  5. phatdoughnut

    phatdoughnut Private E-2

    arg, sorry.. i hate not being able to delete my post.. lets see if this will work.
     

    Attached Files:

  6. phatdoughnut

    phatdoughnut Private E-2

    okay one more question before you guys post up your help, when you tell me to delete something with hijackthis, is it done the same as when you check it and hit fix?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First, you do not show any signs of having the HSA aka Only the Best hijack. You do not need to run the tutorial and there is no way you could have run step 5 because you would not have had an R0 or R1 line with the problem file.

    You need to get the newest HijackThis 1.98.2 (just came out): http://www.majorgeeks.com/download3155.html

    Also you need to get HijackThis into its own directory. Not a temp directory, not your desktop, and do not run it out of a ZIP file. You currently have it here:
    C:\Documents and Settings\Chelsea\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

    Make a c:\Program Files\HJT directory and put the executable in there. That way it has a safe place to store its backups.

    First we need to unregister a DLL file. Click Start, and then click Run. (The Run dialog box appears.)
    Type, or copy and paste, the following text:
    regsvr32 /u C:\WINDOWS\System32\Zedd4.dll
    then click OK. If a dialog box confirming this action appears, click OK.

    Run HijackThis and put check marks on the following lines and then shut down all applications especially Internet Explorer sessions (including the one you are reading this from) and then click Fix:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
    O2 - BHO: Zedd4Proj.clsUnoOne - {08227B4B-54FE-4C4D-809F-BCA46292FC5B} - C:\WINDOWS\System32\Zedd4.dll
    O2 - BHO: EarthLink Popup Blocker - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - (no file)
    O3 - Toolbar: Pop-Up Blocker - {D7F30B62-8269-41AF-9539-B2697FA7D77E} - (no file)
    O8 - Extra context menu item: Write a Review... - http://client.alexa.com/holiday/scr...ions/review.htm
    O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - http://www.napster.com/client/setup.exe
    O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.napster.com/client/isetup.cab

    Did you place this restriction on Internet Explorer Control Panel using SpyBot or another program. If so, leave the next line alone. Otherwise fix it too.
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    Note: I'm not sure what this NewsFlsh.exe program is. It appears to be some kind of WebSniffer. If you do not know what it is and did not install it, this line should be fixed too. But I would first look in Control Panel, Add/Remove Programs to see if there is an uninstaller. If not then fix the below line with HijackThis too.
    O4 - Global Startup: MySoftware NewsFlash.lnk = C:\Program Files\Common Files\MySoftware\NewsFlsh.exe

    Now reboot in safe mode: http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406?OpenDocument&src=sec_doc_nam
    Enable viewing of hidden files and folders: http://forums.majorgeeks.com/showthread.php?t=37650
    And find the below using Windows Explorer and delete them:
    C:\WINDOWS\System32\Zedd4.dll
    C:\Program Files\Common Files\MySoftware <--- The whole directory if you have decided that this is something you did not install or want.
     
    Last edited: Aug 8, 2004
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes. But do not click Fix while any applications other then HijackThis are running. Especially Internet Explorer.
     
  9. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Thanks Chaslang, I stepped out for the evening to see a couple local bands, so I could not respond until now.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Cool! Can you still hear! :D
     
  11. phatdoughnut

    phatdoughnut Private E-2

    Thanks alot chaslang! im gona go try it here in a couple minutes, ill let you know what happens... *crossfiners*
     
  12. phatdoughnut

    phatdoughnut Private E-2

    Thanks alot Chasland and Major. i guess only time will tell if it worked or not. I hope it did, you guys have a great thing goin here, not many people now how much crap can be on your computer even though you have virus scan and firewall. you guys are smart! im a computer dummy. Ive told all my friends about this site, all the awesome programs and stuff you guys got here.

    Juan
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Juan,

    Come back and let us know if everything worked out okay.
     
  14. phatdoughnut

    phatdoughnut Private E-2

    Well everything Is working AWESOME! you guys are THA BOMB! now i have some other questions, but this will be in diff thread...
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds