I could usesome advice/ help with my internet explorer

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by wickety, Oct 15, 2004.

  1. wickety

    wickety Private E-2

    yes now i had some crap on my computer that i went through and followed steps for getting rid of the basic trjan or virus thread that has been posted. my computer now though has been giving me problems in opening up Internet Explorer. it says the process is running, but no window will open up. also i have some process i think still that are doing me no good but i'm not sure how to get rid of them. so i was wondering if maybe i should tr yto delete IE and re instll it, or somehow browse through some other type of prgram ?? i've never done that so i'm in the dark about that. also i'm not sure if someone would be gracious enough to help me out, if it would help if i posted a hijackthis log for someone to look at, cause i don't understand that program as much as i should. so if there is someone out there that knows this problem or would liek to help, i'd be very thankful!

    thank you Ryan
     
  2. DaRkKn1qHt

    DaRkKn1qHt Private First Class

    Well 1st you don't really want to delete IE especially since it is not easy, unless you have and eradictor program. 2nd What programs did you run? 3rd I can help with HJT logs but only if posted properly as an attachemnt.
     
  3. celebration.of.being

    celebration.of.being Private First Class

    Well i cant tell u much about how u can get well along with ur IE but sure can tell u about other browsers. Till ur IE gets fixed..u can download "opera" (from www.opera.com) or "mozilla" browser(from www.mozilla.org) on somebody's pc..and install it on ur pc. it is as simple as IE and u can surf the web with it just like u do with IE...atleast u will be able to surf the web till somebody really intelligent can help u out) anyways i wish u gud luck..bye!
     
  4. Blockhead

    Blockhead Private E-2

    From time to time my Earthlink homepage won't access either, even though my internet connection is logged on. What works for me is to click the MSN butterfly icon on my desktop, and for some reason that accesses MSN's homepage just fine (have to have a password to log in there). Then once I'm there, I just click the little house icon that takes me to Earthlink's homepage and it opens right up. As soon as it opens, I close MSN's homepage.


    Hope this explains it okay. Don't know why mine only does that intermittently, but it's a pain!
     
  5. Kodo

    Kodo SNATCHSQUATCH

    MAJOR GEEKS IS A FILE REPOSITORY SITE! BEFORE YOU SEND PEOPLE TO OTHER SITES, CHECK HERE FIRST !!!!!! this is your second notice.
    Thank you!
     
  6. Insomniac

    Insomniac Billy Ray Cyrus #1 Fan

    I just want to add, I'm a member of quite a few forums, and have visited countless similar sites, and I've yet to see a site with the range of quality, effective, and versatile software that this place has.

    Obviously a lot of effort and time has gone into the software available here.

    Thanks to all those concerned, it really is very impressive! (And no, this isn't a brown-nose job, just stating facts)
     
  7. DaRkKn1qHt

    DaRkKn1qHt Private First Class

    KODO! Is it safe to suggest that they download the information from this website, but if they wish for more information to see the manufacturer's website, and post that link?
     
  8. Kodo

    Kodo SNATCHSQUATCH

    DK, that is fine. I'm only concerned about the actual file download link.
     
  9. celebration.of.being

    celebration.of.being Private First Class

    My dear KODO...i do appreciate this site an lot and found it best. I have joined it a few days back but sure found it the best of all...but whats wrong if a person knows nothing about a internet browser and wud like to know a little bit about them from the official site....WHY U MIND THAT??? Ultimately everything is here to enrich lives...u all better be more sensitive in our replies.
     
    Last edited: Oct 16, 2004
  10. Kodo

    Kodo SNATCHSQUATCH

    The owners of this site don't make their money by sending people to places like download.com

    The proper way would be to post the download to the file here and the official page of the software for official information.

    That's all we ask.
     
  11. celebration.of.being

    celebration.of.being Private First Class

    okie KODO..i get that. i am a newbie on this site and i really apologise if i have done something thats against the code u all follow. i will surely follow the proper procedure next time and thanx a lot for correcting me...bye
     
  12. Kodo

    Kodo SNATCHSQUATCH

    Thank you!
    And welcome (officially) to Major Geeks ;)
     
  13. celebration.of.being

    celebration.of.being Private First Class

    Well thanx a lot to u all there. I have really found this site a great place where people are so warm and are willing to help.Its gr8 to be a part of such a nice lot...KODO u have been soooooo kind.....okie u all GeeKS...out there..keep doing the gr8 job..bye
     
  14. wickety

    wickety Private E-2

    well i followed like all of the instruciton on the get rid of virues/trojans thread, except i remember now that i didn't install a different java platform, but thats it i believe. and yeah if you could tellme, or no i will read on how to attach the hijack this logs and it woudl help.
     
  15. wickety

    wickety Private E-2

    ok it took me a while but if someone could help me again i will attach the results of a hijck:this log. the problem once again, is that my IE will not open up such as ina window, but the program will start running without me knowing it, that is until my computter slows way down or freezes up completely. i have WIndows XP Professional, but i do not have the disc for it, if i needed to re-format, i would have to go back to windows 98. i think now after using xp pro, going back to windows 98, woudl be like going from a porsche, to a geo metro. joke=haha. but yes if someone would take a look at this , i would apreciate it.

    thanks, ryan
     

    Attached Files:

  16. DaRkKn1qHt

    DaRkKn1qHt Private First Class

    Well these are the items that stick out at me.

    These appear to be virui:
    C:\WINDOWS\system32\pcs\pcsvc.exe
    C:\WINDOWS\System32\MSXMLA24.exe
    C:\WINDOWS\System32\devldr32.exe

    Run a virus scan like www.housecall.antivirus.com and see what is found.

    To save space I am attaching all the items I would remove with HJT in a txt file, plz read.

    If anyone else has different opinions plz post.
     

    Attached Files:

  17. wickety

    wickety Private E-2

    hey thanks for that much, i will try to remove those things. and also that housecall scan woudl not load for me. i dont lknow if its because i am not using IE or what, i dont know much about the Mozilla Firefox i am using right now. but i'm sure i can find another online scan website. but thanks a lot foe the help, and if anyone else knows anything, it would also be helpful.

    ryan
     
  18. Kodo

    Kodo SNATCHSQUATCH


    DK,
    there are many more items than you list..

    Wickety.. I won't have time for a while to get back to you .. but I will tell you this. You have the msblast virus on your machine and a crap load of other trojans.

    Chas... if you could interject here as I won't have time , that would be great.
     
  19. wickety

    wickety Private E-2

    ok man, ummm yikes i didn't know all that, i need to get better with this stuff. yeah if someone wants to step in and help me i would love it. its been a real pain in the (bleep) you know and i want to fix er up. and i dont know if it is easier to talk through hear or maybe through email , mine is ryfry314@yahoo.com, in case anyone wants to reach me there. but yeah i know there are some trojans but i'm in the dark as in what to do now. so any help is appreciated.

    thanks
    ryan :)
     
  20. Insomniac

    Insomniac Billy Ray Cyrus #1 Fan

    devldr32.exe is for Creative Labs hardware and is nothing to worry about.

    However, Wickety I don't mean to be rude, but I have never seen a computer with so much useless cr@p, adware, spyware and viruses.

    Please read the Stickies first in the SpyWare Forum.

    That has info and links for the programs and steps you need to take.

    To get rid of MSBlast, make sure you have applied Micro$$oft critical updates, and then download the Removal Tool.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm moving this thread to the Spyware Forum!

    You should have begun by following all the steps in this Sticky thread < READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal >

    But since you did not, lets see if we can start to fix you up.

    Run this W32.Blaster.Worm Removal Tool

    As Insomniac said, C:\WINDOWS\System32\devldr32.exe <--- this is a valid process from Creative Labs. Leave it be.

    You need to uninstall Messenger Plus! 2, it puts adware and LOP on you computer.
    Look in Add/Remove Programs for EbatesMoeMoneyMaker or Ebates and uninstall it.

    What version of DAP (Download Accelerator Plus) are you using? If it is not 7.3, uninstall it and download and re-install 7.3.
    Get it here: http://www.majorgeeks.com/download448.html
    I don't think it is a good idead to use both DAP and MaxSpeed.

    Make sure you have system restore disabled and viewing of hidden files enabled (per the tutorial).
    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Find the below processes and End them:
    pcsvc.exe
    MSXMLA24.exe
    enbiei.exe
    navmgrd.exe
    mslaugh.exe
    z.exe

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.begin2search.com/sidesearch.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.begin2search.com/sidesearch.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
    R3 - Default URLSearchHook is missing
    O1 - Hosts: 216.130.185.143 www.adwave.com
    O1 - Hosts: 216.130.185.143 adwave.com
    O1 - Hosts: 216.130.185.143 www.xzoomy.com
    O1 - Hosts: 216.130.185.143 xzoomy.com
    O1 - Hosts: 216.130.185.143 www.advnt01.com
    O1 - Hosts: 216.130.185.143 advnt01.com
    O1 - Hosts: 216.130.185.143 www.adwave.com
    O1 - Hosts: 216.130.185.143 adwave.com
    O1 - Hosts: 216.130.185.143 www.xzoomy.com
    O1 - Hosts: 216.130.185.143 xzoomy.com
    O1 - Hosts: 216.130.185.143 www.advnt01.com
    O1 - Hosts: 216.130.185.143 advnt01.com
    O1 - Hosts: 216.130.185.143 www.adwave.com
    O1 - Hosts: 216.130.185.143 adwave.com
    O1 - Hosts: 216.130.185.143 www.xzoomy.com
    O1 - Hosts: 216.130.185.143 xzoomy.com
    O1 - Hosts: 216.130.185.143 www.advnt01.com
    O1 - Hosts: 216.130.185.143 advnt01.com
    O1 - Hosts: 216.130.185.143 www.adwave.com
    O1 - Hosts: 216.130.185.143 adwave.com
    O1 - Hosts: 216.130.185.143 www.xzoomy.com
    O1 - Hosts: 216.130.185.143 xzoomy.com
    O1 - Hosts: 216.130.185.143 www.advnt01.com
    O1 - Hosts: 216.130.185.143 advnt01.com
    O1 - Hosts: 216.130.185.143 www.adwave.com
    O1 - Hosts: 216.130.185.143 adwave.com
    O1 - Hosts: 216.130.185.143 www.xzoomy.com
    O1 - Hosts: 216.130.185.143 xzoomy.com
    O1 - Hosts: 216.130.185.143 www.advnt01.com
    O1 - Hosts: 216.130.185.143 advnt01.com
    O1 - Hosts: 216.130.185.143 www.adwave.com
    O1 - Hosts: 216.130.185.143 adwave.com
    O1 - Hosts: 216.130.185.143 www.xzoomy.com
    O1 - Hosts: 216.130.185.143 xzoomy.com
    O1 - Hosts: 216.130.185.143 www.advnt01.com
    O1 - Hosts: 216.130.185.143 advnt01.com
    O1 - Hosts: 216.130.185.143 www.adwave.com
    O1 - Hosts: 216.130.185.143 adwave.com
    O1 - Hosts: 216.130.185.143 www.xzoomy.com
    O1 - Hosts: 216.130.185.143 xzoomy.com
    O1 - Hosts: 216.130.185.143 www.advnt01.com
    O1 - Hosts: 216.130.185.143 advnt01.com
    O1 - Hosts: 216.130.185.143 www.adwave.com
    O1 - Hosts: 216.130.185.143 adwave.com
    O1 - Hosts: 216.130.185.143 www.xzoomy.com
    O1 - Hosts: 216.130.185.143 xzoomy.com
    O1 - Hosts: 216.130.185.143 www.advnt01.com
    O1 - Hosts: 216.130.185.143 advnt01.com
    O1 - Hosts: 216.130.185.143 www.adwave.com
    O1 - Hosts: 216.130.185.143 adwave.com
    O1 - Hosts: 216.130.185.143 www.xzoomy.com
    O1 - Hosts: 216.130.185.143 xzoomy.com
    O1 - Hosts: 216.130.185.143 www.advnt01.com
    O1 - Hosts: 216.130.185.143 advnt01.com
    O1 - Hosts: 216.130.185.143 www.adwave.com
    O1 - Hosts: 216.130.185.143 adwave.com
    O1 - Hosts: 216.130.185.143 www.xzoomy.com
    O1 - Hosts: 216.130.185.143 xzoomy.com
    O1 - Hosts: 216.130.185.143 www.advnt01.com
    O1 - Hosts: 216.130.185.143 advnt01.com
    O1 - Hosts: 216.130.185.143 www.adwave.com
    O1 - Hosts: 216.130.185.143 adwave.com
    O1 - Hosts: 216.130.185.143 www.xzoomy.com
    O1 - Hosts: 216.130.185.143 xzoomy.com
    O1 - Hosts: 216.130.185.143 www.advnt01.com
    O1 - Hosts: 216.130.185.143 advnt01.com
    O1 - Hosts: 216.130.185.143 www.adwave.com
    O1 - Hosts: 216.130.185.143 adwave.com
    O1 - Hosts: 216.130.185.143 www.xzoomy.com
    O1 - Hosts: 216.130.185.143 xzoomy.com
    O1 - Hosts: 216.130.185.143 www.advnt01.com
    O1 - Hosts: 216.130.185.143 advnt01.com
    O2 - BHO: Zedd4Proj.clsUnoOne - {08227B4B-54FE-4C4D-809F-BCA46292FC5B} - C:\WINDOWS\System32\AANTX.dll
    O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dll (file missing)
    O2 - BHO: (no name) - {F0A136C4-6FAA-D984-EB28-42B57300E262} - C:\WINDOWS\Iuyyligy.dll
    O3 - Toolbar: Search - {314E486A-CC0B-EF07-AA44-E834170E8CA7} - C:\WINDOWS\Iuyyligy.dll
    O4 - HKLM\..\Run: [www.hidro.4t.com ] enbiei.exe
    O4 - HKLM\..\Run: [Microsoft Update] navmgrd.exe
    O4 - HKLM\..\Run: [Windows Automation] mslaugh.exe
    O4 - HKLM\..\Run: [z] C:\windows\temp\z.exe
    O4 - HKLM\..\Run: [Pcsv] C:\WINDOWS\system32\pcs\pcsvc.exe
    O4 - HKLM\..\Run: [abedde05727a] C:\WINDOWS\System32\MSXMLA24.exe
    O4 - HKLM\..\Run: [AutoLoaderqtqr1IXlcKWO] "C:\WINDOWS\System32\dxdrac32.exe" /HideUninstall /PC="AM.WILD"
    O4 - HKLM\..\Run: [qE9X36i] dxdrac32.exe
    O4 - HKLM\..\Run: [EbatesMoeMoneyMaker0] "C:\Program Files\Ebates_MoeMoneyMaker\EbatesMoeMoneyMaker0.exe"
    O4 - HKLM\..\Run: [VVSN] C:\Program Files\VVSN\VVSN.exe
    O4 - HKLM\..\RunServices: [Microsoft Update] navmgrd.exe
    O4 - HKCU\..\Run: [Microsoft Update] navmgrd.exe
    O9 - Extra button: (no name) - {91663649-416A-42A5-8E54-B63C1ECA0548} - C:\Program Files\Surfapps.com\PopThis! Free Version\PopThis.dll (file missing)
    O9 - Extra 'Tools' menuitem: PopThis! Options... - {91663649-416A-42A5-8E54-B63C1ECA0548} - C:\Program Files\Surfapps.com\PopThis! Free Version\PopThis.dll (file missing)
    O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebproducts/SmileyCentralInitialSetup1.0.0.5.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/09aa8c831e1494205a02/netzip/RdxIE601.cab
    O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - https://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab


    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\Iuyyligy.dll
    C:\WINDOWS\System32\AANTX.dll
    C:\WINDOWS\system32\enbiei.exe
    C:\WINDOWS\system32 mslaugh.exe
    C:\windows\temp\z.exe
    C:\WINDOWS\system32\pcs\pcsvc.exe
    C:\WINDOWS\System32\MSXMLA24.exe
    C:\WINDOWS\system32\dxdrac32.exe
    C:\Program Files\Ebates_MoeMoneyMaker <-- the whole directory if still there.
    C:\Program Files\VVSN <-- the whole directory
    C:\WINDOWS\system32\navmgrd.exe

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  22. wickety

    wickety Private E-2

    ok well first things first,

    i had followed the stickies a few weeks ago, but i have not been there yet, because i thought i may have sumthing weird or different, that may need special attention.

    and so...

    i ran the worm tool, and it said it could not find the worm on my system, now i dont know if that is after it cleaned it, or it just was not there.

    and i removed messenger plus, but ebates is nowhere to be foudn anywhere on my machine, by me at least.

    and i dont believe any of those processes you said to end were even running.

    barely any of the hjt log things were there either.

    then i also could only find like 3 of the things you told me to delete while in safe mode, so i dont know whats goin on. but my IE has been running ok since yesterday before i did this, so maybe it is taken care of.

    do you think i should still run through the basic spyware removal stickie just to be safe, b/c my antiVir is popping up all the time detecting trojans.

    and also shoudl i do as the 'safe from malware" sticky says and put in a personal firewall?

    i'm attaching the new HJT log to this also.

    thanks
     

    Attached Files:

  23. Kodo

    Kodo SNATCHSQUATCH

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds