Internet explorer not working

Discussion in 'Malware Help (A Specialist Will Reply)' started by nicksimec, Jul 28, 2007.

  1. nicksimec

    nicksimec Corporal

    do i have to download somthing to use UAC or somthing
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what you mean. UAC is part of Vista. It is always there. It is either enabled or disabled.
     
  3. nicksimec

    nicksimec Corporal

    well i cant open it it says type secpol.msc into run but then a message comes up saying windows can not find secpol.msc try typing it again
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you logged in as a local administrator? Look in your system32 folder. Do you see the secpol.msc file?
     
  5. nicksimec

    nicksimec Corporal

    should i download tweakUAC
     
  6. nicksimec

    nicksimec Corporal

    i only have one account on my computer and it is admin and i dont have secpol i have a few secproc
     
  7. nicksimec

    nicksimec Corporal

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You only need to disable it inorder to run GetRunKey and ShowNew. You will need to do that each time you want to run them. Afterwards you should reenable it.


    I will give you two quick registry patches I use to disable and another two disable UAC.

    Now Copy the bold text below to notepad. Save it as DisableUAC.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now Copy the bold text below to notepad. Save it as EnableUAC.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  9. nicksimec

    nicksimec Corporal

    ok i did that
     
  10. nicksimec

    nicksimec Corporal

    and i reccamend giving that link instead of the other one
     
  11. nicksimec

    nicksimec Corporal

    a little earlier today a message came up from counter spy saying a unknow (thing)i forget what it said is trying to change registry values to your startup or someting i said block
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Once you complete ALL the remaining steps in the READ & RUN ME and attach the requested logs we can continue. The only log you have given me thus far is CounterSpy which was way back in message # 40.
     
  13. nicksimec

    nicksimec Corporal

    View attachment shownew log.txt



    i clicked show new and it said scanning please wait
    the process cannot access the file because it is being used by another process.
    file not found than a notepad thing apperard
     
  14. nicksimec

    nicksimec Corporal

    a new message just apperaed from counter spy it says a program not regonized by counster spy,hp print utilty is adding sites to or removing site from internet explorers security zones.these changes could chang your home page or redirect you to malsius sites it disapperd after these changes so it is not word by word
     
  15. nicksimec

    nicksimec Corporal

    and also smitfraudfix did not work i think it is because i use vista
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please wait until you complete the READ ME before posting anymore. I know SmitFraudFix does not work, you already said that. You are supposed to be working thru all steps in the READ ME.
     
  17. nicksimec

    nicksimec Corporal

    i am trying but show new dosent work
     
  18. nicksimec

    nicksimec Corporal

    read post 63
     
  19. nicksimec

    nicksimec Corporal

    did you develop shownew
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes I did and you aleady attached the log for ShowNew so obviously it ran.

    Yes I wrote it.
     
  21. nicksimec

    nicksimec Corporal

    did you look at the log
     
  22. nicksimec

    nicksimec Corporal

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes and did you read message number 66. Please follow those instructions. I will not be posting again until ALL logs have been attached.
     
  24. nicksimec

    nicksimec Corporal

    hijackthis was not downloaded to a file it is just in my c drive
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can download the hijackthis_sfx.exe file anywhere but you need to run it and extract it to the default folder which is C:\Program Files\HijackThis and then you need to rename the EXE file.

    However since you never did step 2 of the READ ME, you could be having problems with all of this.
     
  26. nicksimec

    nicksimec Corporal

    i think i did step 2 i went in windows explorer and press show hidden files
     
  27. nicksimec

    nicksimec Corporal

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Check again! There is more to it then that.
     
  29. nicksimec

    nicksimec Corporal

    ok i did step two
     
  30. nicksimec

    nicksimec Corporal

    now what?
     
  31. nicksimec

    nicksimec Corporal

    what do i do now
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is your copy of Spyware Doctor a paid version or a free trial version?

    Uninstall the CounterSpy trial program now since we are finished with it.

    Also uninstall the below old versions of software:
    Java(TM) SE Runtime Environment 6 Update 1

    Make sure you reboot after uninstalling the above!


    Disable Windows Defender to avoid conflicts with our fixes.:
    • Open Windows Defender
    • Click Tools
    • Click General Settings
    • Scroll down to Real Time Protection Options
    • Uncheck Turn on Real Time Protection (recommended)
    • Close Windows Defender
    Once your log is clean you can re-enable Windows Defender Real Time Protection.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - HKCU\..\Run: [?????????] ??????????????e
    O13 - Gopher Prefix:

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  34. nicksimec

    nicksimec Corporal

    do i remove quarintiend items in counterspy first
     
  35. nicksimec

    nicksimec Corporal

    and i have the free version of spyware doctor soory for bumping
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please start thinking a little before you post messages! You are posting way too many unnecessary message. Just follow the directions that are given and post when you finish all of them.
     
  37. nicksimec

    nicksimec Corporal

    do i unistall spyware doctor it is trial
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Would you please just complete the instructions I already gave you in message # 82 and that I already said again in message # 86 to complete those instructions before posting again. But to answer your question, yes you can uninstall Spyware Doctor since the trial program will not fix anything.
     
  39. nicksimec

    nicksimec Corporal

  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What was the exact error you received? The fixes did not work from HJT or the registry patch. Did you have UAC disable while fixing? Did you receive a success message upon adding the fixME.reg patch to the registry?
     
  41. nicksimec

    nicksimec Corporal

    yes i think it was disabled when you restart your computer does it enable it again
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it should not renable by itself and if you did not have to disable it again to run GetRunKey and ShowNew that mean you still have it disabled.

    Please answer the other questions!
     
  43. nicksimec

    nicksimec Corporal

    i recieved a success message with the fixme.reg thing it said suculffly mergerd or somthing i cannot remenber the error want me to rerun the scans
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Rerun the HijackThis fix but make sure you run it as Administrator by right clicking on the analyse.exe.exe file and selecting Run as and then choose Administrator. If you receive any messages, tell me exactly what they say.

    Did you shut down Windows Defender??

    Then click Start, Run, and enter regedit and click OK. This should open the registry editor. Click on File and select Import. Then navigate to the fixME.reg patch that is on your Desktop and double click on it. Do you get a success message?
     
  45. nicksimec

    nicksimec Corporal

    ok alot of the stuff has been deleted
    the messages says unexpected error occured!
    error#52(bad file name or number) in sub
    get long path(???????????????e.exe)

    then please send a report to merjin and so on
     
  46. nicksimec

    nicksimec Corporal

  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what you are referring too!

    Please answer all questions in messages and address other steps. i.e., Question on Windows Defender and the procedure with regedit.
     
  48. nicksimec

    nicksimec Corporal

    window defender is disabled and i got a succses message from regit import and by stuff i mean registry keys or values
     
  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not according to your logs! Exactly what keys and values are you referring too. Only a few things were removed like:


    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O13 - Gopher Prefix:
     
  50. nicksimec

    nicksimec Corporal

    yes those are the ones i was talking about
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds