Unsolved

This post is more than 5 years old

947

October 23rd, 2004 20:00

Unable To Access Websites That Require a Password-Please Help!

Hello out there!
I must have picked up a bug somewhere, I'm really not sure.  Sometime last week something happended to my computer and I am unable to access my msn email account or any other website that requires a password.  ANY assistance that anyone would provide would be greatly appreciated.
I don't know if any of this information will help but....I subscribe to Norton Antivirus and I had Cybersitter until this AM (had it for about 18 months to try and protect my kids from things I didn't want them to see).  I also have XP.  I tried the system restore function but that did not help.  Norton doesn't list any infected files.  Thanks!!
~Derek

4.8K Posts

October 24th, 2004 00:00

Can you give us more information about what happens when you try and enter passwords on a webpage? What are the symptons and errors being returned?

Mike.

October 24th, 2004 13:00

Thanks for replying Mike!

Well, my initial theory is only partially true because I had to enter a screen name and a password to log onto this forum.  Something is really strange about this problem.  I can access things like ebay and a boating forum but I can't access my MSN email or my Mediacom email or my Delta airlines site or Hilton website (I travel a lot so these websites are invaluable to me but I can't access them on my home computer).  When I enter my user name and password and hit enter, the "this page cannot be displayed" page like you get when you are either not online trying to access a website or when your ISP is down (like Mediacom frequently is).  I think this is secondary but after I found that there was a problem, I uninstalled the Cybersitter program and restrored my computer to an earlier date (before I noticed the problelm).  One strange thing about the system restore is that I cannot scroll back in time to see when updates were made to my computer.  Other strange things are, my Windows updates are "stuck" at 37% downloaded and I frequently hear the sound of a drop of water.  As I'm sure you can tell, I am merely a basic user with limited time to become as familiar with my computer as I would like to be.  Please excuse my obvious ignorance of the subject matter.  If I didn't enter enough information please let me know.

~Derek

4.8K Posts

October 24th, 2004 16:00

Derek,
 
Let's see what's running on your computer...
 
Download HiJackThis; version 1.98.2. Move it to it's own directory, then run it. Click " Scan", then " Save log". Copy/paste what come up, and post it back here. Don't fix anything with it just yet, as most of what it reports is 'good'.
 
Mike.
 

October 24th, 2004 22:00

I thought that was going to take a long time! :-).  OK, I ran the program and there are several dozen items the scan located.  What should I do from here?  Thanks again Mike!

~Derek 

October 24th, 2004 22:00

Thanks Mike, I'll try that now.  I'll let you know when it is done.

~Derek

4.8K Posts

October 24th, 2004 23:00

Derek,
 
Good work!
 
Ok, we'll look it over, and post back.
 
Mike.
 

October 24th, 2004 23:00

OK, Here it goes.........

 

Logfile of HijackThis v1.98.2
Scan saved at 7:23:35 PM, on 10/24/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\BCMSMMSG.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\AdDestroyer\AdDestroyer.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\Program Files\VBouncer\VirtualBouncer.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\cidaemon.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\helpctr.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
C:\Documents and Settings\Derek Wolstenholme\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com/
O2 - BHO: MediaLoads Enhanced - {85A702BA-EA8F-4B83-AA07-07A5186ACD7E} - C:\Program Files\MediaLoads Enhanced\ME2.DLL (file missing)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [KAZAA] C:\Program Files\KaZaA Lite\Kazaa.exe /SYSTRAY
O4 - HKLM\..\Run: [PromulGate] "C:\Program Files\DelFin\PromulGate\PgMonitr.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [C2K] C:\WINDOWS\Cyb2k.exe
O4 - HKCU\..\Run: [EPSON Stylus Photo 820 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /A "C:\WINDOWS\System32\E_S58.tmp"
O4 - Startup: AdDestroyer.lnk = C:\Program Files\AdDestroyer\AdDestroyer.exe
O4 - Startup: PowerReg SchedulerV2.exe
O4 - Startup: Virtual Bouncer.lnk = C:\Program Files\VBouncer\VirtualBouncer.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\E_SRCV02.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/us/en/systemprofiler/SysPro.CAB
O16 - DPF: {70522FA2-4656-11D5-B0E9-0050DAC24E8F} - http://download.iwon.com/ct/pm3/iwonpm_8_1,0,2,5.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toontown.com/sv1.0.11.7/ttinst.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://anu.popcap.com/games/popcaploader_v5.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-32.cab
 
Hey, I did it! :-)

4.8K Posts

October 24th, 2004 23:00

Derek,
 
If your referring to HiJackThis, don't fix anything!...
 
You need to post the log it created back to this thread, so we can take a look at it and tell you which entry(s) need to be removed.
 
Alot of what it reports is good! And you can damage your operating system by removing the wrong entry(s). This is an analysis tool, used to manually check for 'bad' programs.
 
Without viewing the contents of the log it created, there's no way I can tell.
 
Mike.
 

October 25th, 2004 15:00

Hi All!  Does anyone think any of these are "malicious" and/or should any of these be "fixed"?

Any advice will be greatly appreciated!

~Derek

 

2 Intern

 • 

860 Posts

October 26th, 2004 08:00

 Hi

Please run theses Essential Anti Spyware tools everyone needs to run
A Download Spybot     Tutorials on how To Install Spybot Search and Destroy Tutorial2

B Download Ad-aware SE Personal 1.03  Tutorial using Ad-aware 

Also Please
 
and then please  post back the hijackthis log and any finding these scans pick up

4.8K Posts

October 27th, 2004 03:00

Derek,

Yes, there does seem to be a few 'problems' on your system:

You should be able to remove these using "Add/Remove programs", however, be sure to read the link that's provided with "Virtual Bouncer", some have had problems using the automatic install, illegally removing system files.

You might want to use AdAware and Spybot, to see if they can safely remove them for you. Also, they, might come up with alot more 'surprises' hidden on your pc.

After your done, post back a new log.

Mike.

 

 

October 31st, 2004 14:00

Thanks Guys!  I'll do these things now.

~Derek

No Events found!

Top