Unsolved

This post is more than 5 years old

2 Posts

1280

October 4th, 2004 17:00

Some links in IE don't work

I was recently invaded by an Ibis toolbar (btiein) and I think "lop". I have succesfully removed btiein by editing the registry key. And everything works fine except: On some sites that I have used many times in the past, I am unable to use links to other sites. When I click on the link, there is a "burp" sound and I go nowhere. It is very inconvenient. Any suggestions?

2.7K Posts

October 4th, 2004 21:00

You probably need to run the clean up programs
Download, update and run the following
Spybot Search & Destroy    http://www.majorgeeks.com/download2471.html   
 Get it to remove all the RED entries

Ad-aware SE  http://www.lavasoft.de/support/download/#free

Then download
Hijack This          http://www.majorgeeks.com/download3155.html
 

Make a special folder in My Documents  to download it to. Set it to "Scan" and then to create its "Log". This will be long, but copy all of it into Notepad and post it to be checked.

 

2 Posts

October 5th, 2004 15:00

Thank you Mr./Ms. Dunedin.

Your suggested solution pushed me to learn a few new procedures, but the results of the last scan in Hijack This are below.

Logfile of HijackThis v1.98.2
Scan saved at 9:31:52 AM, on 10/5/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Nhksrv.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\DELLMMKB.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe
C:\Program Files\Messenger Plus! 3\MsgPlus1.exe
C:\Program Files\Zero Knowledge\TELUS Security service\Freedom.exe
C:\Program Files\Netropa\OSD.exe
C:\WINDOWS\SYSTEM32\ADIMonEx.exe
C:\Program Files\TELUS eCare\bin\mpbtn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\TELUS eCare\bin\mad.exe
C:\PROGRA~1\HEWLET~1\hpis\common\MOTIVE~1.EXE
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\HAL\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mytelus.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://btzmlkhfpyhmflncakipqh.uk/SvQw7Ml/H12YJNjRwoCJIPrpFFWLrUknfAUNtMtutvhpW0ad50BNpj3p7SCulTaq.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by telus.net®
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;
N1 - Netscape 4: user_pref("browser.startup.homepage", " http://www.onttkpaizxhkpdrvhyjizlqv.org/SvQw7Ml/H11pq3vM_n2ttSzdwc9pY_3ZLkguLkvE3Dg.asp");\nuser_pref("browser.startup.page", 1); (C:\Program Files\Netscape\Users\halojen\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Zero Knowledge\TELUS Security service\pkR.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Zero Knowledge\TELUS Security service\FreeBHOR.dll
O2 - BHO: (no name) - {C38D7CC0-6D50-BF18-9079-7E3E12BEFD3B} - C:\PROGRA~1\32CAST~1\Messflap.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\DELLMMKB.EXE
O4 - HKLM\..\Run: [DIAGENT] C:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [Extra Barb] C:\PROGRA~1\BASESH~1\SafeCloseBird.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus1.exe"
O4 - HKLM\..\Run: [TELUS Security service] C:\Program Files\Zero Knowledge\TELUS Security service\Freedom.exe
O4 - HKLM\..\RunOnce: [IndexCleaner] "C:\Program Files\Zero Knowledge\TELUS Security service\IndexCleanerR.exe"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\RunOnce: [IndexCleaner] "C:\Program Files\Zero Knowledge\TELUS Security service\IndexCleanerR.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: DAEWOO DSL Monitor.LNK = C:\WINDOWS\SYSTEM32\ADIMonEx.exe
O4 - Global Startup: TELUS eCare.lnk = C:\Program Files\TELUS eCare\bin\matcli.exe
O8 - Extra context menu item: &Define - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {2253F320-AB68-4A07-917D-4F12D8884A06} (ChainCast VMR Client Proxy) - http://64.124.45.181/downloads/ccpm_0237.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security2.norton.com/SSC/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/bonnie/us/win/QuickTimeInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/208ed95f2ae574d2b716/netzip/RdxIE601.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003120501/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security2.norton.com/SSC/SharedContent/sc/bin/cabsa.cab
O16 - DPF: {F57D17AE-CE37-4BC8-B232-EA57747BE5E7} - http://66.230.146.53/EPlugin.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab

 

2.7K Posts

October 5th, 2004 21:00

I asked you to make a folder in My Documents to keep HijackThis and its log in.  This is important since using a temp folder could lose any backups of removed items and you would be unable to restore if necessary.
Please reinstall to a special folder in My Documents and run it again.
Get it to remove these two items.

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://btzmlkhfpyhmflncakipqh.uk/SvQw7Ml/H12YJNjRwoCJIPrpFFWLrUknfAUNtMtutvhpW0ad50BNpj3p7SCulTaq.html


O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/208ed95f2ae574d2b716/netzip/RdxIE601.cab


If you are not on a network that uses proxy servers remove this one. If you are not sure just leave it

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;

I cannot find any information on the following 3 entries. Do you know what they are?

N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.onttkpaizxhkpdrvhyjizlqv.org/SvQw7Ml/H11pq3vM_n2ttSzdwc9pY_3ZLkguLkvE3Dg.asp");\nuser_pref("browser.startup.page", 1); (C:\Program Files\Netscape\Users\halojen\prefs.js)

O2 - BHO: (no name) - {C38D7CC0-6D50-BF18-9079-7E3E12BEFD3B} - C:\PROGRA~1\32CAST~1\Messflap.exe

O4 - HKLM\..\Run: [Extra Barb] C:\PROGRA~1\BASESH~1\SafeCloseBird.exe

As you can see they are located at
(C:\Program Files\Netscape\Users\halojen\prefs.js)
C:\PROGRA~1\32CAST~1\Messflap.exe
C:\PROGRA~1\BASESH~1\SafeCloseBird.exe

Have a look at these 3 locations and see if you can identify them but do not remove anything else yet

No Events found!

Top