Jump to content

Recommended Posts

i got another question. i recently downloaded for my wifes login some dragon themes. i didnt know they were loaded with spyware. once i found out i deleted them. ran spybot and adaware and nis2004. on nis it got 13 hits. it deleted 3. i had to hunt down the rest manually. once done run all scans again. nothing showed up. but ever since then when i logon to netzero highspeed my home page, which is netzero and a few other pages on netzero has errors on the page. i tried uninstalling and reinstalling netzero high speed but it still does it. i thought maybe somehow ie6 got screwed up by the spyware. i dont experience any browser hijacking. and everywhere else i go does not give me the done but with errors on page. i havent as of yet been able to get anyone anywhere on different boards to help me. i get ignored on this question. i need to know if i need to reinstall ie6 or not. i sent a request to netzero support on it and they are looking into it. i sent them the log file they asked for to look at. maybe they can help but i thought i'd ask here as well. any help would be greatly appreciated.

Link to comment
Share on other sites

heres the last one i did i just had my ie6 completely screwup on me. i disconnected and tried to reconnect and when it went so far into the connection as to ie6 coming up and starting to load it gave me an internal error and said it had to close. i tried 5 or 6 times but it did it every time. so i thought well, looks like i have to reinstall ie6 anyway. i started the application but it came on and gave me another error saying something about a previous installation was already running. so i rebooted. then tried to logon again this time it did it without any problems.

and it apparently is ok now. i didnt get the done but with errors on page on the netzero homepage. im gonna try a few of the other pages that was screwing up and see if theyre ok as well.

netzero sent me a reply just a bit ago stating they had looked at the cwlog file and there was some 3rd party prgs that was affecting the browser. asked them to tell me what they are.

Logfile of HijackThis v1.98.2

Scan saved at 10:30:59 PM, on 10/21/2004

Platform: Windows XP SP1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe

C:\Program Files\Common Files\Symantec Shared\ccProxy.exe

C:\Program Files\Executive Software\Diskeeper\DkService.exe

C:\WINDOWS\system32\gearsec.exe

C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe

C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\dla\tfswctrl.exe

C:\Program Files\Common Files\Symantec Shared\ccApp.exe

C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe

C:\Program Files\Analog Devices\SoundMAX\Smax4.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe

C:\Program Files\NetZero\exec.exe

C:\Program Files\NetZero\exec.exe

C:\Program Files\NetZero\qsacc\x1exec.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\antispyware\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.netzero.net/s/sp

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://my.netzero.net/s/search?r=minisearch

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://my.netzero.net/s/search?r=minisearch

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://my.netzero.net/s/sp?r=al&cf=sp&...;N=PLHS&O=A

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer scotts

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:7900

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 64.136.29.30;64.136.21.30;64.136.29.34;searchap.untd.com;127.0.0.1;

localhost;*windowsupdate.microsoft.com;*windowsupdate.com;

*wustat.windows.com;*.pogo.com;*test-speed.com;<local>

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: X1IEHook Class - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\X1IEBHO.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll

O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll

O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll

O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll

O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [urlLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe

O4 - HKLM\..\Run: [sSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe

O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe

O4 - HKLM\..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe

O4 - HKLM\..\Run: [soundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\RunOnce: [untd_recovery] C:\Program Files\NetZero\qsacc\x1exec.exe

O4 - Global Startup: APC UPS Status.lnk = ?

O8 - Extra context menu item: Display All Images with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/228

O8 - Extra context menu item: Display Image with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/227

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1098160085765

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://

security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab://http://

security.symantec.com/sscv6...n/bin/cabsa.cab

O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -

http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab

O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) -

O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://

messenger.msn.com/download/MsnMesse...pDownloader.cab://http://

messenger.msn.com/download/...pDownloader.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{43A7A4B3-0F94-48D8-BE4A-73249A7E24B5}: NameServer = 64.136.20.121 64.136.28.121

Link to comment
Share on other sites

There is nothing in your log that gives me any cause for concern. Just as a matter of interest, was the spyware that you downloaded with the theme something called New.net? I ask because I went to download a new theme for myself the other night and it had New.Net bundled with it.. so I aborted.

Anyway... my point is that you can uninstall New.Net from add/remove programs..just deleting it can cause connection problems :(

Link to comment
Share on other sites

no, i dont think it was that it had 2 or 3 other types i noticed in the add/remove section but i just removed them there. since all that happened that night, with cleaning out those spywares using adaware and spybot and nis2004, and chasing down those remaining ones left by nis2004 it couldnt remove, then experiencing that page error problem then the ie6 crash, then rebooting and reloggin on. it all seems to be ok now. after that reboot i got online and had no errors on netzero pages and ie6 seems to be just fine now. i havent got a clue why all that happened, and why it apparently seems to have fixed itself. your guess as good as mine on that.

Link to comment
Share on other sites

well i just had another little problem. ie6 didnt crash or nothing but after i had uninstalled a prg called windvd recorder, cause apperently its just a tril that was on the drivers disk. i had netzero highspeed not come on. just hooked up without it. i ended up checking the internet options page and made a couple changes there. i got things workin again, or so i thought. my wife was on and said it was giving her a error that activex security was not allowing me to possibly view page right. and i got an error page at the bottom like before with the netzero errors. but i only saw them on yahoo and msn this time. so i ended up reinstalling scripten again, cause its the only thing i knew i did before with the netzero ordeal. then logon on. it was going slow. so i thought, maybe i need to clear the temp folder and cookies in case they were corrupted. i did. real slow still. i went to internet options again checked the autodetect setting. and it started going faster. still freezing a bit but its because i deleted all those temp pages and it has to load them all over from scratch. once theyre back in it should be ok.

Link to comment
Share on other sites

im also getting do you want to run script messages too on some pages. but i've checked the internet and intranet and trusted sites security info settings and all allow scripting theyre all enabled so why am i still getting these messages once in a while? is it because i reloaded scripten5.6 in a attempt to fix the page error problems? or maybe i need to just go ahead with the removal of ie6 and reinstall it from the download i got from ms just in case i had to do that? what'ya think nellie?

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy