📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

problems with internet exporer 6......

Options
2

Comments

  • T4i
    T4i Posts: 1,845 Forumite
    Part of the Furniture Combo Breaker
    Logfile of HijackThis v1.99.1
    Scan saved at 11:47:57, on 11/05/05
    Update to SP2 --> Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\Smss.exe
    C:\WINDOWS\system32\Winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Svchost.exe
    C:\WINDOWS\System32\Svchost.exe
    C:\WINDOWS\system32\Spoolsv.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\System32\Svchost.exe
    C:\Program Files\AOL 8.0\waol.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\Program Files\AOL 8.0\shellmon.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\WinRAR\WinRAR.exe
    C:\DOCUME~1\RSGILL~1\LOCALS~1\Temp\Rar$EX01.531\Hi jackThis.exe

    Do you know this site? --> R1 - HKLM\Software\Microsoft\Internet Explorer,Search = http://allstarsearch.net
    Do you know this site? --> R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
    Do you know this site? --> R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cus...//www.yahoo.com
    Always Bad --> O1 - Hosts: auto.search.msn.com 127.0.0.1127.0.0.1 downloads1.kaspersky-labs.com
    O2 - BHO: (no name) - !!78364D99-A640-4ddf-B91A-67EFF8373045} - C:\WINDOWS\system32\appwiz.dll
    O2 - BHO: (no name) - {D8A9A1BB-3F79-37AF-5B80-6653070A14C7} - C:\WINDOWS\System32\xkeznpkb.dll
    O2 - BHO: (no name) - {ED8491BB-124A-029B-76B0-567E373A39F7} - C:\WINDOWS\System32\xkeznpkb.dll
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file) <-- Always Remove
    O3 - Toolbar: &Radio - !!8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [WindowsUpdate] C:\WINDOWS\System\Svchost.exe /s
    O4 - HKLM\..\RunServices: [SystemTools] C:\WINDOWS\System32\kernels32.exe
    O8 - Extra context menu item: &Check Spelling - res://C:\Program Files\ieSpell\ieSpell.dll/SPELLCHECK.HTM
    O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\ieSpell.dll/SPELLOPTION.HTM
    O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: ieSpell - !!0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\ieSpell.dll
    O9 - Extra 'Tools' menuitem: ieSpell - !!0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\ieSpell.dll
    O9 - Extra button: (no name) - !!1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\ieSpell.dll
    O9 - Extra 'Tools' menuitem: ieSpell Options - !!1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\ieSpell.dll
    O9 - Extra button: Messenger - !!4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - !!4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    Do you really trust them? --> O15 - Trusted Zone: *.skoobidoo.com (HKLM)
    Do you really trust them? --> O15 - Trusted Zone: *.slotchbar.com (HKLM)
    Do you really trust them? --> O15 - Trusted Zone: *.windupdates.com (HKLM)
    O15 - Trusted IP range: 81.222.131.59 (HKLM)
    O17 - HKLM\System\CCS\Services\Tcpip\..\!!45A79CDA-DF1D-4563-B277-B8742496AE3D}: NameServer = 152.163.0.26 205.188.64.153
    O17 - HKLM\System\CCS\Services\Tcpip\..\!!9D1FDEF6-26C5-4851-A50D-F01B47C1CB8D}: NameServer = 205.188.146.145
    O17 - HKLM\System\CS2\Services\Tcpip\..\!!45A79CDA-DF1D-4563-B277-B8742496AE3D}: NameServer = 152.163.0.26 205.188.64.153
    O21 - SSODL: SysTray.Exsh - {E1B7D0BE-5f02-4255-96DB-388DFA241900} - C:\WINDOWS\System32\oilldcgd.dll
    O21 - SSODL: SysTray.Exdc - {F1B7D0BE-5f02-4255-96DB-388DFA241900} - C:\WINDOWS\System32\mnoaeghn.dll
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

    I'd start with SP2. Do you need AOL installed?
  • T4i
    T4i Posts: 1,845 Forumite
    Part of the Furniture Combo Breaker
    Do you really trust them? --> O15 - Trusted Zone: *.skoobidoo.com (HKLM)
    Do you really trust them? --> O15 - Trusted Zone: *.slotchbar.com (HKLM)

    If you've not added them into the trusted zones I'd delete them with hijackthis.

    If you run another scan and put a little tick in the box that applies to the entry you want to delete and then press fix or whatever it says.
  • ACID
    ACID Posts: 1,209 Forumite
    Do you know this site? --> R1 - HKLM\Software\Microsoft\Internet Explorer,Search = http://allstarsearch.net
    Do you know this site? --> R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
    Do you know this site? --> R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cus...//www.yahoo.com
    Always Bad --> O1 - Hosts: auto.search.msn.com 127.0.0.1127.0.0.1 downloads1.kaspersky-labs.com

    all above looked dodge apart from google

    ill prob go for sp2 , i have the cd anyway to install it, just gona find it and install it
    btu does that mean all these errors will be removed?>???
  • Rex_Mundi
    Rex_Mundi Posts: 6,312 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker
    Do you really trust them? --> O15 - Trusted Zone: *.windupdates.com (HKLM

    I've found references to this and a trojan as well. I'd fix it using Hijackthis.
    How many surrealists does it take to change a lightbulb?
    ...
    ...
    ...
    ...
    Fish
  • T4i
    T4i Posts: 1,845 Forumite
    Part of the Furniture Combo Breaker
    Get rid of all of those m8 apart from the google one.

    Install SP2 and see if your errors stop. At least your half way to solving your problem then. The NPDocBox.dll is a plugin for IE from Adobe Acrobat. This shouldnt be a problem but Adobe can be very hormonal.
  • ACID
    ACID Posts: 1,209 Forumite
    i left npcdocbox.dll

    hwoever remvoed all others,

    i wont do a restart but
    ill do a quick adaware scan, that shoudl be ok if no errors are raised
  • ACID
    ACID Posts: 1,209 Forumite
    NOW WHEN I RAN ADAWARE
    all i get is critical errors
    in the form of IECache

    is this common?
  • ACID
    ACID Posts: 1,209 Forumite
    right now have switched on th pc, to fin that i still cant access hotmail
    the site is ok it when i entre in my user details??
    same message pop up apppears
  • T4i
    T4i Posts: 1,845 Forumite
    Part of the Furniture Combo Breaker
    What adaware you running?

    Have you used CrapCleaner to delete your IE cache?
  • ACID
    ACID Posts: 1,209 Forumite
    Link Please
    Any Good
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351.1K Banking & Borrowing
  • 253.1K Reduce Debt & Boost Income
  • 453.6K Spending & Discounts
  • 244.1K Work, Benefits & Business
  • 599K Mortgages, Homes & Bills
  • 177K Life & Family
  • 257.4K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.