PDA

View Full Version : IE problem



ubdaddy
2006-01-10, 21:36
Hi there,

I have an IE problem described below, I ran HijackThis V1.99.1 and the log is attached.

I will appreciate any advise.

Thanks,

Yair



IE problem description:
======================

I'm running IE 6.0.2900.2180.xpsp_sp2_gdr.050301_1519 on WInXP-Pro Ver 2002 SP2.

Lately IE fails to reach certain pages while Firfox does not have any problems.

I have scaned the machine using McAfee AntiVirus, SpyBot, Ad-Aware-Se,
PestPatrol, ZoneAlarmPro Anti-Spyware, and Microsoft Anti-malware feature is
also in there.

The machine looks clean.

ZoneAlarmPro privacy settings is set to all "OFF", IE setup is all set to 'default' and
the Privacy is "accept all cookies".

Still it won't get certain pages, just say 'done' and display nothing.

An example of such page is the Israely Soccer lottery organization
http://www.toto.org.il




HijackThis V1.99.1 log:
======================

Logfile of HijackThis v1.99.1
Scan saved at 21:26:49, on 10/01/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
D:\PROGRA~1\PESTPA~2\PPMemCheck.exe
D:\PROGRA~1\PESTPA~2\PPControl.exe
D:\PROGRA~1\PESTPA~2\CookiePatrol.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
D:\Program Files\Zone Labs\ZoneAlarm\ZoneAlarm\zlclient.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
D:\Program Files\Megatec\RUPS 2000\Rupsw32.EXE
D:\Program Files\Motherboard Monitor 5\MBM5.exe
E:\Program Files\FreeProxy\FreeProxy.exe
c:\program files\mcafee.com\agent\mcdetect.exe
C:\WINDOWS\System32\nvsvc32.exe
d:\Program Files\Megatec\RUPS 2000\Rupsd.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\WINDOWS\system32\fxssvc.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
f:\Program Files\ATnotes\ATnotes.exe
E:\Program Files\BOINC\projects\www.climateprediction.net\sulphur_4.22_windows_intelx86.exe
E:\Program Files\BOINC\projects\www.climateprediction.net\sulphur_um_4.22_windows_intelx86.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
E:\Program Files\BOINC\projects\setiathome.berkeley.edu\setiathome_4.18_windows_intelx86.exe
E:\Program Files\BOINC\projects\einstein.phys.uwm.edu\albert_4.37_windows_intelx86.exe
C:\Program Files\Outlook Express\msimn.exe
D:\Program Files\Microsoft Office\Office\WINWORD.EXE
D:\Downloads\ZIPs\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R3 - URLSearchHook: (no name) - {5038FED1-CEFE-11D2-9E74-00A0C945A948} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - D:\Program Files\GetRight\xx2gr.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - d:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [PPMemCheck] D:\PROGRA~1\PESTPA~2\PPMemCheck.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] D:\PROGRA~1\PESTPA~2\PPControl.exe
O4 - HKLM\..\Run: [KeyPatrol] D:\PROGRA~1\PESTPA~2\KeyPatrol.exe
O4 - HKLM\..\Run: [CookiePatrol] D:\PROGRA~1\PESTPA~2\CookiePatrol.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe /nosplash
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [Zone Labs Client] D:\Program Files\Zone Labs\ZoneAlarm\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [McRegWiz] c:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun
O4 - HKCU\..\Run: [ATnotes.exe] f:\Program Files\ATnotes\ATnotes.exe
O4 - Global Startup: RUPS Daemon.lnk = ?
O4 - Global Startup: MBM5.lnk = D:\Program Files\Motherboard Monitor 5\MBM5.exe
O4 - Global Startup: Internet Zahav AZTV Cables Dialer.lnk = ?
O8 - Extra context menu item: Download with GetRight - D:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - D:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.akamai.net
O15 - Trusted Zone: http://Download.Windowsupdate.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-

us/4,0,0,84/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -

http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1121206927926
O17 - HKLM\System\CCS\Services\Tcpip\..\{96A3F4A1-8188-4C6B-B416-7D4C5495B302}: NameServer = 192.116.202.222 213.8.172.83
O23 - Service: BOINC - Unknown owner - E:\Program Files\BOINC\boinc.exe" -daemon (file missing)
O23 - Service: Free Proxy Service (FreeProxy) - Hand-Crafted Software - E:\Program Files\FreeProxy\FreeProxy.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1

\mcafee.com\vso\mcvsrte.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Rupsd - Mega System Technologies, Inc. - d:\Program Files\Megatec\RUPS 2000\Rupsd.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - F:\Program Files\TuneUp Utilities 2006

\WinStylerThemeSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe

ubdaddy
2006-01-13, 02:31
As it turned out my machine was indeed clean.
I was ready to give up and re-install the machine from scratch, when I got the solution from my ISP online technician:
The IE->View->encoding pointed to "Unicode (UTF-8)", and some Web pages don't show anything, not even any giberish, just an empty page.
I just reset it to Auto-select and the missing pages reappeared.

LonnyRJones
2006-01-14, 09:29
Thanks for posting back and mentioning you found a solution :D

Are there any other problems ?

tashi
2006-01-18, 18:39
As the problem appears to be resolved this topic will be archived.
If you need it re-opened please pm me or one of the forum mods.

Cheers.