PDA

View Full Version : Step for step help needed with http://xn--3zo1864a/



old_dude
2006-09-21, 22:16
Hi Young People

Please can someone help this old_dude to fix his internet explorer, it was working fine, then to my horror this page tries to load hxxp://xn--3zo1864a/
I have tried everything I know to fix it but nothing helps.

:sad:

tashi
2006-09-21, 23:00
Hello old_dude,

We have people of all ages helping out here. ;)

Please see our 'sticky' topic:
BEFORE you post and who will advise you. Preliminary Steps (http://forums.spybot.info/showthread.php?t=288)

Follow the procedure and then copy paste the HJT log here into this thread and a helper will advise you as soon as available to do so.

Cheers.

old_dude
2006-09-21, 23:22
Hi

Over the hill and still active :bigthumb:

Must I stop Norton Antivirus and Windows Defender before I begin

Regards

LonnyRJones
2006-09-22, 05:57
Hi

Its not nessesary to disable norton or other programs unless someone actualy says to and why, continue getting a Hijackthis log.

old_dude
2006-09-22, 22:16
Logfile of HijackThis v1.99.1
Scan saved at 22:07:03, on 2006/09/22
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5296.0000)

Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
G:\WINDOWS\system32\svchost.exe
G:\Program Files\Windows Defender\MsMpEng.exe
G:\WINDOWS\System32\svchost.exe
G:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
G:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
G:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
G:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
G:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
G:\WINDOWS\system32\spoolsv.exe
G:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
G:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
G:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
G:\Program Files\Common Files\LightScribe\LSSrvc.exe
G:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
G:\Program Files\Norton AntiVirus\navapsvc.exe
G:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
G:\PROGRA~1\NORTON~2\NORTON~2\NPROTECT.EXE
G:\WINDOWS\system32\nvsvc32.exe
G:\WINDOWS\system32\tcpsvcs.exe
G:\WINDOWS\System32\snmp.exe
G:\PROGRA~1\NORTON~2\NORTON~2\SPEEDD~1\NOPDB.EXE
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\system32\UAService7.exe
G:\WINDOWS\system32\SearchIndexer.exe
G:\WINDOWS\Explorer.EXE
G:\Program Files\lg_fwupdate\fwupdate.exe
G:\Program Files\Common Files\Symantec Shared\ccApp.exe
G:\Program Files\Nero\Nero 7\InCD\InCD.exe
G:\WINDOWS\system32\RUNDLL32.EXE
G:\Program Files\Winamp\winampa.exe
G:\Program Files\DAP\DAP.EXE
G:\Program Files\Windows Defender\MSASCui.exe
G:\Program Files\QuickTime\qttask.exe
G:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
G:\WINDOWS\system32\ctfmon.exe
G:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
G:\Program Files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe
G:\Program Files\Microsoft ActiveSync\wcescomm.exe
G:\Program Files\Plaxo\2.10.0.30\PlaxoHelper.exe
G:\PROGRA~1\MI3AA1~1\rapimgr.exe
G:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
G:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
G:\Program Files\Nikon\NkView6\NkvMon.exe
G:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
G:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
G:\PVSW\Bin\w3dbsmgr.exe
G:\Program Files\UltimateZip\uzqkst.exe
G:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
G:\Program Files\Messenger\msmsgs.exe
G:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =

http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: DAPHelper Class - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} -

G:\PROGRA~1\DAP\dapbho.dll
O2 - BHO: Adobe PDF Reader Link Helper -

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - G:\Program Files\Adobe\Acrobat

7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -

G:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {59879FA4-4790-461c-A1CC-4EC4DE4CA483} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -

G:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper -

{9030D464-4C02-4ABF-8ECC-5164760863C6} - G:\Program Files\Common

Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - G:\Program

Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: XBTB06261 - {D71AE705-872E-47ec-9A4B-6A93C2549AE0} -

G:\PROGRA~1\EMUSIC~2\EMUSIC~1.DLL
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} -

G:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: eMusic Toolbar - {F8CC9B08-C14F-4A5C-B73B-518AFECC067A} -

G:\Program Files\eMusic Toolbar\emusicToolbar.dll
O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} -

G:\PROGRA~1\DAP\dapiebar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE

G:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [LGODDFU] "G:\Program Files\lg_fwupdate\fwupdate.exe"
O4 - HKLM\..\Run: [ccApp] "G:\Program Files\Common Files\Symantec

Shared\ccApp.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] G:\Program Files\Common

Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] G:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE

G:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinampAgent] G:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [DownloadAccelerator] "G:\Program Files\DAP\DAP.EXE"

/STARTUP
O4 - HKLM\..\Run: [Windows Defender] "G:\Program Files\Windows

Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [QuickTime Task] "G:\Program Files\QuickTime\qttask.exe"

-atboottime
O4 - HKLM\..\Run: [ISUSPM Startup]

G:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] G:\Program

Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] G:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]

"G:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [PowerBar] "G:\Program Files\CyberLink DVD

Solution\Multimedia Launcher\PowerBar.exe" /AtBootTime
O4 - HKCU\..\Run: [H/PC Connection Agent] "G:\Program Files\Microsoft

ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [PlaxoUpdate] G:\Program

Files\Plaxo\2.10.0.30\PlaxoHelper.exe -a
O4 - HKCU\..\Run: [AnyDVD] G:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - Startup: Pervasive.SQL Workgroup Engine.lnk = G:\PVSW\Bin\w3dbsmgr.exe
O4 - Startup: UltimateZip Quick Start.lnk = G:\Program

Files\UltimateZip\uzqkst.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: NkvMon.exe.lnk = G:\Program

Files\Nikon\NkView6\NkvMon.exe
O4 - Global Startup: Norton GoBack.lnk = G:\Program Files\Norton

SystemWorks\Norton GoBack\GBTray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Download with &DAP - G:\Program

Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - G:\Program

Files\DAP\dapextie2.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

G:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program

Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite -

{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - G:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} -

G:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... -

{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - G:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} -

G:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra 'Tools' menuitem: Express Cleanup -

{5E638779-1818-4754-A595-EF1C63B87A56} - G:\Program Files\Norton

SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} -

G:\PROGRA~1\DAP\DAP.EXE
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} -

%windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 -

{85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file

missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -

G:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} -

G:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite -

{B863453A-26C3-4e1f-A54D-A2CD196348E9} - G:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F}

- G:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 -

{CCA281CA-C863-46ef-9331-5C8D4460577F} - G:\Program Files\WIDCOMM\Bluetooth

Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} -

%windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 -

{e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network

Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

G:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program

Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage

Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {08BEF711-06DA-48B2-9534-802ECAA2E4F9} (PlxInstall Class) -

https://www.plaxo.com/down/latest/PlaxoInstall.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage

Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) -

https://www-secure.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan

Agent 6.5) -

http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/acti

vex/hcImpl.cab
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) -

http://a516.g.akamai.net/f/516/25175/7d/runaware.download.akamai.com/25175/ci

trix/wficat-no-eula.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} -

http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) -

http://www.cult3d.com/download/cult.cab
O16 - DPF: {40BF816B-D862-41B9-9445-ECA36D5F67F9} (Flatcast Viewer 4.12) -

http://data.flatcast.com/NpFv412.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -

http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (CwlscInstall Object) -

https://scan.safety.live.com/resource/download/scanner/en-us/wlscbase2213.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility

Class) -

http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6C6E003B-9B8C-4CE9-A1D5-A8E3AF0D651A} (Napco Internet Video

Viewer) - http://www.videoalert.net/veCamitX.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -

http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb

_site.cab?1133627250859
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) -

http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer

Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} (WTHoster Class) -

http://install.wildtangent.com/bgn/partners/wildgames/stx/install.cab
O16 - DPF: {ADACAA8F-3595-47FE-9C31-9C7471B9BEC7} (OCXDownloadChecker

Control) - http://geovision.dipmap.com/cab/OCXChecker_8000.cab
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} (Office Update Installation

Engine) - http://officebeta.iponet.net/officeupdate/content/opuc3.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) -

https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {DBAFE6AD-DC14-45DF-A3F7-F8832289A1CD} (DownloadFile Control) -

http://webcam.geovision.com.tw/cab/DownloadFile_8000.cab
O16 - DPF: {E991BDE0-9816-4094-853E-6BDB60F0342D} (Get_ActiveX Control) -

http://apps.corel.com/nos_dl_manager/plugin/IENetOpPlugin.ocx
O16 - DPF: {F6676623-8BBD-479C-A51B-05868728708C} (DigitalDM) -

http://www.digitaldm.com/Plug-in/myebk/c/DIGITALDM2.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} -

G:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} -

G:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - (no file)
O20 - Winlogon Notify: WgaLogon - G:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation -

G:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - G:\Program

Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation -

G:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation -

G:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation -

G:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision

Corporation - G:\Program Files\Common Files\InstallShield\Driver\1050\Intel

32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - G:\Program Files\Nero\Nero

7\InCD\InCDsrv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service

(LightScribeService) - Hewlett-Packard Company - G:\Program Files\Common

Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation -

G:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~2.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec

Corporation - G:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NBService - Nero AG - G:\Program Files\Nero\Nero 7\Nero

BackItUp\NBService.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) -

Symantec Corporation - G:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton UnErase Protection (NProtectService) - Symantec

Corporation - G:\PROGRA~1\NORTON~2\NORTON~2\NPROTECT.EXE
O23 - Service: Norton Protection Center Service (NSCService) - Symantec

Corporation - G:\Program Files\Common Files\Symantec Shared\Security

Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -

G:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - G:\Program

Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec

Corporation - G:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - G:\Program Files\Common

Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation -

G:\PROGRA~1\NORTON~2\NORTON~2\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - G:\Program

Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: UPSMONService - Unknown owner - G:\Program

Files\UPSMON\UPSMON_Service.Exe (file missing)
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC

Austria AG. - G:\WINDOWS\system32\UAService7.exe

old_dude
2006-09-22, 22:19
Is it correct, what I have done, sending this huge text file in a reply ?:oops:

LonnyRJones
2006-09-22, 23:21
Thats fine but for the next logs be sure the formating doesnt get messed up. in notepad turning off than back on wordwrap usualy helps.

What do you see at that webpage ? hxxp://xn--3zo1864a/
and how long has the problem existed ?

Download and run Silentrunners.Vbs post the log it creates please
http://www.silentrunners.org/sr_scriptuse.html click no to not skip the suplimentry searchs
Wait until there is a All Done message !!, Then open and post the log next to it.
Your antivirus script protection might interfear or alert, please allow it to run after a bit box will say done.

Post a combofix log
1. Download this file - combofix.exe
http://download.bleepingcomputer.com/sUBs/combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
If the log is large You might need to post half in one reply half in another.

old_dude
2006-09-23, 08:28
Okay will turn off word wrap, this problem has been around for 6 to 8 weeks, when the page loads it gives a message that internet explorer cannot display the web page.

Will download the files and run them, I will post the results.

old_dude
2006-09-23, 08:46
Startup Programs (TECHNICAL) 2006-09-23 08.28.51.txt:
Your file of 68.8 KB bytes exceeds the forum's limit of 19.5 KB for this filetype. what now

LonnyRJones
2006-09-23, 08:56
You could send silent runner log to me
Send it to submitlonnyATsubratam.org
Replace AT with @ , then include a link back to this thread.
Or you could attach it here http://www.thespykiller.co.uk/forum/index.php?board=1.0

old_dude
2006-09-23, 09:07
I have split the file into four parts, I hope this is okay

old_dude
2006-09-23, 09:09
hope this is done okay, will wait for your next reply, thanks for the help so far

LonnyRJones
2006-09-23, 09:43
Thats fine, thanks.

Im not seeing anything yet, Download "Registry Search Tool" (RegSrch.vbs) from here
http://www.billsway.com/vbspage/
start it and paste in

xn--3zo1864a

hit ok, wait, then when wordpad opens copy that back here please
Note: Your antivirus script protection might interfear, its safe, please allow it to run.

old_dude
2006-09-24, 00:10
I ran the registry search program with the string xn--3zo1864a
it returned a message "no instance of xn--3zo1864a found in registry.

I am going to download the latest beta copy of IE 7 from Microsoft and do a reinstall, will let you know what happens.

old_dude
2006-09-24, 02:38
downloaded new version of IE 7 from Microsoft, this has cured the problem I was having.

Many thanks for your assistance

LonnyRJones
2006-09-24, 03:52
Thats good to here, thanks for posting to let us know.

tashi
2006-10-01, 04:12
As the problem appears to be resolved this topic has been archived. :)

If you need it re-opened please send me or your helper a private message (pm) and provide a link to the thread; this applies only to the original topic starter.