Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
After clicking a window in Internet Explorer or an email link nothing occurs after you click a link the page shows nothing and just keeps loading...I have scaned on line as well as used adaware and spy sweeper its just happened with in the last couple days. I have also noticed something eating up my system when I go on line is worse when I use Yahoo and msn messagers. and it keeps freezing me up.

Have you downloaded Spybot Search and Destroy? If not, get it here. http://www.safer-networking.org/en/mirrors/index.html
Update your antivirus program, Adaware, and Spybot. Boot into safe mode and scan using them. Delete anything found.
Do you also see any strange looking programs running?

I dont have a antivirus program on my PC I am sick and tired of always having to re install window everytime it desides to delet my DLL file because it thinks its a virus. I do daily online virus checks as well as a daily deletion of my temp internet files I thine to a spy sweeper scan......and I haven't had a problem for over 8 months now all of a sudden I have this problem.

And for some stupid reason spybot wont work on my system I keep getting an error everytime I download it.

What DLL file do antivirus programs detect?
I recommend downloading the trial version of NOD32, an antivirus program, at nod32.com for the time. NOD32 doesn't delete/clean any files without your permission, unless you configure it to.
Also, what error do you get when downloading spybot?

Ok error this time is
exception ERead error in modul PYYBOTSD.exe bei 00021E87 Ferhler beim lesen von ilGlobal16.Bitmap: lmageList-Daten konnten nicht aus dem Stream gelesen werden
I have no clue it hasn't work fro ahwile now.
The DLL file that allows you to do everything with explorer..it oviously hasn't happened to you...your lucky....LOL

Are you talking about rundll32.exe? It's uncommon for AVs to detect legitimate system files as viruses, unless the file has been altered, the file it's detecting is actually a virus/trojan/etc designed to look like the file.
For your Spybot error message, I recommend getting help at http://forums.net-integration.net/ .
Also, have you tried using CWShredder? You download it here. http://www.majorgeeks.com/download4086.html

Sorry that I'm not being helpful, but there's one last thing I'll try. If you haven't, download Hijackthis at http://www.majorgeeks.com/download.php?det=3155 , and run it. Save your log, and post your log here. I'll take a look at it, and see if there's anything suspicious in there.

Try this fix from M$, it addresses that issue with IE.
____________________________
The greatest risk is not taking one

Ok I already have hijack I will post it here and I will look into sabertooths idea just thought I would let ya know Must be something wrong with just explorer because I am using crazy browzer now and links are working fine........I have looked into win updates and even looked on IE site and the help they gave didnt help.
Here is the HiJack
Logfile of HijackThis v1.97.7
Scan saved at 10:36:14 PM, on 7/25/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.exe
C:\WINDOWS\SYSTEM\MPREXE.exe
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.exe
C:\OFFICE51\SOINTGR.exe
C:\PROGRAM FILES\ESET\NOD32KRN.exe
C:\WINDOWS\EXPLORER.exe
C:\WINDOWS\TASKMON.exe
C:\WINDOWS\SYSTEM\SYSTRAY.exe
C:\PROGRAM FILES\EASY KEYBOARD\EASYKEY.exe
C:\WINDOWS\SYSTEM\LVCOMS.exe
C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.exe
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.exe
C:\WINDOWS\SYSTEM\TAPISRV.exe
C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\TEATIMER.exe
C:\PROGRAM FILES\INTERNET CALL DIRECTOR\ICD.exe
C:\PROGRAM FILES\COREL\WORDPERFECT OFFICE 2000\PROGRAMS\ALARM.exe
C:\PROGRAM FILES\WINZIP\WZQKPICK.exe
C:\PROGRAM FILES\COREL\WORDPERFECT OFFICE 2000\REGISTER\REMIND32.exe
C:\WINDOWS\SYSTEM\WMIEXE.exe
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.exe
C:\PROGRAM FILES\SMARTPOPUPBLOCKER\SMARTPOPUPBLOCKERTRAY.exe
C:\WINDOWS\SYSTEM\DDHELP.exe
C:\WINDOWS\SYSTEM\RNAAPP.exe
C:\WINDOWS\SYSTEM\PSTORES.exe
C:\PROGRAM FILES\CRAZY BROWSER\CRAZY BROWSER.exe
C:\WINDOWS\SYSTEM\SPOOL32.exe
C:\WINDOWS\DESKTOP\ALL FOLDERS\KEEPERS\HIJACKTHIS.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neopets.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neopets.com
R3 - Default URLSearchHook is missing
F1 - win.ini: run=hpfsched
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O2 - BHO: (no name) - {9527D42F-D666-11D3-B8DD-00600838CD5F} - C:\WINDOWS\SYSTEM\IETie.dll
O2 - BHO: (no name) - {0D929918-C804-4756-B0AC-640EF3F061E9} - C:\PROGRAM FILES\SMARTPOPUPBLOCKER\POPUPBLOCKERBHO.DLL
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_12_0.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_12_0.DLL
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN TOOLBAR\01.01.1721.0\EN-CA\MSNTB.DLL
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [AtiCwd32] Aticwd32.exe
O4 - HKLM\..\Run: [AtiKey] Atitask.exe
O4 - HKLM\..\Run: [SoundFusion] RunDll32 cwcprops.cpl,CrystalControlWnd
O4 - HKLM\..\Run: [SO5 Integrator Pass Two] C:\OFFICE51\SOINTGR.exe
O4 - HKLM\..\Run: [Easykey] C:\Program Files\Easy Keyboard\Easykey.exe
O4 - HKLM\..\Run: [LVComs] c:\windows\SYSTEM\LVComS.exe
O4 - HKLM\..\Run: [CriticalUpdate] c:\windows\SYSTEM\wucrtupd.exe -startup
O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [ynirmz] C:\WINDOWS\ynirmz.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SO5 Integrator Pass One] C:\OFFICE51\SOINTGR.exe
O4 - HKLM\..\RunServices: [NOD32kernel] "C:\Program Files\Eset\nod32krn.exe"
O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
O4 - HKCU\..\Run: [MouseAround] C:\PROGRAM FILES\MOUSEAROUND\MOUSEAROUND.exe /AUTOSTART
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Startup: Event Reminder.lnk = C:\Program Files\Broderbund\PrintMaster\PMREMIND.exe
O4 - Startup: Internet Call Director.LNK = C:\Program Files\Internet Call Director\ICD.exe
O4 - Startup: CorelCENTRAL Alarms.LNK = C:\Program Files\Corel\WordPerfect Office 2000\programs\alarm.exe
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.exe
O4 - Startup: Corel Registration.lnk = C:\Program Files\Corel\WordPerfect Office 2000\Register\Remind32.exe
O8 - Extra context menu item: Download using FlashGet - C:\PROGRAM FILES\FLASHGET\jc_link.htm
O8 - Extra context menu item: Download All by FlashGet - C:\PROGRAM FILES\FLASHGET\jc_all.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O10 - Broken Internet access because of LSP provider 'imon.dll' missing
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?38096.1592476852
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {787EC372-D8AA-40F2-83D3-4BAA20B9A380} (ChainCast VMR Client Proxy) - http://66.250.188.85/cc-production/ccpm_0257.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/1,5,0,4362/mcfscan.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {4F5E4276-C120-11D6-A1FD-00508B9D48EA} (dldisplay Class) - http://www.gamehouse.com/ghdlctl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {AB9820A0-02A9-11D5-A72F-004F4E002BD6} (JFC Classes) - http://igweb04.iamgame.com/java2/cabs/swing.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/autocomplete.cab
O16 - DPF: {9BFC2253-B9D9-477E-9488-CA450232620D} (BinAg1 Class) - https://merlin.telus.net/wizlet/Qualifier/static/controls/WebflowActiveX.CAB

Thanks Sabertooth that was the first thing I did looks like I am going to have to reinstall explore 6 I will wait see what the Hijack has to tell but I think a download is what is needed.
I do thank you Laura for all your help. :O)
Georgina

I already see things to get rid of in your log, but before you touch it, move HijackThis into a permanent folder. Say, you could create a folder in the C:\ and name it hjt. Then, move your HijackThis in your desktop into the hjt folder you made in C:\(make sure that your HijackThis located in C:\hjt\ isn't a shortcut to your desktop one).
It's rather late here, so I'll try to get back to you tomorrow, if nobody else has responded.

hi georgina,
try this:
I assume you have the latest defs from nod32, ok;
download the program APM from this website:
go to the diamond website at this location:http://www.diamondcs.com.au/index.php?page=products, and download this:
APM,
when downloaded, reboot your computer to safe mode, and scan with your anti-virus, you may have the frethem worm, also scan with spybot and adaware if you have them delete all files they come up with.
clean out your cache, temp files, history and cookies folders and clean your recycle bin.
next open up hijackthis.
put a check next to this entry, make sure you don't have anything running, and no windows open:
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {9527D42F-D666-11D3-B8DD-00600838CD5F} - C:\WINDOWS\SYSTEM\IETie.dll
O4 - HKLM\..\Run: [ynirmz] C:\WINDOWS\ynirmz.exe
O8 - Extra context menu item: Download All by FlashGet - C:\PROGRAM FILES\FLASHGET\jc_all.htm
O10 - Broken Internet access because of LSP provider 'imon.dll' missing
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {4F5E4276-C120-11D6-A1FD-00508B9D48EA} (dldisplay Class) - http://www.gamehouse.com/ghdlctl.cab
O16 - DPF: {AB9820A0-02A9-11D5-A72F-004F4E002BD6} (JFC Classes) - http://igweb04.iamgame.com/java2/cabs/swing.cabnext open up APM and unload the ietie.dll from the process list and also if you find it crazy browser.exe
reboot into regular mode and find these files and or folders in your windows and or system directory:
CRAZY BROWSER.exe
ietie.dll
the whole folder C:\PROGRAM FILES\FLASHGET\jc_all.htmall the best,
murve

Ok I downloaded the APM and when I go to run the program it get this program as preformed an illegal operation and will be shut down.
Nothing is working...HHHHEELLPPPPP....LOL....I have also tried to reinstall IE6 but it wont let me what up.
Georgina

hi georgina,
assuming you did the hijackthis process and got rid of those entries, let's try this:
in safe mode hit your control alt delete buttons, this will open up your task list, delete from your task list these files:
ietie.dll and crazybrowser.exe if found.
still in safe mode do a search for these files and folders and delete them from your windows and or system directory:
CRAZY BROWSER.exe
ietie.dll
the whole folder C:\PROGRAM FILES\FLASHGET\jc_all.htm
You should also consider having a process monitor on your computer so go to www.thepublicworks.com security section, and link to System Internals and download free Process Explorer, with that you will be able to see all process on your machine and delete unwanted processes.
all the best,
murve

![]() |
iTunes and Viewpoint Mana...
|
cws.searchx hijack... aga...
|

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |