I am having problems opening up internet explorer I click on the icon and about 5 minutes later I get them to open up, If I click it 10X then 10 of them will open 5 minutes later. I am also having pop-ups etc. I have run Ad-aware 6.1 and spybot search and destroy. S&D finds nothing and ad-aware finds a few things that I erase and then I will run it again later and there are more maybe the same ones? Here is a highjack this log Please Help I have no Idea Thanks Ryun


Logfile of HijackThis v1.99.1
Scan saved at 11:28:34 AM, on 7/28/2005
Platform: Windows 2000 SP3 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\hkcmd.exe
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
C:\PROGRA~1\Ahead\NEROPH~2\data\xtras\mssysmgr.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\PROGRA~1\WINZIP\wzqkpick.exe
C:\Program Files\aeic\wcme.exe
C:\WINNT\system32\r?ndll.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Yahoo!\YOP\yop.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null) ww1.www.rbsdigital.com
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null) www.miwebbusbank.ebanking-services.com
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null) www.bvi.bancodevalencia.es
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null) ww2.dresdner-privat.de
O1 - Hosts: (null)
O1 - Hosts: (null) ww.hsh-nordbank.de
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll
O2 - BHO: HPOVASMD.BrowserSensor - {04047354-D353-11D2-B3EB-0060B03C5581} - C:\WINNT\Downloaded Program Files\hpBrSn24.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Msxml32DOMDocument Class - {6E28339B-7A2A-47B6-AEB2-46BA53782379} - C:\WINNT\System32\dllcache\msxml32.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\NEROPH~2\data\xtras\mssysmgr.exe
O4 - HKCU\..\Run: [Crtp] C:\Program Files\aeic\wcme.exe
O4 - HKCU\..\Run: [Kaiw] C:\WINNT\System32\r?ndll.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O16 - DPF: {04047354-D353-11D2-B3EB-0060B03C5581} (HPOVASMD.BrowserSensor) - https://dealerconnect.chrysler.com/wto/plugin/hpBrSn.cab
O16 - DPF: {4EC8E993-32C1-47F5-A07A-5B0574655AD4} (WXcom Class) -
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) -
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.
O16 - DPF: {E70E3E64-2793-4AEF-8CC8-F1606BE563B0} (WWSpades Control) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{E46192D8-0F5A-43EE-9223-F58BE7AEE625}: NameServer =
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe

Dani AI

Generated

Good start by and a useful tip from about scanning in Safe Mode. The HijackThis output points to two clear red flags: persistent autorun(s) from System32 and extensive hosts-file redirects to banking sites. Those two together explain the long delays when opening Internet Explorer, the flood of pop-ups, and why removals keep reappearing.

Immediate priorities are containment and evidence preservation. The infected PC should be taken off the network and not used for any online banking or password changes. From a separate clean computer, obtain up-to-date removal tools and rescue media; then use Safe Mode (or a bootable rescue ISO) to run a current anti-malware scan plus a rootkit scanner. Persistent or returning items usually mean a running component, a protected restore point, or a rootkit that requires offline removal.

Practical manual steps that often succeed where one-shot scanners do not:

  • Backup the hosts file and any logs first (hosts path on Win2000: C:\WINNT\system32\drivers\etc\hosts; on XP: C:\Windows\System32\drivers\etc\hosts). Clear attributes if needed before editing.
  • Minimal hosts file example to restore (replace the existing file with this after backing it up):
# Default hosts file
127.0.0.1 localhost
  • Use a startup/autorun utility (msconfig or Sysinternals Autoruns) to find and disable unknown HKCU/HKLM Run entries, then locate the associated executables on disk (especially anything in System32 with odd names) and quarantine them. Do not use HijackThis’s “fix checked” blindly; research entries before removal.

Aftercare: assume credentials may be compromised — change passwords only from a clean machine and monitor accounts. If rootkit activity or multiple protected components are found, a clean OS reinstall is the safest long-term fix, especially on older, unsupported systems.

I hope you have a couple of anti virus programs. If not get avg and avast and do a scan in safe mode. I assume you have xp. Hit f8 while boot up. Scan with both anti viurs and spyware. You may even want to get microsofts anti spyware. Its pretty cool and free. Spyware blaster is also a good one. Just run spyware scans and virus scans in safe mode. See if that dosent help......

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.