Custom Search
Join the PC homebuilding revolution! Read the all-new, FREE 200-page online guide: How to Build Your Own PC!
NOTE: Using robot software to mass-download the site degrades the server and is prohibited. See here for more.
Find The PC Guide helpful? Please consider a donation to The PC Guide Tip Jar. Visa/MC/Paypal accepted.
Results 1 to 10 of 10

Thread: IE problem

  1. #1

    IE problem

    my friend got the rootkit virus recently
    it has been deleted
    but whenever he opens IE it says The page you are looking for is currently unavailable. The Web site might be experiencing technical difficulties, or you may need to adjust your browser settings etc etc

    any idea what happens and any solution

  2. #2
    Join Date
    Aug 2001
    Location
    Land of 10,000 Lakes and Minnesota nice!!
    Posts
    11,070
    Is this particular page accessible through your computer? Does this happen with any page typed into the URL box?

    There may be other junk on your friends computer. If the problem exists only with the "home page" in IE and your friend can get on-line, I would suggest an on-line virus scan.

    http://housecall.trendmicro.com/

    Please let us know what it finds.
    Lighten up! --- A merry heart does good like a medicine. (Proverbs 17:22)

  3. #3
    I've had this happen to me before.
    If it is the same problem as mine, you could try Winsock XP Fix.
    it often clears up those kind of problems. has to do with your winsock registry stuff being deleted/broken by virus/spyware removal, I think.

  4. #4
    Join Date
    Jul 2001
    Location
    Wyncote, PA, USA
    Posts
    10,255
    PCWIZ:

    Never link to a program that can chnage the registry and then end with I think.

    That's a recipe for disaster and go do more harm than good.

    First let;s download a copy of Hijack This. Unzip it into a permanent folder. Scan and create a log.

    Post the contents of the log here for review by one of the malware experts.

    Once we have the HJT log we can determine the problem.
    No two moments are alike and a person who thinks that any two moments are alike has never lived.

    A.J. Heschel

  5. #5

    hijack log

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Norton AntiVirus\SAVScan.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\System32\rundll32.exe
    C:\WINDOWS\System32\NotifyPhoneBook.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\WINDOWS\System32\abtqrrsm.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Common Files\Symantec Shared\NMain.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\PROGRA~1\NORTON~1\navw32.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe
    C:\Documents and Settings\Jianny\My Documents\My Received Files\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = fol.singnet.com.sg:8080
    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1001\en-xu\stmain.dll
    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
    O4 - HKLM\..\Run: [AME_CSA] rundll32 amecsa.cpl,RUN_DLL
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Microsoftt rtt r mSAs Service] abtqrrsm.exe
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
    O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe"
    O4 - HKLM\..\RunServices: [Microsoftt rtt r mSAs Service] abtqrrsm.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Microsoftt rtt r mSAs Service] abtqrrsm.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pu...sh/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{4BBBF861-BC52-4518-8C6D-038AFDC0CBB6}: NameServer = 165.21.83.88 165.21.100.88
    O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
    O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

  6. #6

    sasser

    was told there's a sasser worm installed
    where can i download the removal tool??

  7. #7
    Join Date
    Feb 2002
    Location
    Somerset, England
    Posts
    2,762
    No sign of the Sasser worm in your log. There are things that should be fixed.

    Have Hijack This fix all of the following by placing a check in the appropriate boxes and hitting fix checked. Make sure all browser and all Windows Explorer windows are closed before fixing.

    O4 - HKLM\..\Run: [Microsoftt rtt r mSAs Service] abtqrrsm.exe
    O4 - HKLM\..\RunServices: [Microsoftt rtt r mSAs Service] abtqrrsm.exe
    O4 - HKCU\..\Run: [Microsoftt rtt r mSAs Service] abtqrrsm.exe

    Reboot and delete the file abtqrrsm.exe

    These may be hidden files. See HERE for how to show hidden files.

    Please post a followup Hijack this log, and say if your problems persist.
    be wary of strong drink - it may make you shoot at tax collectors, and miss!

  8. #8
    Join Date
    Jul 2001
    Location
    Wyncote, PA, USA
    Posts
    10,255
    When you re-post your log, please post the entire log, including the very top...
    No two moments are alike and a person who thinks that any two moments are alike has never lived.

    A.J. Heschel

  9. #9
    i have a problem with my IE virtually it is not responding. i am a beginner in troubleshooting i have tried running setup but the problem still persists. please assist me

  10. #10
    Join Date
    Feb 2002
    Location
    Somerset, England
    Posts
    2,762
    mwongela, please start your own topic. when doing so, please give as much information about the problem as you can. What version of Windows, and anything else that may be relevant.
    be wary of strong drink - it may make you shoot at tax collectors, and miss!

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •