IE won't open
-
IE won't open
Ever time i open IE i get a error saying that it can not open and there is a check box checked saying ot close and restart. It also has send error report and don't send error report. if i keep the box checked it will keep looping around and closing IE. I can move the box however and go to different web pages. I ran trend virus scan, ad-aware, spybot and microsoft anti-spyware and it is still doing the same thing after i restart. i unchecked several processes in msconfig and i still have this same problem. here is a post of hijack this: can someone please help.
Logfile of HijackThis v1.99.0
Scan saved at 10:52:42 AM, on 3/1/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\OfficeScan NT\ntrtscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\OfficeScan NT\tmlisten.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\OfficeScan NT\ofcdog.exe
C:\OfficeScan NT\PCCNTMON.EXE
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINNT\system32\mdm.exe
C:\Program Files\WinZip\WINZIP32.EXE
C:\Documents and Settings\cross\Local Settings\Temp\HijackThis.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R3 - Default URLSearchHook is missing
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 6\SnagItBHO.dll
O2 - BHO: (no name) - {1AD9B015-796B-7BFF-CF21-38B9F5FA7671} - C:\WINNT\system32\bvbphjeq.dll
O2 - BHO: (no name) - {427F2B06-069D-7E51-6CC4-53E61F4BF0CF} - C:\WINNT\system32\etizeeha.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {588A4A0C-64E0-019C-6F0B-306C2EE3030C} - C:\WINNT\system32\ixkaocll.dll (file missing)
O2 - BHO: (no name) - {F6475C27-A36C-158F-846E-C0AFAF8BD9A4} - C:\WINNT\system32\tcnwuypv.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\OfficeScan NT\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v1...ro.cab34246.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/dim2/de...aploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain =
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain =
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain =
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: OfficeScanNT RealTime Scan - Trend Micro Inc. - C:\OfficeScan NT\ntrtscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12. exe
O23 - Service: OfficeScanNT Listener - Unknown - C:\OfficeScan NT\tmlisten.exe
-
could you please update your version of hijack this to 1.99.1 and then posta fresh hijack this log
thanks
-
ok i will, but i did find out how to solve my problem. I will post it for anyone else that has this same problem/virus.
Go into the command prompt, and navigate to the system32 folder.
Then type [hitting Enter after each line]:
"regsvr32 /u bvbphjeq.dll"
"regsvr32 /u etizeeha.dll"
"regsvr32 /u ixkaocll.dll"
"regsvr32 /u tcnwuypv.dll"
"del bvbphjeq.dll"
"del etizeeha.dll"
"del ixkaocll.dll"
"del tcnwuypv.dll"
Then Run Hijackthis, and fix the following:
O2 - BHO: (no name) - {1AD9B015-796B-7BFF-CF21-38B9F5FA7671} - C:\WINNT\system32\bvbphjeq.dll
O2 - BHO: (no name) - {427F2B06-069D-7E51-6CC4-53E61F4BF0CF} - C:\WINNT\system32\etizeeha.dll
O2 - BHO: (no name) - {588A4A0C-64E0-019C-6F0B-306C2EE3030C} - C:\WINNT\system32\ixkaocll.dll (file missing)
O2 - BHO: (no name) - {F6475C27-A36C-158F-846E-C0AFAF8BD9A4} - C:\WINNT\system32\tcnwuypv.dll
-
You don't really need to use regsvr32, Hijack This does this for you when you check the entries and click Fix Checked.