Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: I need help... CAnt get on web unless in safe mode  (Read 2748 times)

0 Members and 1 Guest are viewing this topic.

mikemillinator

  • Guest
I need help... CAnt get on web unless in safe mode
« on: February 08, 2007, 01:56:53 AM »
So I was being stupid trying to download a crack and My comp picked up 9 trojans!!!! ofcourse it quarantined them right away. Being new to all of this. I just went about my business and was like oh I deleted them. It will be fine. So I try to get on the internet and I can't!!! *censored*. So I mess with the thing for like 6 hours straight and discover a little piece of *censored* called "ctpmon.exe" Some of you may have heard of this or not, but it is a *censored* spyware that puts a little red x at the bottom of the screen and says you need to download an update. Well I'm new but not stupid. So I went into msconfig disabled it and found the file and deleted it. For some reason it is still in msconfig but anyways... On to the real problem... I have no idea why but I cannot get on the internet unless i boot up in safe mode.... I am very concerned but my virus protection picks up nothing and I'm startin' to freak the *censored* out. This is a brand new laptop and I'm gonna be pissed if it craps out on me. So anybody that can tell me anything would be awesome. I've checked the connection.. That's not the problem. It definately starts to download the homepage and then immediately comes up and says that it cannot be displayed. Trend micro pc-cillin picks up nothing. PLEASSEEE HELP!!!!

mikemillinator

  • Guest
Re: I need help... CAnt get on web unless in safe
« Reply #1 on: February 08, 2007, 02:43:34 AM »
forgot to say that my operating system is windows xp home edition

GX1_Man

  • Guest
Re: I need help... CAnt get on web unless in safe
« Reply #2 on: February 08, 2007, 03:37:08 AM »
And what have you tried BESIDES PC Cillin?

Have you had a thorough read here?

http://www.computerhope.com/cgi-bin/yabb/YaBB.cgi?num=1149948530

patio

  • Moderator


  • Genius
  • Maud' Dib
  • Thanked: 1769
    • Yes
  • Experience: Beginner
  • OS: Windows 7
Re: I need help... CAnt get on web unless in safe
« Reply #3 on: February 08, 2007, 04:39:11 AM »
DLoad and run the tool Here in Safe Mode with Sysstem Restore turned off.
Choose option #2 from the main menu.
After doing this you need to DLoad and run Hijack This and post a log here.

And then and most important stay off the warez sites...

patio.   8-)
" Anyone who goes to a psychiatrist should have his head examined. "

mikemillinator

  • Guest
Re: I need help... CAnt get on web unless in safe
« Reply #4 on: February 08, 2007, 02:38:28 PM »
ok. So I downloaded avg's free anti virus software. Ran it... Found nothing. I forgot to mention that I have spybot search and destroy and I also have windows defender. Patio whatever was linked to "here" would not open up. But i did dl hijack this ran it and here is the log......

Logfile of HijackThis v1.99.1
Scan saved at 3:32:15 PM, on 2/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX02.610\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=1061125
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=1061125
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {36DBC179-A19F-48F2-B16A-6A3E19B42A87} - C:\WINDOWS\system32\ipv6monl.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: SQLAgent$MICROSOFTSMLBIZ - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlagent.EXE" -i MICROSOFTSMLBIZ (file missing)
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend M

mikemillinator

  • Guest
Re: I need help... CAnt get on web unless in safe
« Reply #5 on: February 08, 2007, 02:40:49 PM »
icro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE (file missing)


patio

  • Moderator


  • Genius
  • Maud' Dib
  • Thanked: 1769
    • Yes
  • Experience: Beginner
  • OS: Windows 7
Re: I need help... CAnt get on web unless in safe
« Reply #6 on: February 08, 2007, 03:35:37 PM »
Quote
Patio whatever was linked to "here" would not open up.

You have to wait about 15 seconds...First screen says hit any key to continue...2nd screen choose Option #2 as i mentioned.

Remember to run it in Safemode.

This is the tool to remove what you have.

patio.  8-)
" Anyone who goes to a psychiatrist should have his head examined. "

mikemillinator

  • Guest
Re: I need help... CAnt get on web unless in safe
« Reply #7 on: February 08, 2007, 03:38:47 PM »
I apoligize.. what I meant was that it wouldn't display the webpage. The computer will not let me access Bleepingcomputer.com... For one reason or another.. Keep in mind that for some reason I can only access the internet in safe mode.. Thank you so much for your help.

patio

  • Moderator


  • Genius
  • Maud' Dib
  • Thanked: 1769
    • Yes
  • Experience: Beginner
  • OS: Windows 7
Re: I need help... CAnt get on web unless in safe
« Reply #8 on: February 08, 2007, 04:10:11 PM »
Are you able to log on here on that machine or are you on another ? ?
If so send me a PM...
Or try that site again after re-booting into safe mode with networking...
« Last Edit: February 08, 2007, 04:11:15 PM by patio »
" Anyone who goes to a psychiatrist should have his head examined. "

mikemillinator

  • Guest
Re: I need help... CAnt get on web unless in safe
« Reply #9 on: February 09, 2007, 01:53:33 AM »
ok.... Weirdest thing EVER. So I disable my old virus protection and just leave the avg running, and now everything is working fine in regular bootup. I think that maybe there was an error in my pc-cillin or something that was causing me to not be able to access the web... I'm still weirded out though.