Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Internet Explorer Not Finding Web Pages - Hijack This Log  (Read 3766 times)

0 Members and 1 Guest are viewing this topic.

nestor

    Topic Starter


    Greenhorn

    Internet Explorer Not Finding Web Pages - Hijack This Log
    « on: March 24, 2009, 01:42:57 PM »

    This problem is on my work computer - and my managers - and recently on my home computer. 

    IE 7.0.5730.11 on Windows XP, Professional - 2002 - SP3

    IE only works when it wants too.  I have been researching the problem all over the internet and have found a ton of people describing the same problem.  I have tried many of the suggested solutions and nothing has worked. 

    Problem:
    Sometimes IE works the way it is supposed to.  Sometimes it brings up the white screen that says: Internet Explorer cannot find the web page...and suggests reasons for the problems.  Sometimes, I can type in a perfectly good address like: www.ups.com and instead of finding the page, or giving me an error, it takes me to Yahoo (my work computer), AOL Search Engine (my home computer), or AIM Search (my managers computer).  That search engine inputs the website I typed in into its search and will find the exact website.  When I click on the search engines link to the page, it sometimes will go to the page, sometimes not.  Sometimes closing and reopening the browser window and trying again will fix it - sometimes not.  Sometimes, refreshing the screen 15 times will do it.
    Tried Firefox - same thing happens.
    Tried SuperAntiSpyware - doesnt help - only found cookies
    Tried Malwarebytes Anti Malware - doesnt help
    Tried deleting temp files, cookies - all that in Tools - Options on IE - didnt help
    Ran Trend Micro Security Agent - didnt help.
    Ran some other virus search my boss gave me - didnt work.


    I really think its a virus or something.  Like I said - found a ton of blogs online with the same problem - but no one seems to have the answer.

    PLEASE HELP

    Please also see my thread : http://www.computerhope.com/forum/index.php/topic,79298.0.html


    Here is the Hijack This Log:



    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 9:14:10 AM, on 3/24/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16791)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\FileGuard.exe
    C:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\UPS\WSTD\MSSQL$UPSWSDBSERVER\Binn\sqlservr.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Trend Micro\Client Server Security Agent\ntrtscan.exe
    C:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe
    C:\Program Files\Trend Micro\Client Server Security Agent\TmPfw.exe
    C:\Program Files\Trend Micro\Client Server Security Agent\CNTAoSMgr.exe
    C:\Program Files\Trend Micro\Client Server Security Agent\TmProxy.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe
    C:\Program Files\AIM6\aim6.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\PROGRA~1\MAILFR~1\mantispm.exe
    C:\Program Files\RocketDock\RocketDock.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
    C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
    C:\UPS\WSTD\WSTDMessaging.exe
    C:\WINDOWS\system32\MDM.EXE
    C:\Program Files\AIM6\aolsoftware.exe
    C:\Program Files\Intuit\QuickBooks Enterprise Solutions 5.0\qbw32.exe
    C:\Program Files\Common Files\Intuit\QuickBooks\axlbridge.exe
    C:\Program Files\Microsoft Office\Office\OUTLOOK.EXE
    C:\Program Files\Common Files\System\MAPI\1033\nt\MAPISP32.EXE
    C:\UPS\WSTD\WorldShipTD.exe
    C:\UPS\WSTD\upslnkmg.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [NA1Messenger] C:\UPS\WSTD\UPSNA1Msgr.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe" -HideWindow
    O4 - HKLM\..\Run: [OE] C:\Program Files\Trend Micro\Client Server Security Agent\TMAS_OE\TMAS_OEMon.exe
    O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Matador] "C:\PROGRA~1\MAILFR~1\mantispm.exe" -quiet
    O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
    O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-21-789336058-606747145-839522115-1203\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User '?')
    O4 - HKUS\S-1-5-21-789336058-606747145-839522115-1203\..\Run: [Matador] "C:\PROGRA~1\MAILFR~1\mantispm.exe" -quiet (User '?')
    O4 - HKUS\S-1-5-21-789336058-606747145-839522115-1213\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl (User '?')
    O4 - HKUS\S-1-5-21-789336058-606747145-839522115-1251\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl (User '?')
    O4 - HKUS\S-1-5-21-789336058-606747145-839522115-1255\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl (User '?')
    O4 - HKUS\S-1-5-21-789336058-606747145-839522115-1263\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl (User '?')
    O4 - HKUS\S-1-5-21-789336058-606747145-839522115-1265\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp (User '?')
    O4 - S-1-5-21-789336058-606747145-839522115-1213 Startup: ShipGear Web Update.lnk = C:\Program Files\V-Technologies\ShipGear2\WiseUpdt.exe (User '?')
    O4 - S-1-5-21-789336058-606747145-839522115-1255 Startup: ShipGear Web Update.lnk = C:\Program Files\V-Technologies\ShipGear2\WiseUpdt.exe (User '?')
    O4 - Startup: ShipGear Web Update.lnk = C:\Program Files\V-Technologies\ShipGear2\WiseUpdt.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
    O4 - Global Startup: QuickBooks Web Connector.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBWebConnector\QBWebConnector.exe
    O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
    O4 - Global Startup: UPS WorldShip Messaging Utility.lnk = C:\UPS\WSTD\WSTDMessaging.exe
    O4 - Global Startup: UPS WorldShip PLD Reminder Utility.lnk = C:\UPS\WSTD\wstdPldReminder.exe
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - https://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1130955299275
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Bowmandisplays.com
    O17 - HKLM\Software\..\Telephony: DomainName = Bowmandisplays.com
    O17 - HKLM\System\CCS\Services\Tcpip\..\{1B4DFC54-2601-4D87-8241-2DBEE7EBA270}: NameServer = 10.0.0.253
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Bowmandisplays.com
    O17 - HKLM\System\CS1\Services\Tcpip\..\{1B4DFC54-2601-4D87-8241-2DBEE7EBA270}: NameServer = 10.0.0.253
    O18 - Protocol: intu-help-qb1 - {9B0F96C7-2E4B-433E-ABF3-043BA1B54AE3} - C:\Program Files\Intuit\QuickBooks Enterprise Solutions 5.0\HelpAsyncPluggableProtocol.dll
    O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: DeviceShield Client Service (DeviceShield Client) - Lync Software Pty Ltd - C:\WINDOWS\system32\FileGuard.exe
    O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Trend Micro Client/Server Security Agent RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\ntrtscan.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
    O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
    O23 - Service: Trend Micro Client/Server Security Agent Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe
    O23 - Service: Trend Micro Client/Server Security Agent Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\TmPfw.exe
    O23 - Service: Trend Micro Client/Server Security Agent Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\TmProxy.exe

    --
    End of file - 9694 bytes

    harry 48



      Egghead

    • lay back , relax and chill out
    • Thanked: 129
      • Yes
      • Yes
      • Yes
      • Dribbling Pensioner
    • Certifications: List
    • Experience: Familiar
    • OS: Windows 7
    Re: Internet Explorer Not Finding Web Pages - Hijack This Log
    « Reply #1 on: March 25, 2009, 03:31:50 PM »
    http://www.ccleaner.com/download

    remember you cannot have 2 anti virus working on your pc what one have you

     installed

    download the above from ( filehippo  ) when the page opens run and clean what

     ever comes up , also the same with the one below

    http://www.iobit.com/advancedwindowscareper.html

    harry 48


    evilfantasy

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Calm like a bomb
    • Thanked: 493
    • Experience: Experienced
    • OS: Windows 11
    Re: Internet Explorer Not Finding Web Pages - Hijack This Log
    « Reply #2 on: March 25, 2009, 04:25:23 PM »
    Harry, you need to send users to our removal guide please.

    nestor I need all of the logs from here. http://www.computerhope.com/forum/index.php/topic,46313.0.html

    Even if they didn't remove anything I need the information that is in them.

    harry 48



      Egghead

    • lay back , relax and chill out
    • Thanked: 129
      • Yes
      • Yes
      • Yes
      • Dribbling Pensioner
    • Certifications: List
    • Experience: Familiar
    • OS: Windows 7
    Re: Internet Explorer Not Finding Web Pages - Hijack This Log
    « Reply #3 on: March 25, 2009, 04:31:42 PM »
    ok evil i have done that before as well , thank you harry