Computer Hope

Software => Internet browsers => Topic started by: Kapil Goondli on May 26, 2005, 07:28:46 PM

Title:   Can't open Internet Explorer
Post by: Kapil Goondli on May 26, 2005, 07:28:46 PM
My desktop has turned blue and displays a message that reads:
"Fatal error in IE has occured at 0028:c011e36 in VXD VMM (01)+00010e36
Error caused by Trojan-Spy.HTML. Smitfraud.c"

Additional information:

When I try to click on internet explorer, i get the wait hour glass, but nothing happens.

Diagnose/troubleshooting:

I have done a symantec scan, I have a HJT log.
Title: Re:    Can't open Internet Explorer
Post by: dl65 on May 26, 2005, 09:51:56 PM
Kapil Goondli......... Have you run a trojan scanner ?

Ewido is a decent one and it will let you test drive it .......
In the meantime ...is you post your hijackthis log we can have a look at it ......it may lead us to the trojan ...


dl65  ::)
Title: Re:    Can't open Internet Explorer
Post by: Kapil_Goondli on May 27, 2005, 10:34:48 AM
I did run a scan. I get a message saying "c:\WINNT\systemdll.exe doesn't exist".
I tried to run cleanup.exe it said "application error failed to initialize properly".
I can't get on the internet. I click the internet explorer icon and I get the hour glass,
but nothing happens. I have DSL with Comcast and I have to go to another computer to
do anything. Is there another way to conect to the internet on my computer while trying to correct these issues?


Logfile of HijackThis v1.99.1
Scan saved at 9:57:16 PM, on 5/26/2005
Update to SP2 --> Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\Smss.exe
C:\WINNT\system32\Winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\Svchost.exe
C:\WINNT\System32\Svchost.exe
C:\Program Files\Comcast\Security Manager\app\Prism.exe
C:\WINNT\system32\Spoolsv.exe
c:\program files\comcast\security manager\app\CurtainsSysSvcNt.exe
C:\WINNT\System32\Svchost.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\explorer.exe
C:\Program Files\Winamp3\winampa.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\UltimateZip\uzqkst.exe
C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe
C:\HJT\HijackThis..exe

Do you know this site? --> R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://letgohome.com/hp.htm?id=31130123321003
F2 - REG:system.ini: UserInit=C:\WINNT\System32\AUserInit.exe
O2 - BHO: (no name) - {467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E} - C:\WINNT\System32\W8C6S4~1.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_6_0_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Security Manager Popup Blocker - {64634180-B0EA-48B6-82B7-9620D33362C1} - C:\Program Files\Comcast\Security Manager\app\AuthBHO.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [kernelfaultcheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [MMTASK] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Startup: UltimateZip Quick Start.lnk = C:\Program Files\UltimateZip\uzqkst.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\excel.exe/3000
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Companion\Modules\messmod2\v4\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Companion\Modules\messmod2\v4\yhexbmes.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct1_x.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst20040510.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) - http://us.dl1.yimg.com/download.yahoo.com/...ebio5_1_5_0.cab
O20 - AppInit_DLLs: 8hhshm1oz6yuvull.dll.dll.dll.dll.dll.dl l.dll.dll.dll.dll.dll.dll.dll.dll.dll.d ll.dll.dll.dll.dll.dll.dll.dll.dll.dll. dll.dll.dll.dll.dll.dll.dll.dll.dll.dll .dll.dll.dll.dll.dll.dll.dll.dll.dll.dl l.dll.dll.dll.dll.dll.dll.dll.dll.dll.d ll.dll
O23 - Service: Curtains for Windows System Service (CurtainsSysSvc) - Authentium, Inc. - c:\program files\comcast\security manager\app\CurtainsSysSvcNt.exe
Title: Re:    Can't open Internet Explorer
Post by: dl65 on May 27, 2005, 02:46:07 PM
Kapil Goondli.....  ****the machine which generated this hijackthis log is infected with the COOLWEBSEARCH  torojan ........ to remove it go to ...... http://www.intermute.com/spysubtract/cwshredder_download.html    and D/L version 2.15 ...... then run it on the pc ..........then reopen hijack this and remove the following ......( if its still there )

O2 - BHO: (no name) - {467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E} - C:\WINNT\System32\W8C6S4~1.DLL

lets see what it looks like after you reboot .......if necessary repost another log if it presists.

dl65  ::)