Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Had a rundll error, was infected, cleaned, attached HJT, still no IE  (Read 22773 times)

0 Members and 1 Guest are viewing this topic.

CJG

    Topic Starter


    Rookie

    Had a rundll error and posted in the computer software forum.  I ran my HJT and posted it - was told that I was infected.  See thread:
    http://www.computerhope.com/forum/index.php/topic,80283.msg528759.html#msg528759

    I followed the read this first post and cleaned the computer.  Now I have attached the new HJT log.  The good news is I no longer get the Rundll error, but I still no IE (outlook works fine).  Any help from this forum is much appreciated - thanks in advance.

    I have Vista with the SP1 only (and I have no MS windows disk, apparently Sony that it would be good to put it all online)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 9:41:25 PM, on 4/1/2009
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v7.00 (7.00.6001.18000)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
    C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
    C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
    C:\Program Files\Lexmark 9300 Series\lxcqmon.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe
    C:\Program Files\Sony\ISB Utility\ISBMgr.exe
    C:\Program Files\Lexmark 9300 Series\ezprint.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Apoint\Apoint.exe
    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
    C:\Program Files\Apoint\ApMsgFwd.exe
    C:\Program Files\Apoint\Apntex.exe
    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
    C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
    C:\Program Files\Internet Explorer\ieuser.exe
    C:\Windows\System32\mobsync.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local>
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
    O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [WD Drive Manager] C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
    O4 - HKLM\..\Run: [VAIOSurvey] C:\Program Files\Sony Corporation\VAIO Survey\Vista VAIO Survey.exe
    O4 - HKLM\..\Run: [VAIOSecurity] "C:\Program Files\Sony\VAIO Security Center\VSC.exe" 1
    O4 - HKLM\..\Run: [lxcqmon.exe] "C:\Program Files\Lexmark 9300 Series\lxcqmon.exe"
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
    O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
    O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [LXCQCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\LXCQtime.dll,_RunDLLEntry@16
    O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 9300 Series\ezprint.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O4 - Global Startup: Bluetooth Manager.lnk = ?
    O4 - Global Startup: Turbo Tourney 2009 Scheduler.lnk = ?
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O13 - Gopher Prefix:
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
    O16 - DPF: {7FE26BE2-B923-4B41-9834-E84DA1CC1F96} (Closet Control) - http://vsp.closetmaid.com/vsp/cmaidctl_vsp.closetmaid.com_downloader.cab
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    O23 - Service: lxcq_device -   - C:\Windows\system32\lxcqcoms.exe
    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
    O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
    O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
    O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
    O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
    O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
    O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
    O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
    O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
    O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
    O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
    O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
    O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
    O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
    O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
    O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
    O23 - Service: WD Drive Manager Service (WDBtnMgrSvc.exe) - WDC - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

    --
    End of file - 12490 bytes



    CJG

      Topic Starter


      Rookie

      Re: Had a rundll error, was infected, cleaned, attached HJT, still no IE
      « Reply #1 on: April 01, 2009, 09:13:12 PM »
      Forgot to attach the SAS and MBAM logs - here they are:

      [attachment deleted by admin]

      KingPincer



        Intermediate

        Thanked: 9
        Re: Had a rundll error, was infected, cleaned, attached HJT, still no IE
        « Reply #2 on: April 02, 2009, 04:39:38 AM »
        What exactly happens when you open IE does it said IE cannot display web page? Why don't you try installing Mozilla Firefox and see if it will work. 

        CJG

          Topic Starter


          Rookie

          Re: Had a rundll error, was infected, cleaned, attached HJT, still no IE
          « Reply #3 on: April 02, 2009, 05:29:59 AM »
          IE states:

          {Boilerplate}
          IE cannont display the webpage

          Most likely causes:
          • You are not connected to the internet (but outlook works)
          • The website is encoutering problems (tried yahoo and google)
          • There might be a typing error in the address (home page is yahoo)

          I would really like to get IE working rather than installing another browser, but if this is a means to an end I am interested.  Will I ever get IE working again?

          How do I go about the best way to install firefox without the internet on the sick machine?  Memory stick?

          Thanks in advance,
          Crispin

          evilfantasy

          • Malware Removal Specialist
          • Moderator


          • Genius
          • Calm like a bomb
          • Thanked: 493
          • Experience: Experienced
          • OS: Windows 11
          Re: Had a rundll error, was infected, cleaned, attached HJT, still no IE
          « Reply #4 on: April 02, 2009, 12:24:15 PM »
          Try Dial-a-fix.

          Download Dial-a-Fix by djlizard, save it to the desktop then extract it to it's own folder.

          • Open the folder and run Dial-a-fix.exe
          • 2 windows will open. Close the one in the background labeled Restrictive Policies
          • Check the box in section 1, Empty temp folders.
          • Check the box in section 2, Fix Windows Installer.
          • Check the box in section 3, Fix Windows Update.
          • Check the box in section 4, labeled SSL/HTTPS/Cryptography. The 4 boxes under it should be pre-checked
          • Check all boxes in section 5, labeled Registration Center.
          • Click Go
          • OK any error messages if received, but write them down and post them here.
          • Restart the computer when done.
          .
          Is the problem fixed?

          CJG

            Topic Starter


            Rookie

            Re: Had a rundll error, was infected, cleaned, attached HJT, still no IE
            « Reply #5 on: April 02, 2009, 12:24:46 PM »
            Thanks for the additional input, but this has me asking more questions. 

            Since I have already run SAS and MBAM, do I need to do Combofix too?  We have a registry mechanic on the computer (I don't have the name in front of me, but I will tonight when I get home). 

            You mentioned then to download a cleaner (suggested ATF) - do I need this on top of SAS, MBAM, and a "registry mechanic"?

            Thanks again,
            Crispin

            evilfantasy

            • Malware Removal Specialist
            • Moderator


            • Genius
            • Calm like a bomb
            • Thanked: 493
            • Experience: Experienced
            • OS: Windows 11
            Re: Had a rundll error, was infected, cleaned, attached HJT, still no IE
            « Reply #6 on: April 02, 2009, 12:31:17 PM »
            Registry Mechanic can not fix this and I highly suggest you do not run any registry tools on a computer that is not working right. Registry cleaners in reality are just a myth. The only thing that can repair Windows is a Windows disk. Many times they only do more damage.

            If you can not connect still then run Dial-a-fix and let me know how it works.

            If that problem is solved then let me know what is still wrong.

            In this forum I suggest only following advice from someone with Malware Removal Specialist under their user name.

            CJG

              Topic Starter


              Rookie

              Re: Had a rundll error, was infected, cleaned, attached HJT, still no IE
              « Reply #7 on: April 02, 2009, 12:51:08 PM »
              Fantastic you (evilfantasy) appear to be such a person!!!  What should I prepare to do next?

              Thanks in advance!

              Crispin

              evilfantasy

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Calm like a bomb
              • Thanked: 493
              • Experience: Experienced
              • OS: Windows 11
              Re: Had a rundll error, was infected, cleaned, attached HJT, still no IE
              « Reply #8 on: April 02, 2009, 01:01:00 PM »
              Did you need to run Dial-a-fix?

              What problems are you still having?

              CJG

                Topic Starter


                Rookie

                Re: Had a rundll error, was infected, cleaned, attached HJT, still no IE
                « Reply #9 on: April 02, 2009, 02:51:59 PM »
                What is Dial-a-fix?  I'll search it . . .

                Well, I did all steps on the Read Me First Post (SAS found nothing, MBAM found two infections and cleaned them off) and the good news is I no longer get the Rundll error, but I still do not have Internet Explorer, but outlook works fine (so it is able to get to the internet).

                Thanks in advance,
                Crispin

                evilfantasy

                • Malware Removal Specialist
                • Moderator


                • Genius
                • Calm like a bomb
                • Thanked: 493
                • Experience: Experienced
                • OS: Windows 11

                CJG

                  Topic Starter


                  Rookie

                  Re: Had a rundll error, was infected, cleaned, attached HJT, still no IE
                  « Reply #11 on: April 02, 2009, 03:06:53 PM »
                  Will work with Vista? 

                  I wend to the LunarSoft.net site http://wiki.lunarsoft.net/wiki/Dial-a-fix and it says it is not ready for Vista.  Is that information out of date?

                  Thank you for helping me through this exercise,
                  Crispin

                  evilfantasy

                  • Malware Removal Specialist
                  • Moderator


                  • Genius
                  • Calm like a bomb
                  • Thanked: 493
                  • Experience: Experienced
                  • OS: Windows 11
                  Re: Had a rundll error, was infected, cleaned, attached HJT, still no IE
                  « Reply #12 on: April 02, 2009, 03:09:31 PM »
                  Sorry no it will not work with Vista.

                  1. Close any Internet Explorer or Windows Explorer windows that are currently open.
                  2. Open Internet Explorer by clicking the Start button Picture of the Start button, and then clicking Internet Explorer.
                  3. Click the Tools button, and then click Internet Options.
                  4. Click the Advanced tab, and then click Reset.
                  5. In the Reset Internet Explorer Settings dialog box, click Reset.
                  6. When Internet Explorer finishes restoring the settings, click Close, click OK, and then click OK again.
                  7. Close Internet Explorer.

                  Your changes will take effect the next time you open Internet Explorer.

                  How is it now?

                  CJG

                    Topic Starter


                    Rookie

                    Re: Had a rundll error, was infected, cleaned, attached HJT, still no IE
                    « Reply #13 on: April 02, 2009, 03:22:58 PM »
                    I followed the steps provided (excellent by the way) and then I restarted IE.

                    Now when it starts - it starts two simultaneous IE tabs. 

                    The first one trys to go to:

                    Http://go.microsoft.com/fwlink?linkId+76277

                    And the second one goes to:

                    http://www.symantecstore.com/promo=147023

                    Both fail - I get the same IE message ... cannot display the webpage on either tab.  It is also interesting that it is starting two tabs now (it hasn't done that before).

                    Thank you,

                    Crispin

                    evilfantasy

                    • Malware Removal Specialist
                    • Moderator


                    • Genius
                    • Calm like a bomb
                    • Thanked: 493
                    • Experience: Experienced
                    • OS: Windows 11
                    Re: Had a rundll error, was infected, cleaned, attached HJT, still no IE
                    « Reply #14 on: April 02, 2009, 03:26:22 PM »
                    Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

                    Link #1
                    Link #2

                    **Note:  It is important that it is saved directly to your Desktop

                    Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

                    Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
                     
                    Double click combofix.exe & follow the prompts.
                    When finished ComboFix will produce a log for you.
                    Post the ComboFix log in your next reply.

                    Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

                    Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

                    If you have problems with ComboFix usage, see How to use ComboFix