Go Back   Tech Support Forum > Microsoft Support > Internet Browsers and Email > Internet Explorer Forum

Can't Login @ Hotmail.com

This is a discussion on Can't Login @ Hotmail.com within the Internet Explorer Forum forums, part of the Tech Support Forum category.


Closed Thread
 
Thread Tools Search this Thread
Old 08-11-2004, 10:13 AM   #1
Registered Member
 
Join Date: Aug 2004
Location: Montreal, Canada
Posts: 4
OS: Win XP pro


Question

I haven't been able to access Hotmail recently ... even thought all my collegues and friends say that Hotmail works fine for them.

I'm able to access the Login Page, but when i click to Log in ... the next page loads in ½ a second and displays a white page only ... no error code !¿

I'm able to access my internet banking (secure servers), i've tried to modify my security settings on internet pages and/or cookies ... but still no success. I have the same problem when i try to get my e-mails throught my MSN messenger which works fine.

I recently formatted my hard drive, i did get a lot of problem with the Agobot/Morphin virus prior to installing all of my Windows updates, but all viruses/ad-ware are now removed/fixed.

Here is my currect HJT log file:

Logfile of HijackThis v1.97.7
Scan saved at 12:10:42, on 2004-08-11
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\WINDOWS\System32\sysdrv.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\System32\16winupdate32.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Jean-Frédéric\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ierecherche.sympatico.ca
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sympatico.ca
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer fourni par Service Internet Sympatico
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [WindowsRegKey update] 16winupdate32.exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [System Drivers] sysdrv.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [websx] C:\Program Files\websx\int114844.exe -auto
O4 - HKLM\..\RunServices: [WindowsRegKey update] 16winupdate32.exe
O4 - HKLM\..\RunServices: [System Drivers] sysdrv.exe
O4 - HKCU\..\Run: [WindowsRegKey update] 16winupdate32.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O14 - IERESET.INF: START_PAGE_URL=http://www.sympatico.ca
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O16 - DPF: {7589EEE6-E336-11D4-8A7E-EE1D971D9B47} (AcontiX Control) - http://secure.aconti.net/acontix/goodthinxx.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...208.5391435185
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4084486A-3CF2-47FE-AFC2-E80FB6E82584}: Domain = sympatico.ca
O17 - HKLM\System\CCS\Services\Tcpip\..\{4084486A-3CF2-47FE-AFC2-E80FB6E82584}: NameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{701097B7-C63D-4FE2-BA42-99A1912D2E48}: NameServer = 206.47.244.133 206.47.244.52
O17 - HKLM\System\CS1\Services\Tcpip\..\{4084486A-3CF2-47FE-AFC2-E80FB6E82584}: Domain = sympatico.ca
O17 - HKLM\System\CS1\Services\Tcpip\..\{4084486A-3CF2-47FE-AFC2-E80FB6E82584}: NameServer = 192.168.2.1


No one has been able to identify this problem or even be able to help me. My ISP tech support does not support that either.

Please help !!!

__________________
Raffix is offline  
Old 08-13-2004, 03:18 AM   #2
Registered Member
 
Join Date: Aug 2004
Location: Montreal, Canada
Posts: 4
OS: Win XP pro


Confused

I partially solved my problem, i now found a way to get to my e-mails ...

Remember... i said i couldn't login ... everytime i entered my Hotmail Password, i was directed to a white page ... with the message "done" in the status bar.

I just had the great idea to viex the "source" of that white page, here it is:

<HTML><HEAD><meta HTTP-EQUIV="Content-Type" content="text/html; ch****t=iso-8859-1"><META HTTP-EQUIV="REFRESH" CONTENT="0; URL=http://www.hotmail.msn.com/cgi-bin/sbox?did=1&t=5f7S0EQzGD114jovC5gwMy3TG76EpO8JDLz2PGIfHWwyCjRATnCCOUTv0DnA14***i removed a bunch of letters and numbers here for my protection***X36akwEp!htmTPv1OCrSkv3R55kadr1yVYNG*0!hxJ49fTiYtOBRhNiSlRPyReytn8gRZ5q4pFnusxuqQ04WhUf&lc=1033&js=yes&rru=/cgi-bin/HoTMaiL"><script>function OnBack(){}</script></HEAD></HTML>

so i copy the URL found in that script onto my IE address bar ... and voila ... i can access my e-mails !

Does anyone know how to fix that annoying situation.

thx

__________________
Raffix is offline  
Old 08-14-2004, 11:14 AM   #3
TSF Team, Emeritus
 
greyknight17's Avatar
 
Join Date: Jul 2004
Location: New York
Posts: 14,312
OS: Windows 98 & Windows XP Home/Pro

My System

Welcome to TSF.

Please print out or copy this page to Notepad. You should not have any open browsers when you are following the procedures below.

Go to the bottom of this message to get the latest version of HijackThis. If the site is down, you can also get it here.

Turn off system restore by right clicking on My Computer and go to Properties->System Restore and check the box for Turn off System Restore. Click Apply and then OK. Restart your computer. After we are finished with your log file and verified that it's clean, you may turn it back on and create a new restore point.

Go to My Computer->Tools->Folder Options->View tab and make sure that Show hidden files and folders is enabled. Also make sure that the System Files and Folders are showing/visible also.

Make sure to close any open browsers. Go into HijackThis->Config->Misc. Tools->Open process manager. Select the following and click Kill process for each one:

C:\WINDOWS\System32\sysdrv.exe
C:\WINDOWS\System32\16winupdate32.exe

Make sure to close any open browsers you have. Check and fix the following in HijackThis (make sure not to miss any):

O4 - HKLM\..\RunServices: [WindowsRegKey update] 16winupdate32.exe
O4 - HKLM\..\RunServices: [System Drivers] sysdrv.exe
O4 - HKCU\..\Run: [WindowsRegKey update] 16winupdate32.exe
O16 - DPF: {7589EEE6-E336-11D4-8A7E-EE1D971D9B47} (AcontiX Control) - http://secure.aconti.net/acontix/goodthinxx.cab

Any idea what this is for:

O4 - HKLM\..\Run: [websx] C:\Program Files\websx\int114844.exe -auto

Reboot into Safe Mode (hit F8 key until menu shows up). Delete the following Files/Folders (delete folders if no filename is specified) according to their directory (if none, just do a search for them) and delete them if they exist:

C:\WINDOWS\System32\sysdrv.exe
C:\WINDOWS\System32\16winupdate32.exe

Reboot into Normal Mode.

Please download Adaware and install it. Make sure to check for any updates before running it. Also make sure to customize the settings in Adaware for better scan results. Run the scan and fix everything that it finds.

After that's done, restart and post a new HijackThis log file so we can make sure it's clean.
__________________
Please do NOT PM me. Post whatever questions you may have in the forum and we will take a look at it when we get to it. If you have waited for more than 3 days, you may then and ONLY then PM me for assistance. I will take a look at it.
greyknight17 is offline  
Old 08-15-2004, 09:06 AM   #4
Registered Member
 
Join Date: Aug 2004
Location: Montreal, Canada
Posts: 4
OS: Win XP pro



Here's my HJT now ... i had fixed the sysdrv.exe and the 16winupdate32.exe a couple of days again already ... my internet connection is now normal ... but the problem remains with Hotmail !

Logfile of HijackThis v1.97.7
Scan saved at 11:03:12, on 2004-08-15
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\devldr32.exe
D:\Jean-Frédéric\Diablo II\Game.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Jean-Frédéric\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ierecherche.sympatico.ca
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sympatico.ca
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer fourni par Service Internet Sympatico
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O14 - IERESET.INF: START_PAGE_URL=http://www.sympatico.ca
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_fi...7edadac81f3fd5
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O16 - DPF: {7589EEE6-E336-11D4-8A7E-EE1D971D9B47} (AcontiX Control) - http://secure.aconti.net/acontix/goodthinxx.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...208.5391435185
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4084486A-3CF2-47FE-AFC2-E80FB6E82584}: Domain = sympatico.ca
O17 - HKLM\System\CCS\Services\Tcpip\..\{4084486A-3CF2-47FE-AFC2-E80FB6E82584}: NameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{701097B7-C63D-4FE2-BA42-99A1912D2E48}: NameServer = 206.47.244.133 206.47.244.52
O17 - HKLM\System\CS1\Services\Tcpip\..\{4084486A-3CF2-47FE-AFC2-E80FB6E82584}: Domain = sympatico.ca
O17 - HKLM\System\CS1\Services\Tcpip\..\{4084486A-3CF2-47FE-AFC2-E80FB6E82584}: NameServer = 192.168.2.1


I can still access my mail throught the sneaky way of copying the URL contain in the source of the white page i always get ... see above !

Anyone knows why !
__________________
Raffix is offline  
Old 08-16-2004, 02:15 PM   #5
TSF Team, Emeritus
 
greyknight17's Avatar
 
Join Date: Jul 2004
Location: New York
Posts: 14,312
OS: Windows 98 & Windows XP Home/Pro

My System

Go to the bottom of this message to get the latest version of HijackThis. If the site is down, you can also get it here.

Check and fix the following:

O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_f...f7edadac81f3fd5
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52...meInstaller.exe
O16 - DPF: {7589EEE6-E336-11D4-8A7E-EE1D971D9B47} (AcontiX Control) - http://secure.aconti.net/acontix/goodthinxx.cab


Restart your computer and see if you still have the problem. Post a new HijackThis log file.

To help prevent future spyware installations/infections, please read my anti-spyware section and use the tools provided.
__________________
Please do NOT PM me. Post whatever questions you may have in the forum and we will take a look at it when we get to it. If you have waited for more than 3 days, you may then and ONLY then PM me for assistance. I will take a look at it.
greyknight17 is offline  
Old 08-17-2004, 04:45 AM   #6
Registered Member
 
Join Date: Aug 2004
Location: Montreal, Canada
Posts: 4
OS: Win XP pro



I just removed any of the mentionned files from my HJT scan. I rebooted. I started my Internet connection. I went to www.hotmail.com and i entered my e-mail address along with my password. On the next page, i just get a blank page. If i click View.../Source i get this:

<HTML><HEAD><meta HTTP-EQUIV="Content-Type" content="text/html; ch****t=iso-8859-1"><META HTTP-EQUIV="REFRESH" CONTENT="0; URL=http://www.hotmail.msn.com/cgi-bin/sbox?did=1&t=5JKecFX6xD5IpvD1U8MgQARG6fpZrdwsv5I1Yccz2ntKQjkB5KF!cZZhsGt9NC8T*GarkvO0QffnANaBkMwJqEVQ$$&p=5OCC0RABTGioYr82e2xSW4bB*GPgjRQUPd8eRz43Ef34!jdT*i removed a few things here *8VdUyOu!ovVRxq99bs1GXMDqGabhUejYHXH5J3Kg0EWdWFbAf*OcKcUtyX34wLwmQSSzpZnIoFy42NhM569LTeQ0VCBJZjpXB!MxZ1kQt26jAsBCXF!hOV!4FNbcNHN!lrW8W70*MnUiAMdto3FwhYnqdzMyHuUbUoclt8IdQsMwY4G4S"><script>function OnBack(){}</script></HEAD></HTML>

I can access my mail if i copy the URL in this html script to my address bar. I'm not an expert but i think my IE will just not REFRESH to that URL. Propably because it is set to "0" ... or not. I don't understand.

For now, i'm gonna head out to www.windowsupdate.com and will check for updates on IE.

thx for all the help !

ps.: here's my HJT now

Logfile of HijackThis v1.97.7
Scan saved at 06:42:58, on 2004-08-17
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\devldr32.exe
D:\Jean-Frédéric\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ierecherche.sympatico.ca
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sympatico.ca
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer fourni par Service Internet Sympatico
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4084486A-3CF2-47FE-AFC2-E80FB6E82584}: Domain = sympatico.ca
O17 - HKLM\System\CCS\Services\Tcpip\..\{4084486A-3CF2-47FE-AFC2-E80FB6E82584}: NameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{701097B7-C63D-4FE2-BA42-99A1912D2E48}: NameServer = 206.47.244.133 206.47.244.52
O17 - HKLM\System\CS1\Services\Tcpip\..\{4084486A-3CF2-47FE-AFC2-E80FB6E82584}: Domain = sympatico.ca
O17 - HKLM\System\CS1\Services\Tcpip\..\{4084486A-3CF2-47FE-AFC2-E80FB6E82584}: NameServer = 192.168.2.1
__________________
Raffix is offline  
Old 08-25-2004, 03:37 PM   #7
Registered Member
 
Join Date: Aug 2004
Posts: 1
OS: WinXP


Quote:
Originally Posted by Raffix
I'm able to access the Login Page, but when i click to Log in ... the next page loads in ½ a second and displays a white page only ... no error code !¿
Hey Raffix,

I don't have a solution to your problem, but I'm another person that has the same problem, so I thought I'd say hello and maybe make you feel better.

Instead of reading the source and copying the address into the address bar, I found an easier way to get into your messages. You have to log in to hotmail through the normal page (not through msn messenger or anything). So log in to www.hotmail.com, enter your login and password, click enter, wait for the white page to come up, then hit the back button twice. Voila, you're in.

I think this may have been caused by some kind of spy/ad-ware. I don't know what it was, but I had some kind of spyware attack, I ran my spyware cleaner programs (I have four), cleaned everything off, but the page still doesn't work.

-rex
__________________
tcrex2000 is offline  
Old 08-26-2004, 07:20 AM   #8
Registered Member
 
georgeedwards's Avatar
 
Join Date: Aug 2004
Location: West Midlands, UK
Posts: 79
OS: Windows XP Home Edition


Send a message via MSN to georgeedwards
Grin

that greyknight!!! isnt he something!!! fairdos Greyknight, are they paying you or something cos your AMAZING

George - your new admirer and buddy
__________________
georgeedwards is offline  
Old 08-31-2004, 07:14 AM   #9
Registered Member
 
Join Date: Aug 2004
Posts: 2
OS: WinXP


I am having the exact same problem, except none of the same things appear in my hijack this log.

Logfile of HijackThis v1.98.2
Scan saved at 9:07:45 AM, on 8/31/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\carpserv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\HPQ\One-Touch\OneTouch.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\notepad.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Spyware\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.livejournal.com/users/marcasitevah/friends
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [TV Now] C:\Program Files\HPQ\Notebook Utilities\TvNow.exe /RK
O4 - HKLM\..\Run: [Display Settings] C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [QT4HPOT] C:\Program Files\HPQ\One-Touch\OneTouch.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AutoTBar] C:\hp\bin\autotbar.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\Symantec\LIVEUP~1\SNDMon.EXE
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\Quicken\billmind.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\Quicken\QWDLLS.EXE
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted Zone: *.05p.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.scoobidoo.com
O15 - Trusted Zone: *.searchmiracle.com
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/is...88/mcfscan.cab
__________________
marcasitevah is offline  
Old 09-01-2004, 04:41 PM   #10
Registered Member
 
Join Date: Aug 2004
Posts: 2
OS: WinXP


I installed XP SP2 and it fixed the problem.
__________________
marcasitevah is offline  
Old 09-27-2004, 06:48 PM   #11
Registered Member
 
Join Date: Sep 2004
Posts: 1
OS: XP



Hi there, I'm with the same problem, but not just with Hotmail, I cannot access to Gmail, also, I've to run databases and cannot access to any phpMyAdmin so, don't know what to do

this is my log, hope somebody can help me, thanks!!

Logfile of HijackThis v1.98.2
Scan saved at 07:43:31 p.m., on 27/09/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Mixer.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\CMPDPSRV.EXE
C:\Archivos de programa\Microsoft Hardware\Mouse\point32.exe
C:\Archivos de programa\Microsoft Hardware\Keyboard\type32.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Archivos de programa\Google\Gmail Notifier\gnotify.exe
C:\Archivos de programa\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Archivos de programa\Sony Handheld\AlarmApp.exe
C:\Archivos de programa\Sony Handheld\HOTSYNC.EXE
C:\Archivos de programa\stickies\stickies.exe
C:\mysql\bin\mysqld-nt.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\Archivos de programa\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Archivos de programa\Trend Micro\PC-cillin 9\Tmntsrv.exe
C:\Archivos de programa\Trend Micro\PC-cillin 9\PCCCLIENT.EXE
C:\Archivos de programa\Trend Micro\PC-cillin 9\PCCGUIDE.EXE
C:\Archivos de programa\Trend Micro\PC-cillin 9\POP3TRAP.EXE
D:\Archivos de programa\eDonkey2000\edonkey2000.exe
C:\Archivos de programa\MSN Messenger\msnmsgr.exe
C:\Archivos de programa\Internet Explorer\iexplore.exe
C:\Archivos de programa\Macromedia\Advanced Extensions\Advanced Query Wizard\bin\listener.exe
C:\Archivos de programa\Internet Explorer\iexplore.exe
C:\Documents and Settings\CreativeClick\Escritorio\hijackthis.exe

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\archivos de programa\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\archivos de programa\google\googletoolbar2.dll
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [pccguide.exe] "C:\Archivos de programa\Trend Micro\PC-cillin 9\pccguide.exe"
O4 - HKLM\..\Run: [PCCClient.exe] "C:\Archivos de programa\Trend Micro\PC-cillin 9\PCCClient.exe"
O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Archivos de programa\Trend Micro\PC-cillin 9\Pop3trap.exe"
O4 - HKLM\..\Run: [CMPDPSRV] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\CMPDPSRV.EXE
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [IntelliType] "C:\Archivos de programa\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\System32\twink64.exe internat.dll,LoadKeyboardProfile
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Archivos de programa\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Archivos de programa\QuickTime\qttask.exe" -atboottime
O4 - Startup: HotSync Manager.lnk = C:\Archivos de programa\Sony Handheld\HOTSYNC.EXE
O4 - Startup: Stickies.lnk = C:\Archivos de programa\stickies\stickies.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Archivos de programa\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Alarm Manager.LNK = C:\Archivos de programa\Sony Handheld\AlarmApp.exe
O8 - Extra context menu item: &Google Search - res://c:\archivos de programa\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\archivos de programa\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\archivos de programa\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\archivos de programa\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\archivos de programa\google\GoogleToolbar2.dll/cmtrans.html
O12 - Plugin for .spop: C:\Archivos de programa\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - https://components.viewpoint.com/MTS...300/index.html
O16 - DPF: {0EC4C9E3-EC6A-11CF-8E3B-444553540000} (WaveTab Control) - http://www.riffinteractive.com/setup/RiffLick.cab
O16 - DPF: {D6526FE0-E651-11CF-99CB-00C04FD64497} (Microsoft MSChat Control Object) - http://www.riffinteractive.com/setup/MSChatOCX.Cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B7BC4C89-3A43-467E-8D65-57D32E29CA85}: NameServer = 200.33.146.194 200.33.146.202

__________________
arturo is offline  
Closed Thread

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is on
Smilies are on
[IMG] code is on
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Post a Question


» Site Navigation
 > FAQ
  > 10.0.0.2


All times are GMT -7. The time now is 09:39 PM.


Copyright 2001 - 2014, Tech Support Forum

Windows 7 - Windows XP - Windows Vista - Trojan Removal - Spyware Removal - Virus Removal - Networking - Security - Top Web Hosts