Tech Support banner

Status
Not open for further replies.
1 - 18 of 18 Posts

·
Registered
Joined
·
88 Posts
Discussion Starter · #1 ·
cannot open links in new window

Hi guys long time no see. I downloaded vbrun and yazak this morning and since then i haven't been able to click on links. All that happens is the outside window comes up and that's about it. I pulled alot of spyware etc off this thing and i deleted the programs back off but it's still happening. I can't run panda or any other online scan as they open a new window which this thing won't allow me to do. AVG is crap as it hasn't picked up anything so far. Any ideas? :4-dontkno
 

·
TSF Team Emeritus, Microsoft Support
Joined
·
15,478 Posts
Well AVG not picking anything up is a good thing in my opinion :sayyes:


You might want to try and Run the System File Checker

Go to the Run box on the Start Menu and type in:

sfc /scannow ( sfc if not reconized)

This command will immediately initiate the Windows File Protection service to scan all protected files and verify their integrity, replacing any files with which it finds a problem. You will need your Windows cd.
 

·
Registered
Joined
·
88 Posts
Discussion Starter · #3 ·
ok i did that and it didn't show anything up. is it possible that there is something lurking in the registry i haven't found? alot of the spyware etc was in the registry.
 

·
TSF Team Emeritus, Microsoft Support
Joined
·
15,478 Posts
If you feel you are still infected please post a HJT log in the HiJackThisLog Help Forum

When your system is clean and you are still experiencing your issue you may return here for assistance. There is no use trying to address your problem if your system is infected with some type of malware/spyware.

Download and install: HiJackThis.

(Always create a Folder for HiJackThis anywhere but your Temp/Temporary Internet Folders or Desktop. A good place to make a folder would be in My Documents, as this is where it will save the backup files needed if there's a problem.)

Then doubleclick HijackThis.exe, and hit "Do A System Scan And Save Log". Make sure all Windows and Browsers are closed.
When the scan is finished, best to save your text file in the same folder as where you put HiJackthis.


IMPORTANT!!!
Create a New Topic and include a fresh HJT log in the HiJackThisLog Help Forum and Copy/Paste the info from your saved Hijackthis log file into your new topic.

A Moderator/ Security Team Analyst will give you instructions.


***DO NOT TRY TO FIX ANYTHING, MAJOR DAMAGE CAN BE DONE TO YOUR SYSTEM IF THIS TOOL IS USED INCORRECTLY, PLEASE WAIT FOR AN ANALYST/MODERATOR TO GIVE YOU INSTRUCTIONS***


Always describe your problem and any programs you have used to try to resolve your issue. Your description can go a long way to solving/repairing your particular issue.
 

·
Registered
Joined
·
88 Posts
Discussion Starter · #5 ·
Logfile of HijackThis v1.99.1
Scan saved at 4:08:22 PM, on 8/24/05
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\PROGRAM FILES\PLUS!\VIRUSCAN\VSHWIN32.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\TPPALDR.EXE
C:\USBSTORAGE\USBDETECTOR.EXE
C:\PROGRAM FILES\IOMEGA HOTBURN\AUTOLAUNCH.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\PROGRAM\WINZIP\WZQKPICK.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM\HIJACKTHIS.EXE

R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN0\YT.DLL (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Starware - {CA356D79-679B-4b4c-8E49-5AF97014F4C1} - C:\PROGRAM FILES\STARWARE\BIN\STARWARE.DLL (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN0\YT.DLL (file missing)
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\TPPALDR.EXE
O4 - HKLM\..\Run: [USBDetector] C:\USBStorage\USBDetector.exe
O4 - HKLM\..\Run: [Drag'n'Drop_Autolaunch] "C:\Program Files\Iomega HotBurn\Autolaunch.exe"
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [VsecomrEXE] C:\PROGRA~1\PLUS!\Viruscan\VSECOMR.EXE
O4 - HKLM\..\Run: [Vshwin32EXE] C:\PROGRA~1\PLUS!\Viruscan\VSHWIN32.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [Vshwin32EXE] C:\PROGRA~1\PLUS!\Viruscan\VSHWIN32.EXE /NoSplash
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: WinZip Quick Pick.lnk = C:\program\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsearch.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsimilar.html
O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmtrans.html
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} (Sinstaller Class) - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
 

·
Registered
Joined
·
88 Posts
Discussion Starter · #6 ·
the starware i took off as i know for sure that shouldn't be there, everything else is the same
 

·
TSF Team Emeritus, Microsoft Support
Joined
·
15,478 Posts
Reboot into Safe mode and have HJT fix these:
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN0\YT.DLL (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN0\YT.DLL (file missing)

Still in Safe Mode click Start>Run and type in msconfig.
Click the Startup tab and take the check out of the box beside KB891711.EXE

Reboot

Open the Control Panel>Add/Remove Programs and remove Google Toolbar and Yahoo Toolbar/Companion
 

·
Registered
Joined
·
88 Posts
Discussion Starter · #8 ·
ok i've done that and it's still happening. This has been since i downloaded yazak chat client and vbrun that you apparently have to download with it. I did that on the 23rd. Uninstalled them and deleted them off but they may have left something behind. Would Hijackthis have picked that up?
 

·
TSF Team Emeritus, Microsoft Support
Joined
·
15,478 Posts
Its not in your HJT log.
Open Control Panel, click on Add/Remove Programs. Locate Microsoft Internet Explorer SP1 and Internet Tools. Highlight it and click the Add/Remove button.
Abox will open chose the Repair Internet Explorer option.
 

·
TSF Team Emeritus, Microsoft Support
Joined
·
15,478 Posts
Remove either C:\PROGRAM FILES\PLUS!\VIRUSCAN\VSHWIN32.EXE or AVG. Running 2 antivirus programs can cause conflicts and system slow downs.

Only thing left I can think of is a repair installation. You will not lose any of your programs but you will need to reinstall your Windows Critical Updates & Service Packs.
Boot to the 98cd and install using the repair option.
 

·
Registered
Joined
·
88 Posts
Discussion Starter · #13 ·
how do i boot to the cd, do i need the restart disk to do that if so what are the commands to just boot to repair it. Iv'e done a reformat but not a repair
 

·
TSF Team Emeritus, Microsoft Support
Joined
·
15,478 Posts
Actually you could probably do it while the system is booted. Pop the cd in the drive and proceed to install. It should reconize the operating system is already installed and give you a repair option.
 

·
Registered
Joined
·
88 Posts
Discussion Starter · #15 ·
No it didn't give me that option it was just going to reinstall over the top of it. I have got the restart disk though and i know you can use it to run a dianostic, can you tell me how i can use it in that way? Maybe that will bring up something. I've pulled an alexa off this thing to know the bugger hijacked my browser. But i don't think that is causing the problem with the links. Do you want me to run hijack this again?
 

·
Registered
Joined
·
88 Posts
Discussion Starter · #17 ·
i've fixed it, i just reformatted the thing. Thanks for your time and helping me out though it's appreciated!
 

·
TSF Team Emeritus, Microsoft Support
Joined
·
15,478 Posts
The user has stated the issue is resolved. This thread will be closed, if you need it reopened plz pm a moderator
 
1 - 18 of 18 Posts
Status
Not open for further replies.
Top