Forum Home
Press F1
 
Thread ID: 57674 2005-05-09 09:05:00 %THISDIRNAME% mumbo (8069) Press F1
Post ID Timestamp Content User
353657 2005-05-20 08:04:00 i am with iprimus.com.au. I suppose the site has its ip address somewhere mumbo (8069)
353658 2005-05-23 07:23:00 Have done that. now hijack this reads:
Logfile of HijackThis v1.99.1
Scan saved at 4:03:31 PM, on 23/05/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v5.50 (5.50.4134.0100)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE FIREWALL\CPD.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\ACCSTAT.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE FIREWALL\CPDCLNT.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\LXDBOXCP.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\OCBTRAY.EXE
C:\WINDOWS\SYSTEM\LVCOMS.EXE
C:\WINDOWS\SYSTEM32\DRIVERS\KODAKCCS.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\WEBSHOTS\WEBSHOTS.SCR
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE
C:\PROGRAM FILES\KODAK\KODAK EASYSHARE SOFTWARE\BIN\EASYSHARE.EXE
C:\PROGRAM FILES\INCREDIMAIL\BIN\IMAPP.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\TEMP\TD_0001.DIR\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = google.icq.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.icq.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ninemsn.com.au/
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRAM FILES\ICQTOOLBAR\TOOLBAR.DLL
F1 - win.ini: run=lxdboxcp.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRAM FILES\ICQTOOLBAR\TOOLBAR.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [OWCCardbusTray] ocbtray.exe
O4 - HKLM\..\Run: [LVComs] C:\WINDOWS\SYSTEM\LVComS.exe
O4 - HKLM\..\Run: [KodakCCS] C:\WINDOWS\System32\Drivers\KodakCCS.exe
O4 - HKLM\..\Run: [ICSMGR] ICSMGR.EXE
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [McAfee Firewall] "C:\PROGRAM FILES\MCAFEE\MCAFEE FIREWALL\CPD.EXE" /SERVICE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [IncrediMail] C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Startup: WKCALREM.LNK = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
O4 - Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\PROGRAM FILES\ICQTOOLBAR\TOOLBAR.DLL/SEARCH.HTML
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - www5.incredimail.com
O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - sc.groups.msn.com
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) - www.webshots.com
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - messenger.msn.com

Then I get a error box reading loadqm has caused an error in <unknown> Loadqm will now close.
if you continue to experience problems try restarting your computer.
I still can't get any web pages etc.
mumbo (8069)
353659 2005-05-23 07:35:00 That log looks clean.

See if this support.microsoft.com helps.
Speedy Gonzales (78)
353660 2005-05-23 07:42:00 Try disabling loadqm from starting each time the computer boots up. It is used as part of Windows Autoupdating, but may cause internet problems. To disable it go Start > Run. Enter in msconfig - OK. Under the Startup Tab look for loadqm.exe and remove the tick from beside it. Click Apply and OK. Restart the computer, and when you see the message about using Selective Startup for Troubleshooting, put a tick beside "Don't show this message again" and click OK. See if this helps with the internet access. Jen (38)
353661 2005-05-25 07:57:00 I have disabled loadqm but still no luck getting onto the internet. The virus must have destroyed a crutial file or something. I went into system information internet settings /file versions to see if everything was there. It appears a few files are missing. Is this right?
advapi32.dll 4.90.0.3000 64 KB 8/06/2000 5:00:00 PM C:\WINDOWS\SYSTEM Microsoft Corporation
advpack.dll 5.50.4134.100 90 KB 8/06/2000 5:00:00 PM C:\WINDOWS\SYSTEM Microsoft Corporation
browselc.dll 5.50.4134.100 44 KB 8/06/2000 5:00:00 PM C:\WINDOWS\SYSTEM Microsoft Corporation
browseui.dll 5.50.4134.100 804 KB 8/06/2000 5:00:00 PM C:\WINDOWS\SYSTEM Microsoft Corporation
ckcnv.exe File not present Not Available Not Available Not Available
comctl32.dll 5.81.4134.100 568 KB 8/06/2000 5:00:00 PM C:\WINDOWS\SYSTEM Microsoft Corporation
crypt32.dll 5.131.2133.3 464 KB 8/06/2000 5:00:00 PM C:\WINDOWS\SYSTEM Microsoft Corporation
enhsig.dll File not present Not Available Not Available Not Available
iemigrat.dll File not present Not Available Not Available Not Available
iesetup.dll 5.50.4134.100 68 KB 8/06/2000 5:00:00 PM C:\WINDOWS\SYSTEM Microsoft Corporation
iexplore.exe 5.50.4134.100 72 KB 8/06/2000 5:00:00 PM C:\Program Files\Internet Explorer Microsoft Corporation
imagehlp.dll 5.0.2178.1 140 KB 8/06/2000 5:00:00 PM C:\WINDOWS\SYSTEM Microsoft Corporation
inseng.dll 5.50.4134.100 84 KB 8/06/2000 5:00:00 PM C:\WINDOWS\SYSTEM Microsoft Corporation
jobexec.dll 5.0.0.1 60 KB 8/06/2000 5:00:00 PM C:\WINDOWS\SYSTEM Microsoft Corporation
jscript.dll 5.6.0.8513 576 KB 13/01/2003 2:57:58 PM C:\WINDOWS\SYSTEM Microsoft Corporation
jsproxy.dll 5.50.4134.100 24 KB 8/06/2000 5:00:00 PM C:\WINDOWS\SYSTEM Microsoft Corporation
mshtml.dll 5.50.4134.100 2604 KB 8/06/2000 5:00:00 PM C:\WINDOWS\SYSTEM Microsoft Corporation
msjava.dll 5.0.3810.0 925 KB 28/02/2003 6:26:26 PM C:\WINDOWS\SYSTEM Microsoft Corporation
msoss.dll File not present Not Available Not Available Not Available
msxml.dll 8.0.5226.0 516 KB 8/06/2000 5:00:00 PM C:\WINDOWS\SYSTEM Microsoft Corporation
occache.dll 5.50.4134.100 96 KB 8/06/2000 5:00:00 PM C:\WINDOWS\SYSTEM Microsoft Corporation
ole32.dll 4.71.3328.0 776 KB 8/06/2000 5:00:00 PM C:\WINDOWS\SYSTEM Microsoft Corporation
oleaut32.dll 2.40.4515.0 600 KB 8/06/2000 5:00:00 PM C:\WINDOWS\SYSTEM Microsoft Corporation
olepro32.dll 5.0.4515.0 160 KB 8/06/2000 5:00:00 PM C:\WINDOWS\SYSTEM Microsoft Corporation
rsabase.dll 5.0.2133.2 101 KB 8/06/2000 5:00:00 PM C:\WINDOWS\SYSTEM Microsoft Corporation
rsaenh.dll 5.0.2133.2 102 KB 8/06/2000 5:00:00 PM C:\WINDOWS\SYSTEM Microsoft Corporation
rasapi32.dll 4.90.0.3000 244 KB 8/06/2000 5:00:00 PM C:\WINDOWS\SYSTEM Microsoft Corporation
rsasig.dll File not present Not Available Not Available Not Available
schannel.dll 4.89.1962.2133 114 KB 8/06/2000 5:00:00 PM C:\WINDOWS\SYSTEM Microsoft Corporation
shdoc401.dll File not present Not Available Not Available Not Available
shdocvw.dll 5.50.4134.100 1132 KB 8/06/2000 5:00:00 PM C:\WINDOWS\SYSTEM Microsoft Corporation
shell32.dll 5.50.4134.100 2228 KB 8/06/2000 5:00:00 PM C:\WINDOWS\SYSTEM Microsoft Corporation
shlwapi.dll 5.50.4134.100 295 KB 8/06/2000 5:00:00 PM C:\WINDOWS\SYSTEM Microsoft Corporation
url.dll 5.50.4134.100 96 KB 8/06/2000 5:00:00 PM C:\WINDOWS\SYSTEM Microsoft Corporation
urlmon.dll 5.50.4134.100 460 KB 8/06/2000 5:00:00 PM C:\WINDOWS\SYSTEM Microsoft Corporation
vbscript.dll 5.6.0.7426 452 KB 26/02/2002 3:58:06 PM C:\WINDOWS\SYSTEM Microsoft Corporation
webcheck.dll 5.50.4134.100 264 KB 8/06/2000 5:00:00 PM C:\WINDOWS\SYSTEM Microsoft Corporation
win.com Not Available 18 KB 8/06/2000 5:00:00 PM C:\WINDOWS Not Available
wininet.dll 5.50.4134.100 484 KB 8/06/2000 5:00:00 PM C:\WINDOWS\SYSTEM Microsoft Corporation
winsock.dll 4.90.0.3000 21 KB 14/05/2005 5:07:44 PM C:\WINDOWS Microsoft Corporation
wintrust.dll 5.131.2133.2 172 KB 8/06/2000 5:00:00 PM C:\WINDOWS\SYSTEM Microsoft Corporation
wsock.vxd 4.90.0.3000 15 KB 8/06/2000 5:00:00 PM C:\WINDOWS\SYSTEM Microsoft Corporation
wsock32.dll 4.90.0.3000 36 KB 8/06/2000 5:00:00 PM C:\WINDOWS\SYSTEM Microsoft Corporation
wsock32n.dll File not present Not Available Not Available Not Available
Would these missing files be causing me to not find the web pages?
mumbo (8069)
353662 2005-05-25 08:13:00 Hmm this post

forums.pcworld.co.nz

This person had the same prob but with 98 SE. All he/she did was reinstall Internet Explorer.

Try reinstalling IE.
Speedy Gonzales (78)
353663 2005-05-25 08:40:00 how do I reinstall IE? Do I have to uninstall it first and wher is it - not in the program list in add/remove mumbo (8069)
353664 2005-05-25 08:47:00 No need to uninstall it well since it isnt there anyway!

Just download it from the MS site or from a cd, and install over the top of it.

IE 6 SP1
Speedy Gonzales (78)
353665 2005-05-25 09:03:00 thanks very much for your patince. Lets hope it works mumbo (8069)
353666 2005-05-25 09:04:00 thanks very much for your patience. Let's hope this works mumbo (8069)
1 2 3