Internet Explorer Fails to load from one user account

G

Guest

I'm using Windows XP Pro and I'm the administrator and only members of my
immediate family have access to this (home) computer. There are 4 of us.

I, am administrator on this machine but I am not able to run "Internet
Explorer 6.0" and surf the web from my account ( this is the most active
account on the machine). After logging in using my id When I try to run "IE"
(double click the "IE" icon), hour glass for 3 secs and may be tries to start
IE but nothing happens and "IE" cannot be accessed (doesn't load) ... .

However when I use another user ID with limited or Administrator
priviledges, I am able to use IE without any problems.

I've run, "ad-aware" and "Norton Anti-virus".

I didnt have any problem with IE till about 2 weeks back when this started
happening.

Can anyone help me?

Thanks
 
D

Don Varnau

Hi,
It's possible that malware has corrupted IE for some user accounts.
Work through the solutions ([1]CWShredder, [2]Ad-aware, [3]Spybot) at
http://mvps.org/winhelp2002/unwanted.htm Also note the security tips on that
page.

If that routine doesn't clean things up, go to
http://www.aumha.org/a/quickfix.htm Work through steps 1-3, then post a
HijackThis log for analysis (step 4.)

Additional information at:
The Parasite Fight http://www.aumha.org/a/quickfix.htm
More security tips at http://www.aumha.org/a/parasite.htm
Bugs, Glitches & Stuffups: http://www.mvps.org/inetexplorer/Darnit.htm

Hope this helps,
Don
 
G

Guest

Thanks for the help. I tried all the options but problems
still persists. Attaching the log frrom hijackthis.
Please advise :

Logfile of HijackThis v1.98.2
Scan saved at 11:19:44 AM, on 8/16/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\System32\Ati2evxx.exe
E:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
E:\WINDOWS\System32\inetsrv\inetinfo.exe
E:\Program Files\Norton AntiVirus\navapsvc.exe
E:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
E:\Program Files\Norton AntiVirus\SAVScan.exe
E:\WINDOWS\Explorer.EXE
E:\WINDOWS\System32\svchost.exe
E:\Program Files\Common Files\Symantec Shared\CCPD-
LC\symlcsvc.exe
E:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
E:\WINDOWS\System32\atiptaxx.exe
E:\Program Files\ltmoh\Ltmoh.exe
E:\WINDOWS\AGRSMMSG.exe
E:\Program Files\Common Files\Symantec Shared\ccApp.exe
E:\Program Files\Common Files\Real\Update_OB\realsched.exe
E:\Program Files\Messenger\msmsgs.exe
E:\WINDOWS\System32\ctfmon.exe
E:\Program Files\FullScr\notifier.exe
E:\WINDOWS\System32\taskmgr.exe
E:\WINDOWS\System32\notepad.exe
E:\My Shared Folder\Installers\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Search Bar =
http://red.clientapps.yahoo.com/customize/ie/defaults/sb/y
msgr/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Search Bar =
http://red.clientapps.yahoo.com/customize/ie/defaults/sb/y
msgr/*http://www.yahoo.com/ext/search/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start
Page =
http://red.clientapps.yahoo.com/customize/ie/defaults/stp/
ymsgr*http://my.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,
(Default) =
http://red.clientapps.yahoo.com/customize/ie/defaults/su/y
msgr/*http://www.yahoo.com
N3 - Netscape 7: user_pref
("browser.startup.homepage", "http://www.google.com/");
(E:\Documents and Settings\Anurag Moudgil\Application
Data\Mozilla\Profiles\default\1m53zs7z.slt\prefs.js)
N3 - Netscape 7: user_pref
("browser.search.defaultengine", "engine://E%3A%5CProgram%
20Files%5CNetscape%5CNetscape%5Csearchplugins%
5CSBWeb_01.src"); (E:\Documents and Settings\Anurag
Moudgil\Application
Data\Mozilla\Profiles\default\1m53zs7z.slt\prefs.js)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-
7695ECA05670} - E:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn0
\ycomp5_3_12_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-
784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 6.0
\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-
206D7942484F} - E:\Program Files\Spybot - Search &
Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-
8333-CF10577473F7} - e:\program
files\google\googletoolbar2.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-
FADC6B084872} - E:\Program Files\Norton
AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-
00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-
7859DF00B1D6} - E:\Program Files\Norton
AntiVirus\NavShExt.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-
892F-0090271D4F88} - E:\PROGRA~1\Yahoo!\COMPAN~1
\Installs\cpn0\ycomp5_3_12_0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-
009027A5CD4F} - e:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] E:\WINDOWS\IME\imjp8_1
\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] E:\WINDOWS\System32
\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] E:\WINDOWS\System32
\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [LtMoh] E:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility]
E:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb03.exe
O4 - HKLM\..\Run: [QuickTime Task] "E:\Program
Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "E:\Program Files\Common
Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] E:\PROGRA~1
\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [TkBellExe] "E:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SSC_UserPrompt] E:\Program
Files\Common Files\Symantec Shared\Security
Center\UsrPrmpt.exe
O4 - HKLM\..\RunOnce:
[Q828026] "E:\WINDOWS\INF\unregmp2.exe" /UpdateWMP
O4 - HKCU\..\Run: [MSMSGS] "E:\Program
Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\System32
\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] E:\Program Files\Yahoo!
\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Full Screen] E:\Program
Files\FullScr\notifier.exe /INIT
O4 - HKCU\..\Run: [Skype] "E:\Program
Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Mozilla Quick Launch] "E:\Program
Files\Netscape\Netscape\Netscp.exe" -turbo
O4 - Global Startup: Microsoft Office.lnk = E:\Program
Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = E:\Program
Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search -
res://e:\program
files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search -
file:///E:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward &Links -
res://e:\program
files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page -
res://e:\program
files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages -
res://e:\program
files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English -
res://e:\program
files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary -
file:///E:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps -
file:///E:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-
00010333D0AD} - E:\Program Files\Yahoo!
\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-
4E08-11D5-AD55-00010333D0AD} - E:\Program Files\Yahoo!
\Messenger\yhexbmes0521.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-
00C04F795683} - E:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program
Files\Messenger\MSMSGS.EXE
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE}
(TDServer Control) -
http://www.indianrail.gov.in/wfplayer/tdserver.cab
O16 - DPF: {02BED220-FBC7-4392-93A2-3A50B056F78E} -
http://down.plaxo.com/down/release/instub.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE}
(Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin/Av
Sniff.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} -
http://a1540.g.akamai.net/7/1540/52/20031216/qtinstall.inf
o.apple.com/mickey/us/win/QuickTimeInstaller.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5}
(Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/SharedContent/common/bi
n/cabsa.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999}
(YAddBook Class) -
http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suit
e/yautocomplete.cab
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java
Runtime Environment 1.4.1_02) -
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078}
(ActiveDataInfo Class) - https://www-
secure.symantec.com/techsupp/activedata/SymAData.dll
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7}
(ActiveDataObj Class) - https://www-
secure.symantec.com/techsupp/activedata/ActiveData.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6}
(McFreeScan Class) -
http://download.mcafee.com/molbin/iss-loc/vso/en-
us/tools/mcfscan/1,5,0,4321/mcfscan.cab

-----Original Message-----
Hi,
It's possible that malware has corrupted IE for some user accounts.
Work through the solutions ([1]CWShredder, [2]Ad-aware, [3]Spybot) at
http://mvps.org/winhelp2002/unwanted.htm Also note the security tips on that
page.

If that routine doesn't clean things up, go to
http://www.aumha.org/a/quickfix.htm Work through steps 1- 3, then post a
HijackThis log for analysis (step 4.)

Additional information at:
The Parasite Fight http://www.aumha.org/a/quickfix.htm
More security tips at http://www.aumha.org/a/parasite.htm
Bugs, Glitches & Stuffups: http://www.mvps.org/inetexplorer/Darnit.htm

Hope this helps,
Don
--
MVP IE/OE

"AnuragMoudgil"
news:A2F238B2-9D38-4FD0-B215-
(e-mail address removed)...
I'm using Windows XP Pro and I'm the administrator and only members of my
immediate family have access to this (home) computer. There are 4 of us.

I, am administrator on this machine but I am not able to run "Internet
Explorer 6.0" and surf the web from my account ( this is the most active
account on the machine). After logging in using my id
When I try to run
"IE"
(double click the "IE" icon), hour glass for 3 secs
and may be tries to
start
IE but nothing happens and "IE" cannot be accessed (doesn't load) ... .

However when I use another user ID with limited or Administrator
priviledges, I am able to use IE without any problems.

I've run, "ad-aware" and "Norton Anti-virus".

I didnt have any problem with IE till about 2 weeks back when this started
happening.

Can anyone help me?

Thanks

.
 
D

Don Varnau

Hi,
I saw your HJT log at http://forum.aumha.org/viewforum.php?f=30 and it looks
pretty clean. But they'll do a much better analysis of it that I would. All
of the forums that analyze HJT logs are busy, but they'll get to you.

Regards,
Don
--
MVP IE/OE
Please reply to the newsgroup so that others may participate.

Thanks for the help. I tried all the options but problems
still persists. Attaching the log frrom hijackthis.
Please advise :

Logfile of HijackThis v1.98.2
Scan saved at 11:19:44 AM, on 8/16/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
[SNIPPED]
-----Original Message-----
Hi,
It's possible that malware has corrupted IE for some user accounts.
Work through the solutions ([1]CWShredder, [2]Ad-aware, [3]Spybot) at
http://mvps.org/winhelp2002/unwanted.htm Also note the security tips on that
page.

If that routine doesn't clean things up, go to
http://www.aumha.org/a/quickfix.htm Work through steps 1- 3, then post a
HijackThis log for analysis (step 4.)

Additional information at:
The Parasite Fight http://www.aumha.org/a/quickfix.htm
More security tips at http://www.aumha.org/a/parasite.htm
Bugs, Glitches & Stuffups: http://www.mvps.org/inetexplorer/Darnit.htm

Hope this helps,
Don
"AnuragMoudgil"
news:A2F238B2-9D38-4FD0-B215-
(e-mail address removed)...
I'm using Windows XP Pro and I'm the administrator and only members of my
immediate family have access to this (home) computer. There are 4 of us.

I, am administrator on this machine but I am not able to run "Internet
Explorer 6.0" and surf the web from my account ( this is the most active
account on the machine). After logging in using my id
When I try to run
"IE"
(double click the "IE" icon), hour glass for 3 secs
and may be tries to
start
IE but nothing happens and "IE" cannot be accessed (doesn't load) ... .

However when I use another user ID with limited or Administrator
priviledges, I am able to use IE without any problems.

I've run, "ad-aware" and "Norton Anti-virus".

I didnt have any problem with IE till about 2 weeks back when this started
happening.

Can anyone help me?

Thanks
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top