msn browser keeps closing. Help

Discussion in 'Windows - Virus and spyware problems' started by dymx, May 23, 2008.

  1. dymx

    dymx Guest

    I am currently using firefox but just installed the msn browser. I use to have it on my c but uninstalled it. Anyways, every time I sign in, it goes to the msn homepage but when I try to type a url the browser automatically closes. I just did a virus scan and my pc is clean. I just ran hijackthis and below is the log.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 12:31:58 PM, on 5/12/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16414)
    Boot mode: Normal

    Running processes:
    C:\NEBULOS\System32\smss.exe
    C:\NEBULOS\system32\winlogon.exe
    C:\NEBULOS\system32\services.exe
    C:\NEBULOS\system32\lsass.exe
    C:\NEBULOS\system32\svchost.exe
    C:\NEBULOS\System32\svchost.exe
    C:\NEBULOS\system32\svchost.exe
    C:\NEBULOS\system32\spoolsv.exe
    C:\NEBULOS\Explorer.EXE
    C:\NEBULOS\system32\mmm.exe
    C:\Programs\SNP Software\StartupMonitor\StartupMonitor.exe
    C:\Programs\Gamevance\gamevance32.exe
    C:\NEBULOS\system32\ctfmon.exe
    C:\Programs\TaskSwitchXP\TaskSwitchXP.exe
    C:\Programs\Eraser\eraser.exe
    C:\Programs\MSN Messenger\msnmsgr.exe
    C:\Programs\Mozilla Firefox\firefox.exe
    C:\Programs\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programs\Yahoo!\Companion\Installs\cpn\yt.dll
    R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Programs\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programs\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Programs\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
    O2 - BHO: Gamevance Text - {7370F91F-6994-4595-9949-601FA2261C8D} - C:\Programs\Gamevance\gvtl.dll
    O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Programs\Internet\NetTransport\NTIEHelper.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programs\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\NEBULOS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\NEBULOS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\NEBULOS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [PowerTweak Menu] C:\NEBULOS\system32\mmm.exe
    O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Programs\Unlocker\UnlockerAssistant.exe"
    O4 - HKLM\..\Run: [StartupMonitor] "C:\Programs\SNP Software\StartupMonitor\StartupMonitor.exe"
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Programs\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [Gamevance] C:\Programs\Gamevance\gamevance32.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\NEBULOS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [TaskSwitchXP] C:\Programs\TaskSwitchXP\TaskSwitchXP.exe
    O4 - HKCU\..\Run: [Eraser] C:\Programs\Eraser\eraser.exe -hide
    O4 - HKCU\..\Run: [DAEMON Tools] "C:\Programs\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKCU\..\Run: [msnmsgr] "C:\Programs\MSN Messenger\msnmsgr.exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\NEBULOS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [TaskSwitchXP] C:\Programs\TaskSwitchXP\TaskSwitchXP.exe (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [Eraser] C:\Programs\Eraser\eraser.exe -hide (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\NEBULOS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-20\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\NEBULOS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\NEBULOS\system32\CTFMON.EXE (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
    O8 - Extra context menu item: Download all by Net Transport - C:\Programs\Internet\NetTransport\NTAddList.html
    O8 - Extra context menu item: Download by Net Transport - C:\Programs\Internet\NetTransport\NTAddLink.html
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\NEBULOS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\NEBULOS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programs\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programs\Messenger\MSMSGS.EXE
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programs\Yahoo!\Common\yinsthelper.dll
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\NEBULOS\system32\ZoneLabs\vsmon.exe

    --
    End of file - 5250 bytes
     
  2. dymx

    dymx Guest

    anyone?
     
  3. svtstang

    svtstang Regular member

    Joined:
    Apr 23, 2006
    Messages:
    4,564
    Likes Received:
    0
    Trophy Points:
    46
    Fix these, reboot, and please post again.

    R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Programs\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL

    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\NEBULOS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\NEBULOS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\NEBULOS\system32\CTFMON.EXE (User 'SYSTEM')

    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\NEBULOS\system32\CTFMON.EXE (User 'Default user')

    O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
     

Share This Page