internet explorer problem

  sugarbabe 00:30 09 May 2010
Locked

I have just repaired laptop running xp which was hijacked with strange webpage. Now will not load internet explorer.
Tried ccleaner, adaware, spybot but always get same error message:

iexplorer.exe the instruction at 0x100071c5 referenced at 0x100071c5 the memory could not be read, click ok to terminate click on cancel to debug.

tried running xp scan sfc scannow and installed internet explorer 8

can open internet explorer in safe mode.

Any ideas??

  sugarbabe 00:56 09 May 2010

If i click on windows update internet explorer loads.

This is result i get when i run hijack this

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:52:32, on 09/05/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe
C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Acer\eManager\anbmServ.exe
C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
C:\Program Files\OLYMPUS\DeviceDetector\DM1Service.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = click here
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe /boot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates International Inc. - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: CA License Server (CA_LIC_SRVR) - Computer Associates International Inc. - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
O23 - Service: DM1Service - OLYMPUS OPTICAL CO.,LTD - C:\Program Files\OLYMPUS\DeviceDetector\DM1Service.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 3577 bytes

  birdface 09:02 09 May 2010

Sorry not got a clue about HJT.
iexplorer.exe I presume is a spelling mistake and you have added an R at the end which should not be there,
Try running Spybot with the tea timer switched off.
Download and update the free version of Malwarebytes and see what it finds.

click here

  fishmad pete 09:12 09 May 2010

Try running iexplorer without add ons. If iexplorer works in safe mode then its probably an add on that is causing the problem.
Click on start and select search. Type in iexplorer and click search. In the found box click on iexplorer without add ons.
If this works it will mean you will have to look through the add ons to find which one is causing the problem.
see here click here

  Fruit Bat /\0/\ 10:44 09 May 2010

There doesn't seem to be anything really nasty in that log.
A couple of things that slow the machine (tea timer-ctfmon)

The usual problem is your anti virus malware programs blocking access to svchost however I can't see an antivirus program only spybot,

what antivirus
antimalware
firewall
are you using?

  sugarbabe 10:44 09 May 2010

I tried with all add on's switched off still no joy
run malaware and spy bot found nothing.

Is there a way to completely remove and reinstall internet explorer. would that help??

  Pineman100 11:23 09 May 2010

I've no idea whether this will work, but you could try resetting Internet Explorer.

Go to Tools>Internet Options>Advanced tab, and click the Rest button.

  birdface 12:08 09 May 2010

Have you tried it with Spybot Tea Timer switched off.

  sugarbabe 12:51 09 May 2010

i've tried resetting internet explorer. will run spybot with tea timer turned off

  inspectorweb 14:05 21 May 2010

My suggestion. Download and install [url=click here]AnVir Task Manager[/url]. It also has free version. AnVir shows you all startup programs and Windows processes, so you’ll find harmful file within one minute. I always use it when I clean my PC. Sorry for the offtopic

This thread is now locked and can not be replied to.

Elsewhere on IDG sites

Alienware 17 R4 2017 review

These brilliant Lego posters show just what children's imaginations are capable of

Mac power user tips and hidden tricks

Comment réinitialiser votre PC, ordinateur portable ou tablette Windows ?