• Announcements

    • Budfred

      IE 11 copy/paste problem

      It has come to our attention that people using Internet Explorer 11 (IE 11) are having trouble with copy/paste to the forum. If you encounter this problem, using a different browser like Firefox or Chrome seems to get around the problem. We do not know what the problem is, but it seems to be specific to IE 11 and we are hopeful that Microsoft will eventually fix it.
Sign in to follow this  
Followers 0
lalo

start page res://lzuin.dll/index.html#2277

3 posts in this topic

Hi guys my problem is that everytime I open my internet browser my Start page changes to res://lzuin.dll/index.html#22776 or other .dll (xqfta for example) value. Ad ware tells me about the problem but fixing it seems to have no efect over it. Spy bot didnt find any problem on my computer so basically I dont know what to do.

 

I have hjt so if you want me to post my log file just tell me to do so.

 

Thank you guys.

Share this post


Link to post
Share on other sites

I have tried everything, ad aware on safe mode, everything and the problem is still on.

 

So here is my Log file

 

Logfile of HijackThis v1.97.7

Scan saved at 1:40:03 PM, on 7/2/2004

Platform: Windows XP SP1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\System32\ibmpmsvc.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\System32\S3Tray2.exe

C:\WINDOWS\System32\tp4serv.exe

C:\WINDOWS\System32\RunDll32.exe

C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe

C:\PROGRA~1\Norton\vptray.exe

C:\WINDOWS\LTSMMSG.exe

C:\WINDOWS\System32\AEIWLSTA.EXE

C:\program files\quicktime\qttask.exe

C:\WINDOWS\system32\mspe.exe

C:\Program Files\Winamp\Winampa.exe

C:\Program Files\Norton\defwatch.exe

C:\Program Files\Norton\rtvscan.exe

C:\WINDOWS\System32\QCONSVC.EXE

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\ZoneLabs\vsmon.exe

C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

C:\WINDOWS\System32\MsgSys.EXE

C:\WINDOWS\System32\wuauclt.exe

C:\WINDOWS\system32\atlpj32.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Documents and Settings\Eduardo\Desktop\Lalo\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = www.google.com

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = www.google.com

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\lzuin.dll/sp.html#22776

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://lzuin.dll/index.html#22776

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = www.google.com

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = www.google.com

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://lzuin.dll/index.html#22776

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = www.google.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\lzuin.dll/sp.html#22776

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://lzuin.dll/index.html#22776

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\lzuin.dll/sp.html#22776

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = www.google.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = www.google.com

O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll

O2 - BHO: (no name) - {DEAC95BA-B2B1-58A3-F1BA-F72755C50CEB} - C:\WINDOWS\system32\javaqg32.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll

O4 - HKLM\..\Run: [s3TRAY2] S3Tray2.exe

O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe

O4 - HKLM\..\Run: [bMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor

O4 - HKLM\..\Run: [TP4EX] tp4ex.exe

O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe

O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\Norton\vptray.exe

O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe

O4 - HKLM\..\Run: [AEIWLSTA.EXE] AEIWLSTA.EXE

O4 - HKLM\..\Run: [QuickTime Task] "C:\program files\quicktime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [mspe.exe] C:\WINDOWS\system32\mspe.exe

O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"

O4 - HKLM\..\Run: [Ad-aware] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe" +c

O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"

O4 - HKCU\..\Run: [spyware Begone] C:\Program Files\spyware\freescan.exe -FastScan

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html

O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html

O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html

O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html

O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html

O9 - Extra button: Messenger (HKLM)

O9 - Extra 'Tools' menuitem: Messenger (HKLM)

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab

O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab

O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...371/mcfscan.cab

Share this post


Link to post
Share on other sites

Download About:Buster by RubbeR DuckY from

 

http://www.atribune.org/downloads/AboutBuster.zip

 

Then Unzip it to your desktop. Do not run it yet. Print these directions or paste them into a text document as you will be running with your internet explorer closed. Restarting internet explorer may cause a reinfection.

 

Run another hijackthis scan place a check next to the following entries.

O2 - BHO: (no name) - {DEAC95BA-B2B1-58A3-F1BA-F72755C50CEB} - C:\WINDOWS\system32\javaqg32.dll

O4 - HKLM\..\Run: [mspe.exe] C:\WINDOWS\system32\mspe.exe

Then close all windows and click the fix checked button. Now startup About:Buster. Hit ok on the first prompt and then hit start. Next hit ok. Wait till the scan completes and copy the report and save it somewhere. Rerun About:Buster to make sure everything was deleted. Then restart your computer.

 

It is now safe to reopen Internet explorer. Please post a new hijack this log along with a report.

Share this post


Link to post
Share on other sites
Sign in to follow this  
Followers 0