one more thought - can you see anything unusual or the cause of the error in event viewer ?
Main Topics
Browse All TopicsThis machine is running Windows XP MCE. It was infected with Spyware and the owner tried some kind of a reinstallation (from the HP recovery files on the computer). It may have been a Service Pack downgrade in the process.
He brought it in to me and I removed all the remaining Spyware traces. It now scans clean with Ad Aware (2008 and then AE), SuperAntiSpyware, MalwareBytes, Spyware Doctor and Windows Defender.
Now IE7 flashes for a moment and then closes.
I reinstalled SP 2 and all updates. No joy.
I have tried removing IE7 and then IE 6 works fine.
I updated again to IE 7 (have tried from downloaded distributable and through Windows Update).
I registered the ieproxy.dll file (successful, but no help).
I am trying to see if SP 3 will help now.
I know this needs a full format and redo, but there is a language barrier with the people I am trying to help and I am not sure if they need any files off of this. It may come to that if I have no other choice.
Any new ideas?
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
There very well could have been tool bars removed with everything done to this computer. I do not specifically remember moving any, but I think it is likely. Why?
I did try to run the "no add-ons" version of IE 7 and it still behaves the same.
I have also opened Internet Options from the control panel and it is the IE 7 version so I tried the "Reset" under the advanced tab. No change.
In Internet Options, I can see Google Toolbar and soem Yahoo elements that have been disabled in the Manage Add-ons section of Programs.
then it could be not fully removed google or yahoo toolbar, even when they are not seen in add remove programs
try to download any toolbar remover you can get (rather a goog one)
http://www.softpedia.com/g
my "first search result" and see if this helps
I would additionally run this tool
http://www.ccleaner.com/
to get rid of any bad registry data
I forgot to mention I ran CCleaner already - that is always one of the first things I do (helps reduce scan times).
I have forgotten about ETR - that is a great tool (thanks for the reminder). Unfortunately, it doesn't look like it fixed it this time.
Yes, have tried rest a couple times.
I am remote in right now with TightVNC - I will run ETR again (in safe mode) later today when I go back to the office.
Download HijackThis to desktop - http://www.wilderssecurity
Choo
Have you tried ComboFix yet?
I created an entirely new profile and the same issue occurs in that.
I ran HiJackThis (log below).
Running ComboFix right now. Just finished, but still not working.
Logfile of HijackThis v1.99.1
Scan saved at 8:44:50 PM, on 2/1/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\csrss.
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\Ati2ev
C:\WINDOWS\system32\svchos
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\svchos
C:\WINDOWS\system32\svchos
C:\Program Files\Lavasoft\Ad-Aware\aa
C:\Program Files\Alwil Software\Avast4\aswUpdSv.e
C:\Program Files\Alwil Software\Avast4\ashServ.ex
C:\WINDOWS\system32\spools
C:\WINDOWS\system32\Ati2ev
C:\WINDOWS\Explorer.EXE
C:\Program Files\LSI SoftModem\agrsmsvc.exe
C:\WINDOWS\eHome\ehRecvr.e
C:\WINDOWS\eHome\ehSched.e
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\PROGRA~1\ALWILS~1\Avast
C:\WINDOWS\system32\ps2.ex
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon
C:\Program Files\TightVNC\WinVNC.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.e
C:\Program Files\Alwil Software\Avast4\ashWebSv.e
C:\WINDOWS\system32\dllhos
C:\WINDOWS\system32\wbem\w
C:\WINDOWS\System32\alg.ex
C:\WINDOWS\system32\wuaucl
C:\WINDOWS\system32\wbem\w
C:\Documents and Settings\Owner\Desktop\Hij
C:\WINDOWS\system32\vercls
R0 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\TightVNC\WinVNC.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.ex
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
O16 - DPF: {6414512B-B978-451D-A0D8-F
O16 - DPF: {6E32070A-766D-4EE6-879C-D
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aa
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.e
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2ev
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.ex
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.e
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.e
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\TightVNC\WinVNC.exe"
There are some items that need to be removed from your computer.
Open Notepad and copy/paste everything below this line:
File::
c:\windows\[u]0[/u]03647_.
c:\windows\[u]0[/u]03042_.
c:\documents and settings\Ricardo Jr\Application Data\wklnhst.dat
c:\windows\system32\config
Folder::
c:\documents and settings\Owner\PrivacIE
c:\documents and settings\HP_Administrator\
c:\windows\system32\config
c:\documents and settings\Default User\PrivacIE
c:\documents and settings\NetworkService\Pr
c:\documents and settings\All Users\Application Data\775604872
Save it to desktop and name it "CFScript.txt"
Drag CFScript.txt into ComboFix.exe and it should execute automatically.
If the drag doesn't work you'll need to get a LiveCD, for example BartPE and remove these files/folders. while they're offline.
After you do this if it's still occuring, does it happen in Safe Mode w/ networking?
Yea, those are legit processes. Have you tried a repair install of Windows? You know, booting to the CD, pressing Enter on the first page and after it detects that you've already got an XP install then you press R to do an in place upgrade? You'll need the MCE disc that came with it the PC. I would HIGHLY recommend using NLite to slipstream SP3 into the CD. It's very easy to do, just follow the instructions here - http://lifehacker.com/3865
I wouldn't bother with all the other updates, just SP3 if the disc doesn't already have it. From there after the repair you'll have IE6 back on it. Go to Windows Updates and get it up to date with IE7 and patches.
This will overwrite system files that may have become corrupt. But be sure you use the MCE disc with SP3 slipstreamed. Don't overwrite your current SP3 state with a disc that has anything but SP3.
Business Accounts
Answer for Membership
by: Roads_RoadsPosted on 2009-02-01 at 10:10:58ID: 23522151
does it have any additional toolbars installed ? or DID it have and you uninstalled it ?