having a problem n my internet explorer gets closed, now it has happened around 5 times
n it happens randomly when i less expect it the picture im attaching was with my hotmail
n when i click ok the page closes, i wonder if some one could tell me what is it n how can i solve it?
i tried to use hijackthis to check my computer but i got 2 errors n i dunno how to solve them
i also found some lines in my hosts about paypal. i tried to fix them with hijack but i couldnt so i did it manually, i wonder why i had around 5 lines of different paypal sites in my hosts
today i saw a process running but it seems to b a legal windows process, its called conime.exe
i scanned it with virus total n was clean
this is the info about conime
file description console IME
type Application
file version 6.0.6000.16386
product name Microsoft windows operating system
copyright microsoft corporation
size 67.0 kb
date modified 11/2/2006 4:45 Am
language english (united states)
is that a legal file ? i read that most of the time conime is a trojan , a backdoor registered to ghost …
can some one plse help me find out why my internet explorer crashes in windows vista n why i cant run hijackthis
i would appreciate any help
thx
this is the log file from hijack even though i think is not complete cuz it didnt get the proper access, i attach the pictures too
Logfile of HijackThis v1.99.1
Scan saved at 5:38:38 PM, on 11/23/2007
Platform: Unknown Windows (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16546)
Running processes:
C:Windowssystem32Dwm.exe
C:WindowsExplorer.EXE
C:Program FilesWindows DefenderMSASCui.exe
C:Program FilesToshibaPower SaverTPwrMain.exe
C:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe
C:WindowsRtHDVCpl.exe
C:Windowssystemw98eject.exe
C:Windowssystem32 askeng.exe
C:Program FilesMozilla Firefoxfirefox.exe
C:Windowssystem32Taskmgr.exe
C:Windowsexplorer.exe
C:Program FilesYahoo!MessengerYahooMessenger.exe
C:Program FilesWindows LiveMessengermsnmsgr.exe
C:Program FilesWinampwinamp.exe
C:Program FilesInternet Explorerieuser.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesCommon FilesMicrosoft SharedWindows LiveWLLoginProxy.exe
X:Downloadshijackthis_199HijackThis.exe

R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
http://www.internetpolyglot.com/R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL =
http://www.toshibadirect.com/dpdstartR1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 – HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R0 – HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 – HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
O1 – Hosts: ::1 localhost
O2 – BHO: Adobe PDF Reader Link Helper – {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} – C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll
O2 – BHO: SSVHelper Class – {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} – C:Program FilesJavajre1.6.0_03inssv.dll
O2 – BHO: Windows Live Sign-in Helper – {9030D464-4C02-4ABF-8ECC-5164760863C6} – C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O4 – HKLM..Run: [Windows Defender] %ProgramFiles%Windows DefenderMSASCui.exe -hide
O4 – HKLM..Run: [SVPWUTIL] C:Program FilesTOSHIBAUtilitiesSVPWUTIL.exe SVPwUTIL
O4 – HKLM..Run: [TPwrMain] %ProgramFiles%TOSHIBAPower SaverTPwrMain.EXE
O4 – HKLM..Run: [avgnt] “C:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe” /min
O4 – HKLM..Run: [RtHDVCpl] RtHDVCpl.exe
O4 – HKLM..Run: [Skytel] Skytel.exe
O4 – HKLM..Run: [MSConfig] “C:WindowsSystem32msconfig.exe” /auto
O4 – Global Startup: w98Eject.lnk = C:Windowssystemw98eject.exe
O8 – Extra context menu item: E&xport to Microsoft Excel – res://C:PROGRA~1MICROS~3Office12EXCEL.EXE/3000
O9 – Extra button: (no name) – {08B0E5C0-4FCB-11CF-AAA5-00401C608501} – C:Program FilesJavajre1.6.0_03inssv.dll
O9 – Extra Tools menuitem: Sun Java Console – {08B0E5C0-4FCB-11CF-AAA5-00401C608501} – C:Program FilesJavajre1.6.0_03inssv.dll
O9 – Extra button: Send to OneNote – {2670000A-7350-4f3c-8081-5663EE0C6C49} – C:PROGRA~1MICROS~3Office12ONBttnIE.dll
O9 – Extra Tools menuitem: S&end to OneNote – {2670000A-7350-4f3c-8081-5663EE0C6C49} – C:PROGRA~1MICROS~3Office12ONBttnIE.dll
O9 – Extra button: Research – {92780B25-18CC-41C8-B9BE-3C9C571A8263} – C:PROGRA~1MICROS~3Office12REFIEBAR.DLL
O10 – Unknown file in Winsock LSP: c:windowssystem32
laapi.dll
O10 – Unknown file in Winsock LSP: c:windowssystem32
apinsp.dll
O11 – Options group: [INTERNATIONAL] International*
O13 – Gopher Prefix:
O16 – DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) –
http://cdn.scan.onecare.live.com/res…/wlscctrl2.cabO16 – DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) –
http://gfx1.hotmail.com/mail/w2/reso…PUpldro-ro.cabO16 – DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) –
http://www.systemrequirementslab.com/sysreqlab2.cabO17 – HKLMSystemCCSServicesTcpip..{F9211472-6EE8-4E26-BD29-D14B804790CF}: NameServer = 200.13.249.101,200.75.78.78
O18 – Protocol: livecall – {828030A1-22C1-4009-854F-8E305202313F} – C:PROGRA~1WI1F86~1MESSEN~1MSGRAP~1.DLL
O18 – Protocol: ms-help – {314111C7-A502-11D2-BBCA-00C04F8EC294} – C:Program FilesCommon FilesMicrosoft SharedHelphxds.dll
O18 – Protocol: msnim – {828030A1-22C1-4009-854F-8E305202313F} – C:PROGRA~1WI1F86~1MESSEN~1MSGRAP~1.DLL
O18 – Filter hijack: text/xml – {807563E5-5146-11D5-A672-00B0D022E945} – C:PROGRA~1COMMON~1MICROS~1OFFICE12MSOXMLMF.DLL
O20 – Winlogon Notify: psfus – C:Windowssystem32psqlpwd.dll
O23 – Service: Agere Modem Call Progress Audio (AgereModemAudio) – Agere Systems – C:Windowssystem32agrsmsvc.exe
O23 – Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) – Avira GmbH – C:Program FilesAviraAntiVir PersonalEdition Classicsched.exe
O23 – Service: AntiVir PersonalEdition Classic Guard (AntiVirService) – Avira GmbH – C:Program FilesAviraAntiVir PersonalEdition Classicavguard.exe
O23 – Service: Ati External Event Utility – ATI Technologies Inc. – C:Windowssystem32Ati2evxx.exe
O23 – Service: ConfigFree Service (CFSvcs) – TOSHIBA CORPORATION – C:Program FilesTOSHIBAConfigFreeCFSvcs.exe
O23 – Service: @%SystemRoot%ehomeehstart.dll,-101 (ehstart) – Unknown owner – %windir%system32svchost.exe (file missing)
O23 – Service: InstallDriver Table Manager (IDriverT) – Macrovision Corporation – C:Program FilesCommon FilesInstallShieldDriver1150Intel 32IDriverT.exe
O23 – Service: pinger – Unknown owner – C:ToshibaIVPISMpinger.exe
O23 – Service: @%SystemRoot%system32qwave.dll,-1 (QWAVE) – Unknown owner – %windir%system32svchost.exe (file missing)
O23 – Service: @%SystemRoot%system32seclogon.dll,-7001 (seclogon) – Unknown owner – %windir%system32svchost.exe (file missing)
O23 – Service: Swupdtmr – Unknown owner – c:ToshibaIVPswupdateswupdtmr.exe
O23 – Service: TOSHIBA Optical Disc Drive Service (TODDSrv) – TOSHIBA Corporation – C:Windowssystem32TODDSrv.exe
O23 – Service: TOSHIBA Power Saver (TosCoSrv) – TOSHIBA Corporation – C:Program FilesToshibaPower SaverTosCoSrv.exe
O23 – Service: @%ProgramFiles%Windows Media Playerwmpnetwk.exe,-101 (WMPNetworkSvc) – Unknown owner – %ProgramFiles%Windows Media Playerwmpnetwk.exe (file missing)