1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

IE6 corrupts a link address

Discussion in 'Internet Explorer & Microsoft Edge' started by LarryB, 2004/03/20.

Thread Status:
Not open for further replies.
  1. 2004/03/25
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Blocks alot of those baddies from ever getting in. If you use it, check the silent mode or you'll go crazy with popups telling you it's blocking this or that everywhere you go. Markp62 has a link to another program in his signature that does much the same thing, and maybe more, called IEspyads.zip.
     
  2. 2004/03/25
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    Fix or remove this one using IE options
    O15 - Trusted Zone: ebay.doubleclick.net

    fix these also(with IE closed)

    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about :blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about :blank
    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O4 - HKCU\..\Run: [ClockSync] C:\PROGRA~1\CLOCKS~1\Sync.exe /qMore information

    Uninstall ClockSync then let Adaware or SpyBot clean up after it.

    And reboot come back rescan with hijackthis and post a fresh log
    This time all of it we need the header info to, all the way through to the bottom.

    would you summarize for me th problems your having, ?
    any search abnormalities ?

    =========
    O4 - HKCU\..\Run: [Ehas] C:\WINDOWS\Application Data\crch.exe
    would you check the properties of this file please ?

    aboutImmunization

    Dave makes a good point "Did you edit your startup entries in msconfig?" if so enable them reboot come back scan with hijackthis then post a log :)
     

  3. to hide this advert.

  4. 2004/03/26
    LarryB

    LarryB Well-Known Member Thread Starter

    Joined:
    2002/01/09
    Messages:
    847
    Likes Received:
    10
    Everything has been done exc for the ebay.doubleclick as I need that to work in order to use ebay. Even crch.exe is gone.

    Though I am mean and lean, the problem persists. You would like another synopsis. Here it is.

    The links to item pages on ebay notification emails do not work. They do at work, but not at home. Instead of going to the item page , they go to an "Invalid Item" page. It is because somehow, the link address is changed by the addition of "amp;" to it 92 of them actually). I have found that in between clicking the link and the page opening up fully, there is an interim address that flashes in the address bar.

    Original link in the email:

    http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem&item=4002600958&ssPageName=ADME:B:BN:US:1
    The interim llink is:

    http://proxy-mail.mailcity.lycos.com/bin/redirector.cgi?class=1&url=http%3a%2f%2fcgi%2eebay%2ecom%2fws%2feBayISAPI%2edll%3fViewItem%26amp%3bitem%3d4002600958%26amp%3bssPageName%3dADME%3aB%3aBN%3aUS%3a1&uuid=5464&partner_key=mailcity
    and the final link is:

    http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem&[/url]amp;item=4002600958&ssPageName=ADME:B:BN:US:1

    The first and last are identical exc for the addition of 2 "amp; "s (bolded). The text of the invalid message states:

    "The item you requested () is invalid, still pending, or no longer in our database. Please check the number and try again. If this message persists, the item has either not started and is not yet available for viewing, or has expired and is no longer available. "

    Removal of the first "amp;" allows the page to open properly, the second seems superfluous.

    Here is my latest HJT log with header:

    Logfile of HijackThis v1.97.3
    [edited out to save space since its and old version]
    Thanks a lot to both Dave and Lonny for your efforts! Lar
     
    Last edited: 2004/03/26
  5. 2004/03/26
    LarryB

    LarryB Well-Known Member Thread Starter

    Joined:
    2002/01/09
    Messages:
    847
    Likes Received:
    10
    I would like to add something significant. I just took the email from Lycos and forwarded it to my OE acct at Earthlink. From OE, the link works fine. So, it does only happen from the Lycos webmail. Lycos does have some kind of association with mailcity and interim link listed above is plastered with it.

    Something to do with that interim conversion to encode and back to http that it gets messed up?

    Jim Welsh mentioned earlier a possible search engine refferer (whatever that is)?

    Lycos did always do this.
     
    Last edited: 2004/03/26
  6. 2004/03/26
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    I know almost nothing of OE or mailcity, lycos.

    Do you have the option in the right click context menu to copy shortcut, maybe that would help ?


    And PS using an old version could be harmfull HijackThis v1.97.3
    please replace yours and post another log it may pick something else up. but I dont think tis is the problem
    http://tomcoyote.com/hjt/
     
  7. 2004/03/26
    LarryB

    LarryB Well-Known Member Thread Starter

    Joined:
    2002/01/09
    Messages:
    847
    Likes Received:
    10
    Hi Lonny, I just had a frightening revelation. I earlier mentioned that I have been getting these weird little files in c: root. I just noticed a new one called "~" and it contained 231kb. After putting a few different extensions on it to see if I could read it, adding ".html" allowed me to read about 60% of it... and it looked like the contents of my ADDRESS BOOK!!!!!!!!

    I have run 3 AV programs, spybot, Adaware and HJT. Could there be more?? I am going to update the HJT as you suggested.

    New log:

    Logfile of HijackThis v1.97.7
    Scan saved at 11:41:26 PM, on 3/25/04
    Platform: Windows 98 SE (Win9x 4.10.2222A)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\SYSTEM\ATI2EVXX.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
    C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON CLEANSWEEP\CSINJECT.EXE
    C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON UTILITIES\NPROTECT.EXE
    C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SYMTRAY.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\LOGITECH\MOUSE\SYSTEM\EM_EXEC.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\STIMON.EXE
    C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE
    C:\WINDOWS\SYSTEM\HPZTSB07.EXE
    C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\WINDOWS\SYSTEM\TBCTRAY.EXE
    C:\PROGRAM FILES\QUICK RESOURCE V2.01\QUICKRESOURCE201\QUICKRESOURCE.EXE
    C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\MSOFFICE.EXE
    C:\PROGRAM FILES\EXIT 95-98\EXITS95.EXE
    C:\PROGRAM FILES\LANLED\LANLED.EXE
    C:\PROGRAM FILES\PRINKEY 2000 V5.1\PRINTKEY2000.EXE
    C:\PROGRAM FILES\IE NEW WINDOW MAXIMIZER\IEMAXIMIZER.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\WINDOWS\SYSTEM\PSTORES.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
    E:\DOWNLOADS\HIJACKTHIS 1.97\HIJACKTHIS.EXE

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://login.mail.lycos.com/frameset.nlshtml?goto=jumpPage
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8080
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
    O2 - BHO: EarthLink Popup Blocker - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - C:\PROGRAM FILES\EARTHLINK POP-UP BLOCKER\PNEL.DLL
    O2 - BHO: (no name) - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Net Transport\NTIEHelper.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Pop-Up Blocker - {D7F30B62-8269-41AF-9539-B2697FA7D77E} - C:\PROGRAM FILES\EARTHLINK POP-UP BLOCKER\PNEL.DLL
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [EM_EXEC] c:\logitech\mouse\system\em_exec.exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
    O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
    O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb07.exe
    O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe "
    O4 - HKLM\..\Run: [ccRegVfy] "c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe "
    O4 - HKLM\..\Run: [TraySantaCruz] C:\WINDOWS\SYSTEM\TBCTRAY.EXE
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [ATIPOLL] ati2evxx.exe
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [ccEvtMgr] "c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe "
    O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
    O4 - HKLM\..\RunServices: [CSINJECT.EXE] c:\Program Files\Norton SystemWorks\Norton CleanSweep\CSINJECT.EXE
    O4 - HKLM\..\RunServices: [NPROTECT] c:\Program Files\Norton SystemWorks\Norton Utilities\nprotect.exe
    O4 - HKLM\..\RunServices: [SymTray - Norton SystemWorks] c:\Program Files\Common Files\Symantec Shared\SymTray.exe "Norton SystemWorks "
    O4 - HKLM\..\RunOnce: [washindex] C:\Program Files\Cookie Washer\washidx.exe "Larry Block "
    O4 - HKCU\..\RunOnce: [washindex] C:\Program Files\Cookie Washer\washidx.exe "Larry Block "
    O4 - Startup: Event Reminder.lnk = C:\Program Files\Mindscape\PrintMaster\PMREMIND.EXE
    O4 - Startup: QuickResource.lnk = C:\Program Files\Quick Resource v2.01\quickresource201\QuickResource.exe
    O4 - Startup: Microsoft Office Shortcut Bar.Lnk = C:\Program Files\Microsoft Office\Office\MSOFFICE.EXE
    O4 - Startup: POWERR~1.EXE
    O4 - Startup: Exits95-98.lnk = C:\Program Files\Exit 95-98\Exits95.exe
    O4 - Startup: LanLed.lnk = C:\Program Files\LANLED\LANLED.EXE
    O4 - Startup: Printkey2000.lnk = C:\Program Files\Prinkey 2000 v5.1\Printkey2000.exe
    O4 - Startup: iemaximizer.exe.lnk = C:\Program Files\IE New Window Maximizer\iemaximizer.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: Open Frame in &New Window - C:\WINDOWS\WEB\frm2new.htm
    O8 - Extra context menu item: &Highlight - C:\WINDOWS\WEB\highlight.htm
    O8 - Extra context menu item: &Web Search - C:\WINDOWS\WEB\selsearch.htm
    O8 - Extra context menu item: &Links List - C:\WINDOWS\WEB\urllist.htm
    O8 - Extra context menu item: Zoom &In - C:\WINDOWS\WEB\zoomin.htm
    O8 - Extra context menu item: Zoom O&ut - C:\WINDOWS\WEB\zoomout.htm
    O8 - Extra context menu item: I&mages List - C:\WINDOWS\Web\imglist.htm
    O8 - Extra context menu item: Download all by Net Transport - C:\PROGRA~1\XI\NETTRA~1\NTAddList.html
    O8 - Extra context menu item: Download by Net Transport - C:\PROGRA~1\XI\NETTRA~1\NTAddLink.html
    O9 - Extra button: AIM (HKLM)
    O9 - Extra button: ATI TV (HKLM)
    O9 - Extra button: Researcher (HKLM)
    O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
    O15 - Trusted Zone: ebay.doubleclick.net


    Thanks, Larry
     
    Last edited: 2004/03/26
  8. 2004/03/26
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
  9. 2004/03/26
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    It might be best to keep hijackthis in C:\

    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    Fix those unless set with spybot, and read about it in the help file, it realy offers no protection, except against your other PC users, ven then usualy they can still access ie options through control panel.
    since you need those cookies doubleclick, most likely have to uninstall SpyBots bad download blocker, (whoops is see its not installed)

    have you disabled your popup blocker then tried ebays email links through mailcity-lycos.

    Do you want the option in the right click context menu to copy shortcut's, maybe that would help ?
     
  10. 2004/03/26
    LarryB

    LarryB Well-Known Member Thread Starter

    Joined:
    2002/01/09
    Messages:
    847
    Likes Received:
    10
    Well that is a relief!!! MS bites it again. Thanks for your resourcefullness. I also mentioned that I get a bunch of Germanic files names with no extensions and no bytes like:

    ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ|||¿¿¿¿¿¿¿¿¿¿¿¿¿¿¿¿¿¿¿¿¿¿

    or

    ßß|||

    Any clues? You seem to have seen just about everything!

    Thanks, Lar
     
  11. 2004/03/26
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
  12. 2004/03/26
    LarryB

    LarryB Well-Known Member Thread Starter

    Joined:
    2002/01/09
    Messages:
    847
    Likes Received:
    10
    They look pretty odd, too. I just keep deleting them.

    How did the new HJT log look? Are we at a dead end?

    Lar
     
  13. 2004/03/26
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    You might move the shortcuts out of the Startup folder to conserve on resources, especially office, I'm not familiar with
    iemaximizer.exe << good guy but is it really needed ?

    Other that that you log looks great, (I'm not a expert at logs though)


    I'm sure the others will have a clue on you email anomaly
     
  14. 2004/03/26
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Log looks good to me too, except for the 06 entries. I think you should try to contact Lycos about the email link problem. Something happening on their end I think, since it works fine through OE. Maybe their support KB has can shed some light. I'll try to dig around there too (cable is back up today :)).

    Keep us posted!
     
  15. 2004/03/26
    LarryB

    LarryB Well-Known Member Thread Starter

    Joined:
    2002/01/09
    Messages:
    847
    Likes Received:
    10
    I emailed their "support" last night. Their support is notoriously bad so I am not holding my breath. I may try to find additinoal peer support using Lycos as a key word, instead of IE. Not sure where yet, though. I cannot be the only one on the face of the earth with this issue. Maybe at ebay's support area.

    Regarding resources... I know that I should maximize them but I never bottom out and some of these lil 'ol applets (like IE Window Maximizer) just make my surfin' life a joy. A few vices are good for the soul, right?

    What are your thoughts on Pest Patrol software? I just ran into it (or it ran into me) and it seems pretty thorough.

    You guys have been great. I will post any further thoughts on this issue. Thanks!!

    Larry
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.