Annoyances.org
Home » Windows 95 Discussion Forum » Message 1083750942 » Entire Thread Search | Help | Home
  
Internet options and security buttons greyed out!!
Showing all messages in thread #1083750942
Windows 95 Annoyances Discussion Forum


The following are all of the messages in this thread (7 in all), shown in chronological order. Click any message subject to view that message by itself or to view the thread hierarchy.
Internet options and security buttons greyed out!!
Wednesday, May 5, 2004 at 2:55 am
Posted by Jerlyn (4 messages posted)

I can't change my homepage in my internet options. The whole box is greyed out. So, i downloaded some spyware remover and everything was fine, but when i restart my computer the next time the homepage is back to the same one, except that it wasn't greyed out this time. But still i have to keep deleting and changing the link. Even going to Registry Editor won't help cos everything goes back to the same after rebooting. Other than that, under Tools>Internet Options>Security tab, the sites, custom level, and Default level buttons are all greyed out. Even the "Apply" button too. What is the problem???? Please help.. I'm using Windows 98 and IE version 6.0.

[Reply or follow-up to this message]

re: Internet options and security buttons greyed out!!
Wednesday, May 5, 2004 at 3:29 pm
Posted by Ms. Eagle (32447 messages posted)


You didn't say what you used to scan for spyware, so please let us know. There are fake, rip-off programs that people end up with. Do NOT EVER download a program from one of Google's Sponsored ads. A browser hijacker has put restrictions on your system. First, download the CWShredder on the bottom of this page, and run it: CoolWebSearch Chronicles Run the CWShredder.exe file. Close all browser windows and press FIX to scan and clean. Reboot and run the Shredder again. Keep it in a folder, so you have it. Check for Updates frequently using the update feature within the Shredder and replace the previous download. Clear out your TIF, other temp files and ActiveX Controls. Go into Internet Options - General tab. Delete temporary internet files, and choose to delete all Offline content. In Settings, set the size of your TIF folder between 5 - 10 MB. Also, go to Start - Find - Files or folders - in the named box, type: *.tmp and choose Edit - select all - File - delete. Empty the contents of the C:\Windows\temp folder and C:\temp folder, if you have one. Empty Recycle bin. Download SpybotS&D here: Safer-networking.org Close all running programs, install then reboot. Start it and go online and press 'search for updates' tab. (NOTE: if you have problems, select the US or Australian mirror site to download updates from). Download all updates that aren't optional. Close all browser windows and run the scan. When it's finished, 'Check All', and fix everything SpyBot-S&D labels in RED. Reboot. Download 'Hijack This' Unzip 'HT' into a new folder. Close all browser windows and run it offline. Double click the .Exe file to run it. Choose Scan. It'll display a list.Most of the entries listed are necessary or required entries. Don't fix anything, until you know which items to fix. You can check here for a description of the entries in the log: HijackThisTutorial After the scan is finished, the Scan button will turn into Save Log. Press that and copy/paste the contents in a post. Before posting your message, choose this Option: Check this box to preserve your spacing, etc....

Carol

[Reply or follow-up to this message]

re: Internet options and security buttons greyed out!!
Wednesday, May 5, 2004 at 10:30 pm
Posted by Jerlyn (4 messages posted)

Hi there....
Thanks so much for your help! I've followed all your instructions. Well i downloaded my previous spyware remover, Ad-aware 6.0, from www.lavasoft.com.

This is the log from the hijack this scan:
Logfile of HijackThis v1.97.7
Scan saved at 1:23:30 PM, on 5/6/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\INTRENAT.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\CREATIVE\SHAREDLL\CTNOTIFY.EXE
C:\PROGRAM FILES\CREATIVE\SBLIVE\AUDIOHQ\AHQTB.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\PROGRAM FILES\WINAMP3\WINAMPA.EXE
C:\WINDOWS\SYSTEM\P2P NETWORKING\P2P NETWORKING.EXE
C:\PROGRAM FILES\ALTNET\POINTS MANAGER\POINTS MANAGER.EXE
C:\ATI\ATIDESK\ATISCHED.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\RNATHCHK.EXE
C:\PROGRAM FILES\IMESH\CLIENT\IMESHCLIENT.EXE
C:\PROGRAM FILES\CREATIVE\SHAREDLL\MEDIADET.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\TLA.EXE
C:\PROGRAM FILES\ALTNET\DOWNLOAD MANAGER\ASM.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.soucn.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.soucn.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.soucn.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.soucn.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.soucn.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.soucn.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.soucn.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
R3 - URLSearchHook: (no name) - {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [AtiCwd32] Aticwd32.exe
O4 - HKLM\..\Run: [AtiKey] atiptkad.exe
O4 - HKLM\..\Run: [ATIGART] c:\ATI\GART\ATIGART.exe
O4 - HKLM\..\Run: [AtiQiPcl] AtiQiPcl.exe
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Mirabilis ICQ] C:\Program Files\ICQ\NDetect.exe
O4 - HKLM\..\Run: [AME_CSA] rundll32 amecsa.cpl,RUN_DLL
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [P2P NETWORKING] C:\WINDOWS\SYSTEM\P2P NETWORKING\P2P NETWORKING.EXE /AUTOSTART
O4 - HKLM\..\Run: [AltnetPointsManager] C:\Program Files\Altnet\Points Manager\Points Manager.exe -s
O4 - HKLM\..\Run: [WlN32] regedit -s C:\$NtUninstallQ887508$\WINSYS.cer
O4 - HKLM\..\Run: [Intrenat] C:\WINDOWS\intrenat.exe
O4 - HKLM\..\Run: [IEXPLORE.EXE] IEXPLORE.EXE http://www.soucn.net
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [tlA] C:\WINDOWS\SYSTEM\tlA.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [Intrenat] C:\WINDOWS\intrenat.exe
O4 - HKCU\..\Run: [] regedit -s C:\$NtUninstallQ887508$\WINSYS.cer
O4 - HKLM\..\RunOnce: [WlN32] C:\$NtUninstallQ887508$\WINSYS.vbs
O4 - Startup: ATISched.lnk = C:\ATI\ATIDESK\atisched.exe
O4 - Startup: iMesh.lnk = C:\Program Files\iMesh\Client\iMeshClient.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Allow Popups - C:\Program Files\Meaya\Popup Ad Filter\WhiteGetUrl.js
O9 - Extra button: °Ù¶ÈËÑË÷°é (HKLM)
O11 - Options group: [!IESearch] !IESearch
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O12 - Plugin for .mid: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin2.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/swdir.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/drakken/us/win/QuickTimeInstaller.exe
O16 - DPF: {652524F4-F52B-4951-9C1E-30DB62B2B34D} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/ydropper/ydropper1_3sg.cab
O16 - DPF: {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - http://bar.baidu.com/update/IESearch.cab

The http://www.soucn.net is the website that keeps appearing in my homepage and i want to remove it. I have not fixed anything yet from this scan... Do advise me on it! Thanks so much.... Jerlyn

[Reply or follow-up to this message]

re: Internet options and security buttons greyed out!!
Wednesday, May 5, 2004 at 10:54 pm
Posted by Jerlyn (4 messages posted)

Oh ya by the way there is something i forgot to mention, 
that is whenever i right click an icon on my desktop, no matter what file (Winamp, 
internet explorer icons), there is an "extra" option there, tom?????? above 
the other options like Open, Print, Delete, Send to, etc. And when i click on the 
tom?????? again it directs me to the website i don't want. 

[Reply or follow-up to this message]

re: Internet options and security buttons greyed out!!
Thursday, May 6, 2004 at 5:00 pm
Posted by Ms. Eagle (32447 messages posted)


Jerlyn, your system's also infected with viruses. You're using iMesh P2P file sharing app, so you should not be surprised. Do you even have an antivirus program installed?? Get rid of it, you're wide open to all sorts of garbage, hackers, etc. What's in your P2P "bundle"? Trojan VBS Seeker virus: I can give you a start on it, but it's up to you to run a virus scan. You're going to have to boot into Safe Mode, to run Hijack This and fix these entries, so it doesn't run>>> Internat.exe. First create a folder for Hijack This. You can't run it from your desktop, because it creates backups. Cut/Paste into a folder, any folder but a temp folder. Reboot into Safe Mode by pressing and holding the CTRL or F8 key, before Windows loads. Run Hijack This. Select these entries. Choose Fix Checked. Reboot into Safe Mode again to locate and delete the file mentioned below. C:\WINDOWS\LOADQM.EXE C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE C:\WINDOWS\SYSTEM\P2P NETWORKING\P2P NETWORKING.EXE C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\RNATHCHK.EXE C:\PROGRAM FILES\IMESH\CLIENT\IMESHCLIENT.EXE C:\WINDOWS\SYSTEM\TLA.EXE R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.soucn.net R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.soucn.net R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.soucn.net R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.soucn.net R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.soucn.net R1 - HKLM\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.soucn.net R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.soucn.net R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank R3 - URLSearchHook: (no name) - {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - (no file) O2 - BHO: (no name) - {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - (no file) O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe O4 - HKLM\..\Run: [LoadQM] loadqm.exe?? O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"-osboot O4 - HKLM\..\Run: [internat.exe] internat.exe O4 - HKLM\..\Run: [P2P NETWORKING] C:\WINDOWS\SYSTEM\P2P NETWORKING\P2P NETWORKING.EXE /AUTOSTART O4 - HKLM\..\Run: [WlN32] regedit -s C:\$NtUninstallQ887508$\WINSYS.cer O4 - HKLM\..\Run: [Intrenat] C:\WINDOWS\intrenat.exe O4 - HKLM\..\Run: [IEXPLORE.EXE] IEXPLORE.EXE http://www.soucn.net O4 - HKLM\..\Run: [Dit] Dit.exe O4 - HKLM\..\Run: [tlA] C:\WINDOWS\SYSTEM\tlA.exe O4 - HKLM\..\RunServices: [Intrenat] C:\WINDOWS\intrenat.exe O4 - HKCU\..\Run: [] regedit -s C:\$NtUninstallQ887508$\WINSYS.cer O4 - HKLM\..\RunOnce: [WlN32] C:\$NtUninstallQ887508$\WINSYS.vbs O4 - Startup: iMesh.lnk = C:\Program Files\iMesh\Client\iMeshClient.exe O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: Allow Popups - C:\Program Files\Meaya\Popup Ad Filter\WhiteGetUrl.js O9 - Extra button: °Ù¶ÈËÑË÷°é (HKLM) O11 - Options group: [!IESearch] !IESearch O16 - DPF: {BC207F7D-3E63-4ACA-99B5-FB5F8428200C} - http://bar.baidu.com/update/IESearch.cab Locate and delete any and all instances of Internat.exe. C:\WINDOWS\intrenat.exe You can use Find - Files to search for it. Free online Virus Scans, whichever one you prefer: Panda Active Scan Bitdefender Download this .reg file to your Desktop. Double-click on it and answer Yes, to merge into your registry. It will restore all the default Search settings for IE. IEFIX.reg I suggest using SpywareBlaster for spyware prevention. Be sure to check for and download updates after installing it, and frequently thereafter. There's also SpywareGuard, if you want to use both. http://www.javacoolsoftware.com/spywareblaster.html

Carol

[Reply or follow-up to this message]

re: Internet options and security buttons greyed out!!
Monday, May 10, 2004 at 3:07 am
Posted by Jerlyn (4 messages posted)

Hi Carol.. Thanks a lot for your help! Yes i managed to get rid of the blocked buttons and the homepage is now ok! For the hijackthis program, there are still some files i can't locate, like R1 - HKLM\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.soucn.net and O4 - HKLM\..\Run: [tlA] C:\WINDOWS\SYSTEM\tlA.exe even after a search.

I also have the tom????? thing in the shortcut menu when i right click an icon on my desktop. It directs me to the URL if i click on it. Is there anyway to have it removed?

[Reply or follow-up to this message]

re: Internet options and security buttons greyed out!!
Monday, May 10, 2004 at 4:23 am
Posted by Ms. Eagle (32447 messages posted)


What do you mean by you "can't locate" them? Were they still listed in HijackThis, when you ran it again to fix those? If not, they may no longer be there or may not have been running at the time. I don't know what to say, but if you can't find them, I don't know.

[Reply or follow-up to this message]

Tip: Use one of the [Reply or follow-up to this message] links above to add a message to this thread
Return to the Windows 95 Discussion Forum

All content at Annoyances.org is Copyright © 1995-2008 Creative Elementtm All rights reserved.
Please do not plagiarize; redistributing these pages without permission is strictly prohibited.