IE 6 - Page cannot be displayed

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jabski, Sep 14, 2006.

  1. jabski

    jabski Private E-2

    Since Aug. 19, 2006 I have been unable to access two sites, from my desktop, that I have been accessing for years with no problems:
    Cititbank online banking
    https://web.da-us.citibank.com/cgi-bin/citifi/scripts/login2/login
    and
    USDA nutrition information search page
    http://www.nal.usda.gov/fnic/foodcomp/search/

    Both were bookmarked, but I also tried typing in the URLs directly. I am able to access both sites from my laptop over the same DSL broadband connection, so it appears the problem is local to the desktop.

    When attempting to access either site, it times out with a "page cannot be displayed" error message. When trying to access www.citibank.com, in order to link to the online banking page, I get redirected to a Google search page for an unknown address, but the first entry in the list of suggested addresses is, of course, www.citibank.com. [ditto www.myciti.com]

    I can access the main USDA site, but when I follow a link to the search page it times out as above. All of the other sites that I frequent regularly are accessible, including financial sites using https:

    Apparently, something has IE by the neck, but I can't find it. I have run:
    Norton Utilities- WinDoctor, Disk Doctor, Cleanup
    AntiVirus scans
    AdAware spyware scans ...

    Desktop config: Win98 SE
    IE 6 (128-bit encryption)
    This machine is current with the latest Microsoft patches released for Win98

    I have followed the instructions on the HijackThis page with the following exceptions:
    CounterSpy installed and loaded, but hung 'loading spyware definitions' and would not proceed farther.
    Ccleaner, Spybot, and CounterSpy (attempt) were all run in SAFE mode, but I was unable to return to the boot menu on subsequent reboots, so the online scans were run in the NORMAL boot environment. The reason for this is unclear, but I run BootMagic and maybe my timing was off?

    Additional attachments to follow...
     

    Attached Files:

  2. jabski

    jabski Private E-2

    Additional attachments
     

    Attached Files:

    Last edited by a moderator: Sep 14, 2006
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You problem sounds more like a settings issue on your part rather than sounding like malware.

    Please do not post edited/incomplete logs! Where is the full log from ShowNew?

    First you appear to have both McAfee and Symantec AVs installed. See step 3 of the READ ME. Uninstall one.

    Then you should check to make sure you are not blocking those URLs in your firewall. You could make a quick test of shutting down ZoneAlarm and then try to access the sites. What happens?

    If they are not being blocking in your firewall or the multiple AV applications, try the below:

    Download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    Any change?
     
    Last edited: Sep 14, 2006
  4. jabski

    jabski Private E-2

    Thanks for your response.

    I have attached a new ShowFiles report. I did not edit the previous one, so I can not explain why it was truncated.

    The McAfee AV is not installed. Some email virus attacked it a couple of years ago preventing it from running or uninstalling. Apparently there are some remnants left from my attempts at a manual uninstall. Also, Norton AV component of SystemWorks is not installed at this time.

    I did try to access those URLs without ZA running and with popups allowed on the Google toolbar. And I just did so again with the same results.
    www.myciti.com is redirected to the Google search page, and www.da-us.citibank.com produces the 'page cannot be displayed' error.

    I ran Hoster from E: and it said there was no host file? So I ran it from C: and it showed the default file with only the local loopback entry [plus comments]. Any way I did this prior to my repeated attempt to access Citibank and there was no change.

    Any idea why CounterSpy wouldn't run?
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are still not running ShowNew properly! In addition logs are being appended which the program cannot do if it is run normally. The first part of the BAT file would delete previous logs. It looks like the program is not running the first part of the script. Please download ShowNew.zip again and try it again but first make sure you delete all newfiles.txt logs in the C:\ folder. ALSO MAKE SURE YOU EXTRACT all files to a folder on drive C: (DO THE SAME for GetRunKey and attach a new log from it). For Windows 98, these programs must be run from the Windows boot drive.
     
  6. jabski

    jabski Private E-2

    Sorry.
    New logs attached.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are not showing any malware problems.

    Do you use a router in between your PC and DSL modem?

    Instead of using www.citibank.com try using the IP address: 192.193.217.120

    Does that work?

    Also for web.da-us.citibank.com try 192.193.180.86
     
  8. jabski

    jabski Private E-2

    This is becoming more and more weird.
    I do have a Linksys 4-port router/switch between my PCs and the DSL modem, however my laptop, which is also cabled to one of the ports connects to Citibank OK, but my desktop cannot.
    When using either of the Citi IP addresses from the desktop, I get redirected to the Google search page as when using the name. I can, however, go to the Google site using an IP address as well as the name.
    I cannot ping Citi from either machine [ no surprise there], but tracert from the desktop times out from the 1st hop, while tracert from the laptop shows the first 14 hops before the remainder time out. Tracert from the desktop to the Google IP completes OK.
     
  9. jabski

    jabski Private E-2

    It seems that the problem is related to either my local network IP address or my DSL modem. I use DHCP so my desktop almost always has the 1st assigned address. I forced a new address and also cycled my DSL modem which is always on. I can now access citibank by either address. I'll have to narrow it down later.

    Thanks for your help. The IP address idea pointed me to a new line of investigation when I was at a dead end.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Many sites do not answer pings! And a banking institution would definitely be one of them. Just to double check, I cannot ping them either.

    However I see you are now finding (as I was saying) that your problem is not malware.

    Good luck in your hunt to resolve the issue!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds