Can"t access web pages, only can using ip address

Discussion in 'Software' started by h1tm3, Jun 14, 2011.

  1. h1tm3

    h1tm3 Private E-2

    Hello,
    after removing windows xp restore virus i can't normaly go to web pages.
    Now i am here using http://50.23.143.69,
    www.majorgeeks.com, google.com ... not working.
    In safe mode with networking same happens.
    I'm usig windows xp.

    Some info:
    Microsoft Windows XP [Version 5.1.2600]
    (C) Copyright 1985-2001 Microsoft Corp.

    C:\Documents and Settings\user1>ping www.google.com
    Ping request could not find host www.google.com. Please check the name and try a
    gain.

    C:\Documents and Settings\user1>ping 50.23.143.69

    Pinging 50.23.143.69 with 32 bytes of data:

    Reply from 50.23.143.69: bytes=32 time=193ms TTL=45
    Reply from 50.23.143.69: bytes=32 time=191ms TTL=45
    Reply from 50.23.143.69: bytes=32 time=197ms TTL=45
    Reply from 50.23.143.69: bytes=32 time=191ms TTL=45

    Ping statistics for 50.23.143.69:
    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
    Minimum = 191ms, Maximum = 197ms, Average = 193ms

    C:\Documents and Settings\user1>ping majorgeeks.com
    Ping request could not find host majorgeeks.com. Please check the name and try a
    gain.



    C:\Documents and Settings\user1>ipconfig /all

    Windows IP Configuration

    Host Name . . . . . . . . . . . . : mrtuzzaz-fed630
    Primary Dns Suffix . . . . . . . :
    Node Type . . . . . . . . . . . . : Unknown
    IP Routing Enabled. . . . . . . . : No
    WINS Proxy Enabled. . . . . . . . : No

    Ethernet adapter Local Area Connection:

    Connection-specific DNS Suffix . :
    Description . . . . . . . . . . . : VIA Rhine II Fast Ethernet Adapter
    Physical Address. . . . . . . . . : 00-13-8F-B3-5F-7B
    Dhcp Enabled. . . . . . . . . . . : Yes
    Autoconfiguration Enabled . . . . : Yes
    IP Address. . . . . . . . . . . . : 87.247.92.170
    Subnet Mask . . . . . . . . . . . : 255.255.255.0
    IP Address. . . . . . . . . . . . : fe80::213:8fff:feb3:5f7b%4
    Default Gateway . . . . . . . . . : 87.247.92.1
    DHCP Server . . . . . . . . . . . : 217.17.85.157
    DNS Servers . . . . . . . . . . . : 217.17.85.1
    217.17.85.2
    fec0:0:0:ffff::1%1
    fec0:0:0:ffff::2%1
    fec0:0:0:ffff::3%1
    Lease Obtained. . . . . . . . . . : Tuesday, June 14, 2011 2:46:45 PM
    Lease Expires . . . . . . . . . . : Tuesday, June 14, 2011 3:07:25 PM

    Tunnel adapter Teredo Tunneling Pseudo-Interface:

    Connection-specific DNS Suffix . :
    Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
    Physical Address. . . . . . . . . : FF-FF-FF-FF-FF-FF-FF-FF
    Dhcp Enabled. . . . . . . . . . . : No
    IP Address. . . . . . . . . . . . : fe80::ffff:ffff:fffd%5
    Default Gateway . . . . . . . . . :
    NetBIOS over Tcpip. . . . . . . . : Disabled

    Tunnel adapter 6to4 Tunneling Pseudo-Interface:

    Connection-specific DNS Suffix . :
    Description . . . . . . . . . . . : 6to4 Tunneling Pseudo-Interface
    Physical Address. . . . . . . . . : 57-F7-5C-AA
    Dhcp Enabled. . . . . . . . . . . : No
    IP Address. . . . . . . . . . . . : 2002:57f7:5caa::57f7:5caa
    Default Gateway . . . . . . . . . :
    DNS Servers . . . . . . . . . . . : fec0:0:0:ffff::1%1
    fec0:0:0:ffff::2%1
    fec0:0:0:ffff::3%1
    NetBIOS over Tcpip. . . . . . . . : Disabled

    Tunnel adapter Automatic Tunneling Pseudo-Interface:

    Connection-specific DNS Suffix . :
    Description . . . . . . . . . . . : Automatic Tunneling Pseudo-Interface

    Physical Address. . . . . . . . . : 57-F7-5C-AA
    Dhcp Enabled. . . . . . . . . . . : No
    IP Address. . . . . . . . . . . . : fe80::5efe:87.247.92.170%2
    Default Gateway . . . . . . . . . :
    DNS Servers . . . . . . . . . . . : fec0:0:0:ffff::1%1
    fec0:0:0:ffff::2%1
    fec0:0:0:ffff::3%1
    NetBIOS over Tcpip. . . . . . . . : Disabled
     
    Last edited: Jun 14, 2011
  2. sikvik

    sikvik Corporal Karma

    Welcome to MGs h1tm3. :)

    Please follow all the steps in the Read & Run Me

    Attach the requested logs in a new thread in Malware Removal.

    Please be diligent in following the instructions.

    Cheers..
     
  3. satrow

    satrow Major Geek Extraordinaire

    Before you go the malware route, I'd check that the proxy redirect from the old infection has been cleared, set the Internet options for IE (under Tools > Options or via the Control Panel) so that it looks like the attachment.
     

    Attached Files:

  4. h1tm3

    h1tm3 Private E-2

    I try this before, and there is no proxy
     
  5. satrow

    satrow Major Geek Extraordinaire

    Ok, time for a checkup in the Malware forum then :) Follow Post #2.
     
  6. h1tm3

    h1tm3 Private E-2

    Can somebody write from google free proxy ip ?
    I cant go to any page
     
  7. satrow

    satrow Major Geek Extraordinaire

    Ok, let's work out how you connect - ethernet to a router or a cable modem? If it's via a router, which make and model?
     
  8. h1tm3

    h1tm3 Private E-2

    No, its simple lan cable network

    I think something wrong in registry,
    how can i import clean windows registry ?
     
    Last edited: Jun 14, 2011
  9. satrow

    satrow Major Geek Extraordinaire

    Ok, let's try to get OpenDNS setup on your network card directly then. Your original settings are all in the first post, for future reference, write down the original settings before making any changes.

    Change the advanced properties of TCP/IP on your network adapter so that it looks like this:
     

    Attached Files:

  10. h1tm3

    h1tm3 Private E-2

    I need to download opendns from ip or something,
    then i go to http://www.opendns.com/ firefox says server not found

    Can you post me in private message any proxy ip ? I try to use proxy and download opendns
     
    Last edited: Jun 14, 2011
  11. satrow

    satrow Major Geek Extraordinaire

    No, the OpenDNS address is already filled into the settings in my example image, just copy the IP addresses into the same advanced settings tab on your network adapter properties.
     
  12. h1tm3

    h1tm3 Private E-2

    Just copied, made restart, no good news.
     
  13. satrow

    satrow Major Geek Extraordinaire

    Is there a way you can cycle the power on the cable modem you're connected to?
     
  14. h1tm3

    h1tm3 Private E-2

    No, cable coming far away
     
  15. satrow

    satrow Major Geek Extraordinaire

    Ok, I'm pretty much out of ideas on this one, not really my area; I'm pretty sure someone else'll chip in with more appropriate steps to get you fully connected again.
     
  16. Earthling

    Earthling Interplanetary Geek

    Your IP address and gateway address look wrong to my mind. Do you know how to access your router config via your web browser? It's usually something like entering 192.168.0.1 or 192.168.1.1 into the address bar followed by a request for a username and password. If not, can you tell us the make and model number of the router?

    Having said that I must admit I'm having difficulty imagining how you can access the internet at all if the gateway address is wrong :confused
     
  17. theefool

    theefool Geekified

    Also, I'm sure you've done the basics of:

    ipconfig /release
    ipconfig /renew
    ipconfig /registerdns

    Though, that third option is mostly for domain pcs needing updated dns info.

    After putting in the DNS info that satrow gave you, would love to see an updated ipconfig /all

    Also, can you ping the dns servers?

    Also, hopefully ye are using DHCP, instead to static IPs.
     
  18. thisisu

    thisisu Malware Consultant

    You can't access any webpage? correct?

    Regardless, let's do some basic things to fix your connection.


    IE defaults
    - run internet options (inetcpl.cpl)
    - set temp files to 50 MB
    - default all zones
    - default privacy
    - UNcheck "automatically detect settings" in "LAN Settings"
    - restore advanced settings (NOT reset)

    Internet working now?

    If not, proceed to the following:

    For winxp:

    Go into the Control Panel > Network Connections > .. Find your connection, usually it's "Local Area Connection", and VIA Rhine II Fast Ethernet Adapter might attached to it as well.

    Double click this icon
    Properties > New window opens up > Make it match the following:

    http://img146.imageshack.us/img146/5858/networkconn.jpg

    Once it looks the above image,

    press OK to exit out of this window.

    Test your internet now..

    more to come

    ipconfig /flushdns

    download: http://files.snapfiles.com/localdl936/WinsockxpFix.exe
    run, reboot. if you can't dl it from your troublesome computer, can you dl and copy it to a flash drive/floppy/cd from another working pc and bring it to the troublesome pc?
     
    Last edited: Jun 15, 2011
  19. thisisu

    thisisu Malware Consultant

    Start -> Run -> devmgmt.msc -> OK

    You are now in device manager.. any problems ? Yellow exclamation marks?

    View > Show Hidden Devices

    How about now? Yellow exclamation marks?
     
  20. h1tm3

    h1tm3 Private E-2

    Installed cleen copy of windows all works fine.
    That was strangest virus ever in my life, all two days work and nothin... xD
     
  21. Earthling

    Earthling Interplanetary Geek

    To help the helpers would you mind posting another ipconfig /all please?
     
  22. h1tm3

    h1tm3 Private E-2

    Microsoft Windows XP [Version 5.1.2600]
    (C) Copyright 1985-2001 Microsoft Corp.

    C:\Documents and Settings\usr1>ipconfig /all

    Windows IP Configuration

    Host Name . . . . . . . . . . . . : prive-87a9f0e5c
    Primary Dns Suffix . . . . . . . :
    Node Type . . . . . . . . . . . . : Unknown
    IP Routing Enabled. . . . . . . . : No
    WINS Proxy Enabled. . . . . . . . : No

    Ethernet adapter Local Area Connection:

    Connection-specific DNS Suffix . :
    Description . . . . . . . . . . . : VIA Rhine II Fast Ethernet Adapter
    Physical Address. . . . . . . . . : 00-13-8F-B3-5F-7B
    Dhcp Enabled. . . . . . . . . . . : Yes
    Autoconfiguration Enabled . . . . : Yes
    IP Address. . . . . . . . . . . . : 87.247.92.170
    Subnet Mask . . . . . . . . . . . : 255.255.255.0
    Default Gateway . . . . . . . . . : 87.247.92.1
    DHCP Server . . . . . . . . . . . : 217.17.85.157
    DNS Servers . . . . . . . . . . . : 217.17.85.1
    217.17.85.2
    Lease Obtained. . . . . . . . . . : Wednesday, June 15, 2011 9:40:57 PM
    Lease Expires . . . . . . . . . . : Wednesday, June 15, 2011 10:01:37 PM


    C:\Documents and Settings\usr1>
     
  23. Earthling

    Earthling Interplanetary Geek

    Thanks. One more request please - what is the make and model of your router? I ask because I have never seen IPs like yours before and need to understand how they can can be that way and still work.
     
  24. Colemanguy

    Colemanguy MajorGeek

    He more then likely isn't using a router, as thats a public ip assigned to his network card. Simply meaning, he is hooked to a device that isn't doing nat. Depending on the connection method, he might be using wireless point to point or just simply cable or dsl with no router. Its common for the wireless isps around here (Kansas) to give normal public ips to customers.
     
  25. Earthling

    Earthling Interplanetary Geek

    Thanks for that. Setups like that may exist in the UK, it's just that I haven't ever come across it before.
     
  26. Colemanguy

    Colemanguy MajorGeek

    Its pretty rare, but it happens. Glad to be of assistance.
     
  27. h1tm3

    h1tm3 Private E-2

    Look at post #8
    it's simple cable network, no router
     
  28. Colemanguy

    Colemanguy MajorGeek

    Simple lan cable network could describe about 5 different setups involving routers and some not, you could be referring to cable as the internet connection, cables as the connection internaly, its too vague :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds