I Can't view yahoo, google, download.com...

Discussion in 'Malware Help (A Specialist Will Reply)' started by Aug, Jan 5, 2005.

  1. Aug

    Aug Private E-2

    I set my homepage for www.google.com. Whenever I open up Internet Explorer or Firefox it tells me that "We can't find "www.google.com"" I can't go to yahoo either. When I click on the msn search button that pops up, it sends me to some search engine @ http://search.findwhatevernow.com/search.jsp?AF=cmgrb&term=online+casino. I've ran a few virus scans with AVG and PC-Cillin. It told me i had some trojans and then I got rid of them. I've used spybot and Ad-Aware SE (Both updated) and they clear out some things but can't fix my main problem of viewing webpages. My host file just has 127.0.0.1 localhost as the only host in it.

    I'm going to go ahead and attach my HJT log file.

    Could anyone help me fix my browser so I can view these pages?
     

    Attached Files:

  2. PhilliePhan

    PhilliePhan Guest

    Hi Aug,

    You should not be running two different AV at the same time as they may conflict. You ought to uninstall one.

    R3 - URLSearchHook: (no name) - - (no file) ---> May be fixed with HJT

    O2 - BHO: Windows Proxy support DLL - {2DC9D850-144D-11E1-B3C9-10805E499D93} - C:\WINDOWS\system32\winprox.dll ---> I do not know what this is. It could be your problem - Do you recognize it as legit and needed? If not, perhaps fix it as well?


    Make sure ALL Browser Windows are Closed when running HijackThis.

    Sounds like you may need to reset your Web Settings as well!

    PP :)
     
  3. Aug

    Aug Private E-2

    I Uninstalled AVG and used HJT to fix the two problems. What should I do to reset my web settings.

    Here's my latest HJT Log. I closed the windows before I ran the scan.

    I restarted my computer and I was able to View Google's site. I went to yahoo and then tried to go to their e-mail page, but it told me it couldn't find mail.yahoo.com.

    I restarted my computer again and now I can't connect to google and yahoo.
     

    Attached Files:

  4. PhilliePhan

    PhilliePhan Guest

    Hi AUG,

    Your HJT log shows clean.

    To Reset Web Settings:
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    If this doesn't solve the problem, we may need to look at other things such as firewall conflict. Are you running a software firewall? If so, did you disable the Windows Firewall that is on by default in SP2?

    Also, it might be worthwhile to flush the dns cache. Try Start > Run > type cmd > OK

    Then, type: ipconfig /flushdns & hit ENTER.

    That might help as well. Let me know how you fare with the above. I am tied up with a lot of real life issues right now and can only check in to MGs once or twice a day - So please be patient!

    PP :)
     
  5. Aug

    Aug Private E-2

    I did those things and Its still not working. From what I can tell, I think it's hijacked my settings and blocked those sites. Any ideas on how to either A) Reset those settings, or B) fix it?

    I've reinstalled SP2 and that didn't change anything. I'm beginning to think that it didn't hijack just my browsers. Could anyone post me google's IP so I can try to ping it?

    -Aug
     
  6. PhilliePhan

    PhilliePhan Guest

    Hey Aug,

    Just popping in briefly with an idea:
    Take a look at your Hosts file and tell me what it says.

    C:\Windows\System32\Drivers\etc\Hosts - Open with Notepad

    Let's see if malware is blocking you there.

    PP :)
     
  7. Aug

    Aug Private E-2

    Here's the host file.
     

    Attached Files:

  8. PhilliePhan

    PhilliePhan Guest

    Looks OK. Sometimes malware will redirect or block sites via Hosts, but not the case here.

    I've asked one of our more knowledgeable contributors for a 2nd opinion on your thread. Perhaps he will be able to shed some insight. Hang in there.

    PP :)
     
  9. Turcoloco

    Turcoloco MajorGeek

    Hello Aug,

    PP asked me to lend a hand, I have read the previous posts and I could tell you two been busy. Here is what I want to start you with (if you had given the answer before I am sorry but tell me anyway):

    ~ What exact sites are the ones you can't open?
    ~ And what is the message/error?

    * Try these: Start > Control Panel > Internet Options >

    - Privacy tab > (under web sites section click on the button named) Edit.. and make sure none of the sites you are trying to open are 'blocked' on the list. Under Settings section make sure the setting is at 'Medium'.
    - Security tab > click on the button named 'Default Level'.
    - Content tab > click on 'AutoComplete' button, click on 'Clear Forms' and 'Clear Passwords' (followed by OK to confirm).
    - (I believe on the) Programs tab you might have a 'Pop-up blocker, if you do set it to 'Low', also if you see 'Manage my IE add-ons/plug-ins button click on that and tell us what you see in the list. More in the same line, open IE andright-click on an empty part of the gray toolbar where you see [FILE - EDIT - VIEW - FAVORITES - TOOLS - HELP] and if you see any thing else with a checkmark other than (Standard Buttons, Address Bar, Links, Lock Toolbars) uncheck them and also let us know what they were. Close out of IE and re-launch to see if the problem still exist.

    ~ If all else fails, finally (for the sake of troubleshooting the problem) open up Task Manager (CTRL+ALT+DEL) and click on 'Processes' tab, then kill all the processes (and confirm) that matches these:

    C:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe
    C:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe
    C:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe
    C:\Program Files\Trend Micro\PC-cillin 2002\WebTrap.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe
    C:\WINDOWS\system32\MsPMSPSv.exe
    C:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe

    PS. Have you tried any other browsers to see if it was a IE problem or not? (a good alternative would be Firefox)....
     
  10. Aug

    Aug Private E-2

  11. Matacumbie

    Matacumbie Rocky Top

    Hi Aug,

    One other thing you might try. Look in the settings or options in your anti-virus and firewall programs for any pop-up, spam, or ad blockers.

    You may have to search around and find the different settings in each program and experiment, trying these sites after disabling certain features.

    You get the idea, anything that is capable of blocking something.

    Good luck,

    Steve
     
  12. Turcoloco

    Turcoloco MajorGeek

    As addition to what Steve had you check...

    Well, frankly I am a bit baffled....but since you mentioned Firefox crapped out as well this kinda proves that whatever setting/modification has occured, it had to be either TCP/IP related settings or a 3rd party program causing this (including a malware).
    I wanted to make sure you really did check all the IE security/privacy related sections as I suggested, were they really clear or looked ok?
    Also have you tried killing those process that seemed to be a pop-up, IE filtering type of processes? ( all the PC... ones I listed earlier) After killing those still no go?

    Finally, do this: Start > RUN > type cmd > OK at the command prompt type ipconfig /all and press ENTER and tkae a look at the IP addresses for DNS servers in particular to see if they are valid. If so try typing ipconfig /renew press ENTER and then when the screen gets updated type ipconfig /all again and press ENTER to see if the values got updated....if yes check to see if the problem still occurs...
     
  13. PhilliePhan

    PhilliePhan Guest

    Hey Steve, TL -

    Just wanted to pop in and thank you guys for the assist here. I really appreciate it :)

    PP
     
  14. Aug

    Aug Private E-2

    I've tried nuking those processes and getting down to the bare minimum for xp, but it still doesn't work.
    This is my current setup. I've tried to obtain an IP, but I don't have access to the router and it won't let me obtain an IP Automatically.
    IP: 192.168.0.56
    Subnet: 255.255.255.0
    Def Gate: 192.168.0.1

    Use DNS
    Pref: 209.47.15.18
    Alt: 64.157.143.38

    I've tried to obtain automatically, but it doesn't work an it gives me the "Limited Connection" Error.

    Do you think Re-installing XP (w/o Reformatting) would fix this?

    -Aug
     
    Last edited: Jan 8, 2005
  15. Turcoloco

    Turcoloco MajorGeek

    Yes, it more than likely would fix the problem (I probably sounded like the AOL tech support? :p )

    But seriously, that action is definitely not called for, not yet at least, IMO.
    You do use a router, right? IF so then do this please:
    Start > Control Panel > Network Connections
    You should see the Local Area Connection icon, right-click on it and choose Properties.
    High-lite Internet Protocol on the list, then click on the 'Properties' button.
    Check to make sure 'Obtain an IP address automatically' is selected, if not make it so. Also'Obtain DNS Server address automatically' option should be selected too.
    down below, you should see the 'Advanced' button, click on it.
    On the 'IP Settings' tab, it should show 'DHCP Enabled'. The list on the DNS and WINS tabs should be blank, so check on those too.
    Let us know afterwards. ;)
     
  16. Aug

    Aug Private E-2

    Yeah, i've already done those in the past and I just tried em again and no luck. When I try to obtain it automatically it gives me a limited connection (the router recognizes me, but it won't send any packets back so I can't do anything).

    I can't think of much else to try.

    -Aug
     
  17. Turcoloco

    Turcoloco MajorGeek

    Are you sure the router is in good shape? IF your ISP providing you a dynamic IP address, then tr this: shutdown your PC, instead of plugging the network cable coming from the modem cable in to router, plug it directly in the network adapter card in the PC. Reboot and see if the connection looks ok.
    Either way, you could also try this:

    Remove the NIC (network adapter card) from the Device Manager list which should also remove the TCP/IP protocol from the Network Configuration list, if it doesn't remove it yourself. Afterwards, if your NIC is not integrated to the mobo, then you should also try moving it to another PCI slot. Anyhow after rebooting, the NIC drivers gets re-installed automatically, if not do so. Then using the Network configuration wizard re-configure (fresh setup) your Internet connection info (Start > Control Panel > Network Configuration > 'Setup a home or small office network').
    Then check the connection.
     
  18. Aug

    Aug Private E-2

    I really don't think its a hardware issue. The owner's of the appartment complex i'm at won't let me touch the router.

    The only thing that sticks in my mind is the error message I get. I swear, its like they hijacked my computer and I have to go through another server to get anywhere.

    Internet Explorer doesn't show this page normally. http://img62.exs.cx/my.php?loc=img62&image=googleerror4lb.png

    It doesn't look right or anything. Its the same "Template" for Firefox.

    I tried what you said and it still doesn't work.
     
  19. Matacumbie

    Matacumbie Rocky Top

    Aug,

    Why did you have AVG installed?

    Steve
     
  20. Aug

    Aug Private E-2

    Well, I've heard some pretty good reviews from people I know. It picked up viruses that PC-Cillin missed. I installed it after I started having problems. I don't have it installed anymore.

    -Aug
     
  21. Turcoloco

    Turcoloco MajorGeek

    Sorry to hear that you had no luck so far.
    I was going to ask you this but I thought someone already had you do it so I didn't bother but I read from the start and didn't see if you were asked to ping/traceroute the sites?
    Lets do these troubleshooting steps and see what results you get, ok?

    Start > Run > cmd > OK
    Command Prompt window should open up, now type this:
    ping www.google.com then press Enter, what happened?

    now type: ping 216.239.57.99 then press Enter, what happened?

    Note: 216.239.57.99 is Google's IP address.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds