Internet Explorer Settings

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ericvondarkmoor, Aug 5, 2004.

  1. ericvondarkmoor

    ericvondarkmoor Private E-2

    I've got a 2.4 GHz Pentium with 572 ram.

    I just got done removing my explorer hijack with hijack this now it cannot detect my internet settings. I tried restoring my settings to the defaults and still nothing. I think I may have deleted something in the registry. I did disable my java under safe mode. do i need to uninstall it then download it again? my norton liveupdate won't even go out.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall what? You did not install anything. You deleted registry settings if you were using HijackThis. If you installed HijackThis properly and used one of the more current versions, you can have HijackThis undo its changes from the backups.

    Do you recall everything you changed? Did you save a log from before you changed it? Maybe that will refresh your memory.
     
  3. ericvondarkmoor

    ericvondarkmoor Private E-2

    I let hijack this do everything, but I erased a few values before i learned about hijack this. the message i get is Cannot Find Server or DNS Error
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HijackThis does not do anything unless you tell it to. It scans and the it fixes lines that you tell it to fix. Did you try to restore from a backup yet like I suggested?

    You may have broken you LSP chain. You may have to look at using WinSockFix.
     
  5. ericvondarkmoor

    ericvondarkmoor Private E-2

    i don't think i backed up my registry before i deleted the values. i hijacked my computer afterwards
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're not reading what I said to you. HijackThis does its own backups as long as you have a fairly current version. What version did you use? Try to restore from its backups. Run HijackThis and click Config and then Backups.

    You didn't by chance delete everything that HijackThis came up with....did you?

    What OS are you using?
     
  7. ericvondarkmoor

    ericvondarkmoor Private E-2

    i'm using xp. i didn't delete everything, just the files they told me to fix.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Could you please answer all my questions. Go back and read again and answer what I have asked.

    And why do you keep saying "just the files they told me to fix". Who is they? If you are talking about HijackThis, it does not tell you to delete or fix anything. So would you please clarify what you are talking about.
     
  9. ericvondarkmoor

    ericvondarkmoor Private E-2

    i got into the registry and deleted some files. then i used hijack this after wards and ran the log through the hijackthis website. I checked to fix the files they said might be bad and I didn't recognize. i went back to look at the back up log and i don't have one.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Very bad idea. You should not have deleted anything from the registry unless you really know what you are doing and you should do a backup first. The HijackThis tool you are referring to is far from perfect. And it did not say to delete the items it did not recognize. It just said they might be bad. You should have dug into it further youself to find out. HijackThis is not a tool for novices. It is for expert users only. Experts can guide the novices in using it.

    I repeat....What version of HijackThis?

    You may want to look into using WinXP's system restore to bring your PC back to a restore point prior to when you made the changes. Realize that anything else you have done (like install a valid application) will be reverted too but you don't have much of a choice here. Since you don't have backups of your registry or from HijackThis, system restore is your only option unless you do not have it enabled or you removed your restore points.
     
  11. ericvondarkmoor

    ericvondarkmoor Private E-2

    Okay, I'll try that. everything else works though. even my aol explorer works, the only thing i'm having problems with is my IE. my Norton LiveUpdate and my Windows update do not work either
     
  12. ericvondarkmoor

    ericvondarkmoor Private E-2

    do you want me to post my hijackthis log?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well there could be other things that you have not checked yet too.

    See this and scroll down to the heading "Use System Restore": http://www.microsoft.com/windowsxp/using/helpandsupport/getstarted/ballew_03may19.mspx

    You should be able to go back to a date and time before you made these changes as long as you know when you broke it.
     
  14. ericvondarkmoor

    ericvondarkmoor Private E-2

    OK, did the system restore. ran hijackthis. how do i post the log file? do i save it as a doc or txt
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You save it as a .txt file and post it as an attachment to your message.
    Did the restore fix your problem?
     
  16. ericvondarkmoor

    ericvondarkmoor Private E-2

    no it didn't. I can't go back too far because i downloaded Norton Internet security 2004. the thing is I backed it up to last Wed July-28 and my hijack didn't happen until this monday 8-02.
     

    Attached Files:

  17. ericvondarkmoor

    ericvondarkmoor Private E-2

    what do I do now?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then your problem must have started before July-28.
    How are you connecting right now if you have problems?
    Try downloading and running this.http://www.acrodata.com/WinsockXPFix.zip

    You have HijackThis running from a Temp folder. This is a bad idea and perhaps is why you don't have any backups available. Either that or you are running it right from the ZIP file. Again a bad idea (no backups again). Here is where you have it:
    C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Directory 3 for hijackthis_198.zip\HijackThis.exe

    Unzip HijackThis into its own folder. Like c:\Program Files\HijackThis And run it from there.

    First thing you should do is uninstall the My Web Search stuff. Go to Control Panel, Add/Remove Programs and see if you can locate this stuff. They use a variety of names like: MyWeb, MyWebBar, MyWebSearch, etc. Also the TV Media stuff has to go. But let's take one thing at a time.
     
  19. ericvondarkmoor

    ericvondarkmoor Private E-2

    I'm connected through aol. it's my microsoft internet explorer that is giving me problems
     
  20. ericvondarkmoor

    ericvondarkmoor Private E-2

    unzipped hijack this.
    deleted my web search and tv media, still have RON Display, URL Display, LookSmart search, Lycos search and it won't let me remove them. what's the next step?
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I said Uninstall MyWebSearch using Add/Remove programs. Is that what you did?
    And what did you do with TV Media? You said you deleted it? What does that mean?
     
  22. ericvondarkmoor

    ericvondarkmoor Private E-2

    sorry. i uninstalled both of them. I need to quit using the word delete. which files do i tell hijackthis to fix?
     
  23. ericvondarkmoor

    ericvondarkmoor Private E-2

    how does it let me go through aol but not internet explorer?
     
  24. ericvondarkmoor

    ericvondarkmoor Private E-2

    What does Cannot Find Server or DNS error mean?
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is a lot of stuff that has to get fixed. But we need to go slowly here.
    First you most follow a very important rule: Do not fix anything with HijackThis if you have any Internet Explorer windows open! It is better if you shut everything down but for now just make sure you do not click Fix in HJT if any IE sessions are running.

    Let's start by fixing these three lines only:
    O1 - Hosts: 66.197.100.83 auto.search.msn.com
    O1 - Hosts: 66.197.100.83 sitefinder.verisign.com
    O2 - BHO: (no name) - SOFTWARE - (no file)

    Then I want you to reboot. Your next step is to run all of the items listed in this link except you do not need to run HSremove or About:Buster:
    http://forums.majorgeeks.com/showthread.php?t=35407

    Then repeat running Ad-aware & SpyBot S&D after booting in safe mode.
    Then boot in normal mode.
    After doing all that, post a new HijackThis log attachment.

    And I'll talk to you later tomorrow. Gotta go now!
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You either have a configuration error (some files or drivers are missing or corrupted) or your DNS (Domain Name Service) server IP address configuration is not correct or your service provider DNS servers are not resolving domain names (like www.majorgeeks.com) its actual IP address.

    You should have tried running WinSockXPFix almost an hour ago. It may or may not help.

    At any rate you still have other problems too.

    I really have to go NOW! Bye!
     
  27. ericvondarkmoor

    ericvondarkmoor Private E-2

    I tried to uninstall both my websearch and TV Media display in the add/remove programs. I will not let me remove URL Display, RON Display, Lycos Search, or LookSmart Search.

    I ran down the list, I did an online scan using TrendMicro in regular mode, safe mode will not let me connect to the internet. Then I ran CCleaner, Ad-Aware with the VX2, SpyBot S&D and CWshredder. this is my new hijackthis log file
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now click Start, and then click Run. (The Run dialog box appears.) Type, or copy and paste, the following text:
    regsvr32 /u C:\Program Files\TV Media\TvmBho.dll
    then click OK. If a dialog box confirming this action appears, click OK.

    Now click Start, and then click Run. (The Run dialog box appears.) Type, or copy and paste, the following text:
    regsvr32 /u C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pribi\Pribi.dll
    then click OK. If a dialog box confirming this action appears, click OK.


    Run Task Manager (CTRL-ALT-DEL) select Processes and look for these processes again and end them (if found):
    tvm.exe
    tvmd.exe
    tvmd-decompressed.exe
    tvtmd.exe
    id53.exe
    bokja.exe
    sysupd.exe
    stcloader.exe
    IEService.exe

    Run HijackThis and put checks on the following items (DO NOT FIX YET):
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    R3 - URLSearchHook: (no name) - {707E6F76-9FFB-4920-A976-EA101271BC25} - C:\Program Files\TV Media\TvmBho.dll
    O2 - BHO: G1.GZ - {79C03BC5-6C55-4B5B-921F-C02B6F1ABD7B} - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pribi\Pribi.dll
    O2 - BHO: (no name) - {7B55BB05-0B4D-44fd-81A6-B136188F5DEB} - C:\WINNT\questmod-1.dll (file missing)
    O4 - HKLM\..\Run: [stcinstaller] c:\installer\id53.exe
    O4 - HKLM\..\Run: [bokja] C:\WINNT\bokja.exe
    O4 - HKLM\..\Run: [SysUpd] C:\WINNT\sysupd.exe
    O4 - HKLM\..\Run: [stcloader] C:\WINNT\System32\stcloader.exe
    O4 - HKLM\..\RunOnce: [TV Media] C:\Program Files\TV Media\Tvm.exe
    O4 - HKCU\..\Run: [\IEService.exe] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IESERV~1\IEService.exe
    O4 - HKCU\..\RunOnce: [TV Media] C:\Program Files\TV Media\Tvm.exe

    Exit all Internet Explorer sessions. Now click fix in HijackThis.

    Now reboot in safe mode: http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406?OpenDocument&src=sec_doc_nam
    Make sure you can view hidden files and folders: http://forums.majorgeeks.com/showthread.php?t=37650

    Run Task Manager again and look for this process again and end it if found (you need to do this again in safe mode because this is a stubborn one that restarts itself):
    sysupd.exe

    Delete the following:
    C:\installer <---- The whole directory
    C:\WINNT\bokja.exe <--- the file
    C:\Program Files\TV Media <---- The whole directory
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pribi <--- The whole directory
    C:\WINNT\sysupd.exe <--- the file
    C:\WINNT\System32\stcloader.exe <--- the file
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\IESERV~1 <--- The whole directory

    Run HijackThis again in safe mode and double check that all the previously fixed lines are still fixed. If not, fix them again.

    Now reboot in normal mode and post a new HijackThis log. Tell me the results of all these steps and how things are working.
     
  29. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Ill repeat it for you this time Chaslang. Did you do what he said? Your saying you "deleted". Words can be important here... Did you uninstall from add\remove programs what he asked and did you download the tool he asked you to?
     
  30. ericvondarkmoor

    ericvondarkmoor Private E-2

    Okay, I followed all your steps. ran ccleaner, adaware, spybot in safe mode and closed the procesess you told me to. Then i manually deleted those files and directories you listed. rebooted in normal mode ran ccleaner, adaware and spybot again. here is my new hijackthis log. everything works great, except internet explorer. i reset my websettings on there and still cannot find server or DNS error.

    this is what i have in my address window on internet explorer

    http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
     

    Attached Files:

    Last edited: Aug 7, 2004
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay, your HJT log is finally looking pretty good.
    But have you tried (I asked this multiple times now) running WinSockXPFix? See previous messages for a link.
     
  32. ericvondarkmoor

    ericvondarkmoor Private E-2

    I tried looking for a link to winsockXPfix but could not find it.
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's right on this page. About 15 messages back (8/6/2004 00:47). Here is is again:
    http://www.acrodata.com/WinsockXPFix.zip
     
  34. ericvondarkmoor

    ericvondarkmoor Private E-2

    Attached Files:

  35. ericvondarkmoor

    ericvondarkmoor Private E-2

    I'm at my wits end here. I think I'm going to have to call some tech and spend 70$ and hour for them to fix it. Everything works fine, except for my internet explorer. I did my system restore to a point that everything was working fine and my browser was hijacked there too. I can still get online through AOL, but is it safe to use any of my other programs? I have a lot of business to do on here and it's been backing up for a week. What's the next step here?
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is nothing wrong with that address. It is just www.msn.com. What exactly happens when you try to bring up Internet Explorer? What is the exact message that you get (word for word)?

    By the way you HJT log keeps showing: C:\WINNT\system32\freecell.exe
    Why is this running? It is either a game or a virus. Do you know which one? And why is it always running?

    Have you tried bring up Internet Explorer and clicking Tools, Internet Options, the select Connections and then Lan Settings and choose Automatically detec setttings and click OK?
     
    Last edited: Aug 9, 2004
  37. ericvondarkmoor

    ericvondarkmoor Private E-2

    freecell is a game, and it's always on because I'm always playing it while I wait for stuff to load on aol.

    This is what the page says, i copied and pasted it onto this window

    The page cannot be displayed
    The page you are looking for is currently unavailable. The Web site might be experiencing technical difficulties, or you may need to adjust your browser settings.

    --------------------------------------------------------------------------------

    Please try the following:

    Click the Refresh button, or try again later.

    If you typed the page address in the Address bar, make sure that it is spelled correctly.

    To check your connection settings, click the Tools menu, and then click Internet Options. On the Connections tab, click Settings. The settings should match those provided by your local area network (LAN) administrator or Internet service provider (ISP).
    If your Network Administrator has enabled it, Microsoft Windows can examine your network and automatically discover network connection settings.
    If you would like Windows to try and discover them,
    click Detect Network Settings
    Some sites require 128-bit connection security. Click the Help menu and then click About Internet Explorer to determine what strength security you have installed.
    If you are trying to reach a secure site, make sure your Security settings can support it. Click the Tools menu, and then click Internet Options. On the Advanced tab, scroll to the Security section and check settings for SSL 2.0, SSL 3.0, TLS 1.0, PCT 1.0.
    Click the Back button to try another link.



    Cannot find server or DNS Error
    Internet Explorer

    i checked the box for automatically detect settings for both LAN and Dial-Up. I have a dial-up connection 56k modem
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  39. ericvondarkmoor

    ericvondarkmoor Private E-2

    I did sometthing to the java console in safe mode but i don't know what the default settings are. how do i find it under normal mode?
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Could be a little more specific? What did you do in safe mode and why were you doing this anyway? Goto Control Panel and click on Java Plug-in.

    Do what I gave you below?
     
  41. ericvondarkmoor

    ericvondarkmoor Private E-2

    how do I back up the registry and how do I reinstall it if something goes wrong?
     
  42. ericvondarkmoor

    ericvondarkmoor Private E-2

    I ran a network diagnostic under my help and support section and it said my IP address failed.
     
  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds