Posting for friend: followed sticky now no internet at all!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Rick_Lincoln, Mar 27, 2005.

  1. Rick_Lincoln

    Rick_Lincoln Private E-2

    Hello all and firstly many thanks for this informative and helpful site.
    I have read through what to do and think I have covered all bases....as the title of this thread shows I am posting for a friend who will be joining after we sort this out!!

    Background:
    Over approx 1 week....extreme internet slow-down.
    Ran Norton AV (he has full Norton Internet security 2005) and Adaware personal, no problems.
    I suspected spy involvement so got MS antispy, updated it, ran it.
    Removed HotsearchBar!!
    Still no better so googled my way to here...... :)
    D/L and ran CWS thing. Didnt find it. Came back here and noted running it in safe mode... did that and found a CWS toolbar (.aft?? sorry I have to work from memory here).
    Also found new.net (which was on my computer too) but have left it for now since it is not affecting mine so I assume it is not affecting his.
    After all this...... well, now when he opens intenet explorer it takes him straight to "page not found"....clicking any of the links simply clears the screen and says "done". No internet address works at all... it says it cant find server! Now, the funny thing is that MS messenger seems to work, email works, and Norton, antispy, etc. will all update from the net with no problems!!! ntl "Broadband medic" says there is no problem with his connection. This suggests to me a software issue but I simply cannot find it! Home page etc. is all ok according to Internet properties.
    I downloaded HJT and took it to him on disc. We scanned and saved a log file but that was before I did all the cleaning out so it needs scanning again. Searching your databases shows some nasties but the ones I expected to see (the ones where IP addresses are reset) dont appear! (NB I have not "fixed" anything!!) My mate is away until dinner time today, at which point I am going round to try and help him.... any pointers from you guys would be so helpful.... I am now unsure whether it is a hijack or the result of removing a hijack that is causing him problems.
    I know my post here is far from what you say you require but I dont have a lot of the details... only my memory and the out of date HJT log!
    I am hangnig around all this morning so will check for replies often..and will try to answer any questions that may be asked.
    Many thanks.... this would be worth a donation if you can help!!!

    Rick
     
  2. jtpiano

    jtpiano Private E-2

    Look for a tool called LSP Fix. It is not uncommon to break the IP Protocol stack when removing spyware. The tool should help you fix any bad entries "automagically". Let me know if you have any trouble using it. Good luck! :D
     
  3. Rick_Lincoln

    Rick_Lincoln Private E-2

    Many thanks... have already downloaded this!! It is on a disc as well :)
    I will take it round and run it after lunch.
    I will also take the liberty of running another HJT scan and saving it do disc so I can post it here if required...... so if anyone else thinks I should do anything else first then please let me know so I dont have to keep going backwards and forwards!!!

    Thanks again and Happy Easter!

    Rick
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have run ALL of the READ ME FIRST, do the following.


    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).

    LSP-Fix is useful to repair broken LSP chains and some times so is: WinSock FIX for XP (if you have WinXP) See: http://www.snapfiles.com/get/winsockxpfix.html
     
  5. Rick_Lincoln

    Rick_Lincoln Private E-2

    Will do!! Which repair tool would you recommend (XP SP1)

    I have made a note of the Read me stuff and will follow that. Then I will do the LSP fix or Winsock fix and then do a HJT log... is that correct? Sorry to be a pain but want to do it right to avoid sending you guys on wild goose chases!!
     
  6. Rick_Lincoln

    Rick_Lincoln Private E-2

    Hi all!! (Still no internet access for mate so I am still acting as proxy!!)

    Right, I have done it all as far as I can tell!!
    Spybot found a few bits... including one (mywebsearch?) which it keeps telling me it can only delete after a reboot.....even after rebooting!!
    Anyway, I followed the readme file and then ran the winsock fix.
    However, double clicking the IE icon now takes me to "page not found".....no matter what address I put in. The error is "cannot find server or DNS error" but I have checked Internet options and they look OK. Addresses typed into the bar appear to be correctly processed in that the "http//" appears etc. but no page results.
    NB if I am going to have to reinstall bits of his Windows system at all, can the answer be aimed at doing it from a pre-installed version of XP that did not come with a disc please??

    It still seems odd to me that software etc. will still update from the internet and that broadband medic says there is no problem with the connection! This really indicates to me that it is a software problem isnt it?

    Here is the HJT log you requested.

    Many thanks once again in anticipation!
    Rick
     

    Attached Files:

  7. Rick_Lincoln

    Rick_Lincoln Private E-2

    Hi again.... think the log is attached correctly (to my last post under this)!! I read that the more info the better and my mate (bless him) tells me that he is surprised at the number of p2p downloaded songs etc. that need him to acquire licences recently!!!! I think that may be a cue for those that know to slap their foreheads and smile sadly.... Needless to say that he has had a slap!!! I have had a read through the recommended "online" log analysis links and think there are a couple of things that have to go... but in one case a "nasty" in one is flagged as safe in the other!

    Rick
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your messages are a little confusing! Do you internet access or not? It sounds like you cannot access it when you use a browser but other programs seem to have access. Please clarify your problem.

    Have you tried using IP addresses rather than URL's to access websites?

    One thing you must do is use Add/Remove programs to uninstall the below because it contains a load of malware:
    Messenger Plus! 3

    After uninstalling Messenger Plus! 3, do the below.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.isearch.com/index.php?app=SE&affjump=1&affiliate=ODQ6NTo5&Terms=
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    O4 - HKCU\..\Run: [GLUE32] C:\DOCUME~1\GAVINW~1\APPLIC~1\ACTIVE~1\Dentlogovc.exe
    O4 - Global Startup: updater.lnk = C:\Program Files\Common Files\Keenware\wupdater.exe
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O16 - DPF: DigiChat Applet - http://vdo-lax-002.cnshosting.net/DigiChat/DigiClasses/Client_IE_5_0_1_3.cab
    O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32 Class) - http://66.48.68.135/save/makeover.cab
    O16 - DPF: {20AD521D-3A3E-11D4-BC32-0050040D952B} (SwIcdInstall Class) - file://C:\DOCUME~1\GAVINW~1\LOCALS~1\Temp\WZS117.tmp\swicdad.cab
    O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - http://sib1.od2.com/common/Member/ClientInstall/10.01.0004/OCI/setup.exe
    O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297C} - http://download.weatherbug.com/minibug/tricklers/AWS/minibuginstaller.cab?rand=20032255
    O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.brightstreet.com/cif/download/bin/actxcab.cab

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Documents and Settings\GAVINW~1\Application Data\ACTIVE~1\Dentlogovc.exe
    C:\Documents and Settings\GAVINW~1\Local Settings\Temp\WZS117.tmp\swicdad.cab <-- in fact, delete the whole WZS117.tmp folder
    C:\Program Files\Common Files\Keenware <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST).
    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  9. Rick_Lincoln

    Rick_Lincoln Private E-2

    Hi and good morning!!!
    I am gonna print out your instructions and carry out the procedure in an hour or so...... Thank you so much!

    Yes.....applications such as Microsoft antispy and Norton etc. (and, indeed the tools downloaded as part of the read me procedure) have no problems updating themselves via the internet. However, IE does not seem to recognise any address (e.g. www.google.com) as valid, it just says page not available. NTL broadband medic says there is no problem with the connection.

    I will do as instructed and post log later on.

    Rick
     
  10. Rick_Lincoln

    Rick_Lincoln Private E-2

    Hi guys!! No difference I am afraid :-(

    I followed the instructions, although the three files listed for deletion in explorer do not appear to exist... I tried navigating to them and also searching for them without success (Idouble checked the display extensions bit etc.).

    Also to answer your other question... We have tried entering IP numerical addresses too...all with the same result: "Page cannot be found, cannot find server or DNS error"

    I am stumped totally!

    As requested, here is the post procedure HJT log:
    My ongoing thanks for your efforts!!
    Rick
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try opening up a Windows Explorer session by clicking Start and selecting Explore.
    In the space to the right of the Address bar enter http://67.19.72.100 then click Go.

    What happens?

    How do you connect to the Internet (dial-up, cable or DSL)? Do you use a router?

    Also open a command prompt Window by clicking Start, Run, and enter cmd and click OK. In the command prompt window type the below commands each followed by the enter key:
    ipconfig /flushdns
    ipconfig /all > c:\ipcfg.txt
    exit

    Now attach the ipcfg.txt file that was just created to your next message. And is there any change?
     
  12. Rick_Lincoln

    Rick_Lincoln Private E-2

    Right Chas :) firstly, have yourself a SMALL celebratory drink.....since you have had a partial success..... sorry for this long post but I want to give you as much info as I can:

    Firstly, I was a little confused by the first instruction... clicking Start does not give the option "explore"
    But, I tried start, Run, and typed in the number... same error as usual (computer tried to open internet explorer and gave the cant find server/dns error).

    Then I navigated to windows explorer by start, all programs, accessories, windows explorer. I then clicked "search" and then "search the internet" (damn that smug-looking little dog!!!). At this point I got a MSN search bar thing appear.
    I typed in the number you give (without the http bit) and it shows lots of links!
    Typed in "ntlworld.com" (which is mates homepage) and SUCCESS....it opened with full functions!!!! The really wierd thing is that from then on I can get anywhere...and even use his "favourites" folder to zoom round the net.......... so three cheers to you for that!! I can also get to here via typing the address in the search bar!

    However..... closing that down and double clicking the internet explorer icon....no joy whatsoever..it cant find anything!!!

    I have a good feeling that you are gonna tell me you know the problem now....but even if you dont at least my mate can now get around the web albeit in a rather long-winded way!!

    your other questions: It is a cable modem broadband connection. Sorry, dont know what a router is!

    So, to summarise where we are: Navigating to a msn searchbar via "windows explorer"; "Search"; "Search the internet" gives access to internet.

    Double clicking IE icon or navigating to Internet explorer via start, all programs gives no access at all (cant find server).....

    I have attached the ipconfig.txt below.

    Oh, another little sip of your beer for speeding up his navigation by huge amounts (I guess that is to do with removing all the crap!!)!!!!

    I feel this is the last push... unless you are gonne tell me that there is something major wrong with IE itself.. in which case please bear in mind that Windows on his computer was preinstalled and he doesnt have a disc (it is on a partition or something I believe.....totally genuine I hasten to add :)).

    Rick
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry! That was supposed to be right click Start and select Explore.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does the cable mode connect directly to your PC or is there something in between? It looks to me like it connects directly. Which means there is no router.

    Please give this a run: IEFix
     
  15. Rick_Lincoln

    Rick_Lincoln Private E-2

    FAB.... right... one phone call later:
    right click etc. takes him straight to here :-D

    He also says that he has been able to access and collect his webmail (hotmail) without problems too. Still no access via IE though?????????????
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you sse message # 14?
     
  17. Rick_Lincoln

    Rick_Lincoln Private E-2

    #14 just appeared!! (No router by the way)

    He has d/l iefix with no probs and unzipped it. We are both a little confused by the options though... Please forgive my high "wuss" factor but can you tell me what options he should check..."reinstall ie" looks a bit extreme!!

    Rick.... getting a bit excited !!
     
  18. Bob423

    Bob423 Private E-2

    Please excuse me for posting in the middle of this fascinating discussion which I am following since I seem to have a very similar problem. I won't butt in anymore but I just wanted Rick to know he was not alone since I have a very similar problem:
    It starts with:
    - Full internet connection, no problems (XP, DSL, Linksys router)
    - After some surfing (10 minutes to 2 hours), then IE6 loses internet connectivity ("cannot find server"), same with Firefox ("internet connection refused"), OE okay, no problem sending and receiving mail. All diagnostics on DSL connection show okay
    - Did "repair" out of "Local Area Connection Status" screen, no improvement, did ipconfig /renew, still no improvement
    - Deleted temporary internet files, worked once (internet connection reestablished), but since that one time, hasn't worked since. Never deleted the cookies though.
    - Scanned with updated definitions from SpySweeper, Norton AntiVirus, all clean (also used Ad Aware and SpyBot, same results)
    - Have Norton Firewall installed, up to date (subscriptions on SS, NAV and NFW)
    - System is over 2 years old (ouch!) but still okay (2.2MHz P4) and worked fine until about 3 months ago, never lost internet connection - all same hardware (router, DSL modem, etc.)

    I don't expect a reply since you're working with Rick. I just wanted Rick to know he was not alone on this weird IE6 problem (SP2, BTW, all updates directly from Microsoft site).

    Thanks Bob
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! Not the reinstall. Just click the Apply button. It will probably ask for your Windows CD or location of the i386 folder so it can find iexplore.exe.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should check for a router firmware upgrade from Linksys. I have seen several cases where that resolved similar issues. Did you try the ipconfig /flushdns ? If you still have issues you should start you own thread and reference this one instead of posting anymore here.
     
  21. Bob423

    Bob423 Private E-2

    Okay, will do and post my own thread. I've seen posts on a Slipstream 5200 modem problem similar to my problems that was solved with a firmware update. but I have the Slipstream 5667 modem and I haven't seen a firmware update for that one (yet). Haven't thought of the Linksys router, will look.

    I'll start a new thread.

    Thanks!!!!

    Bob
     
  22. Rick_Lincoln

    Rick_Lincoln Private E-2

    Hi Chas.... I am so sorry about this..... his windows OS (SP1) is preinstalled on the computer. He has run the iefix with both of the option boxes ticked (i.e. to say he has not got CD's) and it said "completed" but has not made any difference.
    He ran it again with neither box ticked and the programme is asking for CD's... I guess that he can insert the address of the file on his computer.... can you let me know where to look? You say the folder is i386.... does he simply search for that folder and paster the path into the box?
    I know these are really daft questions but I so firmly routed in the "if it says are you sure say no" mentality that I am scared I am going to set all your good work back!

    I have read the online instructions..... but clicking "cancel" when it asks for CD just seems to set up a loop where it keeps going back to some verification stuff (I am typing this while on the phone to him since I do not want to run the iefix on my own computer since it is OK... so I am talking him through it). We are going out for a beer now so I will check back later.
    Will have one for you!!

    Rick

    Hi Bob and good luck by the way!!!
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The i386 folder can be in a number of spots or may not be on your PC at all (could look on the original CD that came with the PC too).

    It could be:
    c:\i386
    c:\windows\i386
    c:\windows\inf\i386

    A files search may be easier.
     
  24. Rick_Lincoln

    Rick_Lincoln Private E-2

    Thanks Chas!
    I found the folder (C:\Windows\servicepackfiles\i386) and pointed to it as suggested. Something happened for a few seconds before the programme asks for "html32.cnv" and directions to it.... after trying the same folder again (which it wouldnt accept) I clicked cancel and it carried on for a few seconds before informing me that verification was going on (no problems there I can guarantee the version is genuine) but it then said something about files needed being on the CD please insert it now....
    As I said before, the computer in question does not have a windows CD. It was supplied with windows pre-installed on what I believe to be a hidden partition of the disc or something (On the one occasion about a year ago when we had to do a complete restore it did it without any CD's and said it was copying files from somewhere on the computer.... I cannot remember where).

    So, it looks to me like IE is corrupted and I dont know how to re-install it. Can you help at all (and if possible can you also tell me how to back up his "favourites" folder because it is very important to him).

    you have been brilliant so far and I am sorry to have to call on your services again....but my friend has certainly learned a valuable lesson about downloading things with no thought!!! :)..... mind you, so have I!!!!

    Regards
    Rick
     
  25. Rick_Lincoln

    Rick_Lincoln Private E-2

    Hi again... just a thought...could I find any files that iefix asks for on my own computer, copy them to a disc, and paste them on mates computer in the same file? Are the files generic or specific to the system they are on?
    Am also using this as an excuse to bump my post!!
    Rick
     
  26. Rick_Lincoln

    Rick_Lincoln Private E-2

    I wanted to edit below post to avoid multi posting but failed!
    This may sound stupid... but could we simply go to windows update and re-download IE6????? I was gonna say uninstall it first but that would be ridiculous wouldnt it!!!?

    I am sure that if it were that easy then iefix simply would not be needed!

    Rick
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! This would not be the same. What we are trying to do is perform a fix. The fix will re-register certain files. Merely copying the files does not do that.

    I have never need to use IE fix myself and am not that familiar with it.
    You cannot uninstall IE. It is an integral part of the OS. I could try as suggested a re-download and re-install of IE6 and see if that will work.

    This discussing is probably better off being discussed in the Software Forum then here in the Spyware Forum. While Spyware may have caused some of the problems you are having the repairing of IE (if that is all that is wrong) may get better attention in the Software Forum.
     
  28. Rick_Lincoln

    Rick_Lincoln Private E-2

    Thanks Chas!! your help has been really appreciated!!! Shall I start a brand new thread in Software and if I do may I refer the guys there to this thread?

    Once again, many many thanks!!!!

    Rick
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! Start a new thread in Software and clearly state what your remaining problems are. I think the main thing you want to accomplish there is the reinstall or repair of IE6. You can reference this thread for background.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds