Question

http://go.microsoft.com/fwlink/?LinkId=69157 redirects to www.msn.com

Asked by: configreq

I can't change the homepage for IE7; it keeps redirecting to www.msn.com  Recently installed IE7 on XP Pro SP2 laptop which was cleaned from 120 plus spywares, malwares, adwares, trojans, and virus'.  Cleaned with numerous tools.  Tools used:  Norton Antivirus removal, Norton Antivirus, AVG Antivirus, AVG Spware Removal, Webroot Spyware Removal, Registry Mechanic, MRUBlaster, and pick and delete through folders and registry.  Owner didn't have original OS disks, or App disks.  Cannot stop the IE page homepage from being www.msn.com.  First in Inet Options I change to www.google.com or anything else, and it redirects to www.msn.com with the following link:  http://go.microsoft.com/fwlink/?LinkId=69157  When I try to search for this in the registry the CPU heats up kicks into overdrive, the fan can't keep it cool enough and it shuts off.  I cooled it enough with a ice block and fan...don't laugh.  I got to view the search of the registry but nothing was found with this key.  I still can't view all of looking for www.msn.com in the registry without it shutting off.  This may be just a prank left over from all of the mess that that removed from this box.  Or it may be as destructive as phifishing.  At any rate, do you have any idea how to stop it?  Adware.PurityScan, 2o7.net cookie, atlas dmt cookie, remain after all the cleaning.  The ugliest path that keeps getting checked, but doesn't seem to exist in Windows or DOS mode is C:\Program Files\Common Files\?icrosoft.NET.tracert (part of the My Doom Trojan Horse Downloader.Generic3.CVH.  Generic2.CVH was in User\Local Settings\Temporary Internet Files\Content.IE5\57TONLD\lupdate-4295(1).0000.  There are many more; like I said 120 at least.  I know I should reinstall the OS (but I don't have it), nor do I want to go through all of the User apps.

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2007-02-19 at 21:14:22ID22400171
Topics

Anti-Spyware

,

Windows XP Operating System

Participating Experts
5
Points
500
Comments
21

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. (Re-)joining a Domain fails with "... LinkId=517…
    Trying to solve a connection problem in my network (clients couldn't connect at all to a shared printer and connecting with the same clients other shares took several retrials), I decided to leave and rejoin the domain with the particular client (after other solutions didn't ...
  2. spyware
    hello I recently ran microsoft antispyware and removed spyware from my computer and then restored the browser settings to default but for some reason I can't seem to restore my search page as it keeps coming up with this page cannot be displayed ... I've included a hijack t...
  3. Spyware  win32.agent.at and Trojan.Vundo
    Windows xp Home system PC is infected with spyware/malware. I keep runing AVG spyware, Spybot Search and Destroy, and Adaware SE personal. As long as the box is NOT connnected to the ent I can get all of the out of here, save this damn win32.agent.at Once I get a...
  4. 'System.Net.Dns.Resolve(string)' is obsolete: '…
    Here is my current code: IPHostEntry inetServer = Dns.Resolve("www.example.com"); ServerIP = Convert.ToString(inetServer.AddressList[0]); //convert first entry of array to string tbServerIP.Text = ServerIP; //put it in textbox How woul...
  5. IE7 default Home page keeps on reverting to http://go.…
    Hi All I set my home page to www.smh.com.au but each time I reboot my computer, the home page under TOOLS...INTERNET OPTIONS reverts to http://go.microsoft.com/fwlink/?LinkId=69157 When I launch the browser, http://go.microsoft.com/fwlink/?LinkId=69157 flashes briefly i...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: Bartender_1Posted on 2007-02-19 at 21:18:09ID: 18568516

Have you tried running Hijackthis from http://hijackthis.de ?

Download the software, run and save a log file, then you can load the log file into the website and analyze it. It will tell you what is not good on your system, or at least directions to look in.

Or you can post it here and we'll analyze it and tell you what you want to clean.

Hope this helps!

:o)

Bartender_1

 

by: orangutangPosted on 2007-02-19 at 23:05:37ID: 18568822

:) That would be really weird if it was a spyware problem. Why would spyware change your homepage to http://www.msn.com? Or maybe it's really advanced and it says it's MSN but it's really a redirection. Anyway, you could try setting the homepage manually through regedit:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main and HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main

Change the "Start Page" value to what you want.

 

by: orangutangPosted on 2007-02-19 at 23:10:38ID: 18568833

Also, if regedit acts weird, you can also try Tuneup Utilities(http://tuneup.swmirror.com/TU2007TrialEN.exe). It has their own customized version of regedit. Also, use the registry cleaner once you've sorted everything out and your computer is clean of virus/spyware/adware.

 

by: jvuzPosted on 2007-02-20 at 00:36:12ID: 18569037

Does he uses a firewall?

 

by: jvuzPosted on 2007-02-20 at 00:37:26ID: 18569042

Also check your host file (C:\WINDOWS\system32\drivers\etc\hosts)

 

by: SudburyComputerPosted on 2007-02-20 at 04:25:08ID: 18569769

Either Norton or Spysweeper is blocking the change.  My money is on Spysweeper.  Disable Spysweeper and you will notice that the change takes.  Then go into Spysweeper and go through the options until you find home page protection and you will see where you can have it allow you to change the page when you need to.

 

by: rpggamergirlPosted on 2007-02-21 at 14:31:02ID: 18582898

Sometimes homepage are locked by security programs like Norton Zone alarm, SpySweeper, Spybot S&D, Windows Live.
If you're that one of your programs are not locking the homepage then it's definitely malware that's causing it.

As for Purityscan.
1.  Please go to your Add/Remove programs and uninstall any apps by OIN
Oin
Yazzle by Oin
Purityscan by Oin
Snowballwars by Oin
Cowabanga by OIN
or anything similar with Oin in it
If you do not see any icon for "OIN" or "(program) by OIN" in Add/Remove Programs, please download their stand-alone uninstaller.
http://www.outerinfo.com/OiUninstaller.exe.


2.  Can we also look at your hijackthis log?
http://danborg.org/spy/hjt/alternativ.exe
Open Hijackthis, click "Do a system scan and save a logfile" don't fix anything yet.

Then upload the log to any hosting sites,
or go to the below link and login using your Experts-Exchange username and password.
http://www.ee-stuff.com
Click on "Expert Area" tab
type or paste the link to your Question
"Browse" your pc to the location of your Hijackthis log and click "Upload"
Copy the resulting "url" and post it back here.

OR: either this site:
http://www.rafb.net/paste/
then at the bottom left corner click "paste"
Copy the address/url and post it here:

If you have trouble uploading the log elsewhere, then just paste it here.


3.  Here's also a very good scanner:
http://www.superantispyware.com/

 

by: configreqPosted on 2007-02-21 at 19:41:46ID: 18584867

Thank you for all your suggestions.  I am trying multiple solutions.  I will keep you posted.

1.  I do not have hijackthis yet; couldn't easily find--will though
2.  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main did have the http://go.microsoft.com/fwlink/?LinkId=69157 link; however, once changed and changed in Inet Opts, changed back (even w/firewalls stopped).   HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main did not.
3.  I have not tried (http://tuneup.swmirror.com/TU2007TrialEN.exe) yet;
4.  Yes, he does use a firewall; however, tried stopping -- no avail
5.  C:\WINDOWS\system32\drivers\etc\hosts was default -- no avail
6.  Neither Norton or Spysweeper was blocking the change -- no avail
7.  Will not use http://www.outerinfo.com/OiUninstaller.exe; contains Adware.MediaTicket
8.  Still have not gotten hijackthis; plan to upload the edited (protect user)  log for review.
9.  Running http://www.superantispyware.com/ now; 9 threats found so far, including Yassle.

I have approx 20 pages of writeup to do.  This was a very unusual box.  I will post the write up here.  Here is what I have so far:
February 9, 2007

User complaint:  Cannot view web.  Laptop connects, but unable to view.  Numerous errors pop up.
____________________
Checked SSL, TLS settings - good
_____________
Used Cingular Communications Manager – Showed full bars/full connection
____________________
ipconfig –all – showed no connection media, IP 0.0.0.0
____________________
Errors upon bootup:
NT On – Access Scanner Service
szAppName:  szAppVer: 0.0.0.0 szModName:Kernel32.dll
szModVer:5.1.2600.1106 offset 00013887
Symantec Email Proxy
TCP/IP is disabled.  Disable email scanning in your Symantec product options or install TCP/IP 1003,3
http://www.symantec.com/techsupport/servlet/ProductMessages?module=1003&error=3&lanuage=English&product=CC&version=104.0.1.17

_________________________

Microsoft Visual C++ Runtime Library
Runtime Error!
Program C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

.....more to follow :o)




 

by: configreqPosted on 2007-02-21 at 19:47:32ID: 18584895

Dell Inspirion 5100
Pentium 4
CPU 2.8 GHz
512MB RAM
_____________________________________________
Event Type:      Warning
Event Source:      Userenv
Event Category:      None
Event ID:      1524
Date:            2/9/2007
Time:            6:08:39 PM
User:            S-1-5-21-204266967-2096854778-2472988758-1005
Computer:      HOSTNAME
Description:
Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use.  
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
_____________________________________________

Event Type:      Error
Event Source:      SENS
Event Category:      None
Event ID:      0
Date:            2/9/2007
Time:            7:36:53 PM
User:            N/A
Computer:      HOSTNAME
Description:
The description for Event ID ( 0 ) in Source ( SENS ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Event System Win32 Error: No service is operating at the destination network endpoint on the remote system.
, ServiceStart(): SensInitialize() failed.

_____________________________________________
Event Type:      Error
Event Source:      McLogEvent
Event Category:      None
Event ID:      5051
Date:            2/9/2007
Time:            7:43:56 PM
User:            NT AUTHORITY\SYSTEM
Computer:      DRTOM
Description:
The description for Event ID ( 5051 ) in Source ( McLogEvent ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: c:\PROGRA~1\mcafee.com\vso\mcshield.exe, 201608, 808 (0x328), 0x7ffe0304,
 Build Sep  8 2001 15:13:39 / 8.52
 Object being scanned = \Device\HarddiskVolume2\Documents and Settings\UserName\Local Settings\desktop.ini   ( @ 7025 (7024,7019,7011,93))

_____________________________________________

Event Type:      Error
Event Source:      Application Error
Event Category:      (100)
Event ID:      1000
Date:            2/9/2007
Time:            7:44:00 PM
User:            N/A
Computer:      HOSTNAME
Description:
Faulting application , version 0.0.0.0, faulting module KERNEL32.DLL, version 5.1.2600.1106, fault address 0x00013887.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74   Applicat
0008: 69 6f 6e 20 46 61 69 6c   ion Fail
0010: 75 72 65 20 20 20 30 2e   ure   0.
0018: 30 2e 30 2e 30 20 69 6e   0.0.0 in
0020: 20 4b 45 52 4e 45 4c 33    KERNEL3
0028: 32 2e 44 4c 4c 20 35 2e   2.DLL 5.
0030: 31 2e 32 36 30 30 2e 31   1.2600.1
0038: 31 30 36 20 61 74 20 6f   106 at o
0040: 66 66 73 65 74 20 30 30   ffset 00
0048: 30 31 33 38 38 37         013887  
_____________________________________________


 

by: rpggamergirlPosted on 2007-02-21 at 21:09:19ID: 18585187

http://www.outerinfo.com/OiUninstaller.exe <-- this is the uninstaller that uninstall OIN programs if they are not listed in your add/remove programs list.
Malware experts in the most reputable antispyware forums are using it. I know it comes from the company that installs it in the first place but it works when manual removal doesn't.

It's up to you.

 

by: rpggamergirlPosted on 2007-02-21 at 21:32:01ID: 18585252

It's understandable for the uninstaller to be flagged by your antivirus.
just to prove to you that it doesn't come with mediaticket, I downloaded it and run it, of course my Kaspersky alerts me of it being adware purityscan which of course understandable. So I disable Kaspersky, I can assure you it didn't install mediatickets or anything nasty in my pc.

Smitfraudfix that removes smitfraud infection are flags by McAfee and some antivirus as a virus itself. Just like merijn's hijackthis was flag as a virus.
It's common for antiviruses to flag something as nasty, but it is understandable that the OIN uninstaller will be flagged.

Anyway, it's your decision, if you don't trust my advice that's fair enough.

 

by: configreqPosted on 2007-02-21 at 23:57:56ID: 18585647

rpggamergirl.   Now how can you possibly say that I don't trust your advice, I'm happy to have your advice and I've been using the tools you provided for the last 4 hours.  No doubt you know what you are talking about!  As for Purityscan -- its definately part of the promblem:  both Yazzle and Cowabanga.  Just had to pick what to use first.  You can look at the hijack log in that you provided me an excellent link.    And I certainly thank you for http://www.superantispyware.com; I was amazed to still see 19 items left.  What was even more amazing was when it started cleaning, and it kept trying to install itself into the Restore partitions  I ran two different Antispyware and Antivirus tools on two different computers for the http://www.outerinfo.com/OiUninstaller.exe and came up with the same results: MediaTicket; there are many false positives, I'm sure this must be one.  Thanks for everything, but I still need your help.


 

by: configreqPosted on 2007-02-22 at 00:06:56ID: 18585666

February 9, 2007

Ok, guys and gals.  This has become an obsession and I need to get rid of this box!  I have this one final thing to fix and the output of hijackthis is at the bottom of this post.  I have run the latest http://www.superantispyware.com.  I have changed HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main to reflect www.dogpile.com.  I have disabled:  Norton Antivirus, Spyweeper, Superantispy, engaged the wireless modem, brought up IE7, and it still throws the redirect up.  Maybe I'm just tired and not seeing something.

_______________________
Tools used:

WinsockxpFix.exe
Norton_Removal_Tool
20070215-033-x86 NAV defs forced
Norton SystemWorks 2006
avg75free_441a944.exe
avgas-setup-7.5.0.50
CheckIt
cports.zip from nirsoft.net
xp_exe_fix.zip
Helix fprot antivirus
IE7-WindowsXP-x86-enu.exe
Webroot SpySweeper
mrublastersetup.exe
regscanner from nirsoft.net
spywareblastersetup351.exe
myuninst.zip
Registry Mechanic
SuperAntiSpyware.exe
alternativ hijackthis

___________________________________-
Found throughout:
Trojan LuckBar888
Adware Softomate
Adware Click Spring
Adware Drive Clean
Trojan Dropper.Dollar
PurityScan
Webhancer
SaveNow
Not-A-Virus
Adware New Dot Net
Trojan Downloader
Trojan Dropper.Small
Adware Why PPC
Tracking Cookie Clickbank
Tracking Cookie TribalFusion
Tracking Cookie Findwhat
Adware Media Ticket
Adware Command
Adware Maxfiles

_________________________________

User liked viewing porn sites
User did not keep service packs and hot fixes up to date
User accepted that Norton Antivirus had stopped working
User had no firewall
User had no Anti Spyware

_________________________-
Best guess:  user viewed particular porn site
Picked up Webhancer
Opened vulnerabilities for Adwares
Opened port for MyDoom2
Opened vulnerabilities for Dropper.Dollar
Opened port for MyDoom3
Disabled / corrupted Anti-virus portion of Norton SystemWorks
Norton corrupted TCP/IP Stack
Made numerous copies of self in GoBack
Opened port for Dropper.Small
Lost connectivity December 14, 2006

_____________________________

Here's the history:

User complaint:  Cannot view web.  Laptop connects, but unable to view.  Numerous errors pop up.
____________________
Checked SSL, TLS settings - good
_____________
Used Cingular Communications Manager – Showed full bars/full connection
____________________
ipconfig –all – showed no connection media, IP 0.0.0.0
____________________

Check Network Connections

Connected.  Cingular Accelerated Connected.  Full Bars.

ping google.com
Windows Sockets interface, error code 0 returned
_______________________
WINDOWS
IP Configuration
IP Routing Enabled:  No
WINS Proxy Enabled:  No
Ethernet Adapter Wireless Network Connection: 2
Sierra Wireless 3G Adapter
DHCP Enabled: Yes
Autoconfiguration Enabled: Yes
Subnet Mask 0.0.0.0
IP Address 0.0.0.0
Default Gateway
DHCP Server 0.0.0.0

ipconfig /all
no media connected

____________________________

Errors upon bootup:
NT On – Access Scanner Service
szAppName:  szAppVer: 0.0.0.0 szModName:Kernel32.dll
szModVer:5.1.2600.1106 offset 00013887
Symantec Email Proxy
TCP/IP is not disabled.  Disable email scanning in your Symantec product options or install TCP/IP 1003,3
http://www.symantec.com/techsupport/servlet/ProductMessages?module=1003&error=3&lanuage=English&product=CC&version=104.0.1.17
________________________
Microsoft Visual C++ Runtime Library
Runtime Error!
Program C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
______________________________

Program:C:\Program Files\Common Files\Symantec Shared\ccApp.exe
____________________________________
ConfigWiz
Another instance of the Wizard is running
_________________________________
Services running AIM at startup
__________________________________

Checked Logs --- Significant:

Dell Inspirion 5100
Pentium 4
CPU 2.8 GHz
512MB RAM

Event Type:      Warning
Event Source:      Userenv
Event Category:      None
Event ID:      1524Date:            2/9/2007
Time:            6:08:39 PM
User:            S-1-5-21-204266967-2096854778-2472988758-1005
Computer:      HOSTNAME
Description:
Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use.  
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
_____________________________________________

Event Type:      Error
Event Source:      SENS
Event Category:      None
Event ID:      0
Date:            2/9/2007
Time:            7:36:53 PM
User:            N/A
Computer:      HOSTNAME
Description:
The description for Event ID ( 0 ) in Source ( SENS ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may

be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Event System Win32 Error: No service is operating at the destination

network endpoint on the remote system.
, ServiceStart(): SensInitialize() failed.

_____________________________________________
Event Type:      Error
Event Source:      McLogEvent
Event Category:      None
Event ID:      5051
Date:            2/9/2007
Time:            7:43:56 PM
User:            NT AUTHORITY\SYSTEM
Computer:      HOSTNAME
Description:
The description for Event ID ( 5051 ) in Source ( McLogEvent ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer.

You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: c:\PROGRA~1\mcafee.com\vso\mcshield.exe, 201608, 808

(0x328), 0x7ffe0304,
 Build Sep  8 2001 15:13:39 / 8.52
 Object being scanned = \Device\HarddiskVolume2\Documents and Settings\UserName\Local Settings\desktop.ini   ( @ 7025 (7024,7019,7011,93))

_____________________________________________

Event Type:      Error
Event Source:      Application Error
Event Category:      (100)
Event ID:      1000
Date:            2/9/2007
Time:            7:44:00 PM
User:            N/A
Computer:      HOSTNAME
Description:
Faulting application , version 0.0.0.0, faulting module KERNEL32.DLL, version 5.1.2600.1106, fault address 0x00013887.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74   Applicat
0008: 69 6f 6e 20 46 61 69 6c   ion Fail
0010: 75 72 65 20 20 20 30 2e   ure   0.
0018: 30 2e 30 2e 30 20 69 6e   0.0.0 in
0020: 20 4b 45 52 4e 45 4c 33    KERNEL3
0028: 32 2e 44 4c 4c 20 35 2e   2.DLL 5.
0030: 31 2e 32 36 30 30 2e 31   1.2600.1
0038: 31 30 36 20 61 74 20 6f   106 at o
0040: 66 66 73 65 74 20 30 30   ffset 00
0048: 30 31 33 38 38 37         013887  
_____________________________________________

Installed People PC ISP
ipconfig /all
no connection media

uninstalled People PC ISP

____________________________-

googled errors:
Followed SENS error
joined Experts Exchange
Found answer with -- Windows XP Home Can't Get an IP Address_WinsockxpFix.exe

_______________________

GOT CONNECTION
__________________________

Multiple popups
Freezes
Stalls
Overheating

_____________________

Application Errors:

June 2006 System Volume Information \ eatalog.wci is corrupt

July 2006 Classes registry file corrupt

July 2006 msvcrt.dll - bpgame.exe - McAfee

Aug 2006 Outlook MOF

__________________________


Other logs:  Logs saved (Windows format):
______________________________________________

BootTime with hard connect 3 min


____________________________________




Specs of the system:
Display Adapter      Mobility Radeon 7500
Conexant D480 MDC V.92 Modem
Sierra Wireless AirCard 3G Modem
Standard Modem
Multifunction adapters


- Sierra Wireless AirCard 3G
   adapter parent
Network Adapters
- 1394 Net adapter
- Broadcom 440x 10/100 Integrated Controller
- Sierra Wireless Adapter

PCMCIA adapters
- Texas Instruments PCI -4510 cardbus controller

IRQ:
11 – Sierra Wireless 3G Adapter
11 – Sierra Wireless Air Card 3G Modem
10 – Conexant D480 MDC V.92 Modem


____________________________________
Add and Remove
Programs:

Tried to remove:
888Bar
error while uninstall:  New Starter Uninstall:  Completed
Could not load C:\Program Files\Common Files\ {3CA20FSF-OAE5-1033-0428-030211050001}\888Bar.dll
Completed

Adobe Downloader Manager 2.0 (Remove Only)
1/13/2005

Adobe Reader 7.05
1/13/2005

AIM 6.0
12/15/2006


AOL Instant Messenger
11/12/2006

AOL Toolbar 2.0


Cingular Communication Manager
Publisher: Cingular
Version:  5.2.19.0
Cust Supp 1-800-331-0500

Cowabanga by OIN
12/11/2006

Dataware
DAO

Dell Support
2/11/206

Direct X Media Runtime 5.1

HP Document Viewer

Live Update 2.7 / Symantec Corp
1/29/2007
Version 2.7.39.0

McAfee Security Center
6/1/2003

McAfee Virus Scanner Online
6/1/2003

Microsoft Encarta

Microsoft Money 2003
6/1/2003

Microsoft Money 2003 System Pack
6/1/2003

Microsoft PowerPoint Viewer 97
6/11/2003




Microsoft Streets and Trips 2002
6/1/2003

Microsoft Works Setup Launcher
6/1/2003

Microsoft Works 7.0
6/1/2003

Microsoft Works 7.0 Suite Addin
6/1/2003

___________________________________
exported Reg C:\Windows\System32\9FEB07.reg

___________________________________

created Windows Restore Point – appeared to be effective.

xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

***OIN Installations EULA, AVG Antispyware scan report and Hijackthis log removed by rpggamergirl PE***

xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

3 hours trying to use Norton SystemWorks

continuous shutdowns

________________________________

Started Install XP SP2 from CD
2 failures -- over heat
_______________________________

cooled with upside down compressed air

______________________________

Installed XP SP2

______________________________

Posted this at Experts Exchange

I would like to install Symantec Norton SystemWorks 2006 (don't have original software).  I have partially removed a corrupt version of 2006.

I'm working on a Windows XP Pro Dell laptop.  I had the problem where I couldn't connect on all medias.  I used experts-exchange suggested http://www.snapfiles.com/get/winsockxpfix.html and it worked

FANTASTICALLY!  So I not longer had the 'TCP/IP is not disabled.  Disable email scanning in your Symantec product options or install TCP/IP 1003, 3  

http://www.symantec.com/techsupp/servlet/ProductMessages?module=1003&error=3&language=English&product=CC&version=104.0.1.17

I initially thought my problem was tied to a corrupt Symantec Norton SystemWorks 2006.  There were all kinds of problems and would not remove completely. I got desparate and tried to hack Symantec and Norton

out of the registry (backed up) and pick through the directory.  But I get the same problems.  I am trying to reistall the app.  I tried Symantecs' 'NortonRemoval Tool'.  The problem seems to be the Goback.  But even

though the GoBack.rxc is missing, I did get a success restore out of it after a bluescreen scare (use of Webroot Spysweeper (removing 77 instances; latest being 'webhancer' -- a proposed adware that changes reg

and runs in memory).  (may be the initial problem -- December 14, 2006)

Upon bootup, I get Norton 2006 Corrupt - A necessary file could not be loaded: NAVPro   1002, 1  --- which is the same problem as 18 hours ago.  

http://www.symantec.com/techsupp/servlet/ProductMessages?module=1002&error=1&language=English&product=CC&version=104.0.1.17 it puts me back to the removal tool.

__________________________


Deleted Temporary Inet files  
Deleted Trash
Disk Defrag
Removed McAfee -- long process
Removed Symantec Utilities - again

__________________

Posted again:
This is my first time using this.  I guess I need to ask now what?  I have a concern.  The kernel is in my best guess still unstable.  I do not wish to remove the GoBack since it really was able to recover the box nicely.  

I would just like to be able to install the Utilities and the Antivirus, if possible.  Since webhancer, I suspect the laptop as being a bot.  Let's discuss further....I think may be dealing with ADS (alternate data streams)

http://www.microsoft.com/technet/sysinternals/utilities/Streams.mspx in that the HD has 17GB available, yet when trying to choose additional features of Norton SystemWorks, it shows that it will take approx 300MB

to install but to install on 0 (zero) K.  I need to return this box to the user as soon as possible.

_________________

I'm going to try to boot to a linux antivirus and removal tool -- Helix and clean in this fashion.  I will keep you updated.  However, I'd like to hear your direction.

_______________

This didn't work.  Mounted drives but saw 0 files.  Received WARNING:  Hard link count is wrong for /:  This may be a bug in your filesystem driver.  I have downloaded the free version of AVG Anti-Spyware.  So far

Adwares/Malwares found quarantined and/or deleted.  Next I'll run there AV.  Still waiting on hearing your approach.

____________________

SAFE MODE

________________

msconfig

repeats

___________

pic through files -- Program Files\Common Files and registry
LiveUpdate
CheckIt
Norton
Symantec

___________

Finally Norton Removal Tool and remove Norton

________________

Installed / ran CheckIt

_______________

System Passes All

_______________

4 attempts to install Norton SystemWorks
CPU maxed ---- overheat
________________________-

ALL USER DATA BACKED UP TO REMOVABLE MEDIA

_________________________

Installed on its side with fan blowing behind
block of ice to cool to push into intake of laptop

Norton Installed

___________________

There's another 10 pages, but you get the idea:
willing to answer any questions.

________________

webhancer
purityscan
savenow
targetsaver
go.com
zango
findwhat
2o7net

Thank you.

 

by: rpggamergirlPosted on 2007-02-22 at 01:56:22ID: 18586053

>>>> We recommend that you print out a copy of these terms for future reference. Installation and use of the Company's Software is voluntary, and you may terminate this EULA at any time by uninstalling the Company's Software (including the Company's advertising-supported software) using the Microsoft Windows Add/Remove Programs function on your computer or running our uninstaller at http://www.outerinfo.com/OiUninstaller.exe.<<<<


You were not downloading the uninstaller by that looks. You were actually downloading OIN programs itself, that is worst! You might've gone to their website instead of clicking the standalone OIN Uninstaller link.

When I downloaded the OIN Uninstaller, I wasn't presented with any EULA, all it asks was for me to input those 4 letters to make sure that I'm human and not a machine. And then it says that application will be uninstalled and that's it.

You need to just click on this link --> http://www.outerinfo.com/OiUninstaller.exe
it's a direct download, save it to your desktop and run it.


Those in the system restore can be easily remove by fluching system restore points.
NewDotNet would have been the one that cuts off the internet connection, it is well known for that.

You can fix thewse entries in hijackthis:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =  
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: (no name) - {4EB4958B-096F-0A97-4801-0A923F5E899C} - (no file)
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\3.7.0\ViewBarBHO.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.7.0\IEViewBar.dll

O4 - HKCU\..\Run: [Eeulttco] C:\Program Files\Common Files\?ssembly\??oolsv.exe <-- this one is the purityscan entry.

O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Program Files\Poker.com\Poker.exe (HKCU)
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/ZwinkyInitialSetup1.0.0.15.cab


I would uninstall Viewpoints Manager as well.

this file below if still present delete it.
C:\Program Files\Common Files\ {3CA20FSF-OAE5-1033-0428-030211050001}\888Bar.dll


I would also suggest downloading and running combofix or maybe run a rootkit scanner, with all those nasties, I won't be surprised if rootkit is in there as well.
Download this file - combofix.exe
http://download.bleepingcomputer.com/sUBs/combofix.exe
Double click combofix.exe & follow the prompts.
When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

 

by: rpggamergirlPosted on 2007-02-22 at 02:03:00ID: 18586083

I would also suggest to scan for rootkits:

1.  Download (Download the GUI) version of BlackLight, and save it to your desktop.
https://europe.f-secure.com/blacklight/try.shtml
Doubleclick blbeta.exe, accept the agreement, click scan > next.

You'll see a list of all the items it found. There will also be a log on your desktop with the name fsbl.xxxxxxx.log (where xxxxxxx represents numbers). The application finds both bad files and legitimate ones such as "wbemtest.exe", so don't choose the rename option yet! Copy and paste the log it generated in your next reply.


2.  Rootkit Revealer:
http://www.sysinternals.com/files/rootkitrevealer.zip
Unzip it to it own folder or to your desktop.
Run RootkitRevealer.exe and scan your system. When the scan is complete click on File, Save, and save the log file. Post the log here.
In order to minimize RKR log being polluted with legit data run RootkitRevealer on an idle system.

 

by: SudburyComputerPosted on 2007-02-22 at 02:47:21ID: 18586324

There comes a point when it makes more sense to rebuild the system than to keep troubleshooting.  I think you are well past that point.
There may be so many corrupted files by now that the system may never run right.
Backup your data and scrub it well using many scanners and rebuild the system.

 

by: configreqPosted on 2007-02-22 at 16:31:59ID: 18592814

Yes SudburyComputer,

I agree, but I can't stop now--I'm learning far too much.  I'm not getting any money for this box; it was just a really good way to get back into a sideline business -- and back into geeking after 10 years.  The user doesn't seem to have any of the original software either, so it would kind of be a hassel to use mine, activate, download, etc, etc, etc, this is much more fun.

 

by: configreqPosted on 2007-02-22 at 21:20:50ID: 18593975

rpggamergirl,

You know your stuff!!!!  LOTTA ROOT KIT!!!  Wish I could give you 5,000 points!!  I believe this to be a kernel-mode rootkit; hence the former found KERNEL32.DLL corruption; and the unavailability with HELIX to view

drive partions.  Mounted drives but saw 0 files.  Received WARNING:  Hard link count is wrong for /:  This may be a bug in your filesystem driver.

HERE IS THE ANSWER FOR THE REDIRECT:  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG  -- Rootkit Revealer told me.
Data Mismatch between Windows AP and raw hive data  .....It appears to be the last piece (and the most cryptic...no pun intended--well maybe).

Now if I could just get the binary key; or learn how to import one from another computer.....with it being a crypto key, could I just copy it? I wonder.....

If not:  It's OK  the msn is a ligitimate site.  I loaded Opera:  Version 9.10 Build 8679  Platform Win32 System Windows XP Java Sun Java Runtime Environment version 1.5
XHTML+Voice Plug-in not loaded for the main browser to ensure that http://go.microsoft.com/fwlink/?LinkId=69157  does infact redirect to www.msn.com; and it does.


Thank you, thank you....this is one of the cleanest-fastest-boxes that I have ever used.



I used the OIN uninstaller http://www.outerinfo.com/OiUninstaller.exe

I uninstalled Viewpoints Manager Add/Remove

I used https://europe.f-secure.com/blacklight/try.shtml  ---- AWESOME!

I applied all the reg fixes you stated.
Again manually edited HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main; where it shows the redirect; made sure no tools running; made sure no firewall running; changed Inet Options and it

changed back

I removed C:\Program Files\Common Files\ {3CA20FSF-OAE5-1033-0428-030211050001}\888Bar.dll

Sad news:  combofix has been desupported by the author
>>The tool, ComboFix has been temporarily withdrawn. The author discovered a rootkit infection that will intefere with ComboFix's running. This will cause Combofix to be UNSAFE FOR USE on your machine.
Even if you manage to find a mirror for the tool, PLEASE DO NOT RUN THIS TOOL  Apologies for any inconvenience caused <<

xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
***Rootkit Revealer's and Hijackthis' logs removed by rpggamergirl, PE***
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

DONE.  THANK YOU.




 

by: rpggamergirlPosted on 2007-02-22 at 22:13:08ID: 18594162

Sorry about the combofix, yeah it is now withdrawn because if this rootkit -->qwertybot.exe
IF present in the system ,it will caused combofix to malfunction,(deletes all the files in the systemdrive, terrible outcome)

According to sUBs(author), the rootkit involved is relatively easy to disinfect. Reboot to safe mode & HJT fix the O4 entry below:

HKLM\..\Run - [qwertybot.exe] - C:\Windows\system32\qwertybot.exe

Delete files:
C:\Windows\system32\qwertybot.exe
C:\Windows\system32\comdlg77.dll

But, even if the "qwertybot.exe" is not present, some other rootkits that comes along might do the same thing, so the author withdrawn the tool. The file in the link now is just a dummy file.


RKR log, well those in the System volume information is easy to remove by turning off System Restore and rebooting.
Those in Norton's protected bin, if I were you I would turn it off or empty it to recover the lost space. Norton's bin do take up a lot of space, everything goes in there, even the files from the windows recycle bin goes in there, it's the destination of all deleted files.


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG <-- this usually a false positive, it shows up sometimes in RKR, part of the internal encryption used by Microsoft Windows, and the "Seed" variable under that key is heavily protected.


Hijackthis log looks good, you can fix these entries below, these are just registry clutters:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =  
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

Now that this question is closed, we can delete the logs so people don't have to scroll much.
Is the pc okay now?

Thanks for the points!

 

by: configreqPosted on 2007-02-23 at 04:51:10ID: 18595360

rpggamergirl,

Yes, please delete the logs.  I tried to sanitize but I missed.  I was loosing sleep over that last night/this morning.  I would request you keep the first part of my stuff only:
i.e., Tools used:

WinsockxpFix.exe
Norton_Removal_Tool
20070215-033-x86 NAV defs forced
Norton SystemWorks 2006
avg75free_441a944.exe
avgas-setup-7.5.0.50
CheckIt
cports.zip from nirsoft.net
xp_exe_fix.zip
Helix fprot antivirus
IE7-WindowsXP-x86-enu.exe
Webroot SpySweeper
mrublastersetup.exe
regscanner from nirsoft.net
spywareblastersetup351.exe
myuninst.zip
Registry Mechanic
SuperAntiSpyware.exe
alternativ hijackthis

___________________________________-
Found throughout:
Trojan LuckBar888
Adware Softomate
Adware Click Spring
Adware Drive Clean
Trojan Dropper.Dollar
PurityScan
Webhancer
SaveNow
Not-A-Virus
Adware New Dot Net
Trojan Downloader
Trojan Dropper.Small
Adware Why PPC
Tracking Cookie Clickbank
Tracking Cookie TribalFusion
Tracking Cookie Findwhat
Adware Media Ticket
Adware Command
Adware Maxfiles

_________________________________

User liked viewing porn sites
User did not keep service packs and hot fixes up to date
User accepted that Norton Antivirus had stopped working
User had no firewall
User had no Anti Spyware

___________________________________

and the last comment prior to this, if I can pick and choose what stays and goes.

__________________________


I don't know the site policy, I'm new to this.  Again thanks, and I will put the last pieces provided in place.

 

by: rpggamergirlPosted on 2007-02-23 at 06:34:03ID: 18596175

configreg,

It's okay, there is no site policy on posting Hijackthis logs. But it is recommended that logs are uploaded to any hosting sites and only post the link here, or at EE-stuff.com because some logs can be quite lengthy.

I only removed the OIN Installations EULA, AVG Antispyware scan report, 2 Hijackthis logs, Rootkit Revealer's log, and left everything else intact.

In the Hijackthis zone, we don't delete hijackthis logs, well I don't anyway, :)
http://www.experts-exchange.com/Software/Internet_Email/Spy_Ad_Blockers/HijackThis/

Thanks!

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...