rngrfan
asked on
DNS ERROR cant connect to internet
I was working on a friends Sony Viao Desktop P4 120gig HD 256RAM with Windows XP home.
He had almost 700 instances of spyware and adware that I removed with Spybot and Adaware. (should mention that this is before updates were done so Im sure there is more)
Problem now is that after removing that and his Norton Internet security(was expired) I can no longer connect to the internet.
I am on a DSL and have a DLink router.
If I open a command window I do not see any IP addresses. If I type ipconfig /renew nothign happens.
I have check the config settings and everything looks right. (ie autodetect proxy)
If I open Interenet Explorer is see the following res://c:windows/system32/s hdoclc.dll /dnserror. htm
I have even tried to manually enter the IP Subnet and default gateway with no luck
The NIC card is reading my connection because the light on the router is on and the properties on the local area connection under network connections shows being connected at 100Mbps.
Any fixes would be very appreciated. Thank you.
He had almost 700 instances of spyware and adware that I removed with Spybot and Adaware. (should mention that this is before updates were done so Im sure there is more)
Problem now is that after removing that and his Norton Internet security(was expired) I can no longer connect to the internet.
I am on a DSL and have a DLink router.
If I open a command window I do not see any IP addresses. If I type ipconfig /renew nothign happens.
I have check the config settings and everything looks right. (ie autodetect proxy)
If I open Interenet Explorer is see the following res://c:windows/system32/s
I have even tried to manually enter the IP Subnet and default gateway with no luck
The NIC card is reading my connection because the light on the router is on and the properties on the local area connection under network connections shows being connected at 100Mbps.
Any fixes would be very appreciated. Thank you.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
This central link here created and updated by a number of us on Malware/Spyware tools may also be of help.
https://www.experts-exchange.com/questions/20975384/Standard-response-material-re-Spyware-Adware-BHOs-and-other-Malware.html
https://www.experts-exchange.com/questions/20975384/Standard-response-material-re-Spyware-Adware-BHOs-and-other-Malware.html
HijackThis is a great tool, you'll also find there to help scan your system and generate a log of entries to share with us for analysis as well. Sorry for the segmented responses.
ASKER
Well i went thought everything. Now when I open Interenet Explorer is see the following res://c:windows/system32/s hdoclc.dll /pagerror. gif...
Any other ideas?
Any other ideas?
I would run :
http://www.spychecker.com/program/winsockxpfix.html
Thats designed for XP and works great.
>>Well i went thought everything. Now when I open Interenet Explorer is see the following res://c:windows/system32/s hdoclc.dll /pagerror. gif...<<
Is that what the default page is set to?
http://www.spychecker.com/program/winsockxpfix.html
Thats designed for XP and works great.
>>Well i went thought everything. Now when I open Interenet Explorer is see the following res://c:windows/system32/s
Is that what the default page is set to?
Curious if you're building/using VB Accelerator; more about that here:
http://www.vbaccelerator.com/home/VB/Code/Libraries/Resources/Storing_HTML_Resources_in_VB_Applications/article.asp
http://www.vbaccelerator.com/home/VB/Code/Libraries/Resources/Storing_HTML_Resources_in_VB_Applications/article.asp
Also, please advise if OS and IE are current with updates from WindowsUpdate as well.
>> Well i went thought everything. Now when I open Interenet Explorer is see the following res://c:windows/system32/s hdoclc.dll /pagerror. gif...
Its the Most common and annoying Browser hijakcer,,,, u shud see this site to get rid of it >> http://www.pchell.com/support/onlythebest.shtml
If u still cannot fix it, then Download HijackThis v1.98.2, run it, Save the LOG file and Post it here:
http://tools.radiosplace.com/HijackThis.exe
Its the Most common and annoying Browser hijakcer,,,, u shud see this site to get rid of it >> http://www.pchell.com/support/onlythebest.shtml
If u still cannot fix it, then Download HijackThis v1.98.2, run it, Save the LOG file and Post it here:
http://tools.radiosplace.com/HijackThis.exe
ASKER
Here is the file. What need to be gone?
Logfile of HijackThis v1.97.7
Scan saved at 11:33:07 AM, on 8/25/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e xe
C:\WINDOWS\system32\winlog on.exe
C:\WINDOWS\system32\servic es.exe
C:\WINDOWS\system32\lsass. exe
C:\WINDOWS\system32\svchos t.exe
C:\WINDOWS\System32\svchos t.exe
C:\WINDOWS\system32\spools v.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\WindUpdates\WinUpdt. exe
C:\WINDOWS\System32\ezSP_P x.exe
C:\Program Files\WindUpdates\WinKA.ex e
C:\Program Files\MUSICMATCH\MUSICMATC H Jukebox\mm_tray.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Music\SSSvr.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Photo\appsrv\PhotoA ppSrv.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Video\GPVSvr.exe
C:\WINDOWS\System32\VuxP4T w.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.e xe
C:\WINDOWS\System32\ZibK.e xe
C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.e xe
C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.e xe
C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramew ork.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramew ork.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramew ork.exe
C:\Program Files\Sony\giga pocket\RM_SV.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wuaucl t.exe
E:\Tools\Virus\hijack\Hija ckThis.exe
R0 - HKCU\Software\Microsoft\In ternet Explorer\Toolbar,LinksFold erName =
R1 - HKCU\Software\Microsoft\In ternet Connection Wizard,Shellnext = http://www.sony.com/vaiopeople
R3 - URLSearchHook: (no name) - {965A592F-8EFA-4250-8630-7 960230792F 1} - (no file)
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3 D5FEC94A18 3} - C:\PROGRA~1\COMMON~1\WinTo ols\WTools B.dll (file missing)
O2 - BHO: (no name) - {13FD332E-B447-3DF0-8250-6 35579A7261 D} - C:\WINDOWS\System32\cksfqe rn.dll
O2 - BHO: (no name) - {1DAA362D-E810-32F2-D507-6 35579A8704 3} - C:\WINDOWS\System32\rsw.dl l
O2 - BHO: (no name) - {49AF367C-B641-3AA0-8550-6 35579A82C1 E} - C:\WINDOWS\System32\gjxi.d ll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2 06D7942484 F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5886A6DC-AAF4-45E9-979A-8 E5E6DEE30E 7} - C:\Program Files\zSearch\zSearch.dll
O2 - BHO: (no name) - {A43A8055-82EC-FF26-492F-9 37AD27B25A 7} - C:\PROGRA~1\mfcdhide\For name.exe
O2 - BHO: (no name) - {CE188402-6EE7-4022-8868-A B25173A3E1 4} - C:\WINDOWS\System32\mscb.d ll
O2 - BHO: (no name) - {F4E04583-354E-4076-BE7D-E D6A80FD66D A} - C:\WINDOWS\System32\msbe.d ll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0 0A0C908246 7} - C:\WINDOWS\System32\msdxm. ocx
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-F D60B590A87 D} - C:\PROGRA~1\COMMON~1\Real\ Toolbar\Re alBar.dll
O4 - HKLM\..\Run: [WindUpdates] C:\Program Files\WindUpdates\WinUpdt. exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_P x.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATC H Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [4X@95ME57C5BM8] C:\WINDOWS\System32\Dyf0o5 .exe
O4 - HKCU\..\Run: [zSearch] C:\Program Files\zSearch\Zstb.exe
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-0 0105AA9B6A E} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E 099162EEEC 5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4 B4665414BE F} - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4 4455354000 0} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {FF65677A-8977-48CA-916A-D FF81B037DF 3} (WMService Class) - http://download.overpro.com/WildApp.cab
Logfile of HijackThis v1.97.7
Scan saved at 11:33:07 AM, on 8/25/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\spools
C:\WINDOWS\Explorer.EXE
C:\Program Files\WindUpdates\WinUpdt.
C:\WINDOWS\System32\ezSP_P
C:\Program Files\WindUpdates\WinKA.ex
C:\Program Files\MUSICMATCH\MUSICMATC
C:\Program Files\Sony\VAIO Media Integrated Server\Music\SSSvr.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Photo\appsrv\PhotoA
C:\Program Files\Sony\VAIO Media Integrated Server\Video\GPVSvr.exe
C:\WINDOWS\System32\VuxP4T
C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.e
C:\WINDOWS\System32\ZibK.e
C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.e
C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.e
C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramew
C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramew
C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramew
C:\Program Files\Sony\giga pocket\RM_SV.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wuaucl
E:\Tools\Virus\hijack\Hija
R0 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R3 - URLSearchHook: (no name) - {965A592F-8EFA-4250-8630-7
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3
O2 - BHO: (no name) - {13FD332E-B447-3DF0-8250-6
O2 - BHO: (no name) - {1DAA362D-E810-32F2-D507-6
O2 - BHO: (no name) - {49AF367C-B641-3AA0-8550-6
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
O2 - BHO: (no name) - {5886A6DC-AAF4-45E9-979A-8
O2 - BHO: (no name) - {A43A8055-82EC-FF26-492F-9
O2 - BHO: (no name) - {CE188402-6EE7-4022-8868-A
O2 - BHO: (no name) - {F4E04583-354E-4076-BE7D-E
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-F
O4 - HKLM\..\Run: [WindUpdates] C:\Program Files\WindUpdates\WinUpdt.
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_P
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATC
O4 - HKLM\..\Run: [4X@95ME57C5BM8] C:\WINDOWS\System32\Dyf0o5
O4 - HKCU\..\Run: [zSearch] C:\Program Files\zSearch\Zstb.exe
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-0
O16 - DPF: {644E432F-49D3-41A1-8DD5-E
O16 - DPF: {9EB320CE-BE1D-4304-A081-4
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
O16 - DPF: {FF65677A-8977-48CA-916A-D
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Thanks for all your help. Splitting pts since both helped in solution.
^_^
Fantastic news!
Hi - glad I could help :-)
AdAware, new version with updates includes a cleanup option for the HOSTS file and deep scanning; the Spybot S&D tool once updated and using the Immunize function may help further in averting intrusions, though the above information likely should be of help to you in resolving some of the issues noted.
There's an XP tool to help flush dns, though not finding it now; perhaps others will provide info (not at my system).