Forum Index

It appears you have not yet registered with our community which limits what you can do & see. It's Free To register, please click here.





Spyware / Virus Removal Spyware, virus, browser hijack and other malware removal.

Reply
 
Thread Tools Display Modes
  #1  
Old 03-20-2005, 11:20 AM
f15Bashful f15Bashful is offline
Junior Member
 
Join Date: Mar 2005
Posts: 2
I've clean up a bunch of malware but still cannot connect to the internet. I'm using another computer which connects fine...so the cable modem etc are working fine. The LAN connections are both set to auto and look good but just get the 'can't find the server/DNS error' message when trying to start MS IE. Also Mozilla will not work either. Have run winsockfix.exe a couple of times with no luck. Swapping computers to try and fix this problem is driving me crazy.Here's the latest HJT log. Thanks for the review ... Steve
Logfile of HijackThis v1.99.1
Scan saved at 8:40:44 AM, on 3/20/2005
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\Explorer.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\TrojanHunter 4.2\THGuard.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\WINNT\explorer.exe
F:\HijackThis.exe

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [WG511WLU] C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINNT\system32\spool\drivers\w32x86\3\E_SRCV03. EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O12 - Plugin for .bcf: C:\Program Files\Internet Explorer\Plugins\NPBelv32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://usercenter.cox.net/rsuite/sdccommon.../cx_tgctlcm.jsp
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
Reply With Quote
Posted


  #2  
Old 03-20-2005, 01:45 PM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,584
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
I am by no means a newwork guru but here is something you can try:

Recover from Winsock2 corruption

To resolve this issue, delete the corrupted registry keys, and then reinstall the TCP/IP protocol.
Step 1: Delete the corrupted registry keys
1. Click Start, and then click Run.
2. In the Open box, type regedit, and then click OK.
3. In Registry Editor, locate the following keys, right-click each key, and then click Delete:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Servic es\Winsock
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Servic es\Winsock2
4. When you are prompted to confirm the deletion, click Yes.
Note Restart the computer after you delete the Winsock keys. Doing so causes the Windows XP operating system to create new shell entries for those two keys. If you do not restart the computer after you delete the Winsock keys, the next step does not work correctly.
Step 2: Install TCP/IP
1. Right-click the network connection, and then click Properties.
2. Click Install.
3. Click Protocol, and then click Add.
4. Click Have Disk.
5. Type C:\Windows\inf, and then click OK.
6. On the list of available protocols, click Internet Protocol (TCP/IP), and then click OK.
7. Restart the computer.
Reply With Quote
  #3  
Old 03-20-2005, 04:38 PM
f15Bashful f15Bashful is offline
Junior Member
 
Join Date: Mar 2005
Posts: 2
Was able to follow all the steps (even though it is a Win 2K vice XP software package) but when hit OK after the C:\Windows\inf a prompt comes up saying the requested program is not available. Obviously without completing this step MS IE doesn't even see the connection and prompts to 'No connection to the Internet is currently available." ??
Reply With Quote
  #4  
Old 03-20-2005, 04:51 PM
Charlie Charlie is offline
Administrator
 
Join Date: Nov 2004
Posts: 18
On Windows 2000, you can uninstall and re-install the TCP/IP drivers to clear the stack.

1. Open Settings -> Control Panel from the Start menu.
2. Select Network and Dial-up Connections. This will open a dialog with your available connections.
3. Double click on the Local Area Connection (LAN) item. This will open a Local Area Connection Status dialog.
4. Click on the Properties button. This opens a Local Area Connection Properties dialog.
5. In the Components list, select the Internet Protocol (TCP/IP) entry, then click the Uninstall button. Close the dialog by clicking on OK. You may need to restart your computer.
6. Reinstall the Internet Protocol by repeating steps 1 to 5, then click on the Install button. This opens a Select Network Component Type dialog. Choose Protocol, then click the Add button. This opens a Select Network Protocol dialog.
7. In the Manufacturers list, select Microsoft. In the Network Protocol list, select Internet Protocol (TCP/IP). You may need to insert your Windows 2000 disk and browse to find the protocol. Click OK to install. You may need to restart your computer.
8. Resetting the TCP/IP stack is now complete.
Reply With Quote
Reply

  • Submit Thread to Digg Digg
  • Submit Thread to del.icio.us del.icio.us
  • Submit Thread to StumbleUpon StumbleUpon
  • Submit Thread to Google Google
  • Bookmarks

    Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
     
    Thread Tools
    Display Modes

    Posting Rules
    You may not post new threads
    You may not post replies
    You may not post attachments
    You may not edit your posts

    BB code is On
    Smilies are On
    [IMG] code is On
    HTML code is Off
    Forum Jump

    Similar Threads
    Thread Thread Starter Forum Replies Last Post
    RSS-Microsoft Security Advisory (909444): Various Issues After Installing Microsoft Security Bulletin MS05-051 on Systems That Have Non-default File Permissions - 10/14/2005 RSS Importer Security Alerts and vulnerabilities 0 10-14-2005 02:00 AM
    hijack log der Spyware / Virus Removal 46 10-04-2005 06:49 AM
    Drive-by Trojans Exploit Browser Flaws LJM Master Security Alerts and vulnerabilities 0 03-24-2005 02:50 PM
    Firefox is one popular browser Mobo Browsers | Email Software 0 11-27-2004 08:21 PM
    To secure IE, upgrade to XP southernlady Browsers | Email Software 0 09-24-2004 05:25 PM



    All times are GMT -5. The time now is 07:49 PM.


    Firefox 2