DaniWeb IT Discussion Community

DaniWeb IT Discussion Community (http://www.daniweb.com/forums/index.php)
-   Viruses, Spyware and other Nasties (http://www.daniweb.com/forums/forum64.html)
-   -   Page Cannot Be Displayed "Cannot Find Server DNS Error" (http://www.daniweb.com/forums/thread153326.html)

tx_scuba Oct 24th, 2008 2:50 pm
Page Cannot Be Displayed "Cannot Find Server DNS Error"
 
Beating my head against the wall here.

Server 2003 running Terminal Server, so everyone is getting the error.

HiJackThis shows

Broken Internet access because of LSP provider 'e:\documents and settings\administrator\windows\system32\mswsock.dll' missingWinsock

I have run LPSfix and mswsock.dll does not show up in the left pane.

I have removed Winsock and Winsock2 and reinstalled TCP/IP no dice.

NSLookp works fine and I ping the URL.

Please give me your thoughts before I start to reload this weekend.

Many thanks,
matt


PS, I know I have some CoolWatch Crap going on. But that's now causing the issue right?


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:47:39 PM, on 10/24/2008
Platform: Windows 2003 SP2 (WinNT 5.02.3790)
MSIE: Internet Explorer v6.00 SP2 (6.00.3790.3959)
Boot mode: Normal

Running processes:
E:\Documents and Settings\Administrator\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
T:\AVG\avgamsvr.exe
T:\AVG\avgupsvc.exe
T:\AVG\AVGTCP~1\avgtcpsv.exe
E:\WINDOWS\system32\Dfssvc.exe
E:\WINDOWS\System32\dns.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\System32\ismserv.exe
T:\Program Files\LogMeIn\x86\RaMaint.exe
T:\Program Files\LogMeIn\x86\LogMeIn.exe
T:\Program Files\LogMeIn\x86\LMIGuardian.exe
E:\Net2Printer RDP\NPLicenseService.exe
E:\Net2Printer RDP\NPPrinterService.exe
E:\WINDOWS\system32\ntfrs.exe
E:\WINDOWS\system32\srvany.exe
E:\pvsw\bin\w3dbsmgr.exe
E:\WINDOWS\system32\HPZipm12.exe
t:\Program Files\Spyware Doctor\pctsAuxs.exe
t:\Program Files\Spyware Doctor\pctsSvc.exe
E:\WINDOWS\System32\SPDataServer.exe
E:\WINDOWS\System32\SPLicenseManager.exe
E:\WINDOWS\system32\lserver.exe
E:\Program Files\UPHClean\uphclean.exe
E:\WINDOWS\system32\tcpsvcs.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\System32\dmadmin.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\winlogon.exe
T:\Program Files\LogMeIn\x86\LogMeIn.exe
T:\Program Files\LogMeIn\x86\LMIGuardian.exe
E:\Net2Printer RDP\NPServerRDP.exe
E:\WINDOWS\Explorer.EXE
E:\WINDOWS\System32\CNESvrMgr.exe
T:\Program Files\LogMeIn\x86\LogMeInSystray.exe
E:\Program Files\Java\j2re1.4.2_14\bin\jusched.exe
E:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
E:\WINDOWS\system32\ctfmon.exe
E:\Program Files\Java\j2re1.4.2_14\bin\jucheck.exe
T:\Program Files\LogMeIn\x86\LMIGuardian.exe
E:\WINDOWS\system32\wuauclt.exe
T:\Software\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/softAdmin.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = E:\WINDOWS\system32\blank.htm
F2 - REG:system.ini: UserInit=E:\WINDOWS\system32\userinit.exe,
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - e:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - E:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - e:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [CNE Service Manager] E:\WINDOWS\System32\CNESvrMgr.exe
O4 - HKLM\..\Run: [ExtremeSync Background Scheduler] t:\Program Files\SuperFlexible\ExtremeSyncService.exe /TIMERASAPP /STARTUP
O4 - HKLM\..\Run: [LogMeIn GUI] "T:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [ISTray] "t:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "E:\Program Files\Java\j2re1.4.2_14\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "E:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [swg] E:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-27822560-3153235022-2490726440-1157\..\Run: [swg] E:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'Baldemar.Garcia')
O4 - HKUS\S-1-5-21-27822560-3153235022-2490726440-1212\..\Run: [swg] E:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'Bill.Gregoire')
O4 - HKUS\S-1-5-18\..\Run: [] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [] (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = T:\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\j2re1.4.2_14\bin\npjpi142_14.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\j2re1.4.2_14\bin\npjpi142_14.dll
O10 - Broken Internet access because of LSP provider 'e:\documents and settings\administrator\windows\system32\mswsock.dll' missing
O15 - ESC Trusted Zone: http://runonce.msn.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1174271551140
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1174271566906
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.2) - https://java.sun.com/products/plugin...ndows-i586.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/RACtrl.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Crosspointinc.us
O17 - HKLM\Software\..\Telephony: DomainName = Crosspointinc.us
O17 - HKLM\System\CCS\Services\Tcpip\..\{06027414-76EF-4CC7-8514-850A88DFFBC3}: NameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{394AF0B4-8704-4033-BA53-35909518EE27}: NameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{F5F25004-2330-4414-AD6B-B18B1DD8CE2F}: NameServer = 192.168.1.110
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Crosspointinc.us
O17 - HKLM\System\CS1\Services\Tcpip\..\{06027414-76EF-4CC7-8514-850A88DFFBC3}: NameServer = 192.168.0.1
O21 - SSODL: Sysuxdos - {5A2250D1-A4D3-4F17-BC11-D969ACA43209} - E:\WINDOWS\system32\resocdlg.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - T:\AVG\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - T:\AVG\avgupsvc.exe
O23 - Service: AVG7 TCP Server (AVGTCPSv) - GRISOFT, s.r.o. - T:\AVG\AVGTCP~1\avgtcpsv.exe
O23 - Service: ExtremeSync Service (ExtremeSync_Service) - Unknown owner - T:\Program Files\SuperFlexible\ExtremeSyncService.exe
O23 - Service: Google Updater Service (gusvc) - Google - E:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - E:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - T:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - T:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: Net2Printer RDP License Service (NPLicenseService) - FireDaemon Technologies Limited - E:\Net2Printer RDP\Firedaemon\FireDaemon.exe
O23 - Service: Net2Printer RDP Printer Service (NPPrinterService) - FireDaemon Technologies Limited - E:\Net2Printer RDP\Firedaemon\FireDaemon.exe
O23 - Service: Pervasive.SQL Workgroup Engine - Unknown owner - E:\WINDOWS\system32\srvany.exe
O23 - Service: Pml Driver HPZ12 - HP - E:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - t:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - t:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Spector Control Center Server (SPCEAdminSvc) - Unknown owner - t:\SpectorSoft\SpectorCNE\SPCEAdminSvc.exe
O23 - Service: Spector CNE Data Vault (SPDataServer) - Unknown owner - E:\WINDOWS\System32\SPDataServer.exe
O23 - Service: Spector CNE Primary Server (SPLicenseManager) - Unknown owner - E:\WINDOWS\System32\SPLicenseManager.exe

--
End of file - 8334 bytes

joujou.k Dec 6th, 2008 5:08 am
Re: Page Cannot Be Displayed "Cannot Find Server DNS Error"
 
Having the same problem.
Did you manage to sort it out?
I'll appreciate your help

cohen Dec 6th, 2008 7:21 pm
Re: Page Cannot Be Displayed "Cannot Find Server DNS Error"
 
Hello tx_scuba,

Pls do the following:

1. - Download Malwarebytes' Anti-Malware (http://www.download.com/Malwarebytes...=dl&tag=button) to your desktop.

* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure to checkmark the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.

Make sure that you restart the computer.

The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

2. - Run HJT again and post the log.

In your reply, post the logs (in this order):
1. - Malware Bytes Log
2. - Hijackthis Log

At joujou.k - pls create your own thread with a hijackthis log, and then we can help you.

Thanks,

Cohen


All times are GMT -4. The time now is 4:35 pm.

Forum system based on vBulletin Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
©2003 - 2009 DaniWeb® LLC