Reply

Join Date: Nov 2004
Posts: 147
Reputation: cdt1983 is an unknown quantity at this point 
Solved Threads: 2
cdt1983 cdt1983 is offline Offline
Junior Poster

No internet connection

 
0
  #1
Dec 6th, 2004
Hi CaperJack suggested I post a HijackThis report here. My internet connection is not working on my Windows 98 laptop, it is using a USB ethernet adapter and I share files and printers with it but it will not connect to internet. When I run winipcfg I get an error "Failed to initialize Winsock." I have tried reinstalling TCP/IP etc. with no success.. Here is the hijackthis log...any help is appreicated.

----------------------------------------------------------------Logfile of HijackThis v1.97.7
Scan saved at 4:06:16 AM, on 12/6/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://216.65.101.250/sbms/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://216.65.101.250/sbms/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://216.65.101.250/sbms/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.jacksonville.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://216.65.101.250/sbms/
F1 - win.ini: run=hpfsched
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: AOL Instant Messenger (SM) (HKLM)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Macromedia Active Shockwave) - http://download.macromedia.com/pub/s...irector/sw.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE} (Microsoft Office Tools on the Web Control) - http://officeupdate.microsoft.com/Te...loads/outc.cab
O16 - DPF: {A28DAC07-0D34-4A90-A0E6-CEE27208C86D} (CWDL_DownLoadControl Class) - http://www.callwave.com/include/cab/CWDL_DownLoad.cab
O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - http://office.microsoft.com/productu...ntent/opuc.cab
O16 - DPF: {A031D222-B496-11D2-9CC8-00105A10AAF6} (WONWebLauncher Class) - http://www.virtualvegas.com/cab/WONW...herControl.cab
O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - http://216.249.25.152/code/PWActiveXImgCtl.CAB
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! WebCam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {1DEFB8C0-22A7-4E58-B735-43A169CDA2AB} (CWDL_DownLoadControl Class) - http://www.callwave.com/include/cab/CWDL_DownLoad.CAB
O16 - DPF: {72C23FEC-3AF9-48FC-9597-241A8EBDFE0A} (InstallShield International Setup Player) - http://ftp.hp.com/pub/automatic/player/isetupML.cab
O16 - DPF: {89D75D39-5531-47BA-9E4F-B346BA9C362C} (CWDL_DownLoadControl Class) - http://www.callwave.com/include/cab/CWDL_DownLoad.CAB
O16 - DPF: {EE5CA45C-BFAC-48E6-BE6C-3C607620FF43} (IMViewerControl Class) - http://companion.logitech.com/compan.../bin/imvid.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...740.9121527778
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab

------------End of report------------------------------------
Time to Update Specs
ASUS A8N5X 939, AMD Athlon 64 4000+, 1GB PC3200 Dual Channel, 60GB SATA Maxtor OS, 160GB ATA Hitachi Storage
GeForce 7300 GT 256MB PCI-E, Sony 18x Dual Layer DVD-RW
Dell E228WFP 22" @ 1680 x 1050
Reply With Quote Quick reply to this message  
Join Date: Jul 2004
Posts: 764
Reputation: DaveSW is on a distinguished road 
Solved Threads: 17
DaveSW's Avatar
DaveSW DaveSW is offline Offline
Master Poster

Re: No internet connection

 
0
  #2
Dec 6th, 2004
Can you update to the newest version of HJT? it's 1.98.2. Either use the update button, or redownload from http://www.spychecker.com/program/hijackthis.html

Also I'd suggest you move HJT into a folder
e.g. c:\hjt\hijackthis.exe
The reason being that when it creates backups it's a good idea to be able to find them again, rather than having to search the hard drive for them.

Cheers
Reply With Quote Quick reply to this message  
Join Date: Aug 2003
Posts: 9,549
Reputation: caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold 
Solved Threads: 493
Team Colleague
caperjack's Avatar
caperjack caperjack is offline Offline
Posting Prodigy

Re: No internet connection

 
0
  #3
Dec 6th, 2004
Do as suggested above and then run this program and then rerun hikackthis and posta new log .
,,,,,,,,,,,,,,,,,,,,,
Download then unzip and run CWShredder to clean up clicking "FIX" to have it remove all it finds.

CWShredder available from these places :-

http://www.aluriasoftware.com/tools/cwshredder.zip
Or this as a full download without any unzipping required
http://www.downloads.subratam.org/CWShredder.exe
[

We have found that some of the CWS infections can be removed better from safe mode, rather than normal mode.
To get to safe mode use the F8 key while booting the machine. Detailed instructions from here :-
http://service1.symantec.com/SUPPORT...01052409420406
Reply With Quote Quick reply to this message  
Join Date: Nov 2004
Posts: 147
Reputation: cdt1983 is an unknown quantity at this point 
Solved Threads: 2
cdt1983 cdt1983 is offline Offline
Junior Poster

Re: No internet connection

 
0
  #4
Dec 6th, 2004
Hi Dave & Caperjack,

I have no access to the internet on the laptop so I downloaded HijackThis to its hard drive that i'm sharing on the network. Therefore I cannot do an auto update. I tried uninstalling the old version and reinstalling from the link you sent me but it is still version 1.97.1. What do you recommend now? Thanks
Time to Update Specs
ASUS A8N5X 939, AMD Athlon 64 4000+, 1GB PC3200 Dual Channel, 60GB SATA Maxtor OS, 160GB ATA Hitachi Storage
GeForce 7300 GT 256MB PCI-E, Sony 18x Dual Layer DVD-RW
Dell E228WFP 22" @ 1680 x 1050
Reply With Quote Quick reply to this message  
Join Date: Aug 2003
Posts: 9,549
Reputation: caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold 
Solved Threads: 493
Team Colleague
caperjack's Avatar
caperjack caperjack is offline Offline
Posting Prodigy

Re: No internet connection

 
0
  #5
Dec 6th, 2004
most important thing would be to get the CWShredder program and run it .it should clean most of what is bad in the hijack log .
Reply With Quote Quick reply to this message  
Join Date: Nov 2004
Posts: 147
Reputation: cdt1983 is an unknown quantity at this point 
Solved Threads: 2
cdt1983 cdt1983 is offline Offline
Junior Poster

Re: No internet connection

 
0
  #6
Dec 6th, 2004
Originally Posted by caperjack
Do as suggested above and then run this program and then rerun hikackthis and posta new log .
,,,,,,,,,,,,,,,,,,,,,
Download then unzip and run CWShredder to clean up clicking "FIX" to have it remove all it finds.

CWShredder available from these places :-

http://www.aluriasoftware.com/tools/cwshredder.zip
Or this as a full download without any unzipping required
http://www.downloads.subratam.org/CWShredder.exe
[

We have found that some of the CWS infections can be removed better from safe mode, rather than normal mode.
To get to safe mode use the F8 key while booting the machine. Detailed instructions from here :-
http://service1.symantec.com/SUPPORT...01052409420406

Caperjack, I started my PC in safemode and ran CWShredder. It reported that my computer is completely clean.
Time to Update Specs
ASUS A8N5X 939, AMD Athlon 64 4000+, 1GB PC3200 Dual Channel, 60GB SATA Maxtor OS, 160GB ATA Hitachi Storage
GeForce 7300 GT 256MB PCI-E, Sony 18x Dual Layer DVD-RW
Dell E228WFP 22" @ 1680 x 1050
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 9,987
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 754
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: No internet connection

 
0
  #7
Dec 6th, 2004
Reboot into safe mode following the instructions here and rescan with hijackthis. When the scan is finished tick the boxes next to all the following entries, then close all browser and explorer windows, and tell HijackThis to "Fix checked."

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://216.65.101.250/sbms/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://216.65.101.250/sbms/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://216.65.101.250/sbms/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://216.65.101.250/sbms/

Reboot normally after doing the above, rescan with hijackthis, then post that log here please.
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 9,987
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 754
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: No internet connection

 
0
  #8
Dec 6th, 2004
Those entries are CWS domains, so the shredder should have picked them up. Did you have internet explorer closed? Did you *fix* and not *scan* only?
Reply With Quote Quick reply to this message  
Join Date: Nov 2004
Posts: 147
Reputation: cdt1983 is an unknown quantity at this point 
Solved Threads: 2
cdt1983 cdt1983 is offline Offline
Junior Poster

Re: No internet connection

 
0
  #9
Dec 6th, 2004
Originally Posted by crunchie
Those entries are CWS domains, so the shredder should have picked them up. Did you have internet explorer closed? Did you *fix* and not *scan* only?
Hi Crunchie, i had all IE windows closed when I ran the shredder and ran Scan (which didn't result in anything) and fix (said system was clean). I booted in safe mode and the items you suggested I remove are no longer present. Here is the most recent Log:
-------------------------------------------------------------
Logfile of HijackThis v1.97.7
Scan saved at 4:17:18 PM, on 12/6/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\MY DOCUMENTS\HJT\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.jacksonville.com/
F1 - win.ini: run=hpfsched
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: AOL Instant Messenger (SM) (HKLM)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Macromedia Active Shockwave) - http://download.macromedia.com/pub/s...irector/sw.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE} (Microsoft Office Tools on the Web Control) - http://officeupdate.microsoft.com/Te...loads/outc.cab
O16 - DPF: {A28DAC07-0D34-4A90-A0E6-CEE27208C86D} (CWDL_DownLoadControl Class) - http://www.callwave.com/include/cab/CWDL_DownLoad.cab
O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - http://office.microsoft.com/productu...ntent/opuc.cab
O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - http://216.249.25.152/code/PWActiveXImgCtl.CAB
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! WebCam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {1DEFB8C0-22A7-4E58-B735-43A169CDA2AB} (CWDL_DownLoadControl Class) - http://www.callwave.com/include/cab/CWDL_DownLoad.CAB
O16 - DPF: {72C23FEC-3AF9-48FC-9597-241A8EBDFE0A} (InstallShield International Setup Player) - http://ftp.hp.com/pub/automatic/player/isetupML.cab
O16 - DPF: {89D75D39-5531-47BA-9E4F-B346BA9C362C} (CWDL_DownLoadControl Class) - http://www.callwave.com/include/cab/CWDL_DownLoad.CAB
O16 - DPF: {EE5CA45C-BFAC-48E6-BE6C-3C607620FF43} (IMViewerControl Class) - http://companion.logitech.com/compan.../bin/imvid.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...740.9121527778
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
-------------------------------------------------------------
Time to Update Specs
ASUS A8N5X 939, AMD Athlon 64 4000+, 1GB PC3200 Dual Channel, 60GB SATA Maxtor OS, 160GB ATA Hitachi Storage
GeForce 7300 GT 256MB PCI-E, Sony 18x Dual Layer DVD-RW
Dell E228WFP 22" @ 1680 x 1050
Reply With Quote Quick reply to this message  
Join Date: Nov 2004
Posts: 147
Reputation: cdt1983 is an unknown quantity at this point 
Solved Threads: 2
cdt1983 cdt1983 is offline Offline
Junior Poster

Re: No internet connection

 
0
  #10
Dec 6th, 2004
Actually this is what I get when I run CWshredder (Scan only):

CWShredder v1.59.1 scan only report
Please understand that a CWShredder 'Scan only' report
might not be sufficient to troubleshoot an infected system.
You can use HijackThis for that:
http://www.merijn.org/files/hijackthis.zip
http://www.spywareinfo.com/~merijn/files/hijackthis.zip

Windows 98 (4.10.2222 A)
Windows dir: C:\WINDOWS
Windows system dir: C:\WINDOWS\SYSTEM
AppData folder: C:\WINDOWS\Application Data
Username:

Hosts file not present
Found Win.ini file: C:\WINDOWS\win.ini (8383 bytes, A)
Found line in Win.ini: load=
Found line in Win.ini: run=hpfsched
Found System.ini file: C:\WINDOWS\system.ini (2210 bytes, A)
Found line in System.ini: shell=Explorer.exe

- END OF REPORT -
Time to Update Specs
ASUS A8N5X 939, AMD Athlon 64 4000+, 1GB PC3200 Dual Channel, 60GB SATA Maxtor OS, 160GB ATA Hitachi Storage
GeForce 7300 GT 256MB PCI-E, Sony 18x Dual Layer DVD-RW
Dell E228WFP 22" @ 1680 x 1050
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC