i keep getting page cannot be displayed on some site that works on other conputer,i Logfile of HijackThis v1.98.2
Scan saved at 11:13:22 PM, on 11/4/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ISTsvc\istsvc.exe
C:\WINDOWS\System32\rumatike.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\WINDOWS\svchost.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
c:\windows\system32\adprot.exe
C:\Program Files\MSN\MSNCoreFiles\MSN6.EXE
C:\Documents and Settings\new user\Local Settings\Temporary Internet Files\Content.IE5\VWA7JPHB\PlusServicePack_01[1].exe
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\Windows AdTools\WinAdTools.exe
C:\Program Files\Windows AdTools\WinRatchet.exe
C:\Temp\salm.exe
C:\Program Files\BullsEye Network\bin\bargains.exe
C:\Program Files\Web_Rebates\WebRebates1.exe
C:\Program Files\Web_Rebates\WebRebates0.exe
C:\PROGRA~1\eZula\mmod.exe
C:\Documents and Settings\new user\Local Settings\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Program Files\Common Files\Microsoft Shared\Stationery\Blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - C:\Program Files\TV Media\TvmBho.dll
O1 - Hosts: kazza.com
O1 - Hosts: www.kazza.com
O1 - Hosts: kaza.com
O1 - Hosts: www.kaza.com
O1 - Hosts: kaaza.com
O1 - Hosts: www.kaaza.com
O1 - Hosts:
O1 - Hosts: www.kahza.com
O1 - Hosts:
O1 - Hosts:
O1 - Hosts: emule.com
O1 - Hosts: www.emule.com
O1 - Hosts:
O1 - Hosts:
O1 - Hosts: klite.com
O1 - Hosts: www.klite.com
O1 - Hosts:
O1 - Hosts:
O1 - Hosts: kazalite.com
O1 - Hosts: www.kazalite.com
O1 - Hosts:
O1 - Hosts:
O1 - Hosts: kazaalite.com
O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem220.dll
O2 - BHO: LocalNRDObj Class - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - C:\WINDOWS\localNRD.dll
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_12_0.dll
O2 - BHO: SNHlprObj Class - {14b3d246-6274-40b5-8d50-6c2ade2ab29b} - C:\Program Files\Srng\SNHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINDOWS\2_0_1browserhelper2.dll
O2 - BHO: ngsh33.clsIS - {941CA48C-3984-4E7D-AAF8-8755ED76EB50} - C:\WINDOWS\System32\21605.dll
O2 - BHO: IeHelper Class - {A491D208-B353-490F-B81A-A8A3DC97042D} - C:\WINDOWS\System32\smiehlp.dll
O2 - BHO: (no name) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
O2 - BHO: (no name) - {BDF6CE3D-F5C5-4462-9814-3C8EAC330CA8} - (no file)
O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_12_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [Sys Ren] C:\WINDOWS\SysRen.exe /S
O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [vplnmi] C:\WINDOWS\System32\rumatike.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [WyvernWorks Registry Fix-Up] C:\Program Files\WyvernWorks\Registry Fix-Up 2004\Registry Fix-Up 2004.exe -X
O4 - HKLM\..\Run: [srng] \Program Files\Srng\Srng.exe
O4 - HKLM\..\Run: [Windows AdTools] C:\Program Files\Windows AdTools\WinAdTools.exe
O4 - HKLM\..\Run: [salm] c:\temp\salm.exe
O4 - HKLM\..\Run: [qvkrkv] C:\WINDOWS\qvkrkv.exe
O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"
O4 - HKLM\..\Run: [BullsEye Network] C:\Program Files\BullsEye Network\bin\bargains.exe
O4 - HKLM\..\Run: [ErrorGuard] C:\Program Files\ErrorGuard\ErrorGuard.Exe
O4 - HKLM\..\RunOnce: [wextract_cleanup0] rundll32.exe C:\WINDOWS\System32\advpack.dll,DelNodeRunDLL32 "C:\DOCUME~1\NEWUSE~1\LOCALS~1\Temp\IXP000.TMP\"
O4 - HKLM\..\RunOnce: [djtopr1150.exe] "C:\DOCUME~1\NEWUSE~1\LOCALS~1\Temp\djtopr1150.exe"
O4 - HKLM\..\RunOnce: [Vise_41328ffc] C:\WINDOWS\unvise32.exe -r:C:\Program Files\DashBugFree\uninstal.log
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKCU\..\Run: [Windows Registry Repair Pro] C:\Program Files\3B Software\Windows Registry Repair Pro\RegistryRepairPro.exe 4
O4 - HKCU\..\Run: [eZmmod] C:\PROGRA~1\ezula\mmod.exe
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com/installation/Install.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
O16 - DPF: {771A1334-6B08-4A6B-AEDC-CF994BA2CEBE} (Installer Class) - http://www.ysbweb.com/ist/softwares/v4.0/ysb_regular.cab
O16 - DPF: {CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{26DFA12A-77C8-4CA7-ACEF-9642E49E98F0}: NameServer = ,
O17 - HKLM\System\CS1\Services\Tcpip\..\{26DFA12A-77C8-4CA7-ACEF-9642E49E98F0}: NameServer = ,

tried hijackthis and i copied this from the note pad

Dani AI

Generated

Quick diagnosis: the HJT output shows a classic adware/redirect infection — many hosts-file mappings to remote IPs plus nonstandard DNS servers and multiple adware processes/startup entries. That combination will make some sites fail to load even when they work from other machines. Resetting or restoring the hosts file and the network stack is therefore part of the repair, and HijackThis must be used carefully (don’t run it from a temp folder; let it make backups). (support.microsoft.com)

Priority cleanup (what to do now, in order)

  1. Isolate the PC: disconnect the network (unplug or disable the adapter) and back up any irreplaceable data.
  2. Put HijackThis in a permanent folder (e.g., C:\hjt) so its backups are saved, per @dlh6213, then do not fix HJT items blindly — save logs first and post them. (bleepingcomputer.com)
  3. Uninstall obvious PUPs/P2P and rogue utilities via Add/Remove Programs (Kazaa, toolbars, Web_Rebates/Windows AdTools, etc.), empty all Temp and IE temp folders for every user, then run reputable on‑demand cleaners (current anti‑malware and an adware/PUP scanner). Ad‑cleaners and Malwarebytes are the standard tools for this class of infection. (malwarebytes.com)

Network fixes and verification (after malware removal)

  • Restore or clean the hosts file (make a hosts backup first). Microsoft documents hosts-file hijacks and how to restore defaults. (support.microsoft.com)
  • Reset the TCP/IP stack (the Microsoft Netsh utility can do this) and, if Winsock/LSPs look damaged or DNS hijacking symptoms remain, perform a Winsock reset. These steps often clear the “page cannot be displayed” symptom once malware is removed. (support.microsoft.com)
  • Verify your adapter/router DNS settings (malware can change DNS; check the router too — if the router is altered contact your ISP). (support.avast.com)

Follow‑up: after the scans/fixes reboot, run HJT again, save the new log and post it. If repairs are inconsistent or you see system file corruption, consider a repair install or full reinstall — deep infections on XP often justify reinstall. A cleaned log and notes of tools used will let helpers give exact HJT fixes.

Recommended Answers

All 4 Replies

You have a lot to fix there, but there is a notice at the top of this forum requesting that all HijackThis logs be posted in the Security forum. You can either repost it or wait for one of the moderators to move it for you.

Also, before fixing anything with HJT, it needs to be in it's own permanent folder so it can safely save backups in case something goes wrong (like c:\hjt\hijackthis.exe), right now you're running it from a temp folder.

One more thing you should do is empty the contents of all Temp and Temporary Internet folders for all users on the computer. You can also do a search for *.tmp and delete all those files as well.

You have a lot to fix there, but there is a notice at the top of this forum requesting that all HijackThis logs be posted in the Security forum. You can either repost it or wait for one of the moderators to move it for you.

Moving there now, buckle up...

1. As long as you have Kazaa and other P2P programs installed, they will continue to create problems. Go to Add/Remove Programs in the Control Panel and remove them. Run Kazaabegone from here to be sure all remnants of kazaa have been removed:

2. Go to Windows Update to get all the Critical Updates for your system (but don't get SP2 until after you have cleared your system of malware).

3. Before you fix anything with hijackthis, it needs to be put in a permanent folder so it can safely save backups (like c:\hjt\hijackthis.exe); right now you have it in a temp folder.

4. After you put HJT in a different folder, reboot into Safe Mode and empty the contents of all Temp and Temporary Internet folders for all users, and then reboot normally.

5. Go to Add/Remove Programs in the Control Panel and remove Web Rebates and Windows AdTools.

6. Follow the recommendations in this thread to clean up some of the remaining problems:
http://www.daniweb.com/techtalkforums/thread5690.html (don't leave out SpywareBlaster!)

7. Close all windows, scan with HJT, and post a new log.

Try to reset your TCP/IP, this usually works:

Click on Start, then click on Run, and type this in:

netsh int ip reset c:\resetlog.txt

Then click "ok"

A black box should appear and disappear if you typed this in correctly.

Then restart your PC and try to connect again, you should be able to see those pages.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.