User User name Password  
   
Wednesday 5.3.2025 / 13:00
Search AfterDawn Forums:        In English   Suomeksi   På svenska
afterdawn.com > forums > software, operating systems and more > windows - virus and spyware problems > no internet after virus removal
Show topics
 
Forums
Forums
no internet after virus removal
  Jump to:
 
Posted Message
odell1980
Junior Member

1 product review
_
28. November 2008 @ 18:19 _ Link to this message    Send private message to this user   
I did not see the answer to my problem in any of the posts on the previous couple of pages. I recently ran into some issues with my internet. After a few hours on the phone with Microsoft. I was assured that all viruses and spyware had been removed from my system. Then I noticed that my browser would no longer connect to the internet. I have a strong signal. I am even able to ping an IP. I had a tech come out from Road Runner and he said that everything seemed to be working fine but he didn't know what the problem was. I have repaired the network connection, flushed the dns and renewed it. I have released the IP and renewed it. The tech went a little further renewing the winsock and something like the ntshe(not really sure what those are, but it didn't work any way. Also, I do not have any firewalls or antivirus software on my computer. (I was going to install it, but I have no internet to download it.) I also tried to run the Hijackthis.exe file, but it does not seem to work in safe mode. I would greatly appreciate it if someone could help me.
Advertisement
_
__
Senior Member
_
29. November 2008 @ 09:21 _ Link to this message    Send private message to this user   
Hi odell1980

Please run HijackThis in normal mode. Follow these instructions:

Rename HijackThis(.exe) to scanner(.exe).

Next, run scanner(.exe). A window will pop up.

? Click on the button which says Main Menu, then Do a system scan and save a logfile.
? Please wait for the scan to be completed.
? After the scan has completed, a text window will pop up. Please post the contents of this window here.

This will also be located at hijackthis(.txt) in the same folder that HijackThis was originally saved.

NOTE:: Do not fix anything using HijackThis, as this may also damage legitimate components of your computer.

Best Regards :D

Life is but a dream; you dont feel any pain unless you want to or you fall off the bed.
Success is relative; the more success the more relatives.
A computer once beat me at chess, but it was no match for me at kickboxing.
To be or not to be; thats a dumb question.

odell1980
Junior Member

1 product review
_
1. December 2008 @ 01:37 _ Link to this message    Send private message to this user   
Thanks, here is the Hijack this log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:26:57 AM, on 12/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtWLan.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\msiexec.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WinZip\WINZIP32.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [NIS] "C:\Documents and Settings\Ben\Local Settings\Temp\IXP000.TMP\NIS2009_16.0.0.125_OEM90.exe" /RELAUNCH /RUNONCE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - Global Startup: WG111v2 Smart Wizard Wireless Setting.lnk = ?
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDown.../sysreqlab3.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resourc...lscbase6662.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com...obat/nos/gp.cab
O22 - SharedTaskScheduler: lke3iemrl490kgfgdsfd - {C5AF42A3-94F3-42BD-F434-3604832C897D} - (no file)
O22 - SharedTaskScheduler: mcb7uehuj3n8weuhejsw - {C5BF49A2-94F3-42BD-F434-3604812C897D} - C:\WINDOWS\system32\jsne87fidgf.dll (file missing)
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe

--
End of file - 3027 bytes
Senior Member
_
1. December 2008 @ 05:43 _ Link to this message    Send private message to this user   
Hey odell1980

Hmm... that's odd. I was expecting something else from your HijackThis log.

Please run HijackThis.

? Click on the button which says Main Menu, then Do a system scan only.
? Please wait for the scan to be completed.
? After the scan has completed, check the following entries.


O22 - SharedTaskScheduler: lke3iemrl490kgfgdsfd - {C5AF42A3-94F3-42BD-F434-3604832C897D} - (no file) 

O22 - SharedTaskScheduler: mcb7uehuj3n8weuhejsw - {C5BF49A2-94F3-42BD-F434-3604812C897D} - C:\WINDOWS\system32\jsne87fidgf.dll (file missing)

Click on the button Fix checked

NOTE:: Close all browsers before fixing anything.


You may want to try this tool to fix your internet problem: Advanced SystemCare Free.

Best Regards :D

Life is but a dream; you dont feel any pain unless you want to or you fall off the bed.
Success is relative; the more success the more relatives.
A computer once beat me at chess, but it was no match for me at kickboxing.
To be or not to be; thats a dumb question.

odell1980
Junior Member

1 product review
_
1. December 2008 @ 12:55 _ Link to this message    Send private message to this user   
Deleting those two files and the software did not fix my problem.
Here is a new Hijack This log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:50:59 PM, on 12/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtWLan.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - Global Startup: WG111v2 Smart Wizard Wireless Setting.lnk = ?
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDown.../sysreqlab3.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resourc...lscbase6662.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com...obat/nos/gp.cab
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe

--
End of file - 2527 bytes
Senior Member
_
2. December 2008 @ 04:25 _ Link to this message    Send private message to this user   
Hi odell1980

So it's not a winsock problem, dns problem, ISP problem..... can I assume that it's a browser problem?

Can you try a different browser other than Internet Explorer? How about Firefox or TheWorld?

Firefox is the popular choice, but it is indeed a little heavy on disk space. TheWorld browser is perhaps the best browser to use for testing; it is small and takes up little space. It can be found here: http://www.ioage.com/en/index.htm

If you are asked to import your settings from Internet Explorer, say No!

Best Regards :D

Life is but a dream; you dont feel any pain unless you want to or you fall off the bed.
Success is relative; the more success the more relatives.
A computer once beat me at chess, but it was no match for me at kickboxing.
To be or not to be; thats a dumb question.

odell1980
Junior Member

1 product review
_
2. December 2008 @ 10:45 _ Link to this message    Send private message to this user   
Actually, none of my browsers will open including firefox, ie6, or msn explorer. However, they all work just fine in safe mode.
Senior Member
_
2. December 2008 @ 22:30 _ Link to this message    Send private message to this user   
Hey odell1980

Hmm... that's odd. Let's do a little more analysis.

Now, please download ComboFix.
With ComboFix, at the download window, please rename it to Combo-Fix(.exe) before downloading it. Save it to your Desktop.

Please disable all security programs, such as antiviruses, antispywares, and firewalls.

? Run Combo-Fix.exe and follow the prompts.
? Accept the End-User License Agreement.
? Allow the Recovery Console to be installed.
? When you see the window below, click on Yes.


? When the Recovery Console has been installed, click on Yes to start the scan.



**Understand that things like your system clock changing and your desktop disappearing might happen. Do not worry, because all will be restored later.
? Wait for the scan to be fully completed.
? If it requires a reboot, please do so.
? After the scan has completed entirely, please post the log here. The log will be located at C:\ComboFix(.txt)

Do not click on the ComoboFix window, as it may cause it to stall.

Best Regards :D

Life is but a dream; you dont feel any pain unless you want to or you fall off the bed.
Success is relative; the more success the more relatives.
A computer once beat me at chess, but it was no match for me at kickboxing.
To be or not to be; thats a dumb question.

odell1980
Junior Member

1 product review
_
5. December 2008 @ 14:34 _ Link to this message    Send private message to this user   
I am unable to download that file.
Senior Member
_
6. December 2008 @ 02:47 _ Link to this message    Send private message to this user   
Hey odell1980

I meant in safe mode. Can you download it in safe mode with networking?

Best Regards :D

Life is but a dream; you dont feel any pain unless you want to or you fall off the bed.
Success is relative; the more success the more relatives.
A computer once beat me at chess, but it was no match for me at kickboxing.
To be or not to be; thats a dumb question.

EricCarr
Member
_
6. December 2008 @ 03:25 _ Link to this message    Send private message to this user   
Check the browsers for a proxy setting. I had some malware that set all my browsers to a proxy setting.

AMD Quad 9950, Asus Motherboard, 2G Kingston Ram, 512MB Asus 8600GT, Samsung DVD Rom sh- d162c, LG Rom GDR8163B,
LG Burner h62n
odell1980
Junior Member

1 product review
_
6. December 2008 @ 17:42 _ Link to this message    Send private message to this user   
It will not let me download anything of the sort in safe mode. If it is not a anti-virus then I can. Also, I am not sure what a proxy setting is or how to check it.
Advertisement
_
__
 
_
odell1980
Junior Member

1 product review
_
7. December 2008 @ 02:41 _ Link to this message    Send private message to this user   
Hey guys,
Thanks for all of the help you have given me. Unfortunately I gave up on trying to fix this problem and reformatted my HDD. I really appreciated your assistance.

Thanks,
odell1980
afterdawn.com > forums > software, operating systems and more > windows - virus and spyware problems > no internet after virus removal
 

Digital video: AfterDawn.com | AfterDawn Forums
Music: MP3Lizard.com
Gaming: Blasteroids.com | Blasteroids Forums | Compare game prices
Software: Software downloads
Blogs: User profile pages
RSS feeds: AfterDawn.com News | Software updates | AfterDawn Forums
International: AfterDawn in Finnish | AfterDawn in Swedish | AfterDawn in Norwegian | download.fi
Navigate: Search | Site map
About us: About AfterDawn Ltd | Advertise on our sites | Rules, Restrictions, Legal disclaimer & Privacy policy
Contact us: Send feedback | Contact our media sales team
 
  © 1999-2025 by AfterDawn Ltd.

  IDG TechNetwork