1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

No Internet Access

Discussion in 'Virus & Other Malware Removal' started by Antlin, Feb 9, 2005.

Thread Status:
Not open for further replies.
  1. Antlin

    Antlin Thread Starter

    Joined:
    Feb 9, 2005
    Messages:
    2
    Hi - Hope somebody can help me :eek:)

    My Laptop (running Windows 2000 professional and Internet Explorer) runs fine standalone, but cannot access the internet.

    I have tried two dialup ISP's - the screen shows "registering" for ages and then appears to connect, but explorer says The page cannot be Displayed.....Cannot find server or DNS Error

    When I use outlook express to download my email I get No socket error 11001 Error Number 0x800CCC0D

    And when I insert my Belkin wireless network card to access a wireless network I get an "Authority Error" WINNT/services/services.exe shutdown unexpectedly giving 1 minute before a restart.

    I then got hold of an updated copy of AVG and ran it, and it found the Trojan Horse IRC/BackDoor.SdBot.27.BN in WINNT\System32\wuapdate16.exe and deleted that file, and Spybot found Alexa Related and DSO Exploit and Fixed those, but the problem persists.

    I have now downloaded Hijackthis, and run it after a reboot, the log follows.

    Thanks - Anthony :eek:)

    Logfile of HijackThis v1.99.0

    Scan saved at 10:57:33 a.m., on 10/02/2005

    Platform: Windows 2000 SP4 (WinNT 5.00.2195)

    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Running processes:

    C:\WINNT\System32\smss.exe

    C:\WINNT\system32\winlogon.exe

    C:\WINNT\system32\services.exe

    C:\WINNT\system32\lsass.exe

    C:\WINNT\system32\ibmpmsvc.exe

    C:\WINNT\system32\svchost.exe

    C:\WINNT\System32\svchost.exe

    C:\WINNT\system32\spoolsv.exe

    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe

    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe

    C:\Program Files\CA\eTrust Antivirus\InoRpc.exe

    C:\Program Files\CA\eTrust Antivirus\InoRT.exe

    C:\Program Files\CA\eTrust Antivirus\InoTask.exe

    C:\WINNT\system32\regsvc.exe

    C:\WINNT\system32\MSTask.exe

    C:\WINNT\System32\WBEM\WinMgmt.exe

    C:\WINNT\system32\svchost.exe

    C:\WINNT\Explorer.EXE

    C:\WINNT\system32\tp4mon.exe

    C:\WINNT\System32\ibmpmsvc.exe

    C:\WINNT\system32\ltmsg.exe

    C:\PROGRA~1\CA\ETRUST~1\realmon.exe

    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe

    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe

    C:\WINNT\system32\internat.exe

    C:\Program Files\Belkin Corporation\Belkin Wireless Network Monitor Utility and Driver\RtlWake.exe

    C:\Hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.nz/

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

    O3 - Toolbar: @msdxmLC.dll,[email protected],&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx

    O4 - HKLM\..\Run: [TrackPointSrv] tp4mon.exe

    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon

    O4 - HKLM\..\Run: [IBMPMSVC] %SystemRoot%\System32\ibmpmsvc.exe -helper

    O4 - HKLM\..\Run: [LTWinModem1] ltmsg.exe 9

    O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s

    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP

    O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe

    O4 - HKCU\..\Run: [internat.exe] internat.exe

    O4 - Global Startup: RtlWake.lnk = C:\Program Files\Belkin Corporation\Belkin Wireless Network Monitor Utility and Driver\RtlWake.exe

    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm

    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm

    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

    O17 - HKLM\System\CCS\Services\Tcpip\..\{220B7970-66CF-4C18-A770-E9BA716EEA4B}: NameServer = 192.168.1.1,202.27.184.3

    O17 - HKLM\System\CS1\Services\Tcpip\..\{220B7970-66CF-4C18-A770-E9BA716EEA4B}: NameServer = 192.168.1.1,202.27.184.3

    O17 - HKLM\System\CS2\Services\Tcpip\..\{220B7970-66CF-4C18-A770-E9BA716EEA4B}: NameServer = 192.168.1.1,202.27.184.3

    O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe

    O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe

    O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe

    O23 - Service: IBM PM Service - IBM Corp. - C:\WINNT\system32\ibmpmsvc.exe

    O23 - Service: eTrust Antivirus RPC Server - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe

    O23 - Service: eTrust Antivirus Realtime Server - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe

    O23 - Service: eTrust Antivirus Job Server - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe
     
  2. Antlin

    Antlin Thread Starter

    Joined:
    Feb 9, 2005
    Messages:
    2
    Any bright ideas anyone? I found some info on the net saying that the WinNT error was related to invalid shared device entries in the Registry LANMANAGER, but mine is empty (except for "Default") Looks like I might have to get the machine reloaded - sigh :eek:(
     
As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/328687

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice