1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

[SOLVED] IE 6 and c:\\windows\systems\SHDOCLC.DLL.dnserror.htm

Discussion in 'Web & Email' started by gregwix, Jan 3, 2004.

Thread Status:
Not open for further replies.
Advertisement
  1. gregwix

    gregwix Thread Starter

    Joined:
    Jan 3, 2004
    Messages:
    9
    Can someone point me to somewhere to help me? I cannot load IE 6 at all. Netscape and Mozilla are unaffected.

    Incredifind showed up. Norton Anitvirus was running but my ZoneAlarm Pro 4.538 was down when it showed. I think I've gotten rid of incredifind. I ran Spybot and Adaware 6 Plus to no avail.

    Nothing I do works. I still cannot load IE.

    c:\\windows\systems\shdoclc.dll.dnserror.htm is what shows after the "finding ev1.net" (my home page) goes away.

    I am running win 98 SE, with a 266 Mhz with 256 ram. It was fine before this happened.

    When I get paid, I'll gladly donate.

    Thank you
     
  2. brushmaster1

    brushmaster1

    Joined:
    Jun 15, 2002
    Messages:
    3,337
    Have you tried going to another URL in IE after the DNS server error page appears?
     
  3. dvk01

    dvk01 Moderator Malware Specialist

    Joined:
    Dec 14, 2002
    Messages:
    55,138
    First Name:
    Derek
    go to http://www.merijn.org/files/hijackthis.zip , and download 'Hijack This!'.
    Unzip it and make sure it is unzipped & placed into it's own folder, not a temporary folder. Then doubleclick the Hijackthis.exe.
    Click the "Scan" button, when the scan is finished the scan button will become "Save Log" click that and save the log.
    Go to where you saved the log and click on "Edit > Select All" then click on "Edit > Copy" then Paste the log back here in a reply.
    It will possibly show issues deserving our attention, but most of what it lists will be harmless or even required,
    so do NOT fix anything yet.
    Someone here will be happy to help you analyze the results.
     
  4. gregwix

    gregwix Thread Starter

    Joined:
    Jan 3, 2004
    Messages:
    9
    Thank you for replying. Here is what you asked for. It sure it a foreign language to me.

    Logfile of HijackThis v1.97.7
    Scan saved at 10:07:20 AM, on 1/4/04
    Platform: Windows 98 SE (Win9x 4.10.2222A)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON CLEANSWEEP\CSINJECT.EXE
    C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON UTILITIES\NPROTECT.EXE
    C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SYMTRAY.EXE
    C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\STARTER.EXE
    C:\PROGRAM FILES\MICROSOFT HARDWARE\KEYBOARD\SPEEDKEY.EXE
    C:\PROGRAM FILES\MICROSOFT HARDWARE\MOUSE\POINT32.EXE
    C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON ANTIVIRUS\NAVAPW32.EXE
    C:\WINDOWS\SYSTEM\RNAAPP.EXE
    C:\WINDOWS\SYSTEM\TAPISRV.EXE
    C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
    C:\PROGRAM FILES\PESTPATROL\PPCONTROL.EXE
    C:\PROGRAM FILES\PESTPATROL\PPMEMCHECK.EXE
    C:\PROGRAM FILES\PESTPATROL\COOKIEPATROL.EXE
    C:\WINDOWS\RUNDLL32.EXE
    C:\PROGRAM FILES\MAILWASHER\MAILWASHER.EXE
    C:\PROGRAM FILES\OUTLOOK EXPRESS\MSIMN.EXE
    C:\WINDOWS\SYSTEM\PSTORES.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
    C:\PROGRAM FILES\MOZILLA.ORG\MOZILLA\MOZILLA.EXE
    C:\MY DOWNLOAD FILES\HIJACKTHIS\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Everyones Internet
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.eznsearch.com/index.htm
    R3 - URLSearchHook: (no name) - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - (no file)
    N1 - Netscape 4: user_pref("browser.startup.homepage", "http://my.netscape.com/index2.psp"); (C:\Program Files\Netscape\Users\gregwix\prefs.js)
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: @msdxmLC.dll,[email protected],&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
    O4 - HKLM\..\Run: [Microsoft IntelliType Pro] "C:\Program Files\Microsoft Hardware\Keyboard\speedkey.exe"
    O4 - HKLM\..\Run: [POINTER] C:\Program Files\Microsoft Hardware\Mouse\point32.exe
    O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\NORTON~1\NAVAPW32.EXE
    O4 - HKLM\..\Run: [NPROTECT] C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
    O4 - HKLM\..\Run: [CriticalUpdate] C:\WINDOWS\SYSTEM\wucrtupd.exe -startup
    O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
    O4 - HKLM\..\Run: [PestPatrol Control Center] C:\Program Files\PestPatrol\PPControl.exe
    O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
    O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
    O4 - HKLM\..\RunServices: [CSINJECT.EXE] C:\Program Files\Norton SystemWorks\Norton CleanSweep\CSINJECT.EXE
    O4 - HKLM\..\RunServices: [NPROTECT] C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
    O4 - HKLM\..\RunServices: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\SymTray.exe "Norton SystemWorks"
    O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
    O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
    O9 - Extra button: Real.com (HKLM)
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
    O10 - Broken Internet access because of LSP provider 'lsp.dll' missing
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37871.356724537
    O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} - https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
    O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - http://office.microsoft.com/productupdates/content/opuc.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl) - http://secure2.comned.com/signuptemplates/ActiveSecurity.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/11d1ab8d1620e6ccb615/netzip/RdxIE601.cab
    O16 - DPF: Yahoo! MahJong Solitaire - http://download.games.yahoo.com/games/clients/y/mjst3_x.cab
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...pple.com/bonnie/us/win/QuickTimeInstaller.exe
    O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE} (Microsoft Office Tools on the Web Control) - http://officeupdate.microsoft.com/TemplateGallery/downloads/outc.cab
    O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
    O16 - DPF: ConferenceRoom Java Client - http://irc.theamateurchat.com/java/cr.cab
    O16 - DPF: {1FDEC088-A699-46FE-BF76-D5FD6DAE6150} (UCSearch.ucUCSearch) - http://www.armbender.com/UCSearch.CAB
    O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} - http://www.netpaloffers.net/NetpalOffers/DMO1/emCraft1.cab


    Again, thank you.
     
  5. Bob Cerelli

    Bob Cerelli

    Joined:
    Nov 2, 2002
    Messages:
    22,468
    I assume IE is set not to use any proxy server is you don't need one.

    Just as a test, can you uninstall (not disable) any firewall or internet restricting software. It looked like there were several listed.

    There have been quite a few posts where people thought they had ZoneAlarm either configured correctly or disabled. As soon as they uninstalled it, IE started working.

    Again, just as a test. In general it's best to eliminate as many possiblities when troubleshooting.
     
  6. gregwix

    gregwix Thread Starter

    Joined:
    Jan 3, 2004
    Messages:
    9
    Hello. No, I have not yet "uninstalled" ZoneAlarm". I only disabled it and that didn't work. I'll uninstall it next.
    I can only guess that IE is not set to use a proxy server, as my ISP is not one. I just know that before Incredifind showed up, all was working.
    Yes, I have tried entering a url I know is valid and hitting enter. The same thing happens. I get that same message.

    Neither Mozilla, which I downloaded recentely, or Netscape seems to be affected.

    A Thank you to all who try to help.
     
  7. Bob Cerelli

    Bob Cerelli

    Joined:
    Nov 2, 2002
    Messages:
    22,468
  8. gregwix

    gregwix Thread Starter

    Joined:
    Jan 3, 2004
    Messages:
    9
    http://www.kephyr.com/spywarescanne...ind/index.phtml
    The above link given to me by Mr. Cerelli would not open with either Netscape or Mozilla, with both saying they could not locate it.

    I have run Spybot S&D, Adaware 6, and the Spysweeper suggested above.

    I am now going to uninstall, then reinstall ZoneAlarm Pro. I'll let people know what happens.
     
  9. Bob Cerelli

    Bob Cerelli

    Joined:
    Nov 2, 2002
    Messages:
    22,468
    Just tried both links and they opened ok.

    Also, just for testing, don't reinstall Zone Alarm until IE is working. That's just to eliminate it as a possible source of the problem.

    You might want to double check your connection settings in IE.

    You also might want to just download and re-install IE 6 SP1. Perhaps it was damaged from that program. Removing the spyware doesn't always reverse its effects.
     
  10. cybertech

    cybertech Moderator

    Joined:
    Apr 16, 2002
    Messages:
    72,113
    Run HJT again and put checks against these:

    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.eznsearch.com/index.htm
    R3 - URLSearchHook: (no name) - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - (no file)
    O10 - Broken Internet access because of LSP provider 'lsp.dll' missing
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/11d1ab8d1620e6...ip/RdxIE601.cab
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...meInstaller.exe
    O16 - DPF: {1FDEC088-A699-46FE-BF76-D5FD6DAE6150} (UCSearch.ucUCSearch) - http://www.armbender.com/UCSearch.CAB
    O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} - http://www.netpaloffers.net/NetpalO...O1/emCraft1.cab

    Close all browser windows before clicking "fix checked".

    Reboot your machine.
     
  11. cybertech

    cybertech Moderator

    Joined:
    Apr 16, 2002
    Messages:
    72,113
    Forgot to say this will fix your broken winsock download the LSP-Fix.
     
  12. gregwix

    gregwix Thread Starter

    Joined:
    Jan 3, 2004
    Messages:
    9
    I have now done all as suggested above and I have IE 6 back. When I fixed the LSP-Fix, it said 0 items changed. I don't know what that means, but along with everything else, and ZoneAlarm Pro reinstalled after IE 6 loaded, all seems to be ok again.

    A BIG thank you. I wish I was rich, I'd send a big donation. All I can do is make a small donation to those that helped, when I get paid, which I will.

    Thank you very much.
     
  13. Bob Cerelli

    Bob Cerelli

    Joined:
    Nov 2, 2002
    Messages:
    22,468
    Sounds like from everything, it was the IE6 reinstall that was the change that got it working again. Good work and thanks for letting us know.
     
  14. gregwix

    gregwix Thread Starter

    Joined:
    Jan 3, 2004
    Messages:
    9
    Mr. Cerelli. It had to be something else or just a part of the fix. I had uninstalled and reinstalled IE6 a few times, even tried the "repair" button when that screen came up. I tried reinstalling IE 6 after ZoneAlarm was uninstalled. No go.

    After I did the fixes that Cybertech suggested, then reinstalled IE 6, then checked IE 6, it came up. I reinstalled ZA Pro, and all is working again.

    I do again thank everyone that helped. I would never have been able to do anything on my own.
     
  15. Bob Cerelli

    Bob Cerelli

    Joined:
    Nov 2, 2002
    Messages:
    22,468
    I guess it just wasn't entirely clear specifically what had been done to solve the problem. Glad it all worked out.

    Good information for how much those Trojan programs can affect the way the computer function.
     
  16. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/192244

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice