16 Posts

June 14th, 2004 17:00

What is that? I'm pretty green on this stuff.

Community Manager

 • 

56.9K Posts

June 14th, 2004 17:00

TerriLynn,

Welcome to the Dell Community Forum (DCF).
List all the software and/or hardware changes made to the system BEFORE this issue arose. List all the troubleshooting steps you have taken. Have you run a virus checker?

REMINDER - Even if you know the sender, never open attachments until you have scanned them with a virus checker

(1) RUN THIS VIRUS CHECKER
* Go here
http://housecall.antivirus.com
* Click "Scan Now. It's Free!"
* Choose your country, click Go
* Give it 5 or 10 minutes to build the first time
* Put checks by your hard disk drive, floppy, or zip disk letters
(whatever needs scanning)
* Click "Scan" and "Autoclean"
* Close all boxes when finished
* Click Start- Windows Updates
* Click Scan for Updates
* Load all Critical Updates
* When finished close all boxes
* If you have identified a virus, go here to find a remover:
http://www.sarc.com/avcenter/tools.list.html

(2) SPECIFIC VIRUS REMOVAL TOOLS
* Go here for cleaning tools:
http://www.beforeyoukillyourcomputer.com/virus.htm
* On the right, scroll down to Removal Tools
* Click your virus. Download the tool and follow it's instructions

(3) DOWNLOAD/INSTALL SPYBOT SEARCH & DESTROY
* Go here:
http://www.safer-networking.org/index.php?page=mirrors
* After Downloading and installing SpyBot Search & Destroy, first press Online, and search for, put a check mark at, and install all updates
* Next, close all Internet Explorer windows, hit 'Check for Problems', and have SpyBot remove all it finds

(4) DOWNLOAD/INSTALL AD AWARE
* Go here:
http://www.lavasoftusa.com/support/download/
* After installing Ad-Aware, and before running the program, press "check for updates now".
Click "Connect" and install all updated components available. Click 'Finish'
* Press "Scan Now", then 'next', and let Ad-Aware scan your drives
* It will find a number of "bad" files and registry keys. Click 'Next' again
* Check all found items, and click 'next' once more
* It will ask you whether you'd like to remove all checked items. Click OK
* Always reboot the computer between each program - both of these may find things that they need to have a reboot of the machine to clear - please reboot and let them finish

(5) OTHER FREE AVG ANTIVIRUS
* Go here:
http://www.grisoft.com/us/us_dwnl_free.php

(6) FREE POPUP STOPPER
* Go here:
http://www.panicware.com/product_psfree.html

181 Posts

June 14th, 2004 17:00

Hello terrilyn and Chris,

I dont intend to crosspost. But just a suggestion, a hijackthis log might show something . 

Community Manager

 • 

56.9K Posts

June 14th, 2004 17:00

TerriLynn,

Set Internet Explorer to the defaults.
* Click Start- Control Panel
* Click Network and Internet Connections
* Click Internet Options
* Click the "Delete Files" button, insert a check, click OK
* Click the "Clear History" button, click Yes or OK
* Under Home Page, change it to http://www.google.com or whatever you like
* Click the "Use Current" button
* Click Apply
* Click the Security tab
* Click the "Default Level" button
* Click Apply
* Click the Privacy tab
* Click the "Default" button
* Click Apply
* Click the Programs tab
* Check the box "IE should check to see whether it is the default browser"
* Click Apply
* Click the Advanced tab
* Click the "Restore Defaults" button
* Click Apply
* Click Apply and/or OK. Close all boxes. Try to get onto MSN.com

16 Posts

June 14th, 2004 17:00

I have not added anything to the compute That I can remember. I ran spybot, adaware and norton professional. Ad Aware found 9 files low threat. Norton shows nothing.

16 Posts

June 14th, 2004 17:00

Chris I tried what you said and I can access msn now. Thank you!!!!!

16 Posts

June 14th, 2004 18:00

If I go through the steps listed above for internet explorer tools I get this message res://C:\WINDOWS\System32\shdoclc.dll/dnserror.htm when I click use current after entering the homepage address. Any ideas?? MSN is not working again.

16 Posts

June 14th, 2004 18:00

Chris-I lied!  I can pull up the website now, but if I try to click on a link I get the unable to display page "unable to find server" reply.

16 Posts

June 15th, 2004 15:00

What is a hijack log and how might it help?

181 Posts

June 15th, 2004 16:00

Hello,.

Please download HIJACKTHIS from the link below...

http://spywareinfo.com/~merijn/files/HijackThis.exe

Then, unzip it to a permanent folder say for example c:\Hijackthis .... run hijackthis....hit SCAN....then hit SAVE LOG.... copy and paste the log in your post....

DO NOT FIX OR REMOVE ANYTHING ANYTHING WITH HIJACKTHIS FOR MOST AOF THE ENTRIES ARE USUALLY HARMESS/ESSENTIAL

16 Posts

June 15th, 2004 20:00

 

This is what I got from the hijack scan. Now what??? P.S. Thanks for the Help

Logfile of HijackThis v1.97.7
Scan saved at 3:27:16 PM, on 6/15/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Terri Lynn\Local Settings\Temporary Internet Files\Content.IE5\4VNRAW11\HijackThis[1].exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msnbc.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://rd.yahoo.com/customize/ymsgr/defaults/*http://my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/ymsgr/defaults/sb/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.fisi.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Fisi.Net
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://rd.yahoo.com/customize/ymsgr/defaults/su/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=40
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.1501.0\en-us\msntb.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Ad-aware] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe" +c
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Save with Download Manager... - C:\Program Files\J River\Media Jukebox\DMDownload.htm
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .mpg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.fisi.net/
O16 - DPF: Yahoo! Checkers - http://download.games.yahoo.com/games/clients/y/kt3_x.cab
O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt1_x.cab
O16 - DPF: Yahoo! Spelldown - http://download.games.yahoo.com/games/clients/y/sdt1_x.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - https://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} (Microsoft Office Template and Media Control) - http://office.microsoft.com/templates/ieawsdc.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) - http://download.microsoft.com/download/0/5/c/05c905f4-dd30-427d-a3de-373c3e5552fc/msSecAdv.cab?1075218360781
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralInitialSetup1.0.0.8.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0309.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/02f3cec39381eb6b1d18/netzip/RdxIE601.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {928626A3-6B98-11CF-90B4-00AA00A4011F} (SurroundVideoCtrl Object) - http://autos.msn.com/components/ocx/survid/MSSurVid.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/essentials/ymmapi_0727.dll
O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78E} (SassCln Object) - http://www.microsoft.com/security/controls/Sasser/20/SassCln.CAB
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://download.yahoo.com/dl/mail/autocomplete.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE} (Microsoft Office Tools on the Web Control) - http://officeupdate.microsoft.com/TemplateGallery/downloads/outc.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/eng/check/qdiagh.cab?307
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.yahoo.com/dl/toolbar/yiebio5_1_5_0.cab
O16 - DPF: {F7DC2A2E-FC34-11D3-B1D9-00A0C99B41BB} (Zoom Class) - http://www.zoomify.com/download/zoomify305.cab

 

181 Posts

June 16th, 2004 11:00


Hello ,


Close all browser windows . Run Hijackthis .Hit SCAn button .Put a check mark on these entries and hit FIX CHECKED button.


R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=40
R3 - Default URLSearchHook is missing


O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralInitialSetup1.0.0.8.cab


O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/02f3cec39381eb6b1d18/netzip/RdxIE601.cab

Reboot.


See if that helps.


Does this happen only in case of MSN?


Also,.

Click on TOOLS - INTERNET OPTIONS

Then Hit DELETE FILES , DELETE COOKIES, and DELTE HISTORY  buttons.

Message Edited by baskar1234 on 06-16-2004 07:38 AM

16 Posts

June 16th, 2004 12:00

Is that what I just did below?? I am so green at all of this.

181 Posts

June 16th, 2004 15:00

Hello Terilynn,

Try those fixes in Hijackthis that i have mentioned in my previous post. See if that helps.

16 Posts

June 17th, 2004 13:00

I made this fixes in the hijack log you suggested. Everything seems to be working well. Thank you so much!! I really appreciate the input from everyone!
No Events found!

Top