PDA

View Full Version : My computer websites down!



Mutaher
28-12-07, 22:34
Hello,

I have been expereriencing problems on my computer, I cannot seem to access any websites except for google, and I could access some once or twice in like 6 hours. What happened is that I play a game called Runescape, an online game that uses Java, I was playing it this morning then suddenly the game froze, so I tried to go on the homepage of the game and it worked perfect, but I could not access the features of the website and the game itself, also google was working fine well, after a hour or so the runescape homepage stopped working, my msn messenger could not get throught to the internet and my other programs that use the internet could not get acces through either, and i tried other sites none. worked at all except for google, but I could only access 2 or 3 of the results I searched help for, I have scanned my computer and its safe, I used spybot, adware lavasoft, avg, avg antispyware, stinger and my firewall is Zone Alarm, I use Mozilla Firefox, Internet explorer and netscape cannot get through either.
I know it is not my Internet supplier or modems fault because my laptop is using the same as my computer and it works good on my laptop.

So could someone please help me, I need access to the internet asap.
Thank you.

PeterStoba
28-12-07, 22:38
Use your laptop if it is that urgents, only thing i can think of is are the cables in?

Mutaher
28-12-07, 23:06
Ive said that google works and a few other sites, but alot of other websites dont, so yes the cables are in.

Aaron
29-12-07, 01:09
The only thing I can think of, off the top of my head, is either that your ISP is having issues, or that there is something screwy with your dns servers. I had a very similar problem earlier this year and it turned out to be the DNS servers going a bit mad..

Mutaher
29-12-07, 02:29
I just noticed, theres a program running called iexplorer.exe, and in task manager it shows it takes alot of cpu power, also slows my computer down, I ended its process many times and it appears back, there 2 of them running, but one take cpu power, I also looked this up and i found this:

'iexplorer.exe is a process belonging to the AdClicker advertising program. This process monitors your browsing habits and distributes the data back to the author's servers for analysis. This also prompts advertising popups. This process is a security risk and should be removed from your system'

It says something about browsing so could it be this? I am currently trying to remove it.

monkey56657
29-12-07, 08:24
Remove that yeah ^

Also check the firewall software...It may have gotten a bit messed up.

Mutaher
29-12-07, 18:16
I removed iexplorer.exe, now there 2 iexplore.exe running and one of then is doing the same thing iexplorer.exe was doing...=-Z

Could I get help on removing this?

Micky007
29-12-07, 18:38
dont you have any firewall or anti virus or spyware or adware bla bla bla on ur pc?

Micky007
29-12-07, 18:40
if not if i was you id go buy BitDefender, No1 firewall, No1 Anti-Virus and also does spyware, adware etc...

iv had it for a year now and its truely is awsome, its only £25 (i think) and you get it for 2 yrs and it works on 2 PCs !

Micky007
29-12-07, 18:44
http://www.bitdefender.com/PRODUCT-2195-en--BitDefender-Internet-Security-2008.html

price has now changed from when i got it, you can now put it on 3 pcs and for 1ur its $39 but if you want 2 yrs its $60 which is £30, still cheap and for 3 pcs for 2yrs !

theres also an option for 1 user account and for 2 yrs, its same price as for 3 users, so stick with the 3 users one for 2yr ;)

Biodoid
29-12-07, 20:41
iexplore.exe is the main executable for Microsoft Internet Explorer

PeterStoba
29-12-07, 20:58
iexplore.exe is the main executable for Microsoft Internet Explorer
That is what i thought

Jiggles
29-12-07, 21:04
Close down iexplorer.exe then you will lose the menu bar and any explorer windows. if you do it then al you need to to to restart it its in task manger file, run, then type 'Explorer' the run it and i then explorer then should start up.

Micky007
29-12-07, 21:39
Close down iexplorer.exe then you will lose the menu bar and any explorer windows. if you do it then al you need to to to restart it its in task manger file, run, then type 'Explorer' the run it and i then explorer then should start up.

iexplorer.exe is Internet Explorer

your on about explorer.exe

Jiggles
29-12-07, 22:17
DOH!

too many Explorers...

Mutaher
29-12-07, 22:28
i have lots of protection programs, but none of then detect it, and zone alarm firewall, il try that one u put up..see if it detects it :mrgreen::mrgreen:


i got rid of iexplorer.exe, now there 2 iexplore.exe running, not 2 iexplorer.exe, i said 2 iexplore.exe, its re not rer, one seems like the one that should be there, and the other one is taking 99% cpu power and slowing my computer down, i took the net cable out and then iexplore.exe kept telling me to connect the internet, plus i dont use internet explorer, i use mozilla firefox, and it seems to be have blocked access all the sites except for google, i suspect iexplore.ere for that also.

Mutaher
29-12-07, 22:53
Iexplorer.exe

'DISABLE AND REMOVE iexplorer.exe IMMEDIATELY. This process is most likely an adware or spyware. It is highly recommended to run a FREE performance scan (http://www.liutilities.com/products/campaigns/plib/spplib) to automatically optimize memory, CPU and Internet settings.'


Iexplore.exe

'iexplore.exe is the main executable for Microsoft Internet Explorer. This Microsoft Windows application allows you to surf the world wide web and the Internet. This program is a non-essential process, but should not be terminated unless suspected to be causing problems.

Note: iexplore.exe could also be a process which belongs to the . This program is a non-essential process, but should not be terminated unless suspected to be causing problems.

Note: iexplore.exe is a process which is registered as a trojan. This Trojan allows attackers to access your computer from remote locations, stealing passwords, Internet banking and personal data. This process is a security risk and should be removed from your system.

Determining whether iexplore.exe is a virus or a legitimate Windows process depends on the directory location it executes or runs from.'

The bit i made italic doesnt make me feel safe having it on my computer...

Mutaher
29-12-07, 23:06
Micky, i cant install BitDefender into my pc, because it needs access to the internet to download packages, and my computer doesnt go through...=-Z

alexnifty
30-12-07, 03:14
Go here and download Hijackthis (http://www.spywareinfo.com/~merijn/programs.php). You'll need to find a PC connected to the net, but its a very small file (392KB).

Run hijackthis and select "Do a system scan and save a logfile".

Paste the logfile on the forum here and we can get a good look at whats running and from where.

Micky007
30-12-07, 05:21
Micky, i cant install BitDefender into my pc, because it needs access to the internet to download packages, and my computer doesnt go through...=-Z

what you mean "my computer doesnt go through"??

Micky007
30-12-07, 05:22
Go here and download Hijackthis (http://www.spywareinfo.com/%7Emerijn/programs.php). You'll need to find a PC connected to the net, but its a very small file (392KB).

Run hijackthis and select "Do a system scan and save a logfile".

Paste the logfile on the forum here and we can get a good look at whats running and from where.


Id be very carefull with what you delete with Hijack this as i remember using it a few years ago and it was picking up things that Windows needs to boot up and work etc.... and if they where deleted then your, well...... ****ed, i dont know if its changed since then but just be carefull.

alexnifty
30-12-07, 05:52
Id be very carefull with what you delete with Hijack this as i remember using it a few years ago and it was picking up things that Windows needs to boot up and work etc.... and if they where deleted then your, well...... ****ed, i dont know if its changed since then but just be carefull.

Hijackthis spits out a list of registry entries to do with programs that start with windows and dll's that load. MOST of them are perfectly legitimate entries which you shouldn't touch.

You don't delete everything it comes up with, thats not its function!

Thats why I asked for the results to be pasted, as I can run it through a p****r and see if anything is wrong (like an evil .dll for example).

EDIT: apparently I am not allowed to say 'par$er'

Micky007
30-12-07, 06:15
lol, yea Hijack This should not be used for the novice people out there;)

Mutaher
30-12-07, 14:35
lol, ive used Hijack lots of times, its still installed inmy computer, and micky what I meant my computer doesnt go through is that all programs are blocked to the internet and firefox only accesses google, and other few sites, not the ones I need though.
Heres my log, sorry for the late reply:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:01:06, on 30/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://uk.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://uk.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://uk.search.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://uk.search.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [memo site kind that] C:\Documents and Settings\All Users\Application Data\Grid Blue Memo Site\up new.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [STManager] C:/Program Files/SpeedTouch/Dr SpeedTouch/drst.exe -b
O4 - HKCU\..\Run: [RdrScr] C:\DOCUME~1\Mama\APPLIC~1\SKIPCO~1\baitseek.exe
O4 - HKCU\..\Run: [Uniblue SpyEraser] "C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe" -m
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: TomTom HOME.lnk = C:\Program Files\TomTom HOME\TomTomHOME.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://mutaher-da-1-u-al-kno.spaces.live.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{AB32513C-F2C0-4483-8845-1D513237B1E1}: NameServer = 212.50.160.28,194.106.33.42

Mutaher
30-12-07, 14:36
O18 - Protocol: bw+0 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bw+0s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bw-0 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bw-0s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bw00 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bw00s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bw10 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bw10s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bw20 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bw20s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bw30 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bw30s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bw40 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bw40s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bw50 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bw50s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bw60 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bw60s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bw70 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bw70s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bw80 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bw80s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bw90 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bw90s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwa0 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwa0s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwb0 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwb0s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwc0 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwc0s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwd0 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwd0s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwe0 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwe0s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwf0 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwf0s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - (no file)
O18 - Protocol: bwg0 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwg0s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwh0 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwh0s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwi0 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwi0s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwj0 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwj0s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwk0 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwk0s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwl0 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwl0s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwm0 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwm0s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwn0 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwn0s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwo0 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwo0s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwp0 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwp0s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwq0 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwq0s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwr0 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwr0s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bws0 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bws0s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwt0 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwt0s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwu0 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwu0s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwv0 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwv0s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bww0 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bww0s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwx0 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwx0s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwy0 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwy0s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwz0 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: bwz0s - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O18 - Protocol: offline-8876480 - {BEB383EF-71E7-48FD-9668-E3F98ECEE5D4} - (no file)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762# # (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O24 - Desktop Component 0: (no name) - http://65.54.162.250/cgi-bin/getmsg/images.jpg?&msg=11E20470-34ED-4F4E-9C24-160C6AE00873&start=0&len=6650&mimepart=3&curmbox=00000000-0000-0000-0000-000000000001&b=9f3e256a46863f4aa46c7ec53119fafb&disk=10.1.106.206_d1682&login=nadeemys&domain=hotmail%2ecom&hm___sig=b2deffee01c6760f89ca92ef9f7d2fc5a4c88666a 1812944

--
End of file - 15558 bytes

alexnifty
31-12-07, 08:01
Ok so, you have a lot of programs that start with windows, I would try and keep them to a minimum, but they shouldnt block the web.


I couldnt actually get your HTJ log to par$e here (http://hjt.networktechs.com/). Anyway...

The following caught my eye:

O17 - HKLM\System\CCS\Services\Tcpip\..\{AB32513C-F2C0-4483-8845-1D513237B1E1}: NameServer = 212.50.160.28,194.106.33.42

Did you set this yourself in your network settings? Your computer is being pointed at 212.50.160.28 and 194.106.33.42 to resolve web addresses. Normally its something like 192.168.1.1.


Also everything with (no file) at the end should be removed with HJT.

Mutaher
31-12-07, 15:03
so ive to remove all the ones with no file at the end, il do that now.

I didnt set anything, my ip is 192.168.1.1.

Rotten
31-12-07, 16:37
start menu ->
run ->
cmd ->
ipconfig /flushdns
ipconfig /renew


try that

alexnifty
31-12-07, 18:16
start menu ->
run ->
cmd ->
ipconfig /flushdns
ipconfig /renew


try that

Good idea, does "Repair Network Connection" do the same thing?



so ive to remove all the ones with no file at the end, il do that now.

I didnt set anything, my ip is 192.168.1.1.

Your IP is 192.168.1.1? Thats normally the IP of your router!

Try going into your network connection settings and specifying:

YOUR IP: 192.168.1.2
Subnet Mask: 255.255.255.0
Defalt Gateway: 192.168.1.1 (This depends on your connection to the internet, if its via a router then usually its this, if its a modem then use your laptop to find what Gateway it connects through).
Preferred DNS Server: 192.168.1.1 (Again, this depends on how you connect).


An example of my settings (http://www.alexnifty.co.uk/images/ipSettings.jpg). I'm on vista but it is identical to XP (Vista being essentially a reskin, *grumble* :lol:).

Rotten
31-12-07, 18:23
Good idea, does "Repair Network Connection" do the same thing?


yeah, sorry if that was posted above, didnt see it

alexnifty
31-12-07, 18:25
yeah, sorry if that was posted above, didnt see it

It wasn't actually :lol: One of those simple things you forget.

So to sum up: 'Repair Connection' for the win...?

Rotten
31-12-07, 18:29
yeah mate, if my microsoft exams' taught me anything it's the most simple problem is often the hardest to find, and most likely to be skipped :-P

Mutaher
31-12-07, 20:03
oooooooo thanks, it was my dns server, some how it was changed...:|

Its all working now thanks 8)

alexnifty ftw!!

alexnifty
01-01-08, 15:56
oooooooo thanks, it was my dns server, some how it was changed...:|

Its all working now thanks 8)

alexnifty ftw!!

Great! Thanks, I accept paypal and forum rep ;)


I wonder what changed your DNS settings though :confused:

Rotten
01-01-08, 22:38
didn't i mention the dns fix? lol

alexnifty
02-01-08, 00:57
didn't i mention the dns fix? lol

Sort of... From his HJT log it showed that his DNS had been set manually; far as I can tell 'ipconfig /renew' only works when it's set automatically by DHCP.

EDIT: Cue popcorn...