Spyware preventing IE from connecting to internet?

P

Phoenix

Hey, Hope someone can help as this has been driving me
nuts for 3 days now. My home PC is on Win XP Pro. My
internet connection is through 'always on' broadband.
Now I can't be absolutely sure but I'm this problem
appears to have occured since I last downloaded and
installed a MS Windows update (via the manager that sits
in the system tray). What happens is my broadband
connection is showing as connected fine but when I launch
IE, I just get 'Page cannot be Displayed' error whatever
site I try and get onto. Now I have experienced spyware
that changes your homepage etc but this isn't happening
this time. I just don't get my pages loading at all.
In addition to the MS Update culprit suspicions, I found
various Mal and Spyware after scanning my computer. I
have managed to clear a considerable amount of this off
my machine (including registry)but still have the
following that I am struggling to shift no matter what
utilities I try: Alexa Related (replace file), Cydoor
(replace file), Lop (file) and WMP - client ID (reg
change). I have done a virus scan on the machine (AVG)
which came up with nothing.
Any help would be hugely appreciated as I am still unable
to get online. I have the ability to download anything
anyone my suggest as I am on my work PC at the moment and
have my emergency laptop at home as backup!
Please please please someone come up with something new
for me to try or tell me you've had the same experience
and know how to come through to the other side!
 
P

Phoenix

Meant to put my it_girrrl e-mail address on my post.
Please drop me an e-mail / post with anything I could
try...
 
R

rb

I have experienced the same problem with my cable modem.
When I can't browse any pages I reset my modem and that
usually works. Some modems don't have a reset button,
just unplug the power for a few seconds. As with the
spyware, are you unable to remove it with your scanning
software? Try rebooting your computer and holding down
the shift button during bootup. This will disable all of
the programs that start up at boot. Then run your
spyware program. If that doesn't work, try downloading
Startup Cop from PCMag.com. You can monitor all startup
programs that are in your registry that may not show up
in your startup folder and also disable them. I hope
this helps.
 
X

XPUSER

Phoenix said:
Hey, Hope someone can help as this has been driving me
nuts for 3 days now. My home PC is on Win XP Pro. My
internet connection is through 'always on' broadband.
Now I can't be absolutely sure but I'm this problem
appears to have occured since I last downloaded and
installed a MS Windows update (via the manager that sits
in the system tray). What happens is my broadband
connection is showing as connected fine but when I launch
IE, I just get 'Page cannot be Displayed' error whatever
site I try and get onto. Now I have experienced spyware
that changes your homepage etc but this isn't happening
this time. I just don't get my pages loading at all.
In addition to the MS Update culprit suspicions, I found
various Mal and Spyware after scanning my computer. I
have managed to clear a considerable amount of this off
my machine (including registry)but still have the
following that I am struggling to shift no matter what
utilities I try: Alexa Related (replace file), Cydoor
(replace file), Lop (file) and WMP - client ID (reg
change). I have done a virus scan on the machine (AVG)
which came up with nothing.
Any help would be hugely appreciated as I am still unable
to get online. I have the ability to download anything
anyone my suggest as I am on my work PC at the moment and
have my emergency laptop at home as backup!
Please please please someone come up with something new
for me to try or tell me you've had the same experience
and know how to come through to the other side!
===============================================
I have been running XP Pro for over a year now and have installed
every critical update, every Windows update, and every driver update
that has been available from the Windows Update site. No problem.
So it is my humble opinion that people who do get into trouble after
doing a Windows Update get into that trouble because they are finally
forced to do a reboot and whatever virus or spyware that has been
lurking around on their system suddenly activates and starts causing
problems and they of course blame the Windows Update. For you to
have actually detected spyware and still think your problem may be due
to the Windows Update makes no sence to me. Of course it is the
spyware that has caused your Internet browsing problem. It is also
possible that your winsock keys in the registry may be damaged.

Consider trying the following suggestions:

Control Panel | Internet Options | General tab

Delete all cookies
Delete all temporary internet files
(include all offline content)
Remove all Downloaded Program Files
To do that, you click on that "settings"
button and then click on the "View Objects"
button and then right click and choose remove
for all of them, if any, one at a time.
Close the Downloaded Program Files window,
Click OK to the Settings window.
Now clear History

Now click on the "Advanced" tab at the top
of Internet Options.
In the Browsing section, uncheck the box for
"Enable third-party browser extensions (requires restart)"
Click "Apply" and then "OK" at the bottom
of Internet Options
Close out of Control Panel

Restart the computer

Download one or both of these Anti Spyware programs
and install them, update them and scan your system
and delete any spywares that may be found. If you have a
working Anti Virus program, then update it and scan with it,
otherwise use one of these free online virus scanners:

Ad-aware 6.0 build 181
http://download.com.com/3000-2144-10214379.html?tag=list

Spybot - Search & Destroy 1.2
http://download.com.com/3000-2144-10194058.html?tag=list

Panda ActiveScan
http://www.pandasoftware.com/activescan/

TrendMicro Houscall Anti Virus Scan
http://housecall.trendmicro.com/

====================================================

Possible damaged winsock key damage:

Please read this whole reply before proceeding with any suggestions.

Issue:

on this XP Home/Pro computer,
when trying to browse the Internet,
you are getting "Page Cannot Be Displayed" and
when you go to the command prompt window
and run ipconfig /all, you get an APIPA in the form of 169.254.x.x.
Then immediately run ipconfig /renew, you get this error message:

"An operation was attempted on something that is not a socket"

If so, you have a damaged winsock2 key in the registry.

You should check System Information (winmsd)
START > RUN - type in winmsd and click OK
Expand Components / Network / click on Protocol -
if the section headings item of "Name" have a value
starting with anything other than MSAFD or RSVP
then that is probably what is causing the problem.

Examples:

MSAFD Tcpip [TCP/IP]
MSAFD Tcpip [UDP/IP]
RSVP UDP Service Provider
RSVP TCP Service Provider
MSAFD NetBIOS [\Device\NetBT_Tcpip...
and so on

It may be a third-party firewall or a Spyware or a Virus.
("New.Net" is a common spyware for example)
Make sure that MSCONFIG is in Normal Startup
and then see if uninstalling the third party firewall
(best done from its own uninstall program if available)
or the Spyware from Add Remove Programs will
resolve the issue. If it's a virus, then only an Anti Virus Program
will be able to deal with that.

You may want to try downloading either Ad-Aware 6 or Spybot
to another computer and then installing one of them on the infected XP
Home/Pro
computer and try to wipe out Spyware and see if that resolves the issue.

Ad-aware 6.0 build 181
http://download.com.com/3000-2144-10214379.html?tag=list

Spybot - Search & Destroy 1.2
http://download.com.com/3000-2144-10194058.html?tag=list


If none of that works or is possible, you could try this method
for replacing the winsock and winsock2 registry keys:

Uninstall any third-party proxy software or firewall programs before
proceeding.

Step 1: Delete registry keys

A)Open Regedit from the Run line
B)Go to both of the following keys, EXPORT each of them, and then delete
them:
(To export a key, you right click on it and choose "export" - you can choose
where to export them to -
DESKTOP is handy -
and you need to type in a file name such as "exported Winsock key" /
"exported WinSock2 key"
and then click on SAVE)

HKLM\SYSTEM\CurrentControlSet\Services\Winsock
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2
C)Restart the computer

NOTE: It is important to restart the computer after deleting the Winsock
keys.
Doing so causes the XP operating system to recreate shell entries for those
two
keys. If this is not done, the next step does not work correctly.

Step 2: Install TCP/IP on top of itself

A)Open the properties window of the network connection (Local Area
Connection)
B)Click Install
C)Click Protocol, then Add
D)Click Have Disk
E)Type the path to the \%systemroot%\inf folder (usually C:\Windows\inf) and
click OK
(if you try to click Browse, then browse to the \inf folder,
it may not show up in the list)
F)You should now see "Internet Protocol (TCP/IP)" in the list of available
protocols. Select it and click OK.
G)Restart the computer

When the computer reboots you will have functional Winsock keys.
If so, then be sure to delete the exported winsock and winsock2 reg files.
(You don't want to accidentally put them back in the registry)

Side effects and possible problems:

This method will restore basic functionality to the Winsock keys, but is not
a
complete rebuild. On a default install of Windows XP the registry key:
HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\
Parameters\Protocol_Catalog9\Catalog_Entries will have 11 sub-keys.
When applying this method, the Catalog_Entries will only have 3 sub-keys.
However, it works and there does not appear to be any side effects.
The missing entries relate back to the:
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces key.
Also, third-party proxy software or firewalls may need to be reinstalled.


==========================================================
 
P

Phoenix

I used SpyFerret to detect the spyware as Ad-aware just
didn't detect this stuff. Unfortunately, you have to buy
a license before SpyFerret will let you use the 'cleanup'
option, typical!
I'll try your suggestions tonight. My broadband is
through my NTL cable TV top box so I guess I should try
resetting the power on that, though it's never done this
kind of thing to me before..

Cheers.
 
P

Phoenix

Thanks, certainly alot for me to try. Though I have
tried quite a few of your suggestions already. I've been
using Win update longer than you me thinks but wouldn't
trust it implicitly - have you seen any news releases on
the Spybot-W worm? See Sophos extract below. Still
leaves me foxed as nothing inidicates IE is affected by
this worm and my virus scan (IDEs updated on a daily
basis) has picked up nothing.

"In order to run automatically on system startup the worm
copies itself to the file wupdated.exe in the Windows
system folder and registers itself as the wupdated
(Windows Update Service) service process."

I'm a big fan of the Ad-aware software so have been down
that road already. In the end it was Spy Ferret that
detected the spy/mal ware that Ad-aware failed to pick
up. However, SF isn't free - if you want to cleanup you
have to buy a license!

I have a feeling you could be on the money with the
winsock thing as I tried running the repair wizard on my
Broadband connection and it came back with failure
message when trying to renew the IP. Guess I'm gonna have
to cough up for SpyFerret license, make myself a big cup
of tea and settle in for a long night!

Cheers for all new ideas!

-----Original Message-----
Hey, Hope someone can help as this has been driving me
nuts for 3 days now. My home PC is on Win XP Pro. My
internet connection is through 'always on' broadband.
Now I can't be absolutely sure but I'm this problem
appears to have occured since I last downloaded and
installed a MS Windows update (via the manager that sits
in the system tray). What happens is my broadband
connection is showing as connected fine but when I launch
IE, I just get 'Page cannot be Displayed' error whatever
site I try and get onto. Now I have experienced spyware
that changes your homepage etc but this isn't happening
this time. I just don't get my pages loading at all.
In addition to the MS Update culprit suspicions, I found
various Mal and Spyware after scanning my computer. I
have managed to clear a considerable amount of this off
my machine (including registry)but still have the
following that I am struggling to shift no matter what
utilities I try: Alexa Related (replace file), Cydoor
(replace file), Lop (file) and WMP - client ID (reg
change). I have done a virus scan on the machine (AVG)
which came up with nothing.
Any help would be hugely appreciated as I am still unable
to get online. I have the ability to download anything
anyone my suggest as I am on my work PC at the moment and
have my emergency laptop at home as backup!
Please please please someone come up with something new
for me to try or tell me you've had the same experience
and know how to come through to the other side!
===============================================
I have been running XP Pro for over a year now and have installed
every critical update, every Windows update, and every driver update
that has been available from the Windows Update site. No problem.
So it is my humble opinion that people who do get into trouble after
doing a Windows Update get into that trouble because they are finally
forced to do a reboot and whatever virus or spyware that has been
lurking around on their system suddenly activates and starts causing
problems and they of course blame the Windows Update. For you to
have actually detected spyware and still think your problem may be due
to the Windows Update makes no sence to me. Of course it is the
spyware that has caused your Internet browsing problem. It is also
possible that your winsock keys in the registry may be damaged.

Consider trying the following suggestions:

Control Panel | Internet Options | General tab

Delete all cookies
Delete all temporary internet files
(include all offline content)
Remove all Downloaded Program Files
To do that, you click on that "settings"
button and then click on the "View Objects"
button and then right click and choose remove
for all of them, if any, one at a time.
Close the Downloaded Program Files window,
Click OK to the Settings window.
Now clear History

Now click on the "Advanced" tab at the top
of Internet Options.
In the Browsing section, uncheck the box for
"Enable third-party browser extensions (requires restart)"
Click "Apply" and then "OK" at the bottom
of Internet Options
Close out of Control Panel

Restart the computer

Download one or both of these Anti Spyware programs
and install them, update them and scan your system
and delete any spywares that may be found. If you have a
working Anti Virus program, then update it and scan with it,
otherwise use one of these free online virus scanners:

Ad-aware 6.0 build 181
http://download.com.com/3000-2144-10214379.html?tag=list

Spybot - Search & Destroy 1.2
http://download.com.com/3000-2144-10194058.html?tag=list

Panda ActiveScan
http://www.pandasoftware.com/activescan/

TrendMicro Houscall Anti Virus Scan
http://housecall.trendmicro.com/

====================================================

Possible damaged winsock key damage:

Please read this whole reply before proceeding with any suggestions.

Issue:

on this XP Home/Pro computer,
when trying to browse the Internet,
you are getting "Page Cannot Be Displayed" and
when you go to the command prompt window
and run ipconfig /all, you get an APIPA in the form of 169.254.x.x.
Then immediately run ipconfig /renew, you get this error message:

"An operation was attempted on something that is not a socket"

If so, you have a damaged winsock2 key in the registry.

You should check System Information (winmsd)
START > RUN - type in winmsd and click OK
Expand Components / Network / click on Protocol -
if the section headings item of "Name" have a value
starting with anything other than MSAFD or RSVP
then that is probably what is causing the problem.

Examples:

MSAFD Tcpip [TCP/IP]
MSAFD Tcpip [UDP/IP]
RSVP UDP Service Provider
RSVP TCP Service Provider
MSAFD NetBIOS [\Device\NetBT_Tcpip...
and so on

It may be a third-party firewall or a Spyware or a Virus.
("New.Net" is a common spyware for example)
Make sure that MSCONFIG is in Normal Startup
and then see if uninstalling the third party firewall
(best done from its own uninstall program if available)
or the Spyware from Add Remove Programs will
resolve the issue. If it's a virus, then only an Anti Virus Program
will be able to deal with that.

You may want to try downloading either Ad-Aware 6 or Spybot
to another computer and then installing one of them on the infected XP
Home/Pro
computer and try to wipe out Spyware and see if that resolves the issue.

Ad-aware 6.0 build 181
http://download.com.com/3000-2144-10214379.html?tag=list

Spybot - Search & Destroy 1.2
http://download.com.com/3000-2144-10194058.html?tag=list


If none of that works or is possible, you could try this method
for replacing the winsock and winsock2 registry keys:

Uninstall any third-party proxy software or firewall programs before
proceeding.

Step 1: Delete registry keys

A)Open Regedit from the Run line
B)Go to both of the following keys, EXPORT each of them, and then delete
them:
(To export a key, you right click on it and
choose "export" - you can choose
 
N

no1

I borrowed these URL's from a post by Kent England:

http://www.symantec.com/avcenter/venc/data/trojan.qhosts.html
http://vil.nai.com/vil/content/v_100719.htm

Check them out. There is a trojan that affects only Internet Explorer
and redirects home pages like Google, Alta Vista, etc. to another URL.

Have you tried changing your default home page to something else in
the options section of IE? Also, when you get the error message saying
the page cannot be displayed, have you tried manually typing in a URL
you know works into the IE address bar?

If either of these works, then IE is OK and just being redirected. I
suggest downloading another browser when you get on line, if for
nothing else as a backup. I use Opera, which is free and Mozilla is
free too (Netscape is based on Mozilla). I find each browser has it's
strong points and weak points. I don't use IE because it's a bit of a
monster and a favourite target of exploiters. However, it does have
Active-X, and I use it when the other browsers don't see a site too
well. Even at that, I run it through a proxy to bring it under
control.
 
P

Phoenix

Thought I'd do an update so anyone else who might
experience my problem can know the bad news!
I'm pretty sure there is no virus. My homepage is not
being changed by any mal/spyware, it just doesn't
display. I've tried typing in addresses that I know are
valid and still get 'page cannot be displayed'.
I tried to do a repair on my broadband connection though
it shows as being active in the system tray and get
failure messages when trying to renew IP.
So I tried removing and recreating the winsock and
winsock2 keys and still no joy.
So, I'm throwing in the towel, formatting my drive and
starting again! Something is way screwy and my registry
is probably shot to pieces anyway with all the Spyware
that has visited it so a clean sheet may be the best
thing for it.
Thank you for all the ideas people have suggested I try!
 
B

brian

Before doing anything drastic to a file search for HOSTS
and rename the HOSTS file (NOT the SAM Files) to
HOSTS.OLD. Then restart and try to connect to any
website.

Brian
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top