PDA

View Full Version : Ie6



korky45
03-28-2004, 12:45 PM
I am having a problem with Internet Explored 6. While downloading yesterday
I was unable to load any web pages although my broadband connection was ok and the download continued until completion.

This happend the day before as well, but I was able to correct things by disconnecting and re-booting. Now however, I cannot get IE to work at all, it installs but will not load any web pages.

I get a an error message saying //C:\windows\system\shdoclc.dll/dns.error.

As a temporary solution to have access to the internet I have loaded netscape 7 - which appears to be working fine. I would like to know what the problem is with IE though.

I have tried uninstalling and reinstalling IE without any success. Im not even sure if it uninstalled properly as explorer was still there after the uninstall.

Can anyone help please? :)

Quantax
03-28-2004, 12:56 PM
Did you do an I.E. repair? In Win 98 this entails going from Start to Run, type in msinfo32 and click Tools and then click Internet Explorer repair tool. There's also the program Ieradicator which involves a radical removal of I.E. as well. If you chose this, then you'd need to re-install I.E.

Mark Miller
03-28-2004, 01:09 PM
Which windows are you running? In XP there is no uninstall of ie6 but a work around in their knowledge base.
Mark
http://support.microsoft.com/search/default.aspx?InCC_hdn=True&Catalog=LCID%3D1033%26CDID%3DEN-US-KB%26PRODLISTSRC%3DON&Product=&KeywordType=ALL&Titles=false&numDays=&maxResults=25&Queryl=ie6&Query=ie6&QuerySource=gsfxSearch_Query&srchExtraQry=

korky45
03-28-2004, 01:20 PM
Thanks Quantax - msinfo32 has done the trick!

Netscape looks faster though, I may decides to keep after trials. Lots of adds came with the browser they will have to go 1st if I am to keep.

Im am running win98se, Mark, but I think when I uninstalled IE6 it was an update, and I am left with original version IE5,

mjc
03-28-2004, 03:08 PM
What you have done may only be a temporary solution, your symptoms sure sound like a malware infestation...

Please post a HijackThis (http://tomcoyote.com/hjt/) log....

PrntRhd
03-28-2004, 03:14 PM
I have been searching on this one, mjc is likely correct (as usual),
it may be a problem in Winsock2.dll created by something.

Paul Komski
03-28-2004, 04:29 PM
As mjc says - check for malware.

... but also clear your cache of temporary internet files if you havent already done so.

korky45
03-28-2004, 06:20 PM
OK I've posted Hijackthis log.
Its mainly meaningless to me - hope you can help?



Logfile of HijackThis v1.97.7
Scan saved at 12:17:11 AM, on 3/29/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
C:\PROGRAM FILES\MOTHERBOARD MONITOR 5\MBM5.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\PROGRAM FILES\FREERAM\FREERAM.EXE
C:\PROGRAM FILES\SAGEM\SAGEM F@ST 800-840\DSLMON.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\LEXPPS.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\windows\googletoolbar1.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\googletoolbar1.dll
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\GRISOFT\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [MBM 5] "C:\PROGRAM FILES\MOTHERBOARD MONITOR 5\MBM5.EXE"
O4 - HKLM\..\Run: [autoclk] autoclk.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKCU\..\Run: [BySoft FreeRAM] C:\PROGRAM FILES\FREERAM\FREERAM.EXE
O4 - Startup: EPSON Background Monitor.lnk = C:\ESM2\Stms.exe
O4 - Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - User Startup: EPSON Background Monitor.lnk = C:\ESM2\Stms.exe
O4 - User Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O8 - Extra context menu item: Open Frame in &New Window - C:\WINDOWS\WEB\frm2new.htm
O8 - Extra context menu item: &Highlight - C:\WINDOWS\WEB\highlight.htm
O8 - Extra context menu item: &Web Search - C:\WINDOWS\WEB\selsearch.htm
O8 - Extra context menu item: &Links List - C:\WINDOWS\WEB\urllist.htm
O8 - Extra context menu item: Zoom &In - C:\WINDOWS\WEB\zoomin.htm
O8 - Extra context menu item: Zoom O&ut - C:\WINDOWS\WEB\zoomout.htm
O8 - Extra context menu item: I&mages List - C:\WINDOWS\Web\imglist.htm
O8 - Extra context menu item: Spellin&g - C:\WINDOWS\web\Spell_It.htm
O8 - Extra context menu item: &Google Search - res://C:\WINDOWS\GOOGLETOOLBAR1.DLL/cmsearch.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\WINDOWS\GOOGLETOOLBAR1.DLL/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\WINDOWS\GOOGLETOOLBAR1.DLL/cmsimilar.html
O8 - Extra context menu item: Backward &Links - res://C:\WINDOWS\GOOGLETOOLBAR1.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate into English - res://C:\WINDOWS\GOOGLETOOLBAR1.DLL/cmtrans.html
O9 - Extra button: Wallpaper (HKLM)
O9 - Extra 'Tools' menuitem: &Toolbar Wallpaper (HKLM)
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: TakeGames (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O12 - Plugin for .bcf: C:\PROGRA~1\INTERN~1\Plugins\NPBelv32.dll
O12 - Plugin for .PDF: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {6FB9FE59-7D3B-483D-9909-C870BE5AFA1F} (DiskHealth Class) - http://www.pcpitstop.com/pcpitstop/diskhealth.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?38005.4550810185
O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - http://dload.ipbill.com/del/loader.cab
O16 - DPF: {AE9DCB17-F804-11D2-A44A-0020182C1446} (IntraLaunch.MainControl) - file://E:\SuperCD\IntraLaunch.CAB
O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - http://www.pcpitstop.com/mhLbl.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78D} (DoomCln Object) - http://www.microsoft.com/security/controls/DoomCln.CAB
O16 - DPF: {88C51E90-8E9C-4C96-8A45-574D88B63FAF} (Matrix Class) - http://acceso.masminutos.com/laaplicacion.cab

Thanks:)

mjc
03-28-2004, 08:50 PM
I don't see anything particularly nasty, but i do see one item that could cause all sorts of problems...ZoneAlarm.

If the config file becomes corrupted, net access becomes spotty at best.

So, one of the recommended fixes is to delete the current config and startover, reconfiguring it.

Also there are a few things that you could do without. Check the box next to these items 9close all Windows, browser and otherwise, except HJT) and then click on the fix button....



O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - http://dload.ipbill.com/del/loader.cab
O16 - DPF: {AE9DCB17-F804-11D2-A44A-0020182C1446} (IntraLaunch.MainControl) - file://E:\SuperCD\IntraLaunch.CAB
O16 - DPF: {88C51E90-8E9C-4C96-8A45-574D88B63FAF} (Matrix Class) - http://acceso.masminutos.com/laaplicacion.cab

Also, you have one item that I can't find much info on, most of my resources indicate it is an autostart item, but have no info.

O4 - HKLM\..\Run: [autoclk] autoclk.exe

Could you please right click on it and select Properties and provide any info you find?

Also, would you please send it to here (submissions@mjc1.com) (please include a link to your thread in your email)

korky45
03-29-2004, 04:31 AM
Thanks mjc, I've done the fixes you recommended, but the only reference I can find to autoclk.exe is in the registry. I cannot find it anywhere else on the PC.

I've also searched the web for info on this entry, and it seems to be associated with adware although no one gives a real definition.

Can I not just fix it and see what happens?

Thanks:)

mjc
03-29-2004, 02:52 PM
I would really love to get my hands on that critter......and yes I know that we don't know what it is, we haven't been able to get a sample of it to pin down what it is related to.

But, since HJT shows the path it should be there...do you have Explorer set to show all files, including hidden and OS files?

If after making sure that all files are showing it still can't be found , then yes, go ahead and fix it.......

korky45
03-30-2004, 05:14 AM
Hijackthis has not removed "autoclk" from the registry. I assume I can go in and manually delete the two entries, but I will spend a bit more time searching Explorer in the hope of finding the "critter".

I have set Exporer to show all files, View/FolderOptions/View/Files/Show all files.

I think that's all I need to do - if there is any advice on how to best proceed in the hunt for the critter it would be welcome!

thanks :)

korky45
03-30-2004, 06:34 AM
Should have added this before - don't know it it helps?

REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\Doc Find Spec MRU]
"a"=""
"MRUList"="bacjighfed"
"b"="autoclk"
"c"="doc find spec MRU"
"d"="GTA"
"e"="crazy taxi3"
"f"="takeagame"
"g"="hijackthis"
"h"="autoclk.exe"
"i"="run"
"j"="hklm"

mjc
03-30-2004, 03:52 PM
That key is just a list of the Most Recently [b}U[/b]sed items, in your Search....those are the things you last searched for.

korky45
03-30-2004, 04:31 PM
OK, thanks mjc, its gone then. Highjackthis no longer lists autoclk.

Thanks for the help its been great.:)