dnserror

  1. #1
    stripeyzebra is offline Newbie

    dnserror

    Hey,

    I cannot use Internet Explorer at ALL!! It says "page cannot be displayed" and displays C:WINDOWS\System32/shdoclc.dll/dnserror.html at the bottom of the screen. Its driving me crazy

    Here is my log:

    Logfile of HijackThis v1.99.0
    Scan saved at 6:43:41 PM, on 2/15/2005
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\SVPHOST.exe
    C:\WINDOWS\System32\rspcs.exe
    C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
    C:\WINDOWS\Mixer.exe
    C:\WINDOWS\System32\msmsgv.exe
    C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
    C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\WINDOWS\System32\wvsvc.exe
    C:\WINDOWS\System32\msams.exe
    C:\WINDOWS\System32\npmsys.exe
    C:\WINDOWS\System32\navupdaterx.exe
    C:\Program Files\Windows Media Player\wmplayer.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\hijackthis\hijackthis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.co.uk
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.co.uk
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.co.uk
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R3 - Default URLSearchHook is missing
    O4 - HKLM\..\Run: [RSPC Driver D] rspcs.exe
    O4 - HKLM\..\Run: [Windows Media Player] msams.exe
    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
    O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
    O4 - HKLM\..\Run: [NT Logging Service] syslog32.exe
    O4 - HKLM\..\Run: [Norton Personal Firewall] npmsys.exe
    O4 - HKLM\..\Run: [NAV Auto Updates] navupdaterx.exe
    O4 - HKLM\..\Run: [Starting up] wvsvc.exe
    O4 - HKLM\..\Run: [Windows32 Messenger Service] msmsgv.exe
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
    O4 - HKLM\..\Run: [Windows TM] SVPHOST.exe
    O4 - HKLM\..\RunServices: [RSPC Driver D] rspcs.exe
    O4 - HKLM\..\RunServices: [Windows Media Player] msams.exe
    O4 - HKLM\..\RunServices: [Windows TM] SVPHOST.exe
    O4 - HKLM\..\RunServices: [Norton Personal Firewall] npmsys.exe
    O4 - HKLM\..\RunServices: [NAV Auto Updates] navupdaterx.exe
    O4 - HKLM\..\RunServices: [Starting up] wvsvc.exe
    O4 - HKLM\..\RunServices: [Windows32 Messenger Service] msmsgv.exe
    O4 - HKLM\..\RunOnce: [Windows TM] SVPHOST.exe
    O4 - HKCU\..\Run: [Windows Media Player] msams.exe
    O4 - HKCU\..\Run: [RSPC Driver D] rspcs.exe
    O4 - HKCU\..\Run: [Norton Personal Firewall] npmsys.exe
    O4 - HKCU\..\Run: [NAV Auto Updates] navupdaterx.exe
    O4 - HKCU\..\Run: [Starting up] wvsvc.exe
    O4 - HKCU\..\Run: [Windows32 Messenger Service] msmsgv.exe
    O4 - HKCU\..\Run: [Windows TM] SVPHOST.exe
    O4 - HKCU\..\RunOnce: [Windows TM] SVPHOST.exe
    O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1105450888959
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/...sh/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{232B0196-8FA2-498E-8248-E8E63A053C1B}: NameServer = 80.225.250.178 80.225.250.186
    O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

    Any help you can give me would be very much appreciated.
    Thank you for your time!


  2. #2
    owen is offline D-A-L Team Member (UK)
    Close all browser windows, restart Hijack This and put a checkmark next to the following entries:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R3 - Default URLSearchHook is missing
    O4 - HKLM\..\Run: [RSPC Driver D] rspcs.exe
    O4 - HKLM\..\Run: [Windows Media Player] msams.exe
    O4 - HKLM\..\Run: [NT Logging Service] syslog32.exe
    O4 - HKLM\..\Run: [Norton Personal Firewall] npmsys.exe
    O4 - HKLM\..\Run: [NAV Auto Updates] navupdaterx.exe
    O4 - HKLM\..\Run: [Starting up] wvsvc.exe
    O4 - HKLM\..\Run: [Windows32 Messenger Service] msmsgv.exe
    O4 - HKLM\..\Run: [Windows TM] SVPHOST.exe
    O4 - HKLM\..\RunServices: [RSPC Driver D] rspcs.exe
    O4 - HKLM\..\RunServices: [Windows Media Player] msams.exe
    O4 - HKLM\..\RunServices: [Windows TM] SVPHOST.exe
    O4 - HKLM\..\RunServices: [Norton Personal Firewall] npmsys.exe
    O4 - HKLM\..\RunServices: [NAV Auto Updates] navupdaterx.exe
    O4 - HKLM\..\RunServices: [Starting up] wvsvc.exe
    O4 - HKLM\..\RunServices: [Windows32 Messenger Service] msmsgv.exe
    O4 - HKLM\..\RunOnce: [Windows TM] SVPHOST.exe
    O4 - HKCU\..\Run: [Windows Media Player] msams.exe
    O4 - HKCU\..\Run: [RSPC Driver D] rspcs.exe
    O4 - HKCU\..\Run: [Norton Personal Firewall] npmsys.exe
    O4 - HKCU\..\Run: [NAV Auto Updates] navupdaterx.exe
    O4 - HKCU\..\Run: [Starting up] wvsvc.exe
    O4 - HKCU\..\Run: [Windows32 Messenger Service] msmsgv.exe
    O4 - HKCU\..\Run: [Windows TM] SVPHOST.exe
    O4 - HKCU\..\RunOnce: [Windows TM] SVPHOST.exe

    Click Fix Checked

    Then boot into Safe Mode and ensure that you are showing Hidden Files and Folders.

    Delete the following files and folders:
    C:\WINDOWS\System32\rspcs.exe
    C:\WINDOWS\System32\msams.exe
    C:\WINDOWS\System32\npmsys.exe
    C:\WINDOWS\System32\navupdaterx.exe
    C:\WINDOWS\System32\wvsvc.exe
    C:\WINDOWS\System32\SVPHOST.exe

    Reboot and post a fresh log

  3. #3
    stripeyzebra is offline Newbie
    Thank you so much Owen you are a legend!!!

    My new log:

    Logfile of HijackThis v1.99.0
    Scan saved at 11:09:18 PM, on 2/15/2005
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
    C:\WINDOWS\Mixer.exe
    C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
    C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\hijackthis\hijackthis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.co.uk
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.co.uk
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.co.uk
    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
    O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
    O4 - HKLM\..\Run: [Starting up] wvsvc.exe
    O4 - HKLM\..\RunServices: [Starting up] wvsvc.exe
    O4 - HKCU\..\Run: [Starting up] wvsvc.exe
    O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1105450888959
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/...sh/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{232B0196-8FA2-498E-8248-E8E63A053C1B}: NameServer = 80.225.250.178 80.225.250.186
    O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

  4. #4
    owen is offline D-A-L Team Member (UK)
    Close all browser windows, restart Hijack This and put a checkmark next to the following entries:

    O4 - HKLM\..\Run: [Starting up] wvsvc.exe
    O4 - HKLM\..\RunServices: [Starting up] wvsvc.exe
    O4 - HKCU\..\Run: [Starting up] wvsvc.exe

    Click Fix Checked

    Reboot and post a fresh log

  5. #5
    stripeyzebra is offline Newbie
    hey owen

    i placed a check next to those items however it seems that they have reinstalled themselves.. and my browser is still getting redirected to the same dnserror.

    Here is my log again:
    Logfile of HijackThis v1.99.0
    Scan saved at 3:43:22 PM, on 2/17/2005
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
    C:\WINDOWS\Mixer.exe
    C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
    C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
    C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Windows Media Player\wmplayer.exe
    C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
    C:\PROGRA~1\Altnet\DOWNLO~1\ASM.exe
    C:\Program Files\hijackthis\hijackthis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.co.uk
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.co.uk
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.co.uk
    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
    O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
    O4 - HKLM\..\Run: [Starting up] wvsvc.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
    O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
    O4 - HKLM\..\RunServices: [Starting up] wvsvc.exe
    O4 - HKLM\..\RunOnce: [MicrosoftAntiSpywareCleaner] C:\Program Files\Microsoft AntiSpyware\gcASCleaner.exe
    O4 - HKCU\..\Run: [Starting up] wvsvc.exe
    O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1105450888959
    O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/v...fo/webscan.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/...sh/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{232B0196-8FA2-498E-8248-E8E63A053C1B}: NameServer = 80.225.250.178 80.225.250.186
    O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

    thanks again!

  6. #6
    owen is offline D-A-L Team Member (UK)
    Save 20% on AVG Internet Security 2012 Suite!
    Update your version of Hijack This from my signature please.

    Then get to http://windowsupdate.microsoft.com and download and install all Critical Updates and Service Packs. This is crucial or else anything we fix could potentially return. Also check back after you have install Service Pack 2 to check for anymore updates.

+ Reply to Thread