This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

An Useen Power Blocking My Web Pages.....

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello To All,

I'm new to this forum and I'm in most desperate need of help as well. Since Dec.23 I have not been able to view any web pages using my DSL broadband service. My only way to get online has been thru dial up. I've contacted my ISP provider and they couldn't help, and the manufacturer was clueless too. I've also taken my PC to two different PC repair shops and they may find a trojan or some adware and tell me I'm good to go, but once I get my PC home and make all my connections, it's still a no go. I've ran the network diagonostics feature and it keeps telling me that the internet explorer web configuration proxy isn't configured. No matter how hard I try or what settings I use, nothing changes. My PC shows that the LAN connection is on and the two PC's at the taskbar show that I have an established internet connection, but something's blocking me from viewing the pages. I'm trying to narrow it down to one of two possible problems, either I'm having some type of weird DNS problem or there's an intruder on my system who moves in shadows. Hopefully you guys can peep my log file and tell me if I have an unwanted guest.


Logfile of HijackThis v1.99.0
Scan saved at 10:01:20 AM, on 1/29/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\SECRETMAKER\secretmaker.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Eggs\stinger.exe
C:\Documents and Settings\Dennis Hunter\Desktop\A Jacker's Nightmare\hijackthis199.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.sprint.earthlink.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.sprint.earthlink.net
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: IeHelper Class - {A491D208-B353-490F-B81A-A8A3DC97042D} - C:\WINDOWS\System32\smiehlp.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://us8l.hpwis.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{B5312669-D437-49AB-B4D9-8DFC94901949}: NameServer = 207.69.188.187 207.69.188.186
O17 - HKLM\System\CCS\Services\Tcpip\..\{D3751531-1F7F-4AD1-AAD1-77571093AFE4}: NameServer = 192.168.1.1
O23 - Service: Ati HotKey Poller - Unknown - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: HP Configuration Interface Service - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
Hi Dennis, Welcome to TomCoyote forum. I am not sure I can help you with this one, but we will give it a go.

First, some questions. This does not identify with search engines and I doubt very much it is McAfee's stinger removal tool. If you do not know what it is, we will remove it. If you do, please tell be for future reference, first time I have seen this article in thousands of logs.
C:\Eggs\stinger.exe

Next you have two Name Server Numbers in the 017 area of the log, to be sure nothing is bad here, this is what I find. Let me know about this also:

[removed] = Earthlink

192.168.1.1 = These are usually valid, what can you tell me, won't hurt to check.
Possible this is for Dialup?


You have these programs onboard and while the first one is new, I know the second may block removal attempts, you should turn them and other programs that block changes when you run HJT.
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe

As a final note, Your name for the HJT folder is fine, just as long as you store nothing in it but Logs, backups and the HJT.exe. Thanks.
A Jacker's Nightmare\hijackthis199.exe

O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
This is a bad Norton BHO, see this: http://computercops.biz/clsid-516.html
something might need to be reinstalled with the missing file, I will remove it.

O14 - IERESET.INF: START_PAGE_URL=http://us8l.hpwis.com
Not needed, something HP stuck on you to keep you watching their adds.

I fear none of this is your problem, but unless you know otherwise, I will remove those items. See if it changes anything, if not I will see if I can point you in the direction of someone who may know more about this issue.

Open Task Manager then the Processes Tab, if this item is running, end process on it:
C:\Eggs\stinger.exe

Scan with HijackThis and check these two items:

O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O14 - IERESET.INF: START_PAGE_URL=http://us8l.hpwis.com

Close all programs but HJT and all browser windows then click on "Fix Checked"

Locate and delete this folder if you don't know what it is: C:\Eggs\>>> folder
Clean Like this: Start, Run type "cleanmgr" without the quotes then ok. Check and remove anything windows locates.

Empty the recycle bin and restart the computer. Post a new log with any comments you have, use the following two links to stay in this thread.
When replying to your topic, please use the
http://forums.tomcoyote.org/style_images/1/t_reply.gif
button NOT the
http://forums.tomcoyote.org/style_images/1/t_new.gif
button.
Thanks…pskelley
TomCoyote forum
Classroom Advanced
If you get help here consider a donation:
http://tomcoyote.com/donate.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI