This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Can't access Google.com, browser redirects to Surch

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Let's try the following please:
  • Please try to access www.google.com between each step to determine if the step fixed the problem.
  • How to reset Internet Protocol (TCP/IP) in Windows XP
    Use the Guided Help please
    http://support.microsoft.com/?id=299357

  • If you download and double click on this small app, it will restore all the default search fuctions for IE.
    http://www.spywareinfo.com/downloads/tools/IEFIX.reg
    Save it to your desktop.
    Right click on the file IEFIX.reg and select Merge.

  • Lets try a different browser. Click the link and download FireFox and give it a try.
    http://www.mozilla.com/firefox/
Please let me know if anything helped.
I tried all three suggestions, reset the TCP/IP stack, reset IE default settings and still couldn't access google.com. I installed Mozilla Firefox and tried to access www.google.com and couldn't get to it either. I double checked on Firefox using the google IP address and could access it then…..
Let's check for Rootkits

STEP 1.
======
GMER
Please create a new subfolder in the Program Files folder called GMER. If you have an older version of GMER installed, you must delete it.
  • Download GMER and extract it to the C:\program files\GMER folder.
  • Run the Gmer.exe program by double-clicking the executable file (gmer.exe) in Windows Explorer.
    You may be prompted to scan immediately if GMER detects rootkit activity.
  • If you are prompted to scan your system click "yes" to begin the scan.
  • If you are not prompted, Click the "Rootkit" tab, then click "Scan".
At the end of the scan, click "Copy" to copy the scan results to the clipboard. Then paste the results in a notepad file and also paste them back in a reply here.


STEP 2.
======
Combofix
  • Download this file - combofix.exe
  • Double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall


STEP 3.
start > Run > copy and paste in:
sfc /scannow
Click 'OK'
You will need your XP/2000/ME disk. If you don't have it and instead only have a recovery CD, there is a work around. View the following link for a tutorial:

http://www.updatexp.com/scannow-sfc.html

sfc - system file checker, retrieves the correct version of the file from %Systemroot%\System32\Dllcache or the Windows installation source files, and then replaces the incorrect file.

If you want to see what was replaced, right click My Computer > manage, expand event viewer > system.

Please post the GMER log, the ComboFix log and a new hijackthis log.
OK, ran GMER (report attached), ran Combofix (report attached), and system file checker (appears that nothing was changed), and HJT (report attached).

Thanks

GMER 1.0.11.11390 - http://www.gmer.net
Rootkit 2006-12-03 17:21:48
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.11 —-

SSDT 86E15480 ZwAlertResumeThread
SSDT 86E15FD0 ZwAlertThread
SSDT 86A83188 ZwAllocateVirtualMemory
SSDT 86DC0EC8 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS ZwCreateKey
SSDT 86E0EC40 ZwCreateMutant
SSDT 86E4D188 ZwCreateThread
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS ZwDeleteKey
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS ZwDeleteValueKey
SSDT 86E22B88 ZwFreeVirtualMemory
SSDT 86E2FA18 ZwImpersonateAnonymousToken
SSDT 86E14410 ZwImpersonateThread
SSDT 86CF3A98 ZwMapViewOfSection
SSDT 86E0DF28 ZwOpenEvent
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess
SSDT 86E24B60 ZwOpenProcessToken
SSDT 86E1FD08 ZwOpenThreadToken
SSDT 86E27298 ZwResumeThread
SSDT 86E1EA20 ZwSetContextThread
SSDT 86E21298 ZwSetInformationProcess
SSDT 86E1E3D8 ZwSetInformationThread
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS ZwSetValueKey
SSDT 86E0CFD0 ZwSuspendProcess
SSDT 86E16E58 ZwSuspendThread
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess
SSDT 86E1D420 ZwTerminateThread
SSDT 86E227A8 ZwUnmapViewOfSection
SSDT 86D03188 ZwWriteVirtualMemory

—- Files - GMER 1.0.11 —-

ADS …

—- EOF - GMER 1.0.11 —-





Cathleen Brackin - 06-12-03 17:26:28.64 Service Pack 2
ComboFix 06.11.27W - Running from: "C:\Documents and Settings\Cathleen Brackin\Desktop"

((((((((((((((((((((((((((((((( Files Created from 2006-11-03 to 2006-12-03 ))))))))))))))))))))))))))))))))))


2006-12-03 17:05 d——– C:\Program Files\GMER
2006-11-30 20:08 d——– C:\Program Files\Mozilla Firefox
2006-11-30 20:08 d——– C:\Documents and Settings\Cathleen Brackin\Application Data\Mozilla
2006-11-30 19:38 d——– C:\Program Files\ACW
2006-11-25 17:23 d——– C:\WINDOWS\system32\Kaspersky Lab
2006-11-25 17:08 d——– C:\Hoster
2006-11-24 19:42 3,968 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2006-11-24 19:41 d——– C:\Program Files\Grisoft
2006-11-23 22:12 51,072 –a—— C:\WINDOWS\system32\drivers\ikhlayer.sys
2006-11-23 22:12 30,592 –a—— C:\WINDOWS\system32\drivers\ikhfile.sys
2006-11-23 22:11 d——– C:\Program Files\Spyware Doctor
2006-11-23 22:11 d——– C:\Documents and Settings\Cathleen Brackin\Application Data\PC Tools
2006-11-22 21:46 d——– C:\hijackthis[1]
2006-11-22 21:35 d——– C:\WINDOWS\pss
2006-11-22 20:34 2,924 –a—— C:\WINDOWS\system32\tmp.reg
2006-11-22 20:16 d——– C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2006-11-22 19:49 dr-h—– C:\Documents and Settings\Cathleen Brackin\Recent
2006-11-22 19:35 d——– C:\Program Files\CCleaner
2006-11-21 23:22 d——– C:\Program Files\Anonymizer
2006-11-20 21:30 d——– C:\Program Files\Lavasoft
2006-11-20 21:30 d——– C:\Documents and Settings\Cathleen Brackin\Application Data\Lavasoft
2006-11-20 20:55 d——– C:\Program Files\Spybot - Search & Destroy
2006-11-20 20:55 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2006-11-20 20:16 d——– C:\Program Files\Windows Defender
2006-11-20 20:08 44,891 –a—— C:\WINDOWS\system32\CAUnst.exe
2006-11-20 17:19 d——– C:\Program Files\xerox
2006-11-20 15:56 d–h—– C:\WINDOWS\PIF
2006-11-20 15:46 d——– C:\Program Files\Norton Internet Security
2006-11-20 15:45 48,768 –a—— C:\WINDOWS\system32\S32EVNT1.DLL
2006-11-20 15:45 110,952 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2006-11-17 08:36 d——– C:\6b63edb6a9d703c31da6a06e
2006-11-08 16:47 45,985 –a—— C:\WINDOWS\system32\ViscalcUninstaller.exe
2006-11-08 16:46 36,864 –a—— C:\WINDOWS\system32\vismozwm.exe
2006-11-08 12:41 97,455 –a—— C:\WINDOWS\5-a0c18a429b8010fee34ee31d9073371d.exe
2006-11-08 12:41 66,267 –a—— C:\WINDOWS\10-47488c40c3cddfee98fc3b173f6d7beb.exe
2006-11-08 12:41 36,864 –a—— C:\WINDOWS\system32\slimkfce.exe
2006-11-08 12:41 24,576 –a—— C:\WINDOWS\system32\msxml3a.dll
2006-11-08 12:40 356,663 –a—— C:\WINDOWS\12-b101c483c2fe3ac4a2bd5fae3377ef4f.exe
2006-11-08 11:28 365,132 –a—— C:\WINDOWS\7-7c15eb3352bcc3049d7e9e974ad283bf.exe
2006-11-08 11:28 d——– C:\WINDOWS\system32\SearchEnhancer
2006-11-06 16:03 275,576 –a—— C:\WINDOWS\system32\drivers\srtspl.sys
2006-11-06 16:03 245,880 –a—— C:\WINDOWS\system32\drivers\srtsp.sys
2006-11-06 16:03 24,184 –a—— C:\WINDOWS\system32\drivers\srtspx.sys
2006-11-04 14:14 1,245,696 –a—— C:\WINDOWS\system32\msxml4.dll


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-12-03 12:57 ——– d——– C:\Program Files\Common Files\Symantec Shared
2006-11-29 22:40 ——– d——– C:\Documents and Settings\Cathleen Brackin\Application Data\AdobeUM
2006-11-28 19:24 ——– d——– C:\Program Files\Common Files
2006-11-22 19:35 ——– d——– C:\Program Files\Yahoo!
2006-11-21 23:54 ——– d—s—- C:\Documents and Settings\Cathleen Brackin\Application Data\Microsoft
2006-11-20 20:16 ——– d——– C:\Program Files\Common Files\Microsoft Shared
2006-11-20 17:10 ——– d——– C:\Program Files\Windows Media Player
2006-11-20 17:10 ——– d——– C:\Program Files\QuickTime
2006-11-20 17:10 ——– d——– C:\Program Files\PokerStars.NET
2006-11-20 17:09 ——– d——– C:\Program Files\InstallShield Installation Information
2006-11-20 17:09 ——– d——– C:\Program Files\HPQ
2006-11-20 17:09 ——– d——– C:\Program Files\FinePixViewer
2006-11-20 16:25 ——– d——– C:\Program Files\Symantec
2006-11-20 07:43 337 –a—— C:\Documents and Settings\Cathleen Brackin\Application Data\internaldb1942.dat
2006-11-20 07:40 49 –a—— C:\Documents and Settings\Cathleen Brackin\Application Data\internaldb41.dat
2006-11-20 07:39 ——– d——– C:\Program Files\Quicken
2006-11-20 07:29 0 –a—— C:\Documents and Settings\Cathleen Brackin\Application Data\internaldb6500.dat
2006-11-17 22:38 69632 –a—— C:\Documents and Settings\Cathleen Brackin\Application Data\internaldb4827.dat
2006-11-17 22:38 0 –a—— C:\Documents and Settings\Cathleen Brackin\Application Data\internaldb5436.dat
2006-11-17 08:36 ——– d——– C:\Program Files\Internet Explorer
2006-11-16 11:53 0 –a—— C:\Documents and Settings\Cathleen Brackin\Application Data\internaldb2391.dat
2006-11-13 08:22 0 –a—— C:\Documents and Settings\Cathleen Brackin\Application Data\internaldb9169.dat
2006-11-13 08:22 0 –a—— C:\Documents and Settings\Cathleen Brackin\Application Data\internaldb1869.dat
2006-11-08 11:28 9216 –a—— C:\Documents and Settings\Cathleen Brackin\Application Data\internaldb8467.dat
2006-11-08 11:28 23 –a—— C:\Documents and Settings\Cathleen Brackin\Application Data\inifile41.ini
2006-11-08 11:28 151 –a—— C:\Documents and Settings\Cathleen Brackin\Application Data\internaldb9912.dat
2006-11-08 11:28 0 –a—— C:\Documents and Settings\Cathleen Brackin\Application Data\internaldb6334.dat
2006-10-31 22:14 ——– d——– C:\Program Files\SeeAndTalk
2006-10-30 11:03 4 –ah—– C:\WINDOWS\uccspecb.sys
2006-10-19 18:45 ——– d——– C:\Program Files\Canon
2006-10-14 16:10 ——– d——– C:\Program Files\Google
2006-10-13 07:35 142336 –a—— C:\WINDOWS\system32\nwprovau.dll
2006-10-03 19:22 ——– d——– C:\Documents and Settings\Cathleen Brackin\Application Data\HP
2006-09-13 00:01 1084416 –a—— C:\WINDOWS\system32\msxml3.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ATIModeChange"="Ati2mdxx.exe"
"AGRSMMSG"="AGRSMMSG.exe"
"Cpqset"="C:\\Program Files\\HPQ\\Default Settings\\cpqset.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\j2re1.4.2_03\\bin\\jusched.exe"
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"UpdateManager"="\"C:\\Program Files\\Common Files\\Sonic\\Update Manager\\sgtray.exe\" /r"
"SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\""
"DXDllRegExe"="dxdllreg.exe"
"HPHUPD05"="c:\\Program Files\\HP\\{45B6180B-DCAB-4093-8EE8-6164457517F0}\\hphupd05.exe"
"HPHmon05"="C:\\WINDOWS\\system32\\hphmon05.exe"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\hpztsb09.exe"
"REGSHAVE"="C:\\Program Files\\REGSHAVE\\REGSHAVE.EXE /AUTORUN"
"eFax 4.2"="\"C:\\Program Files\\eFax Messenger 4.2\\J2GDllCmd.exe\" /R"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"osCheck"="\"C:\\Program Files\\Norton Internet Security\\osCheck.exe\""
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex]
@=""

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000004

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"



~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

backup-20061125-165250-895
O4 - HKCU\..\Run: [Chckup] C:\WINDOWS\system32\Netverchk.exe
backup-20061125-165250-878
O4 - HKCU\..\Run: [ItalU] C:\WINDOWS\system32\italfds.exe

Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\MP Scheduled Scan.job
C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Cathleen Brackin.job

Completion time: 06-12-03 17:27:35.17
C:\ComboFix.txt … 06-12-03 17:27





Logfile of HijackThis v1.99.1
Scan saved at 10:03:45 PM, on 12/3/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hphmon05.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\eFax Messenger 4.2\J2GDllCmd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\eFax Messenger 4.2\J2GTray.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Palm\HOTSYNC.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\hijackthis[1]\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://64.233.167.99/
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [eFax 4.2] "C:\Program Files\eFax Messenger 4.2\J2GDllCmd.exe" /R
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - Global Startup: eFax 4.2.lnk = C:\Program Files\eFax Messenger 4.2\J2GTray.exe
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q304&bd=pavilion&pf=laptop
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1124151744866
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1157856502777
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/…_1/axofupld.cab
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) - http://hgtv2.view22.com/view22/app/view22rte.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/web_…aploader_v6.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
http://groups.google.com/group/microsoft.p…3ee283cbb822a19

I guess you pointed the problem, there was Norton Symantec, but it had been
"desactivated" manually (and it probably matches with the date the Internet
problems). By manually I mean all services related to Norton Symantec were
stopped and desactivated (not any uninstall option anywhere). I relaunch the
whole set of Norton services but is doesn"t solves the problem. Probably the
winsock's fix broke the "Internet threw norton" connectivity. Now, the
Windows FW is activated (I also asked for the windows FW default parameters).
I finally download and run Norton Removal Tool 1.20.4 and it did the trick !!

==========================
I noticed that you use Norton. I found the above and thought maybe you should try to uninstall Norton.
http://service1.symantec.com/SUPPORT/tsgen…005033108162039

Turn on Windows XP firewall (we do not want to stay with this firewall but want to see if Norton is somehow causing problems).

Try the Google.com and see if you can connect.

Then try the this
======
WinsockXPfix
Download WinsockXPfix
Locate the Winsockxpfix.exe and double click and click Run.
The VB_WinFix Win 1.2 window will appear.
Click Fix

Try the Google.com again

Now reinstall your Norton: Your Norton provided protection so we do not want to forget about that.

You have some files that I would like to have checked out.

Please download the Suspicious File Packer → http://www.safer-networking.org/files/sfp.zip

Unzip it to the desktop and run it.
Paste the following list of filepaths into the Suspicious File Packer window:
C:\WINDOWS\system32\vismozwm.exe
C:\WINDOWS\5-a0c18a429b8010fee34ee31d9073371d.exe
C:\WINDOWS\10-47488c40c3cddfee98fc3b173f6d7beb.exe
C:\WINDOWS\system32\slimkfce.exe
C:\WINDOWS\12-b101c483c2fe3ac4a2bd5fae3377ef4f.exe
C:\WINDOWS\7-7c15eb3352bcc3049d7e9e974ad283bf.exe

Allow SFP to pack the files. This will generate a CAB archive on your desktop.
Please submit it to this site → http://www.bleepingcomputer.com/submit-malware.php?channel=4

Please include a link to this topic in the message.
http://forums.tomcoyote.org/index.php?show…mp;#entry335885

I will be watching for your response.
Thanks, I removed Norton and still couldn't access using www.google.com, I ran winsockxpfix and still couldn't access google. I sent the cab file to the site you listed.
I am afraid I am stumped on this one. Is it only www.google.com that times out? Does it happen on any other website? Do you have more than one computer? Does it happen on others? Who is your Internet Service Provider?
Yes, www.google.com is the only site that I'm having problems with. I can't use my other laptop right now to check the if I can get to www.google.com from that machine. My ISP is Cavtel (Cavalier telephone) DSL. Thanks
I am sorry that I have not been able to resolve your problem. Have you tried calling your ISP's technical support and ask about the google access problem? Also I would be curious about if you can access google from another computer.
This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Also follow the recommendations in Tony Klein's article
So how did I get infected in the first place?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI