|
|
Phil Tozer
Unregistered
|
|
Hello there
For the last couple of days i have started to encounter a rather annoying problem.
On web sites such as statravel, traifinders or even HSBC the mail web site opens fine but i click on a link such as "find this flight" or "go to account page" a new window opens but apparently it cannot find server. Here is some of what it says:
" The page cannot be displayed The page you are looking for is currently unavailable. The Web site might be experiencing technical difficulties, or you may need to adjust your browser settings. "
Is it something to do with my javascript maybe??
Any help would be great
Phil Tozer
--------------------------------------------------------------------------------
|
|
Phil Tozer
Unregistered
|
|
me again. On one of the pages that wont open i clicked on properties and this is what was on there
"res://C:\WINDOWS\System32\shdoclc.dll/dnserror.htm#https://www.ebank.hsbc.co.uk"
dunno if this helps?
|
putasolutions
regular
Reg'd: Tue
Posts: 12155
Loc: Infinity and beyond
|
|
Try this
Open Internet Explorer Go to Tools | Internet options | Advanced Tab In the Browsing section, Uncheck Enable 3rd party browser extensions Click Apply Restart your computer
Of all the Things I've lost, I miss my mind the most
|
Phil Tozer
Unregistered
|
|
Iain,
Thanks again for your help. Unfortunately it seems to of made no difference as the page still cannot be displayed
I havent made any changes that i know off in the last couple of days since this has started happening. Any more ideas?
Phil Tozer
|
putasolutions
regular
Reg'd: Tue
Posts: 12155
Loc: Infinity and beyond
|
|
Go to this site, and download 'Hijack This!'.
Unzip it, launch Hijack This, then press Scan, and press Save Log
This will generate a text file that will list all running processes, all applications that are loaded automatically when you start Windows, and more.
open that file Go to Edit | Select all Now click Edit | copy to copy it Come back to web user, Right Click and paste its contents here
Of all the Things I've lost, I miss my mind the most
|
Phil Tozer
Unregistered
|
|
here it is Iain
Logfile of HijackThis v1.94.0 Scan saved at 13:34:06, on 19/07/2003 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar=http://www.iesearch.freeserve.com/iesearch/default.htm R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL=http://www.freeserve.com/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\System32\blank.htm R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=%SystemRoot%\system32\blank.htm O2 - BHO: BabeIE - {00000000-0000-0000-0000-000000000000} - C:\PROGRA~1\COMMON~2\Toolbar\cnbabe.dll O2 - BHO: (no name) - {00000EF1-34E3-4633-87C6-1AA7A44296DA} - C:\WINDOWS\System32\mpz300.dll O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet4_88.dll O3 - Toolbar: Teoma Bar - {4194307F-65BB-454A-81D4-9E8A9D7CBAEA} - C:\WINDOWS\System32\teomabAB.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: &SearchBar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [CookieWall] C:\Program Files\AnalogX\CookieWall\cookie.exe O4 - HKLM\..\Run: [winnet] C:\PROGRA~1\COMMON~2\Toolbar\winnet.exe O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup O8 - Extra context menu item: Add A Page Note - C:\Program Files\CommonName\Toolbar\createnote.htm O8 - Extra context menu item: Bookmark This Page - C:\Program Files\CommonName\Toolbar\createbookmark.htm O8 - Extra context menu item: Dictionary Search - javascript:external.menuArguments.location.href="javascript:TeomaBarcommand='cmd-search-selection-word'" O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Email This Link - C:\Program Files\CommonName\Toolbar\emaillink.htm O8 - Extra context menu item: Search using CommonName - C:\Program Files\CommonName\Toolbar\navigate.htm O8 - Extra context menu item: Teoma Search - javascript:external.menuArguments.location.href="javascript:TeomaBarcommand='cmd-search-selection'" O9 - Extra button: Related (HKLM) O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM) O9 - Extra button: Real.com (HKLM) O9 - Extra button: Yahoo! Messenger (HKLM) O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM) O9 - Extra button: Messenger (HKLM) O9 - Extra 'Tools' menuitem: Messenger (HKLM) O10 - Hijacked Internet access by New.Net O10 - Hijacked Internet access by New.Net O10 - Hijacked Internet access by New.Net O10 - Hijacked Internet access by New.Net O10 - Hijacked Internet access by New.Net O11 - Options group: [CommonName] CommonName O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.com/ O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe O16 - DPF: {470A6E01-15A3-49B3-B8B9-8EDF4AC1A480} (Teoma Installer Control) - http://sp.ask.com/docs/teoma/toolbar/download/teomab-inst.cab O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - http://dload.ipbill.com/del/loader.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Phil
|
putasolutions
regular
Reg'd: Tue
Posts: 12155
Loc: Infinity and beyond
|
|
You have been hijacked by new.net
Go to Start | Control Panel Add/Remove Programs Find New.net and click Remove
Rerun hijack this and repost your logfile. Sorry if this seems long winded, but this spyware rubbish does cause all sorts of problems
Of all the Things I've lost, I miss my mind the most
|
Phil Tozer
Unregistered
|
|
I removed the program as requested and here is my log file
Logfile of HijackThis v1.94.0 Scan saved at 13:54:59, on 19/07/2003 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar=http://www.iesearch.freeserve.com/iesearch/default.htm R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL=http://www.freeserve.com/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\System32\blank.htm R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=%SystemRoot%\system32\blank.htm O2 - BHO: BabeIE - {00000000-0000-0000-0000-000000000000} - C:\PROGRA~1\COMMON~2\Toolbar\cnbabe.dll O2 - BHO: (no name) - {00000EF1-34E3-4633-87C6-1AA7A44296DA} - C:\WINDOWS\System32\mpz300.dll O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O3 - Toolbar: Teoma Bar - {4194307F-65BB-454A-81D4-9E8A9D7CBAEA} - C:\WINDOWS\System32\teomabAB.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: &SearchBar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [CookieWall] C:\Program Files\AnalogX\CookieWall\cookie.exe O4 - HKLM\..\Run: [winnet] C:\PROGRA~1\COMMON~2\Toolbar\winnet.exe O8 - Extra context menu item: Add A Page Note - C:\Program Files\CommonName\Toolbar\createnote.htm O8 - Extra context menu item: Bookmark This Page - C:\Program Files\CommonName\Toolbar\createbookmark.htm O8 - Extra context menu item: Dictionary Search - javascript:external.menuArguments.location.href="javascript:TeomaBarcommand='cmd-search-selection-word'" O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Email This Link - C:\Program Files\CommonName\Toolbar\emaillink.htm O8 - Extra context menu item: Search using CommonName - C:\Program Files\CommonName\Toolbar\navigate.htm O8 - Extra context menu item: Teoma Search - javascript:external.menuArguments.location.href="javascript:TeomaBarcommand='cmd-search-selection'" O9 - Extra button: Related (HKLM) O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM) O9 - Extra button: Real.com (HKLM) O9 - Extra button: Yahoo! Messenger (HKLM) O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM) O9 - Extra button: Messenger (HKLM) O9 - Extra 'Tools' menuitem: Messenger (HKLM) O11 - Options group: [CommonName] CommonName O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.com/ O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe O16 - DPF: {470A6E01-15A3-49B3-B8B9-8EDF4AC1A480} (Teoma Installer Control) - http://sp.ask.com/docs/teoma/toolbar/download/teomab-inst.cab O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - http://dload.ipbill.com/del/loader.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
|
putasolutions
regular
Reg'd: Tue
Posts: 12155
Loc: Infinity and beyond
|
|
Ok Now we may be winning
Re run Hijack This and check the following :
O2 - BHO: BabeIE - {00000000-0000-0000-0000-000000000000} - C:\PROGRA~1\COMMON~2\Toolbar\cnbabe.dll O2 - BHO: (no name) - {00000EF1-34E3-4633-87C6-1AA7A44296DA} - C:\WINDOWS\System32\mpz300.dll O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL O3 - Toolbar: Teoma Bar - {4194307F-65BB-454A-81D4-9E8A9D7CBAEA} - C:\WINDOWS\System32\teomabAB.dll O3 - Toolbar: &SearchBar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [winnet] C:\PROGRA~1\COMMON~2\Toolbar\winnet.exe O8 - Extra context menu item: Add A Page Note - C:\Program Files\CommonName\Toolbar\createnote.htm O8 - Extra context menu item: Bookmark This Page - C:\Program Files\CommonName\Toolbar\createbookmark.htm O8 - Extra context menu item: Dictionary Search - javascript:external.menuArguments.location.href="javascript:TeomaBarcommand='cmd-search-selection-word'" O8 - Extra context menu item: Email This Link - C:\Program Files\CommonName\Toolbar\emaillink.htm O8 - Extra context menu item: Search using CommonName - C:\Program Files\CommonName\Toolbar\navigate.htm O8 - Extra context menu item: Teoma Search - javascript:external.menuArguments.location.href="javascript:TeomaBarcommand='cmd-search-selection'" O11 - Options group: [CommonName] CommonName 016 - DPF: {470A6E01-15A3-49B3-B8B9-8EDF4AC1A480} (Teoma Installer Control) - http://sp.ask.com/docs/teoma/toolbar/download/teomab-inst.cab O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - http://dload.ipbill.com/del/loader.cab
Click Fix Checked Reboot your computer
Now Download Spybot if you haven't already done so
Now press Settings | Settings again. Go to the Webupdate section, and check Display also available beta versions.
Now press Online, and search for, put a check mark at, and install all updates.
Next, close all Internet Explorer windows, hit Check for Problems, and have SpyBot remove all it finds. That should remove most of your spy/adware that is left .
Go to C:\Program Files using Windows Explorer If there is a New.net file, right Click it and click Delete Almost there, reboot your computer and see if you can log onto HSBC
Of all the Things I've lost, I miss my mind the most
|
Phil Tozer
Unregistered
|
|
Iain , i checked the relevant boxes on hijack this. But after starting spybot i have no settings option?
Phil
|
putasolutions
regular
Reg'd: Tue
Posts: 12155
Loc: Infinity and beyond
|
|
You pressed the Fix Checked, yes?
Sorry, you should be in Advanced mode for Spybot
Of all the Things I've lost, I miss my mind the most
|
Phil Tozer
Unregistered
|
|
yes i did fixed check
Sorry but there is no advanced option on my spybot either (version 1.2) the only options along the top are "File" - which only iuninstall and check for problems. Also along the top is language selcet and help.
Along the side of spybot i have the following tabs
Search & Destroy Recoivery Immunize Update # Donations
Phil
|
Phil Tozer
Unregistered
|
|
i have run spybot check for problems trwice now but both times about half way through when scanning "C2 Lop" it crashes
|
putasolutions
regular
Reg'd: Tue
Posts: 12155
Loc: Infinity and beyond
|
|
Go to Start | Programs | Spybot S&D Click Advanced there
Have a quick look at the tutorial here
Of all the Things I've lost, I miss my mind the most
|
Phil Tozer
Unregistered
|
|
Iain, i have done all as you requested but with no luck im afraid as the page still wont load.
Another example of thisis on http://www.trailfinders.com
when i click on "viewtrail - view your booking" the page wil say it cannot be displayed . Here are thew page properitesres:
//C:\WINDOWS\System32\shdoclc.dll/dnserror.htm#https://secure.trailfinders.co
|
putasolutions
regular
Reg'd: Tue
Posts: 12155
Loc: Infinity and beyond
|
|
I was eliminating elements, now I know that spyware isn't causing the problem, we can move onto the next potential solution
Open Internet Explorer Go to Help | About Internet Explorer What cipher strength does it show?
Of all the Things I've lost, I miss my mind the most
|
Phil Tozer
Unregistered
|
|
Iain, thanks for your perseverance.
My cypher strength is 128-bit
Phil
|
putasolutions
regular
Reg'd: Tue
Posts: 12155
Loc: Infinity and beyond
|
|
Ok your cipher strength is fine
Let's try deleting all your cookies and your temporary internet Files
Open internet Explorer Click Tools | Internet options | General tab Click the Delete cookies & the Delete Files buttons
Of all the Things I've lost, I miss my mind the most
|
Phil Tozer
Unregistered
|
|
Done that to no avail unfortunately
Phil
|
putasolutions
regular
Reg'd: Tue
Posts: 12155
Loc: Infinity and beyond
|
|
Ok try this
Go to Start | Run type in regsvr32 schannel.dll
Of all the Things I've lost, I miss my mind the most
|