Google - only part of page loads

Discussion in 'malware problems & news' started by dags, Nov 8, 2003.

Thread Status:
Not open for further replies.
  1. dags

    dags Registered Member

    Joined:
    Aug 6, 2003
    Posts:
    15
    Ever since formatting & reinstalling XP a week or so ago, I can't seem to get to Google with IE or Netscape. The URL says that I am at Google, but the page looks like this http://www.photobucket.com/albums/0803/sdag1/google.gif, actually the page is blank, except for the "GLE" which is in the top left corner.

    Ad-aware, Spybot S&D, FixQhost & Vet all come back clean.
    Hijackthis log looks like this

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\VetMsgNT.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\WINDOWS\AGRSMMSG.exe
    C:\Program Files\Ahead\InCD\InCD.exe
    C:\PROGRA~1\Vet\VetTray.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Netscape\Netscape\Netscp.exe
    C:\Program Files\Gigabyte\Gigabyte Windows Utility Manager\gwum.exe
    C:\Program Files\Delux\PS2 Keyboard English Edition\keyboard.exe
    C:\Program Files\FinePixViewer\QuickDCF.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\Program Files\Windows & Internet Washer\cseraser.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\dags111\Desktop\security\HijackThis196.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.members.optusnet.com.au/sdag1
    N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\dags111\Application Data\Mozilla\Profiles\default\uyubcetp.slt\prefs.js)
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: SysShield IE Popup Blocker - {9A23B8A4-C6C9-4A68-8FA6-5F905DC8FF80} - C:\Program Files\Windows & Internet Washer\PKExt.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
    O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
    O4 - HKLM\..\Run: [VetTray] C:\PROGRA~1\Vet\VetTray.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Mozilla Quick Launch] "C:\Program Files\Netscape\Netscape\Netscp.exe" -turbo
    O4 - Startup: Windows & Internet Washer.lnk = C:\Program Files\Windows & Internet Washer\cseraser.exe
    O4 - Global Startup: gwum.lnk = C:\Program Files\Gigabyte\Gigabyte Windows Utility Manager\gwum.exe
    O4 - Global Startup: PS2 Keyboard English Edition.lnk = ?
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O17 - HKLM\System\CCS\Services\Tcpip\..\{58F91D59-CD9C-45AF-B8F0-5AF52BA961DE}: NameServer = 198.142.0.51 203.2.75.132
    O17 - HKLM\System\CS1\Services\Tcpip\..\{58F91D59-CD9C-45AF-B8F0-5AF52BA961DE}: NameServer = 198.142.0.51 203.2.75.132

    ps. Can anyone pls tell me how to disable that annoying instant messenger pop up thingy

    Thanks
    Steve o_O
     
  2. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,332
    Location:
    Netherlands
    Hi dags,

    For the messenger spam: http://www.spywareinfoforum.com/articles/spam/messenger.php

    For the Google problem can you try if this links gives you the full page: http://216.239.33.99/ ?

    Regards,

    Pieter
     
  3. dags

    dags Registered Member

    Joined:
    Aug 6, 2003
    Posts:
    15
    Hi Pieter,
    That google IP loads the full page.
    I'll try the link for the messenger spam
    Thanks
    Steve
     
  4. dags

    dags Registered Member

    Joined:
    Aug 6, 2003
    Posts:
    15
    Messenger disabled
    Thanks
    Steve
     
  5. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,332
    Location:
    Netherlands
    Hi dags,

    The fact that the direct IP link loads the full page, implicates a DNS problem or some software blocking the rest.

    As a workaround add this line to your hosts file:

    216.239.33.99 www.google.com

    You can find your hosts file here:
    Windows 95/98/ Me c:\windows\hosts
    Windows NT/2000 c:\winnt\system32\drivers\etc\hosts
    Windows XP c:\windows\system32\drivers\etc\hosts

    Let me know if that solves it.

    Regards,

    Pieter
     
  6. dags

    dags Registered Member

    Joined:
    Aug 6, 2003
    Posts:
    15
    "windows can not open this file:
    to open this file, windows needs to know what program created it etc"

    Tried "use the web service to find appropriate program" option, but it could'nt find the page.
     
  7. TonyKlein

    TonyKlein Security Expert

    Joined:
    Feb 9, 2002
    Posts:
    4,350
    Location:
    The Netherlands
    If you're referring to the Hosts file, just choose Notepad.exe to open it.
     
  8. dags

    dags Registered Member

    Joined:
    Aug 6, 2003
    Posts:
    15
    ok, done that.
    Rebooted and Google still not loading
    I've cut & pasted the IP into a notepad on desktop, so it's not a huge problem. My only concern was that maybe it was indicating some sort of trojan or something.
    Thanks
    Steve
     
Loading...
Thread Status:
Not open for further replies.