torindkflt
New member
- Local time
- 3:36 PM
- Messages
- 7
SOLVED - DNS lookup fails, but only in web browsers
This problem has been solved. If you are having a similar problem and have found your way here from Google or elsewhere, check my success post in this thread for an explanation of how I fixed it. No guarantees it'll fix the problem you're having, but it may at least step you in the right direction.
Greetings. This is my first post on these particular forums.
I am currently in the process of disinfecting a computer for a customer, it is running Windows 7 64-bit. It was infested with a multitude of malware. The cleanup is still progressing, however I am at a point now where I require a properly working internet connection in order to finish the cleanup process.
Unfortunately, I have encountered a head-scratcher of a problem. No matter which web browser I use, I cannot load any websites whatsoever. I've tried IE, Firefox and Chrome, they all fail with their respective errors indicating that the DNS lookup for the address failed.
Now, here's the odd part...it's ONLY the web browsers that this is occurring on. For example, if I open a Command Prompt window and enter "ping www.google.com", it will return the proper IP and respond normally with no errors. In addition, Windows Update is able to successfully connect and download updates with no errors. Whatever this issue is, it seems to affect only web browsers.
Here are the things I have tried, none of these have resolved this issue so far:
-Ran SFC to check for missing/corrupt system files. No errors were detected.
-Reset the TCP/IP stack using the netsh command.
-Uninstalled and reinstalled the network adapters.
-Reset Windows Firewall to defaults.
-Verified there are no suspicious/incorrect LSP entries.
-Verified there are no suspicious/incorrect HOSTS entries.
Here's a list of the malware scanners I have run so far:
-Spybot Search & Destroy 1.62 Portable
-SuperAntiSpyware Portable
-Malwarebytes
And here's some additional malware scanners I plan on running during my continued cleanup:
-Microsoft Security Essentials (Currently scanning, results pending ETA 1-2 hours)
-Spybot 2
-ClamWin Portable
-Trend Micro HouseCall (Can't run until the internet is fixed)
-HitmanPro
-Any additional scanners you recommend
Spybot, SAS and MBAM were all run from a bootable Win7PE disc, thus I have no logs from them. Here is a log from HijackThis. As I said, cleanup is still in progress, so there's bound to still be some bad entries:
I would appreciate any input with this issue. Thank you.
================
UPDATE: MSE scan found nothing. I was unable to run Spybot 2 because it couldn't download updates. So, whatever is causing this issue is affecting it too. I will see about manually downloading updates for it later.
HitmanPro, on the other hand, was able to connect and download updates, so I did a scan with it. It found some stuff and removed them, but this did not fix the problem. The log from HitmanPro is too large for me to C&P here, so I've attached it. BTW, CVCSUtil.exe is a false positive. It's an old program I wrote in Visual Basic many years ago leftover from when I used to put my cleanup tools on CD, and HitmanPro alerted on it because it doesn't have a valid digital signature and is loaded by autorun.inf (All it does is pop up a message box saying where to send the disc if found).
I have to leave for work in 10 minutes, so I do not have time to do any further scans right now. I'll keep updating this as I finish my scans, and try other methods to repair the network connection.
This problem has been solved. If you are having a similar problem and have found your way here from Google or elsewhere, check my success post in this thread for an explanation of how I fixed it. No guarantees it'll fix the problem you're having, but it may at least step you in the right direction.
Greetings. This is my first post on these particular forums.
I am currently in the process of disinfecting a computer for a customer, it is running Windows 7 64-bit. It was infested with a multitude of malware. The cleanup is still progressing, however I am at a point now where I require a properly working internet connection in order to finish the cleanup process.
Unfortunately, I have encountered a head-scratcher of a problem. No matter which web browser I use, I cannot load any websites whatsoever. I've tried IE, Firefox and Chrome, they all fail with their respective errors indicating that the DNS lookup for the address failed.
Now, here's the odd part...it's ONLY the web browsers that this is occurring on. For example, if I open a Command Prompt window and enter "ping www.google.com", it will return the proper IP and respond normally with no errors. In addition, Windows Update is able to successfully connect and download updates with no errors. Whatever this issue is, it seems to affect only web browsers.
Here are the things I have tried, none of these have resolved this issue so far:
-Ran SFC to check for missing/corrupt system files. No errors were detected.
-Reset the TCP/IP stack using the netsh command.
-Uninstalled and reinstalled the network adapters.
-Reset Windows Firewall to defaults.
-Verified there are no suspicious/incorrect LSP entries.
-Verified there are no suspicious/incorrect HOSTS entries.
Here's a list of the malware scanners I have run so far:
-Spybot Search & Destroy 1.62 Portable
-SuperAntiSpyware Portable
-Malwarebytes
And here's some additional malware scanners I plan on running during my continued cleanup:
-Microsoft Security Essentials (Currently scanning, results pending ETA 1-2 hours)
-Spybot 2
-ClamWin Portable
-Trend Micro HouseCall (Can't run until the internet is fixed)
-HitmanPro
-Any additional scanners you recommend
Spybot, SAS and MBAM were all run from a bootable Win7PE disc, thus I have no logs from them. Here is a log from HijackThis. As I said, cleanup is still in progress, so there's bound to still be some bad entries:
Code:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:15:09 AM, on 3/1/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16464)
Boot mode: Normal
Running processes:
F:\HJT\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.toshiba.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.toshiba.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: TOSHIBA Media Controller Plug-in - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll
O4 - HKLM\..\Run: [ToshibaServiceStation] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
O4 - HKLM\..\Run: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Toshiba\Toshiba Online Backup\Activation\TOBuActivation.exe" UNATTENDED
O4 - HKLM\..\Run: [ToshibaAppPlace] "C:\Program Files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [DW6] "C:\Program Files (x86)\The Weather Channel FW\Desktop\DesktopWeather.exe"
O4 - HKCU\..\Run: [DW7] "C:\Program Files (x86)\The Weather Channel\The Weather Channel App\TWCApp.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [Exetender] "C:\Program Files (x86)\Free Ride Games\GPlayer.exe" /runonstartup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: c:\progra~3\browse~1\261095~1.52\{c16c1~1\browse~1.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Toshiba Laptop Checkup Application Launcher (Norton PC Checkup Application Launcher) - Symantec Corporation - C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\SymcPCCULaunchSvc.exe
O23 - Service: Common Client Job Manager Service (PCCUJobMgr) - Symantec Corporation - C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\ccSvcHst.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - Unknown owner - C:\windows\system32\TODDSrv.exe (file missing)
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 8498 bytes
================
UPDATE: MSE scan found nothing. I was unable to run Spybot 2 because it couldn't download updates. So, whatever is causing this issue is affecting it too. I will see about manually downloading updates for it later.
HitmanPro, on the other hand, was able to connect and download updates, so I did a scan with it. It found some stuff and removed them, but this did not fix the problem. The log from HitmanPro is too large for me to C&P here, so I've attached it. BTW, CVCSUtil.exe is a false positive. It's an old program I wrote in Visual Basic many years ago leftover from when I used to put my cleanup tools on CD, and HitmanPro alerted on it because it doesn't have a valid digital signature and is loaded by autorun.inf (All it does is pop up a message box saying where to send the disc if found).
I have to leave for work in 10 minutes, so I do not have time to do any further scans right now. I'll keep updating this as I finish my scans, and try other methods to repair the network connection.
Attachments
Last edited:
My Computer
At a glance
Windows 7 64-bit
- Computer type
- PC/Desktop
- OS
- Windows 7 64-bit
rb: button
