PDA

View Full Version : 169 ip address - HJT log



mwcubsnut
30-06-2009, 12:41 PM
I can not get this laptop to connect to the internet!! I even tried to uninstall and reinstall the network driver, I also tried the WinSock fix. Still nothing. Someone suggested that it may be a virus and not an IP issue.

I have tried the iprelease and renew but cant because the media is disconnected!! Here is the HJT log and thank you in advance for anyone who can help!!


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:20:40 AM, on 1/24/2003
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Documents and Settings\bob\Desktop\HijackThis\HijackThis.exe

O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

--
End of file - 2201 bytes

Speedy Gonzales
30-06-2009, 12:44 PM
Is that all of it? It looks a bit short

Get rid of Symantec, its probably that, thats screwing things up

You can tick these entries then tick fix checked

Close browsers

O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE

O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE

If this is on broadband, reset the modem. Then reconfigure it. As modem/routers can also get hit by DNSchanger. Which wont appear in a log, and you cant get rid of it until you reset the router.

mwcubsnut
30-06-2009, 12:47 PM
Yes that is it and I thought I did get rid of the Symantec!!

mwcubsnut
30-06-2009, 12:48 PM
No router either, well not when it is in my posession. It was hooked up to a router with the owner but not since I have had it. Connecting directly with the ethranet cord...

Speedy Gonzales
30-06-2009, 12:50 PM
Umm no thats what these belong to

O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')

23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Did you uninstall it?? You didnt delete its folder/s, without uninstalling it did you? That wont uninstall it. It must be going through a router or something to get here tho? Unless youre on dialup

wratterus
30-06-2009, 12:54 PM
Run this (ftp://ftp.symantec.com/public/english_us_canada/removal_tools/Norton_Removal_Tool.exe). Part of Norton might be left there stuffing things up.

mwcubsnut
30-06-2009, 01:24 PM
What is this?

O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll

wratterus
30-06-2009, 01:26 PM
Run LSPFix (http://www.cexx.org/LSPFix.exe) and remove nwprovau.dll.

Blam
30-06-2009, 01:56 PM
Its not not nasty, its usually for the IPX / SPX protocol, but its rarely used these days.

If its getting a 169 IP then it means it can't get a proper IP from the DHCP server.

Try running WinsockFix. Should fix any DHCP issues:
http://www.softpedia.com/get/Tweak/Network-Tweak/WinSockFix.shtml

EDIT: Just read your post, I've seen that you've already run winsockfix, sorry:p

What happens when you try to ping the default gateway? HAve you tried setting a static IP?

Blam

mwcubsnut
30-06-2009, 02:52 PM
I am not sure which of the above worked but I am online! Thanks so very much to all! I need to install an AV - AVG? Avast?

wratterus
30-06-2009, 03:05 PM
Probably Nortons. It's useless so blame this on it. :D

Not AVG - Avast is much better. :)