It is currently Tue Sep 01, 2026 3:05 pm


IE error HELP!

All versions of Windows 7, 2008 and Vista including 32 bit and 64 bit

Moderator: icecube

IE error HELP!

Postby davv3000 » Wed Jan 28, 2004 5:35 am

I keep getting a page that says, "Can't find server" that pops up at the same time I access any variety of web sites. The 'properties' of this error window is as follows>

res://C:\WINDOWS\System32\shdoclc.dll/dnserror.htm#http://www.belgiandip.com/go.php?l=0007

Can anyone tell me how to get rid of it? I've tried all the spyware killer programs.

Help...
User avatar
davv3000
Newbie
Newbie
 
Posts: 14
Joined: Wed Jan 28, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby brad » Wed Jan 28, 2004 11:25 am

It's adware. I actually went to the URL in the link you posted and opnste.exe started running in my processes. "Open Site" had been installed. I've uninstalled it after Stopping the Process.
I'd run (Again) making sure to update it first. You may also want to run (after updating) and .
brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Thanks

Postby davv3000 » Wed Jan 28, 2004 4:17 pm

Thank you... I figured it was adware, but I'm not the 'expert' by a long shot. Funny how some things still seem to creep past my firewall. I've been getting spam everyday since that happened.
User avatar
davv3000
Newbie
Newbie
 
Posts: 14
Joined: Wed Jan 28, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Very annoying spyware...

Postby davv3000 » Thu Jan 29, 2004 3:55 am

Okay... I have ran; Hijack This, Ad-Aware, Spybot, and Spyware blaster and I still cannot get this IE fault to go away. I've had 3 virus attempts thru email (rejected by Norton) and more spam in the last week than I've had in 6 months, many repeats from the same spammers. This is terribly annoying. I'm running Zone Alarm Pro 4 as I have for at least a year, and that used to be sufficient. I need to know how to get these culprits out of my PC.

res://C:\WINDOWS\System32\shdoclc.dll/dnserror.htm#http://www.belgiandip.com/go.php?l=0007

I'm desperate, help..... :mad:
User avatar
davv3000
Newbie
Newbie
 
Posts: 14
Joined: Wed Jan 28, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby DwnSthGaBoyz » Thu Jan 29, 2004 5:01 am

only thing i can think of is to re-install ie and if you havent already then upgrade to 6.0, and try to make sure the settings on your internet are set correctly, set them to default then try again.
User avatar
DwnSthGaBoyz
Geek
Geek
 
Posts: 32
Joined: Fri Jan 23, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby brad » Thu Jan 29, 2004 11:21 am

Try setting your Home Page to none. IE / Tools / Internet Options.
Also, delete your Temporary Internet files.
If you still can't fix it, post your HiJackThis Log File.
brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Annoying spyware or virus.

Postby davv3000 » Fri Jan 30, 2004 5:01 am

I tried everything that was recommended and I'm about to dump my PC in the garbage can. These sharks won't leave my computer! Norton detected it as a virus, but the deletion didn't rid me of it... I run Window Washer a couple of times a week, which deletes the temp files, so I don't know what else to do.

Logfile of HijackThis v1.97.3
Scan saved at 8:49:09 PM, on 1/29/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\system32\gearsec.exe
C:\PROGRA~1\NORTON~1\NORTON~2\GHOSTS~2.EXE
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\tmccall.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
C:\Program Files\WordWeb\wweb32.exe
C:\WINDOWS\explorer.exe
C:\PROGRA~1\Webshots\WebshotsTray.exe
C:\WINDOWS\System32\mevtmsgn.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\hijackthis[1]\HijackThis.exe

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [QD FastAndSafe] C:\Program Files\Norton SystemWorks\Norton CleanSweep\QDCSFS.exe /scheduler
O4 - HKLM\..\Run: [instal] D:\install\install.exe
O4 - HKLM\..\Run: [tmccall] C:\WINDOWS\System32\tmccall.exe
O4 - HKLM\..\Run: [workflo] D:\install\workflow.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [mevtmsgn] C:\WINDOWS\System32\mevtmsgn.exe
O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O4 - Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: AIM (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: symsupportutil - https://www-secure.symantec.com/techsup ... rtutil.CAB
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0309.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200 ... taller.exe
O16 - DPF: {427273CC-764E-11D3-823D-006097F90453} (Pixami Image Editor Control) - http://www.imagestation.com/common/clas ... r=1,1,0,30
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/C ... 4979976852
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://active.macromedia.com/flash2/cabs/swflash.cab
O16 - DPF: {D670D0B3-05AB-4115-9F87-D983EF1AC747} (AOL Downloader Plugin) - http://pak02.pictures.aol.com/ygp/aol/p ... 0.9.14.cab
O16 - DPF: {DC765522-D5BE-49C9-AF5F-8C715A44BA28} (MS Investor Ticker) - http://fdl.msn.com/public/investor/v9.5/ticker.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsup ... veData.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
O16 - DPF: {FA53CFF8-B253-49DE-9B13-3A6129830AF0} - http://130.94.70.13/player/allcast100702_18.cab
User avatar
davv3000
Newbie
Newbie
 
Posts: 14
Joined: Wed Jan 28, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby brad » Fri Jan 30, 2004 7:34 am

In your running Processes I see C:\WINDOWS\System32\tmccall.exe.
I have never seen nor can I find anything on it.
I'd do a search on your computer and see what it's associated to. You can rename it tmccall.old and see if you lose anything....if so you can name it back. Hope that's it.
Also, here's an excellent guide for HiJackThis. It explains everything about the log file. There are several more things on yours to check out.
brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Still lingering

Postby davv3000 » Sat Jan 31, 2004 2:21 am

Okay, I completely killed the TMCALL.EXE process and it didn't seem to do anything positive or negative. I keep getting an email virus attempt (W32.Dumaru.Z) on a daily basis also. I wonder if it is related to this problem? How can I un-install Internet Explorer 6 and re-install it? That's the only thing I haven't tried (I've tried everything within the scope of my intermediate PC knowledge). Anymore ideas, anyone?

:evil:
User avatar
davv3000
Newbie
Newbie
 
Posts: 14
Joined: Wed Jan 28, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby brad » Sat Jan 31, 2004 10:32 am

brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Virus and adware.

Postby davv3000 » Sat Jan 31, 2004 8:50 pm

Yes, I do believe the virus was blocked. I am keeping my fingers crossed, that the original problem is in fact gone. I re-booted and my firewall blocked the "TMCCALL.EXE" access. I have been web surfing a great deal and the fault hasn't reappeared today. Hopefully the thorn in my side is gone, this thing was enough to make me go crazy. You guys are great (Brad) Thanks. Maybe one day I will be as PC savvy! :wink:
User avatar
davv3000
Newbie
Newbie
 
Posts: 14
Joined: Wed Jan 28, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby brad » Sat Jan 31, 2004 9:27 pm

Sometimes it takes awhile to find the fix and it always takes teamwork...
Glad you're Ok for now. Tell your friends about us.....
brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top


Return to Windows 7, 2008 and Vista

Who is online

Users browsing this forum: No registered users and 1 guest

cron