• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

Browser/website trouble

TheJTrain

Senior member
1. Overview
New Dell laptop (Vostro 1400) has Internet issues, but only in specific, repeatable & reproducible doses.

2. Full description
- Neither Firefox nor IE can successfully load any .yahoo.com sites (www., mail., etc.). The "waiting for" or "opening page" message in the status bar just hangs there, and the page never loads.
- Other sites that I've randomly tried that also don't work: msnbc.com, fool.com
- Mail.google.com gives the same result, but other .google.com sites work normally (www., images., news., maps., etc.).
- Other sites that I've tried randomly that appear to work just fine: reason.com, anandtech.com, youtube.com
The three other PCs that go through the same router to our broadband connection have none of these symptoms - all three can successfully access, 100% of the time, all of the sites that fail on the new Dell Vostro.

3. History
Yes, it used to work normally, every webpage we tried was available, including all the ones listed above that don't work anymore. We've had that laptop since April, and the problems only just started this past weekend.

4. Repeatable?
Yes, it's very consistent. The sites listed above always give the same error, and other sites are always accessible.

5. Already tried these steps:
- I verified that the network settings on the Laptop's adapters are set up exactly the same as the other PCs (I use Static IPs, enter DNS servers manually based on what my router tells me, and WEP & MAC filtering on the wireless).
- I can successfully ping the domain names (yahoo.com for example) from the CMD window on the Dell Vostro and I get a normal response.
- The LMHOSTS file is empty.
- Scans with Spybot, Ad-Aware, HijackThis (as far as I and the online analyzer can tell), & AVG turn up nothing worse than ad-tracking cookies
- However, one time when I let IE try and load Yahoo without aborting, after 15 minutes the AVG resident shield popped up a warning that it had found Win32/Heur in one of the gibberish-named files in Temporary Internet Files, but when I went to look there was no such file in the folder specified in the warning. A search turned up some comments about how the Heur warning is often a false positive. Not sure what to make of this.

6. My software:
WinXP Pro SP2
IE 6
Firefox 3

7. My hardware:
Dell Vostro 1400
Core2Duo T5270 @1.4 GHz
2GB RAM

I'll get started running some of the online scanners & vulnerability checkers from mechBgon's post, but probably won't be able to get to it until tomorrow night.

Thanks all,
Jason
 
Looks like the standard unedited version that comes with WinXP - other than the typical commented stuff at the top explaining what it does, it just has the localhost line:

127.0.0.1 localhost

Running F-Secure, Trend Micro HouseCall, Panda ActiveScan, Secunia's PSI & F-Secure HealthCheck right now. Wish me luck!
 
I've had an interesting time over the last couple hours trying to run those checks. Here's a chronology:
- Ran F-Secure on Firefox; requires Active X
- Ran F-Secure on IE; it finds 6 viruses & 1 spyware
- When I click the "automatic disinfect" button, IE crashes without warning
- Repeat, same thing happens
- Run TrendMicro HouseCall on Firefox; the only option it gives me is the Java applet
- It gets stuck on the "updating HouseCall & starting scan"; wait 15 minutes, no change
- Run TrendMicro HouseCall on IE; two options, Java applet & browser plug-in; choose browser plug-in
- It gets stuck on the "updating HouseCall & starting scan"; after ~10 minutes IE crashes with no warning
- Run Panda ActiveScan on Firefox; prompted to download the Firefox plugin; as soon as the .exe is done saving, a new tab opens up letting me know that the website "antispywaremaster.com" was tagged as dangerous and Firefox (or maybe Google?) prevented me from going there
- Install the plugin, go back to Panda ActiveScan and start the scan/download ActiveScan 2.0; the progress bar finishes but then comes back with "download could not be completed because of an error"
- Download the Secunia PSI's .exe file; as soon as it's done saving, Firefox crashes, with the error report dialog window & everything
- When I select "Restart Firefox" and "Restore session", the "antispywaremaster.com is a dangerous site" tab opens up again

At this point I'm really thinking that things are screwed up beyond my ability to fix. Any thoughts from the experts out there?

Jason
 
Any thoughts from the experts out there?

an ounce of prevention is worth a pound of cure, was the first thought to cross my mind. Malware is preventible.


1) What were the six malwares that the F-Secure scanner found, do you remember the names?

2) Is your router secured? There are trojans which will alter your router's setup if the Admin password has been left at default settings. That reportedly includes switching it to malicious DNS server entries. If in doubt, do a hard-reset of the router, and immediately change the Admin password.

3) Don't place too much reliance on antivirus software for protection. If you want higher detection rates, try AntiVir PersonalEdition Classic in place of AVG, but it's still just a net with fewer holes in it, on any given day.

4) For a cleanup routine, try John's malware-removal guide.



If it were me, I'd certainly nuke it to smithereens using DBAN and then reinstall Windows and secure it, but people sometimes don't want to have to reinstall 50 games and 20 other pieces of software, configure it, etc, so whatever works best for you.
 
Thanks mechBgon - since it's so new I'm not too worried about starting over from scratch. It's my wife's work (self-employed) computer so we paid the extra for Dell's on-site service, so I'm thinking I'll just give them a call and say, hey, it's all screwed up, come nuke it and start over. Though I might just look and see if Dell gave us one of those handy-dandy "recovery" CDs and maybe I'll just do it myself.

The viruses F-Secure found are:
Trojan-Downloader:W32/ConHook.GH
Adware:W32/Virtumonde.AO
Trojan.Win32.Monder
Rootkit.Win32.Podnuha
Vundo.gen38
Trojan.Win32.Monder.zh
Trojan.Win32.Monder.zf
Rootkit.Win32.Podnuha.it

Yikes!

EDIT: Ack! Sorry robisbell I shut it down after I posted this but before I saw your post. I'll try that one another time (it's 1am!)
 
Ugh, rootkits and Vundo. I'd be pushing the big red NUKE IT NOW button if it were me :evil: If at all possible, do set it up with the separated Admin and non-Admin accounts, and use the non-Admin account for daily routine. Incredible safety boost right there. And of course, steadfastly resist any urge to download and install anything that isn't strictly necessary (screensavers, codec packs, games, etc).

Also, get IE7 installed, even if she doesn't routinely use IE herself.
 
Back
Top