Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

IE tries to connect using old ISP - Hijacked?[RESOLVED]


  • This topic is locked This topic is locked

#1
Gizz

Gizz

    Member

  • Member
  • PipPip
  • 14 posts
Hi. Got referred from the browser forum 'cos it might be a highjacker causing my probs!
I use Firefox as default browser and have Tiscali Broadband as ISP. Some sites still need IE to run, but IE refuses to connect to Tiscali and tries to connect using Freeserve, which was my old dial up ISP and so it doesn't work. Reinstalled my Broadband modem, and now it doesn't even connect to anything using Firefox - it insists on using IE. Have tried changing net connections options and firewalling dial up and so forth with no luck...

Have used Cleanup, Ad-Aware, CWShredder and Spybot S&D as directed, and finally here is my HJT log. Hope you guys can help. You'll have a friend for life if you can!!


Logfile of HijackThis v1.99.1
Scan saved at 20:11:11, on 15/05/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Softwin\BitDefender8\vsserv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-gb\msnappau.exe
C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe
C:\Program Files\Softwin\BitDefender8\bdoesrv.exe
C:\Program Files\Softwin\BitDefender8\bdnagent.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\PROGRA~1\Webshots\webshots.scr
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\The Fat Controller\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.freeserve...rch/default.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.co.uk
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co...:en-US:official
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.freeserve.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.co.uk
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co...:en-US:official
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Freeserve
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://www-cache.freeserve.com:8080;ftp=http://www-cache.freeserve.com:8080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-gb\msnappau.exe"
O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe
O4 - HKLM\..\Run: [BDOESRV] C:\Program Files\Softwin\BitDefender8\\bdoesrv.exe
O4 - HKLM\..\Run: [BDNewsAgent] C:\Program Files\Softwin\BitDefender8\bdnagent.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.com/
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg...v43/yacscom.cab
O16 - DPF: {8699D723-6DC6-47D3-B55C-489BA006B917} - http://membersites.n.../webinstall.cab
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender8\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - Softwin - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
  • 0

Advertisements


#2
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 33,101 posts
Check the items listed below in HijackThis, close all windows except HijackThis and click Fix checked:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.freeserve...rch/default.htm

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.freeserve.com/

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://www-cache.freeserve.com:8080;ftp=http://www-cache.freeserve.com:8080

O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.com/

O16 - DPF: {8699D723-6DC6-47D3-B55C-489BA006B917} - http://membersites.n.../webinstall.cab

Then reboot and let me know if it works as it should.

Regards,
  • 0

#3
Gizz

Gizz

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Appreciate the reply - I know you guys are well busy lately!!

Did what you said and rebooted. Firefox works as default browser ok, but IE still says it can't find the server! Shall I re-post a new log? I'm not even sure its a malware problem...! :tazz:
  • 0

#4
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 33,101 posts
Yes. Please post a new log.

I was pretty confident that fixing the ProxyServer would get rid of your problem.

Regards,
  • 0

#5
Gizz

Gizz

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Logfile of HijackThis v1.99.1
Scan saved at 16:59:09, on 21/05/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-gb\msnappau.exe
C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe
C:\Program Files\Softwin\BitDefender8\bdoesrv.exe
C:\Program Files\Softwin\BitDefender8\bdnagent.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
C:\PROGRA~1\Webshots\webshots.scr
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Softwin\BitDefender8\vsserv.exe
C:\Documents and Settings\The Fat Controller\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co...:en-US:official
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co...:en-US:official
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Freeserve
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-gb\msnappau.exe"
O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe
O4 - HKLM\..\Run: [BDOESRV] C:\Program Files\Softwin\BitDefender8\\bdoesrv.exe
O4 - HKLM\..\Run: [BDNewsAgent] C:\Program Files\Softwin\BitDefender8\bdnagent.exe
O4 - HKLM\..\Run: [adiras] adiras.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg...v43/yacscom.cab
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender8\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - Softwin - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
  • 0

#6
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 33,101 posts
  • Download the Registry Search Tool.
  • Unzip the contents of RegSrch.zip to a convenient location.
  • Double-click on RegSrch.vbs.
  • If you have an anti-virus installed it might prompt you about a running script. Please ignore this warning and allow the script to run.
  • In the "Enter search string (case insensitive) and click OK..." box paste this string:
    • freeserve
  • Click "OK" to search the registry for that string.
  • Wait for a few minutes while it completes the search.
  • Click "OK" to open the results in WordPad.
  • Copy and paste the entire results into your next post.
Regards,
  • 0

#7
Gizz

Gizz

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
REGEDIT4
; RegSrch.vbs © Bill James

; Registry search results for string "freeserve" 21/05/2005 17:26:08

; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


[HKEY_USERS\S-1-5-21-3289834387-1615061138-1316817595-1008\Identities\{783D25BB-B5A1-4EAC-84D8-51504AAFC31B}\Software\Microsoft\Outlook Express\5.0]
"WindowTitle"="Outlook Express provided by Freeserve"

[HKEY_USERS\S-1-5-21-3289834387-1615061138-1316817595-1008\Identities\{783D25BB-B5A1-4EAC-84D8-51504AAFC31B}\Software\Microsoft\Outlook Express\5.0]
"BodyBarPath"="http://www.freeserve...eviewpane.html"

[HKEY_USERS\S-1-5-21-3289834387-1615061138-1316817595-1008\Identities\{783D25BB-B5A1-4EAC-84D8-51504AAFC31B}\Software\Microsoft\Outlook Express\5.0]
"HelpUrl"="http://www.freeserve.com/help/"

[HKEY_USERS\S-1-5-21-3289834387-1615061138-1316817595-1008\RemoteAccess\Profile\Freeserve Hometime]

[HKEY_USERS\S-1-5-21-3289834387-1615061138-1316817595-1008\Software\Microsoft\Internet Account Manager\Accounts\00000001]
"Account Name"="pop.freeserve.com"

[HKEY_USERS\S-1-5-21-3289834387-1615061138-1316817595-1008\Software\Microsoft\Internet Account Manager\Accounts\00000001]
"POP3 Server"="pop.freeserve.com"

[HKEY_USERS\S-1-5-21-3289834387-1615061138-1316817595-1008\Software\Microsoft\Internet Account Manager\Accounts\00000001]
"SMTP Server"="smtp.freeserve.com"

[HKEY_USERS\S-1-5-21-3289834387-1615061138-1316817595-1008\Software\Microsoft\Internet Account Manager\Accounts\00000002]
"Account Name"="news.freeserve.com"

[HKEY_USERS\S-1-5-21-3289834387-1615061138-1316817595-1008\Software\Microsoft\Internet Account Manager\Accounts\00000002]
"NNTP Server"="news.freeserve.com"

[HKEY_USERS\S-1-5-21-3289834387-1615061138-1316817595-1008\Software\Microsoft\Internet Explorer\Help_Menu_URLs]
"Online_Support"="http://www.freeserve.com/help/"

[HKEY_USERS\S-1-5-21-3289834387-1615061138-1316817595-1008\Software\Microsoft\Internet Explorer\Main]
"Window Title"="Microsoft Internet Explorer provided by Freeserve"

[HKEY_USERS\S-1-5-21-3289834387-1615061138-1316817595-1008\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\Freeserve Channels]

[HKEY_USERS\S-1-5-21-3289834387-1615061138-1316817595-1008\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Freeserve]

[HKEY_USERS\S-1-5-21-3289834387-1615061138-1316817595-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"Freeserve Hometime"=hex:3c,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,\
  • 0

#8
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 33,101 posts
How many accounts are there on your computer?

It looks to me as if one of them is still using freeserve.

I will need some more info:
Click Start > Run > type or copy&paste regedit /e c:\iamacc.txt "HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\Accounts" > OK

This will create the file c:\iamacc.txt
Please find it and post the content.

Regards,
  • 0

#9
Gizz

Gizz

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
I have 2 accounts: 1 Administrator and 1 Limited. Used to have 1 other limited account, but recently deleted it...


Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\Accounts]
"AssociatedID"=hex:bb,25,3d,78,a1,b5,ac,4e,84,d8,51,50,4a,af,c3,1b
"PreConfigVer"=dword:00000004
"PreConfigVerNTDS"=dword:00000001
"ConnectionSettingsMigrated"=dword:00000001

[HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\Accounts\00000001]
"Account Name"="pop.freeserve.com"
"Connection Type"=dword:00000003
"Server Read Only"=dword:00000000
"POP3 Server"="pop.freeserve.com"
"POP3 Use Sicily"=dword:00000000
"SMTP Server"="smtp.freeserve.com"
"SMTP Use Sicily"=dword:00000000

[HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\Accounts\00000002]
"Account Name"="news.freeserve.com"
"Connection Type"=dword:00000003
"Server Read Only"=dword:00000000
"NNTP Server"="news.freeserve.com"
"NNTP Use Sicily"=dword:00000000

[HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\Accounts\Active Directory GC]
"LDAP Server ID"=dword:00000000
"Account Name"="Active Directory"
"LDAP Server"="NULL"
"LDAP Search Return"=dword:00000064
"LDAP Timeout"=dword:0000003c
"LDAP Authentication"=dword:00000002
"LDAP Simple Search"=dword:00000000
"LDAP Bind DN"=dword:00000000
"LDAP Port"=dword:00000cc4
"LDAP Resolve Flag"=dword:00000001
"LDAP Secure Connection"=dword:00000000
"LDAP User Name"="NULL"
"LDAP Search Base"="NULL"

[HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\Accounts\Bigfoot]
"LDAP Server ID"=dword:00000001
"Account Name"="Bigfoot Internet Directory Service"
"LDAP Server"="ldap.bigfoot.com"
"LDAP URL"="http://www.bigfoot.com"
"LDAP Search Return"=dword:00000064
"LDAP Timeout"=dword:0000003c
"LDAP Authentication"=dword:00000000
"LDAP Simple Search"=dword:00000001
"LDAP Logo"=hex(2):25,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,46,00,69,00,\
6c,00,65,00,73,00,25,00,5c,00,43,00,6f,00,6d,00,6d,00,6f,00,6e,00,20,00,46,\
00,69,00,6c,00,65,00,73,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,\
73,00,5c,00,62,00,69,00,67,00,66,00,6f,00,6f,00,74,00,2e,00,62,00,6d,00,70,\
00,00,00

[HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\Accounts\VeriSign]
"LDAP Server ID"=dword:00000002
"Account Name"="VeriSign Internet Directory Service"
"LDAP Server"="directory.verisign.com"
"LDAP URL"="http://www.verisign.com"
"LDAP Search Return"=dword:00000064
"LDAP Timeout"=dword:0000003c
"LDAP Authentication"=dword:00000000
"LDAP Search Base"="NULL"
"LDAP Simple Search"=dword:00000001
"LDAP Logo"=hex(2):25,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,46,00,69,00,\
6c,00,65,00,73,00,25,00,5c,00,43,00,6f,00,6d,00,6d,00,6f,00,6e,00,20,00,46,\
00,69,00,6c,00,65,00,73,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,\
73,00,5c,00,76,00,65,00,72,00,69,00,73,00,69,00,67,00,6e,00,2e,00,62,00,6d,\
00,70,00,00,00

[HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\Accounts\WhoWhere]
"LDAP Server ID"=dword:00000003
"Account Name"="WhoWhere Internet Directory Service"
"LDAP Server"="ldap.whowhere.com"
"LDAP URL"="http://www.whowhere.com"
"LDAP Search Return"=dword:00000064
"LDAP Timeout"=dword:0000003c
"LDAP Authentication"=dword:00000000
"LDAP Simple Search"=dword:00000001
"LDAP Logo"=hex(2):25,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,46,00,69,00,\
6c,00,65,00,73,00,25,00,5c,00,43,00,6f,00,6d,00,6d,00,6f,00,6e,00,20,00,46,\
00,69,00,6c,00,65,00,73,00,5c,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,\
73,00,5c,00,77,00,68,00,6f,00,77,00,68,00,65,00,72,00,65,00,2e,00,62,00,6d,\
00,70,00,00,00
  • 0

#10
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 33,101 posts
OK save that file to use a s a backup in case it gets worse. :tazz:

Copy the part in bold below into notepad and save it as remfree.reg

REGEDIT4

[-HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\Accounts\00000001]

[-HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\Accounts\00000002]


Doubleclick the file and confirm you want to merge it with the registry.
It may take a reboot for the changes to kick in.

Regards,
  • 0

Advertisements


#11
Gizz

Gizz

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Did all that, it asked me for confirmation that I wanted to add it to registry. Said OK and it came up with:

Cannot import C:\Documents: Error opening the file. There may be a disk or file system error.

:tazz:
  • 0

#12
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 33,101 posts
Was Outlook running when you tried to use that file?

Or did you forget to actually save that file to your HD before double-clicking it?

Regards,
  • 0

#13
Gizz

Gizz

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Outlook wasn't running and the file was saved good and proper! Got round it by opening registry editor and imported the file, which seemed to work. Well, it said it had merged it succesfully. Rebooted, but IE still isn't working.

:tazz:
  • 0

#14
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 33,101 posts
Can you find:
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\Rasphone.pbk

Rightclick and open the file in Notepad. Post the content.

Regards,
  • 0

#15
Gizz

Gizz

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
[Tiscali Broadband]
Encoding=1
Type=1
AutoLogon=0
UseRasCredentials=1
DialParamsUID=2656930
Guid=C28D8DFD8A733B49A27424A99CBDDECA
BaseProtocol=1
VpnStrategy=0
ExcludedProtocols=3
LcpExtensions=1
DataEncryption=8
SwCompression=1
NegotiateMultilinkAlways=1
SkipNwcWarning=0
SkipDownLevelDialog=0
SkipDoubleDialDialog=0
DialMode=0
DialPercent=0
DialSeconds=0
HangUpPercent=0
HangUpSeconds=0
OverridePref=15
RedialAttempts=0
RedialSeconds=1
IdleDisconnectSeconds=0
RedialOnLinkFailure=0
CallbackMode=0
CustomDialDll=
CustomDialFunc=
CustomRasDialDll=
AuthenticateServer=0
ShareMsFilePrint=0
BindMsNetClient=1
SharedPhoneNumbers=0
GlobalDeviceSettings=0
PrerequisiteEntry=
PrerequisitePbk=
PreferredPort=ISDN12-0
PreferredDevice=USB ADSL WAN Adapter
PreferredBps=0
PreferredHwFlow=1
PreferredProtocol=1
PreferredCompression=1
PreferredSpeaker=1
PreferredMdmProtocol=0
PreviewUserPw=0
PreviewDomain=0
PreviewPhoneNumber=0
ShowDialingProgress=0
ShowMonitorIconInTaskBar=1
CustomAuthKey=-1
AuthRestrictions=632
TypicalAuth=1
IpPrioritizeRemote=1
IpHeaderCompression=1
IpAddress=0.0.0.0
IpDnsAddress=0.0.0.0
IpDns2Address=0.0.0.0
IpWinsAddress=0.0.0.0
IpWins2Address=0.0.0.0
IpAssign=1
IpNameAssign=1
IpFrameSize=0
IpDnsFlags=0
IpNBTFlags=1
TcpWindowSize=0
UseFlags=0
IpSecFlags=0
IpDnsSuffix=

NETCOMPONENTS=
ms_msclient=1
ms_server=0
ms_psched=1

MEDIA=isdn
Port=ISDN12-0
Device=USB ADSL WAN Adapter

DEVICE=isdn
PhoneNumber=0,38
AreaCode=
CountryCode=44
CountryID=44
UseDialingRules=0
Comment=
LastSelectedPhone=0
PromoteAlternates=0
TryNextAlternateOnFail=1
LineType=0
Fallback=1
EnableCompression=1
ChannelAggregation=1
Proprietary=0
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP