Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Missing Wininet.dll [CLOSED]


  • This topic is locked This topic is locked

#1
dpham

dpham

    Member

  • Member
  • PipPip
  • 37 posts
I have the PSGuard problem and after I try to move with Xoftspy, Ad-ware... which did not work... Then I have a problem with windows where I can not open any more. I got an error message from Explore said I am missing this file WININET.DLL. I found this link from another person, but I have not try it yet.

http://www.geekstogo...&hl=wininet.dll

the problem that I have is the window just show the desktop without out any Icon or task bar. I can open the Task Manager to see which one is running and that's all. I am woundering that how can I do the copy and paste if I can not access to the windown? Should I start if from DOS and using the copy from dos command? If that was the cased, can you post the copy command from DOS again please? It has been awhile since I use the DOS.

I also read a lot of post one how to remove the PSguard... and the more I read, the more confuse that I have. Can you post or show me the link for, one and for all, remove this spyware PSGuard?

Thanks a lot. This website is great and I already learn a lot from here.
  • 0

Advertisements


#2
Excal

Excal

    Malware Slayer Extraordinaire!

  • Retired Staff
  • 12,739 posts
Hi dpham and welcome to GeeksToGo! My name is Excal and I will be helping you.


lets see if we can get your Explorer back up.

Copy everything in the box below and paste it into notepad. Go up to "File > Save As..." and click the drop-down box to change the "Save As Type" to "All Files". Save it as wininet.bat on your desktop.

dir %Systemdrive%\wininet.dll /a h /s > files.txt
start notepad files.txt


Double click wininet.bat and when it is ready it will open files.txt
Copy the content of files.txt and paste it here.


(in order to get notepad up, hit cctrl/alt/del and go to file. then to newtask (run) and type in notepad.exe.)

:tazz:

Excal
  • 0

#3
dpham

dpham

    Member

  • Topic Starter
  • Member
  • PipPip
  • 37 posts
Hi Excal

How are you doing? At first I would like to thanks for your help. This would be a life saving for me.
Now, the PC that I have this problem is at home I before I try any thing I just want to understand very well on the procedure step. Please excuse me for to be slow.

I got the first instruction with is create the file name WININET.BAT and instead of saving in "Desktop," I save it on the floppy so I can transfer into my infection PC. Now, here is my questions.
1. How can I copy this file to "infection PC" desktop? After reboot the PC and click OK on the Explore message about missing WIMINET.DLL file, all it showes my desktop background without any icon or command. Do I have to do this from DOS? if I did that, would it show in the Desktop?

2. I am not sure I understand the second part where you want me to open. Assume I am be able to open the file in Text and copy the content. Where do you want me to Paste into? if I understand correctly, I can type / copy the content from the quote / wininet.bat and paste int the Task Manager/File/New Task (Run...)?

Please let me know if it is correct or not. Thanks and I would love to try this.
  • 0

#4
dpham

dpham

    Member

  • Topic Starter
  • Member
  • PipPip
  • 37 posts
Also Excal
I can copy this file wininet.dll from other pc (non infection) and paste to infection pc by boot from dos? If not, is there any where out there can I download this "clean" Wininet.dll file? Thanks
  • 0

#5
Excal

Excal

    Malware Slayer Extraordinaire!

  • Retired Staff
  • 12,739 posts
its no problem at all, you ask as many question as you need to!!

The .bat file I want you to make, will tell me where a clean copy of wininet.dll is in your computer so we can copy a new one.

you can actually just type all that information on to notepad in your infected PC, and then remember where you put it, and run it from take manager.
(if you hit ctrl/alt/del taks manager will appear. Go to the top where it says file, then go to new task (run) and you can type Notepad.exe, you can use the same process to run the .bat after you save it. just put in the path where you saved it to.)

I hope this helps, let me know if you need anything else.

Thanks,

:tazz:

Excal
  • 0

#6
dpham

dpham

    Member

  • Topic Starter
  • Member
  • PipPip
  • 37 posts
Hi Excal, I understand now. Actually, I test it on my work PC. I know this is an early question but which directory will have a healthy wininet.dll file? Or how do I know that would be a healthy file so I can copy it overy to my system32? Thanks
  • 0

#7
Excal

Excal

    Malware Slayer Extraordinaire!

  • Retired Staff
  • 12,739 posts
it can be in a few places, thats why I need that run so I can see where a good one is and the file size.



Excal
  • 0

#8
dpham

dpham

    Member

  • Topic Starter
  • Member
  • PipPip
  • 37 posts
Hi Excal
Here is the log file coming out:

Volume in drive C is BeNa_C
Volume Serial Number is 7049-4592

Directory of C:\WINDOWS\$hf_mig$\KB834707\SP2QFE

09/29/2004 11:27 AM 656,896 wininet.dll
1 File(s) 656,896 bytes

Directory of C:\WINDOWS\$hf_mig$\KB867282\SP2QFE

01/27/2005 10:08 AM 657,920 wininet.dll
1 File(s) 657,920 bytes

Directory of C:\WINDOWS\$hf_mig$\KB883939\SP2QFE

05/02/2005 01:57 PM 658,944 wininet.dll
1 File(s) 658,944 bytes

Directory of C:\WINDOWS\$hf_mig$\KB890923\SP2QFE

03/10/2005 12:43 AM 657,920 wininet.dll
1 File(s) 657,920 bytes

Directory of C:\WINDOWS\ServicePackFiles\i386

08/04/2004 12:56 AM 656,384 wininet.dll
1 File(s) 656,384 bytes

Total Files Listed:
5 File(s) 3,288,064 bytes
0 Dir(s) 7,507,615,744 bytes free


Please let me know which one is good to copy back to system32. Thanks
  • 0

#9
dpham

dpham

    Member

  • Topic Starter
  • Member
  • PipPip
  • 37 posts
Hi Excal
Thanks a lot for your help, I copy the file from C:\WINDOWS\ServicePackFiles\i386 and paste to system32. I got the windown back
I run the hijackthis and here is my log file:

Logfile of HijackThis v1.99.1
Scan saved at 7:08:41 PM, on 9/1/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
D:\Download.com\ZoneAlarm\zlclient.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\E_S00RP1.EXE
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\SAgent4.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
D:\Download\Virus\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.bestwebsl...earch.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bestwebslinks.com/bar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.bestwebsl...earch.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.bestwebsl...earch.php?qq=%1
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.bestwebslinks.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [Zone Labs Client] D:\Download.com\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Control Pad - {28D44DAD-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\Verizon Online Control Pad\VerizonControlPad.Exe
O9 - Extra 'Tools' menuitem: Control Pad - {28D44DAD-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\Verizon Online Control Pad\VerizonControlPad.Exe
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\TV\EXPLBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.7vn.com
O15 - Trusted Zone: http://www.gamecopyworld.com
O15 - Trusted Zone: http://*.intranet_nt2000
O16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} - http://softdev.adelp...ad/tgctlins.cab
O16 - DPF: {0335A685-ED24-4F7B-A08E-3BD15D84E668} - http://dl.filekicker...IL/PhPSetup.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....467&clcid=0x409
O16 - DPF: {640B39C1-D713-464F-92C3-75BD972B95EE} - http://download.side...00721/sb028.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1120881005062
O16 - DPF: {90051A81-3018-4826-8B38-DD60B6B53F9C} (Snapfish File Upload ActiveX Control) - http://www.costcopho...ostcoUpload.cab
O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} - http://cabs.roings.com/cabs/ieplug.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: EPSON V3 Service2(03) (EPSON_PM_RPCV2_01) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\E_S00RP1.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Epson Printer Status Agent4 (StatusAgent4) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\SAgent4.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

I am not seem to have a problem with PSGuard now. but can you check and let me know. Again thanks a lot for you help. You save me a lot of work. Thanks Excal and Geeks To Go web site
  • 0

#10
Excal

Excal

    Malware Slayer Extraordinaire!

  • Retired Staff
  • 12,739 posts
Thats exactly what I was going ot have you do with the Wininet, good job :tazz:



open Hijackthis and do a scan. Please check off the following items:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.bestwebsl...earch.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bestwebslinks.com/bar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.bestwebsl...earch.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.bestwebsl...earch.php?qq=%1
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.bestwebslinks.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O16 - DPF: {640B39C1-D713-464F-92C3-75BD972B95EE} - http://download.side...00721/sb028.cab
O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} - http://cabs.roings.com/cabs/ieplug.cab


click FIX CHECKED then close Hijackthis

The Temp folders should be cleaned out periodically as installation programs and hijack programs leave a lot of junk there. Download CleanUp! (Alternate Link if the main link does not work) and install it.


Run CleanUp! and click on CleanUp! button. When it asks you if you want to logoff, click on Yes.

reboot

Run this online virus scan: ActiveScan - Please save and post the results from the scan!
  • 0

#11
dpham

dpham

    Member

  • Topic Starter
  • Member
  • PipPip
  • 37 posts
thanks Excal, I will try when I get home tonight. Have a good weekend
  • 0

#12
Excal

Excal

    Malware Slayer Extraordinaire!

  • Retired Staff
  • 12,739 posts
Thanks :)

I will be here :)

:tazz:

Excal
  • 0

#13
Excal

Excal

    Malware Slayer Extraordinaire!

  • Retired Staff
  • 12,739 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP