mikehende Posted May 30, 2017 Posted May 30, 2017 Hello Pete [or anyone else], my cousin's win10 laptop stopped going to the net. I ran the usual scans and cleaned out some stuff but still same deal so I am in need of some help please. Please see the reports but note that when I had first run mbam, I didn't pay attention to the language so it was in french and I could get the log therefore I am posting a screenshot of what it had found. Quote
mikehende Posted May 30, 2017 Author Posted May 30, 2017 # AdwCleaner v6.047 - Logfile created 30/05/2017 at 10:56:46 # Updated on 19/05/2017 by Malwarebytes # Database : 2017-05-19.1 [Local] # Operating System : Windows 10 Home (X64) # Username : William - DESKTOP-82NSOA6 # Running from : F:\AV Softwares\AdwCleaner.exe # Mode: Clean # Support : https://www.malwarebytes.com/support ***** [ Services ] ***** ***** [ Folders ] ***** ***** [ Files ] ***** ***** [ DLL ] ***** ***** [ WMI ] ***** ***** [ Shortcuts ] ***** ***** [ Scheduled Tasks ] ***** [-] Task deleted: YCMServiceAgent ***** [ Registry ] ***** ***** [ Web browsers ] ***** [-] [C:\Users\William\AppData\Local\Google\Chrome\User Data\Default\Web data] [search Provider] Deleted: aol.com [-] [C:\Users\William\AppData\Local\Google\Chrome\User Data\Default\Web data] [search Provider] Deleted: ask.com ************************* :: "Tracing" keys deleted :: Winsock settings cleared ************************* C:\AdwCleaner\AdwCleaner[C0].txt - [1008 Bytes] - [30/05/2017 10:56:46] C:\AdwCleaner\AdwCleaner[s0].txt - [1530 Bytes] - [30/05/2017 10:56:31] ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [1154 Bytes] ########## Quote
mikehende Posted May 30, 2017 Author Posted May 30, 2017 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 8.0.7 (07.03.2016) Operating System: Windows 10 Home x64 Ran by William (Administrator) on Tue 05/30/2017 at 10:12:23.18 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ File System: 5 Successfully deleted: C:\ProgramData\1455496454.bdinstall.bin (File) Successfully deleted: C:\ProgramData\1455496878.bdinstall.bin (File) Successfully deleted: C:\ProgramData\1455497607.bdinstall.bin (File) Successfully deleted: C:\ProgramData\1459140556.bdinstall.bin (File) Successfully deleted: C:\ProgramData\1462076091.bdinstall.bin (File) Registry: 2 Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{5A987836-71CB-4EDC-81D8-F32079DA6332} (Registry Key) Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{5A987836-71CB-4EDC-81D8-F32079DA6332} (Registry Key) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on Tue 05/30/2017 at 10:15:47.21 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Quote
mikehende Posted May 30, 2017 Author Posted May 30, 2017 SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 05/30/2017 at 10:11 AM Application Version : 6.0.1194 Database Version : 11920 Scan type : Complete Scan Total Scan Time : 00:15:23 Operating System Information Windows 8 64-bit (Build 6.02.9200) UAC On - Limited User Memory items scanned : 992 Memory threats detected : 0 Registry items scanned : 61595 Registry threats detected : 0 File items scanned : 21511 File threats detected : 0 ============ End of Log ============ Quote
FPCH Staff Tony D Posted May 30, 2017 FPCH Staff Posted May 30, 2017 Is it trying to connect wirelessly or wired (Ethernet cable)? If wirelessly, make sure the wireless radio is turned on. Do you see a list of available networks? Do other computers connect to the Internet at your cousin's place? Also check the Device Manage to ensure that there are no red or yellow marks associated with the network drivers. Quote
mikehende Posted May 30, 2017 Author Posted May 30, 2017 I had gone through all of what's mentioned above. I tried both type connections, same deal. The wireless switch is turned on. All networks are showing. I have his laptop here at my home. The DM didn't show any yellowed networking items. Also windows Network troubleshooting did not find anything. Quote
FPCH Staff Tony D Posted May 30, 2017 FPCH Staff Posted May 30, 2017 OK, good. Can you ping the router? If yes, then go one step further and ping a site like www.google.com. Quote
FPCH Staff Tony D Posted May 30, 2017 FPCH Staff Posted May 30, 2017 Can't find host when ping router or Google? Quote
mikehende Posted May 30, 2017 Author Posted May 30, 2017 can't find host pinging google but shows connection to the router Quote
FPCH Staff Tony D Posted May 30, 2017 FPCH Staff Posted May 30, 2017 Can you ping 65.199.32.183 Quote
FPCH Staff Tony D Posted May 30, 2017 FPCH Staff Posted May 30, 2017 Then you have a DNS issue. Check your DNS settings. Are they set to Auto? Quote
mikehende Posted May 30, 2017 Author Posted May 30, 2017 I have zero issues with any of my other pc's on the network so I don't have a networking issue here. The problem exists only with his laptop in the same way that he is having at his home. Quote
FPCH Staff Tony D Posted May 30, 2017 FPCH Staff Posted May 30, 2017 You don't have a networking issue, you have a DNS issue. DNS is what translates URLs to IP addresses. You can get to Google by pinging their IP address (65.199.32.183), but you can't if you use the URL. Check the DNS settings on the laptop. Quote
mikehende Posted May 30, 2017 Author Posted May 30, 2017 Ohh I see, I had thought you were referring to my network itself. The laptop's DNS settings is set to "Obtain DNS server address automatically". Quote
FPCH Staff Tony D Posted May 30, 2017 FPCH Staff Posted May 30, 2017 Try configuring the DNS to use Open DNS. Those settings are: 208.67.222.123 208.67.220.123 Also, post your hosts file. It's located at C:\Windows\System32\Drivers\etc. You should be able to open it with NotePad. Copy and past the contents here. Quote
FPCH Staff Tony D Posted May 30, 2017 FPCH Staff Posted May 30, 2017 by "Doesn't work" are you saying that the laptop still won't connect to the Internet after configuring it to use Open DNS? Please post the host file. Quote
mikehende Posted May 30, 2017 Author Posted May 30, 2017 Yes exactly. # Copyright © 1993-2009 Microsoft Corp. # # This is a sample HOSTS file used by Microsoft TCP/IP for Windows. # # This file contains the mappings of IP addresses to host names. Each # entry should be kept on an individual line. The IP address should # be placed in the first column followed by the corresponding host name. # The IP address and the host name should be separated by at least one # space. # # Additionally, comments (such as these) may be inserted on individual # lines or following the machine name denoted by a '#' symbol. # # For example: # # 102.54.94.97 rhino.acme.com # source server # 38.25.63.10 x.acme.com # x client host # localhost name resolution is handled within DNS itself. # 127.0.0.1 localhost # ::1 localhost Quote
FPCH Staff Tony D Posted May 30, 2017 FPCH Staff Posted May 30, 2017 Thanks, that looks good. Temporarily, turn off the firewall. btw: what firewall are you using? I have to leave for a while. I"ll check back later on. Quote
mikehende Posted May 30, 2017 Author Posted May 30, 2017 The system doesn't allow me to turn the firewall on/off. It is showing "These settings are being managed by vendor application Bitdefender firewall. Quote
FPCH Staff Rustys Posted May 30, 2017 FPCH Staff Posted May 30, 2017 Tony just going to jump in real quick and add to the advice you have already given. Just to clarify Does it tell you that there is no network connection or you open a browser attempt to access a site and it goes no where and displays an error of some sort. Just some questions I have. 1. It stopped going on the net have you tried a different browser? 2. Do you have a thumb drive that you can use to copy files from the system with the issue to another system that you can post from? 3. Flush the DNS list Open and Administrator Command Prompt by pressiung the Windows Key + X and then Select Command Prompt (Admin) Type ipconfig /flushdns Try browsing and see if that help Download Minitoolbox on a working system and use the thumb drive to put the file on the desktop and run on the affected system. Run the tool by right-mouse click and select "Run as Administrator". Check mark following radio buttons: Flush DNS Report IE Proxy Settings Reset IE Proxy Settings Report FF Proxy Settings Reset FF Proxy Settings List content of Hosts List IP configuration Click Go the results will appear as a txt file on your Desktop. Please copy & paste this report in your next reply. Quote "Confucius could give answer to that... unfortunately Confucius not here at moment."
mikehende Posted May 30, 2017 Author Posted May 30, 2017 Just to clarify Does it tell you that there is no network connection or you open a browser attempt to access a site and it goes no where and displays an error of some sort. Just some questions I have. 1. It stopped going on the net have you tried a different browser? 2. Do you have a thumb drive that you can use to copy files from the system with the issue to another system that you can post from? 3. Flush the DNS list Type ipconfig /flushdns Try browsing and see if that help . It shows as connected to my network. Yes tried both IE and chrome flush did not help. MiniToolBox by Farbar Version: 17-06-2016 Ran by William (administrator) on 30-05-2017 at 14:48:30 Running from "F:\AV Softwares" Microsoft Windows 10 Home (X64) Model: HP 15 Notebook PC Manufacturer: HP Boot Mode: Normal *************************************************************************** ========================= Flush DNS: =================================== Windows IP Configuration Successfully flushed the DNS Resolver Cache. ========================= IE Proxy Settings: ============================== Proxy is not enabled. No Proxy Server is set. "Reset IE Proxy Settings": IE Proxy Settings were reset. ========================= Hosts content: ================================= ========================= IP Configuration: ================================ Realtek PCIe FE Family Controller = Ethernet 2 (Connected) Realtek RTL8188EE 802.11 bgn Wi-Fi Adapter = Wi-Fi (Media disconnected) # ---------------------------------- # IPv4 Configuration # ---------------------------------- pushd interface ipv4 reset set global icmpredirects=enabled set interface interface="Ethernet 2" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled set interface interface="Local Area Connection* 1" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled set interface interface="Local Area Connection* 2" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled set interface interface="Wi-Fi" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled set interface interface="Local Area Connection* 3" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled popd # End of IPv4 configuration Windows IP Configuration Host Name . . . . . . . . . . . . : DESKTOP-82NSOA6 Primary Dns Suffix . . . . . . . : Node Type . . . . . . . . . . . . : Hybrid IP Routing Enabled. . . . . . . . : No WINS Proxy Enabled. . . . . . . . : No DNS Suffix Search List. . . . . . : fios-router.home Wireless LAN adapter Local Area Connection* 2: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Microsoft Wi-Fi Direct Virtual Adapter Physical Address. . . . . . . . . : 4A-E2-44-0F-29-F2 DHCP Enabled. . . . . . . . . . . : Yes Autoconfiguration Enabled . . . . : Yes Ethernet adapter Ethernet 2: Connection-specific DNS Suffix . : fios-router.home Description . . . . . . . . . . . : Realtek PCIe FE Family Controller #2 Physical Address. . . . . . . . . : B0-5A-DA-DB-DE-49 DHCP Enabled. . . . . . . . . . . : Yes Autoconfiguration Enabled . . . . : Yes Link-local IPv6 Address . . . . . : fe80::3409:f0c:2d2f:6216%3(Preferred) IPv4 Address. . . . . . . . . . . : 192.168.1.15(Preferred) Subnet Mask . . . . . . . . . . . : 255.255.255.0 Lease Obtained. . . . . . . . . . : Tuesday, May 30, 2017 10:57:47 AM Lease Expires . . . . . . . . . . : Wednesday, May 31, 2017 10:57:47 AM Default Gateway . . . . . . . . . : 192.168.1.1 DHCP Server . . . . . . . . . . . : 192.168.1.1 DHCPv6 IAID . . . . . . . . . . . : 95443674 DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-1D-BA-E1-9B-B0-5A-DA-DB-DE-49 DNS Servers . . . . . . . . . . . : 192.168.1.1 NetBIOS over Tcpip. . . . . . . . : Enabled Wireless LAN adapter Wi-Fi: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : fios-router.home Description . . . . . . . . . . . : Realtek RTL8188EE 802.11 b/g/n Wi-Fi Adapter Physical Address. . . . . . . . . : 48-E2-44-0F-29-F2 DHCP Enabled. . . . . . . . . . . : Yes Autoconfiguration Enabled . . . . : Yes Tunnel adapter isatap.fios-router.home: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : fios-router.home Description . . . . . . . . . . . : Microsoft ISATAP Adapter Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes Tunnel adapter Teredo Tunneling Pseudo-Interface: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes DNS request timed out. timeout was 2 seconds. Server: UnKnown Address: 192.168.1.1 DNS request timed out. timeout was 2 seconds. DNS request timed out. timeout was 2 seconds. DNS request timed out. timeout was 2 seconds. DNS request timed out. timeout was 2 seconds. Ping request could not find host google.com. Please check the name and try again. DNS request timed out. timeout was 2 seconds. Server: UnKnown Address: 192.168.1.1 DNS request timed out. timeout was 2 seconds. DNS request timed out. timeout was 2 seconds. DNS request timed out. timeout was 2 seconds. DNS request timed out. timeout was 2 seconds. Ping request could not find host yahoo.com. Please check the name and try again. Pinging 127.0.0.1 with 32 bytes of data: Reply from 127.0.0.1: bytes=32 time<1ms TTL=128 Reply from 127.0.0.1: bytes=32 time<1ms TTL=128 Ping statistics for 127.0.0.1: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 0ms, Maximum = 0ms, Average = 0ms =========================================================================== Interface List 8...4a e2 44 0f 29 f2 ......Microsoft Wi-Fi Direct Virtual Adapter 3...b0 5a da db de 49 ......Realtek PCIe FE Family Controller #2 10...48 e2 44 0f 29 f2 ......Realtek RTL8188EE 802.11 b/g/n Wi-Fi Adapter 1...........................Software Loopback Interface 1 9...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter 13...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface =========================================================================== IPv4 Route Table =========================================================================== Active Routes: Network Destination Netmask Gateway Interface Metric 0.0.0.0 0.0.0.0 192.168.1.1 192.168.1.15 35 127.0.0.0 255.0.0.0 On-link 127.0.0.1 331 127.0.0.1 255.255.255.255 On-link 127.0.0.1 331 127.255.255.255 255.255.255.255 On-link 127.0.0.1 331 192.168.1.0 255.255.255.0 On-link 192.168.1.15 291 192.168.1.15 255.255.255.255 On-link 192.168.1.15 291 192.168.1.255 255.255.255.255 On-link 192.168.1.15 291 224.0.0.0 240.0.0.0 On-link 127.0.0.1 331 224.0.0.0 240.0.0.0 On-link 192.168.1.15 291 255.255.255.255 255.255.255.255 On-link 127.0.0.1 331 255.255.255.255 255.255.255.255 On-link 192.168.1.15 291 =========================================================================== Persistent Routes: None IPv6 Route Table =========================================================================== Active Routes: If Metric Network Destination Gateway 1 331 ::1/128 On-link 3 291 fe80::/64 On-link 3 291 fe80::3409:f0c:2d2f:6216/128 On-link 1 331 ff00::/8 On-link 3 291 ff00::/8 On-link =========================================================================== Persistent Routes: None **** End of log **** Quote
FPCH Staff Tony D Posted May 30, 2017 FPCH Staff Posted May 30, 2017 (edited) The system doesn't allow me to turn the firewall on/off. It is showing "These settings are being managed by vendor application Bitdefender firewall.So you need to go to the Bitdefender app to turn off the firewall. Bitdefender can probably be accessed via the Notification Area (that's next to the clock). You may have to right click on it and go to settings. Edited May 30, 2017 by Tony D Quote
Recommended Posts