Help - Search - Members - Calendar
Full Version: wininet.dll
Gladiator Security Forum > Malware Help Forum > HELP! Think you are Infected?
thomas
Hello,

I have a major problem. All of a sudden most of the applications in windows are useless. Each time I want to open it I get the error "classs not registered"
And upon starting I also get the error "THis application failed to start because wininet.dll was not found.....

I already tried the most logic solutions. Like re-installing the wininet.dll, but I can't get paste or unzip it in the system32 folder. acces denied or something?
I don't know.

I followed the steps here downloading adaware and spybot but they both freeze upon installing, giving the following errors "Runtime error (at 10:1166) Acces denie violation at adress 000000000000.

I also get an error with spybot.

hijackthis succeeded, you find the log below

By the way I have Vista Ultimate

I hope you find this problem

thanks

thomas



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:59:19, on 7/04/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\ApVxdWin.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\CyberLink\Shared files\brs.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\WebProxy.exe
C:\Windows\system32\conime.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\wermgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Antivirus 2008\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\Windows\system32\Shdocvw.dll
O13 - Gopher Prefix:
O16 - DPF: {0D6709DD-4ED8-40CA-B459-2757AEEF7BEE} (Dldrv2 Control) - http://download.gigabyte.com.tw/object/Dldrv.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus 2008\PsCtrls.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus 2008\pavsrvx86.exe
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus 2008\PsImSvc.exe
O23 - Service: Panda PSK service (PskSvcRetail) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus 2008\PskSvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

--
End of file - 8401 bytes
LoPhatPhuud
Your log is clean.

THe error you describe is most likely beyond hte scope of this forum but we can at least try to see if the wininet error can be cleared. Its needs to be registered as well as being physically there. Try this...

Start -> run, then enter

regsvr32 %windows%/system32/wininet.dll
thomas
I tried your suggestion

But I received the following error message

THe module regsvr32 %windows%/system32/wininet.dll failed to load. MAke sure the binary is stored at the specific path or debug it to check for problems with the binary or dependent.dll files

I also want to ad that before my PC started malfunctioning i noticed the computer was working slower.

And last week I used smitfraudfix because I had malware that I could not remove. "unidentified trojan....computer is infected...



Hope you still have something up your sleeve?

Already thanks for the qiuck reply

Thomas
LoPhatPhuud
Try the command again, but this time as:
regsvr32 C:\WIndows\system32\wininet.dll

And let me know if it works. If not, most likely the best path is to flatten and repave (Reformat and re-install)

I'll check to see if I can find any other similar issue and if so, what was done.
LoPhatPhuud
When did you install Panda? Did the problem start about the time you installed or updated Panda?


Where did you get the Panda installer? (from Panda web site, other major download site, warez site?)
thomas
The problems indeed started with an error from Panda.

By the way the new run command gave the same error, so it seems a reformat is the obvious choice.

I will wait a couple of days for a miracle.

Maybe a light at the end of the tunnel ? I found someone with the same problem on a Belgian (i'm also Belgian) website, ands strangely enough around the same time this error occured

the link below is to that site

http://www.pc-helpforum.be/f167/vista-wininet-dll-prob-9195/


If you want to pull the plug on this problem, can you give me a tip to retrieve the vital documents. Because I can't get in to the explorer, I started, through use of notepad, recovering one document at a time on my external hard drive.


Again much thanks for the help.

greetings


THomas
LoPhatPhuud
THere is another user here with the same problem.

Uninstall Panda using Add/Remove Programs, then reboot and let me know what is happening. Panda is the common link in both logs.

If Panda is indeed the problem, then check with their website to see if others are reporting the same issue. IBe sure you install an AV if you hold off on Panda. AVG, Avast, and Avira all offer good, free AV that will do in the interim.


If you have trouble uninstalling Panda 2008, check this link: http://www.pandasecurity.com/homeusers/sup...&idIdioma=2
thomas
Hello Lophatphuud,

The problem is solved, thanks to u. Muchos gracias

I did skip one step in your advice. Instead of uninstalling Panda first, i went straight to the website of panda and there they gave a solution to the problem they have caused with one of their latest updates.

If you are interested this is the link http://www.pandasoftware.be/nl/thuisgebrui...servicesupport/

De Panda Antivirus software kan op Windows Vista machines het bestand 'wininet.dll' identificeren als een bestand waar een virus in zit. Als gevolg hiervan wordt het bestand verwijderd. Dit kan voorkomen op Windows Vista computer die nog geen Service Pack 1 geïnstalleerd hebben. Inmiddels wordt het bestand niet meer als geïnfecteerd bestand geïdentificeerd.


Om het probleem op te lossen dient u het 'wininet.dll' bestand terug te plaatsen, dit kan onder andere op volgende wijze:


Start uw computer op in veilige modus met netwerkmogelijkheden. Om dit te doen drukt u tijdens het opstarten een aantal keer op de F8 toets. Kies in het menu voor de veilige modus met netwerkmogelijkheden.


Eens de pc gestart is klikt u op het Start icoon en typt daar 'cmd.exe', druk dan op enter.


In de opdrachtprompt geeft u dan het volgende in:


'ftp 62.99.76.3' en druk dan op enter

Typ nu 'panda' gevolgd door een enter

Type nogmaals 'panda' wederom gevolgd door een enter

Eens u zich in de ftp map bevindt, typt u 'bin' gevolgd door enter

Op de volgende regel typt u dan 'mget solution.exe' en druk enter. Als om bevestiging wordt gevraagd drukt u 'y' (of 'J') in.

Geef nu 'quit' in en druk op enter.

Typ nu 'solution.exe' en druk op enter.


Once again thanks, if I ever come across you I'll buy you a beer (or 2)

Greetings

Thomas
LoPhatPhuud
Thanks.

Glad we got it solved.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.