[Resolved] WebShield preventing internet browsing after a while(DNS Fails)

I noticed a problem today after installing avast last night. My internet browsing stops after a while. I get the cannot find page message of I can see it downloading webpage files but the page never refreshes and shows me the new page. I tried turning off the XP firewall when this problem happens and disabling WebShield but it doesn’t help. If I repair the Internet connection in XP, I can start browsing again but the it fails again soon after that. I had to actually terminate the WebShield service and reboot the PC to prevent this from happening.

I am using XP Home w/SP2 and IE with all the latest updates. I am using the 4.6.623 avast. I see posts about allowing the webshield service in the firewall but it works for a while as it is and then stops…so I don’t think it’s that. Anyone else notice this?

I doubt that it is Web Shield causing this problem as it would prevent access period, not after a while, it either works or it doesn’t. The fact that disabling Web Shield doesn’t seem to make a difference would also point to something else.

How does Terminating Web Shield prevent this happening? Rebooting the PC is likely to have been what resolved an issue.

The XP firewall is ok for inbound protection, but provides no outbound protection.

There may well be some adware/spyware/malware that is having an effect on your computer.

If you haven’t already got this software, download, install, update and run it.

  1. Ad-Aware
  2. Spybot Search and Destroy
  3. Spywareblaster
  4. Download HijackThis.zip - HiJackThis Tutorial post a copy of the contents of the HiJackThis log file here.

Well, I checked my system with Ad-Aware. I did the complete test after downloading new definition files and it is clean. This is also happening on another PC in the house that I installed avast on. They are both XP Home SP2. If it’s not webshield, could it be another module in avast? It’s very strange that this started happening after installing avast. Thanks.

I hve the same problem and i am running the smae stuff…any ideas?

ogfile of HijackThis v1.99.1
Scan saved at 14:31:56, on 17/04/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\FreeMeter\FreeMeter.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Documents and Settings\Bob Smith\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchAssistant = http://www.google.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.google.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://www.google.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.co.uk
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.co.uk
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.google.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.co.uk
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.google.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.google.co.uk
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.google.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = MIKE
O1 - Hosts: 64.246.26.137 sina.com.cn
O1 - Hosts: 64.246.26.137 163.com
O1 - Hosts: 64.246.26.137 sohu.com
O1 - Hosts: 64.246.26.137 list2004.com
O1 - Hosts: 64.246.26.137 worldmpeg.com
O1 - Hosts: 64.246.26.137 casino.com
O1 - Hosts: 64.246.26.137 lycos.com
O1 - Hosts: 64.246.26.137 excite.com
O1 - Hosts: 64.246.26.137 dmoz.org
O1 - Hosts: 64.246.26.137 wisenut.com
O1 - Hosts: 64.246.26.137 teoma.com
O1 - Hosts: 64.246.26.137 search.com
O1 - Hosts: 64.246.26.137 www.search-all-fast.com
O1 - Hosts: 64.246.26.137 geosites.com
O1 - Hosts: 64.246.26.137 full-search.net

O1 - Hosts: 64.246.26.137 search-all-fast.com
O1 - Hosts: 64.246.26.137 www.full-search.net
O1 - Hosts: 64.246.26.137 www.umaxsearch.com
O1 - Hosts: 64.246.26.137 umaxsearch.com
O1 - Hosts: 64.246.26.137 www.pizdato.biz
O1 - Hosts: 64.246.26.137 search-motor.com
O1 - Hosts: 64.246.26.137 pizdato.biz
O1 - Hosts: 64.246.26.137 www.search-motor.com
O1 - Hosts: 64.246.26.137 38.117.144.162
O1 - Hosts: 64.246.26.137 209.66.114.129
O1 - Hosts: 64.246.26.137 xml.umaxfeed.com.com
O1 - Hosts: 64.246.26.137 searchmiracle.com
O1 - Hosts: 64.246.26.137 x.full-tgp.net
O1 - Hosts: 64.246.26.137 www.searchmiracle.com
O1 - Hosts: 64.246.26.137 www.search-and-more.com
O1 - Hosts: 64.246.26.137 x.full-tgp.net
O1 - Hosts: 64.246.26.137 home.peoplepc.com
O1 - Hosts: 64.246.26.137 peoplepc.com
O1 - Hosts: 64.246.26.137 all-find.net
O1 - Hosts: 64.246.26.137 www.start-page.info
O1 - Hosts: 64.246.26.137 start-page.info
O1 - Hosts: 64.246.26.137 www.young-devils.com
O1 - Hosts: 64.246.26.137 young-devils.com
O1 - Hosts: 64.246.26.137 toolbarpartner.net
O1 - Hosts: 64.246.26.137 www.toolbarpartner.net
O1 - Hosts: 64.246.26.137 www.teocash.com
O1 - Hosts: 64.246.26.137 cgi.gammae.com
O1 - Hosts: 64.246.26.137 teens-dream.com
O1 - Hosts: 64.246.26.137 the.sextracker.com
O1 - Hosts: 64.246.26.137 new-iframe.biz
O1 - Hosts: 64.246.26.137 troyporn.com
O1 - Hosts: 64.246.26.137 213.159.117.133
O1 - Hosts: 64.246.26.137 213.159.117.150
O1 - Hosts: 64.246.26.137 66.180.174.16
O1 - Hosts: 64.246.26.137 find-on-the-net.com
O1 - Hosts: 64.246.26.137 first-time.biz
O1 - Hosts: 64.246.26.137 toolbarcash.com
O1 - Hosts: 64.246.26.137 www.vesbiz.biz
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - (no file)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O4 - HKLM..\Run: [AWMON] “C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe”
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM..\Run: [TkBellExe] “C:\Program Files\Common Files\Real\Update_OB\realsched.exe” -osboot
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: FreeMeter.lnk = C:\Program Files\FreeMeter\FreeMeter.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra ‘Tools’ menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: ICQ 4.0 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra ‘Tools’ menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-

C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe
O9 - Extra ‘Tools’ menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted IP range: 64.127.104.144
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab28177.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15009/CTSUEng.cab
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://files.ea.com/downloads/rtpatch/v2/EARTPX.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/21330e7b6c9634615b23/netzip/RdxIE601.cab
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab28177.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) -
O16 - DPF: {CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA} -
O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} -
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15010/CTPID.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab28177.cab
O16 - DPF: {FFFF0003-0001-101A-A3C9-08002B23E0CC} - http://direct.data-line.us/gba990.exe
O17 - HKLM\System\CCS\Services\Tcpip..{03AE00B0-980B-4D2E-886D-6CAE3474CD39}: NameServer = 194.72.9.38 194.74.65.68
O17 - HKLM\System\CS1\Services\Tcpip..{03AE00B0-980B-4D2E-886D-6CAE3474CD39}: NameServer = 194.74.65.68 194.72.9.34
O17 - HKLM\System\CS4\Services\Tcpip..{03AE00B0-980B-4D2E-886D-6CAE3474CD39}: NameServer = 194.72.9.38 194.74.65.68
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: ERDAS License Server - Unknown owner - C:\Program Files\Leica Geosystems\Shared\Bin\NTx86\lmgrd.exe (file missing)
O23 - Service: iPod Service (iPodService) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: RadClock - Unknown owner - C:\WINDOWS\system32\RadClock.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

I think is probably the Web shield…i try to load up a site…it gets abit loaded then it sits there…nothing happens…when i disengage the websheild it then restarts and it’s normal…but i’m leaving myself open…NOT GOOD!

I see from your hijackthis log that you have(or had) norton installed + kerio firewall.So i think these is where you should look for your problem.I don’t know personally but i have heard that norton can cause problems when unnistaling(not removing itself properly)

Hello
I had the same problem. It isn’t avast problem. You must try to uninstall lastest windows update (14 or 15 april), who “repair” problem with tcp/ip. When I do it, my web browsers back tu normal work. Try It.

I know that doing the IP Repair works but only for a while and then it happens again. I didn’t put the latest Windows updates on my pc untill last night and the problem manifested yesterday before that so it is not the updates. I found that it is DNS that stops working. If I try going to a site using its IP instead of the DNS it works. If I manually enter my cable companies DNS entries in my Local Area Connection’s TCP properties, it works. I was getting DNS automatically. It was getting it from my Motorola SBG900 Gateway. The gateway gets them from the cable company. Now, why all of a sudden can my PC no longer use that setting? The gateway has the correct entries in it. Is there a problem with the gateway? I am going to try to to a reset on the gateway and see if that corrects the problem for good. Could avast be affecting the way TCP properties is working on my PC???

Try to ping the adres as name and as it’s IP. When I was ping sitest i had very good times, but when I wrote name this site to browser, it’s didn’t opened…

Another test which works. When I was delete cookies and temporary internet files, this sites was opened for a while. When I tried to re-open this site it’s don’t works…

P.S. I hope that You understand my broken english…

I think I understand. When the problem occurs, I cannot ping a site by name. It fails. However, I could ping a site by IP. That’s how I know it’s DNS. I reset my cable modem gateway to factory defaults and then re-configured it. Now I will see if it happens again. If it happens again, I am going to uninstall avast and see if I still have the problem. If I do, then I will get the gateway replaced. If I don’t, then I will have to think avast is causing the issue somehow.

Your cable Internet provider wouldn’t happen to be Comcast, would it? They are notorious for DNS problems, especially recently.

No. I have Adelphia Cable here. It’s not the cable company. My gateway gets the proper DNS from the cable co. When my PC is set to get DNS from the gateway. It fails. If I set my PC to get DNS from the cable co. directly, its fine.

The problem looks like it’s resolved. My modem/gateway was faulty. I replaced it and everything appears normal now. I have been running fine now for about 1 week. Just thought I would close this thread.

You can edit the thread Subject add say [Resolved] at the end say.