IE7 and Firefox Internet Access deux

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by flatlandersj, Nov 5, 2008.

  1. flatlandersj

    flatlandersj Private E-2

    firefox and ie cannot display any pages. much the same with the recent post IE7 and Firefox Internet Accessbut i wanted to post my own so that the logs may receive attention

    along with the issues i get a java script error when trying to access a page in firefox i will attach a screen shot of the error.
     

    Attached Files:

  2. flatlandersj

    flatlandersj Private E-2

    and the java script error vvv
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, flatlandersj

    Please attach the requested log from running ComboFix - it's location would be:

    C:\ComboFix.txt
     
  4. flatlandersj

    flatlandersj Private E-2

    guess i missed one, there you go. It is from the same time as the others.
     

    Attached Files:

  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, flatlandersj

    * It may be helpful to print these instructions or Copy & Paste them into a notepad doc, as you need to be offline while doing the following:

    Step 1:
    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Step 2:
    We need to use ComboFix to remove some malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    c:\windows\system32\1E99800F3F.sys
    
    Folder::
    G:\Program Files\Viewpoint
    
    Driver::
    Viewpoint Manager Service
    
    Registry::
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] 
    

    Step 3:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Step 4:
    Delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    Step 5:
    Run Ccleaner


    Step 6:
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).


    Then attach the below logs to your next reply:
    • C:\MGlogs.zip
    • C:\combofix.txt

    Make sure you tell me how things are working now!
     
  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :)

    * Refer to Step 2:

    After pasting the text in the code box into Notepad:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      [​IMG]
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    NOW, continue on to Step 3:...
     
  7. flatlandersj

    flatlandersj Private E-2

    ok so i ran everything but... I forgot to uninstall messenger untill right before running MGlogs. I didn't want to go through the sequence again without prior approval.
    I still have no internet access yet I can connect to the other computers on the network. Firefox still gives me the java error and Comodo pops up with stuff trying to reach the net when I start Firefox or explorer.

    the only thing that throws a flag is when starting Firefox, Comodo says that jgsnotify.exe is trying to connect to the internet. not sure if that's significant.
     

    Attached Files:

  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  9. flatlandersj

    flatlandersj Private E-2

    theres the log for you.

    the path is G:\Program Files\Java\jre6\bin\jqsnotify.exe
    i misread the file name in the previous post so the above is the correct name.
     

    Attached Files:

  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello again, flatlandersj

    "G:\Program Files\Java\jre6\bin\jqsnotify.exe" is a legit file from Sun Microsystems, Inc.

    Please download and run
    WinSock XP Fix 1.2.

    Next run the C:\MGtools\GetLogs.bat file again by double clicking on it Note: if using Vista, use right click and select Run As Administrator).


    Then attach the C:\MGlogs.zip log to your next reply.

    Remember to tell me if you still have problems.
     
  11. flatlandersj

    flatlandersj Private E-2

    So it is finally working. The winsockxpfix did it. The first thing I did was update Comodo and AVG. I have SUPER antispyware running should I? or is it redundant?

    another question,
    with the winsock was it malware or could it have been an update that corrupted the dll?
    I ask because I'm having a similar problem with my laptop and I would like to try and fix that now.

    Thank you so much for helping me to fix my computer :)
     

    Attached Files:

  12. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;)

    Your logs are clean, flatlandersj.

    It's kind of hard to say but it very well could have been the malware infection... and your question about the anti-malware scanners are answered below:

    Please start a new thread if you wish your laptop cleaned. And since you have similar problems with it, go ahead and run WinSock XP Fix 1.2. on it AFTER first completing the READ & RUN ME First guide.


    You're Very Welcome! Safe surfing! [​IMG]
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds