Infected Computer w/No Internet Access (After Running Anti-Virus Etc Programs!)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by kc17, Aug 3, 2006.

  1. kc17

    kc17 Private E-2

    Please help! I followed the steps (as best I could) listed in "What to do before you post HijackThis Log" but I'm certain that my computer is still infected. If someone could please decipher what is wrong, I would be VERY grateful. (FYI - I'm pretty computer illiterate so if I am saying too much, not enough, I apologize.)

    Background: I have no internet access on my home desktop, but another desktop in same room has access. After I ran the anti-virus, etc. programs (listed below), I tried to get back on the internet and, for about 3 minutes, I had access. But then it stopped again.

    Computer Specs: (Specs from my Belarc summary, but let me know if you need more specific info.)

    System:Dell4600i
    OS:Windows XP SP2 (build 2600)
    Processor:2.80 GHz Intel Pentium 4, 8mb cache, 512kb secondary cache
    Drives: Maxtor 120GB Hard Drive, 119.97 GB capacity, 73.07 GB free space
    Samsung DVD-ROM SD-616E
    TEAC DVD+RW DV-W50E
    Memory: 512MB
    Nvidia GeForce 6200 Graphics Card
    SoundMAX Integrated Digital Audio
    Communication: BCM V.92 56K Modem; Intel(R) Pro/100 VE Network Connection.
    Virus Protection: ZoneAlarm Security Suite 6.5.722.000; avast! antivirus 4.7.844; Norton Antivirus 2005 [*I uninstalled this thing with Symantec uninstall tool a while back, so I have no idea how this freakin' thing keeps coming back...]


    I ran the following programs in Safe Mode with clean results:
    CCleaner
    Windows Malicious Removal Tool
    Ad-Aware SE Personal
    Spybot S&D
    CWShredder
    Kill2Me
    McAfee AVERT Stinger

    Ewido found the virus "Agobot.XB" which I deleted from quarantine.
    ZoneAlarm found the trojan "Backdoor.Win32.mIRC.bacd" which I deleted.
    ZoneAlarm also found a virus "Zipper.2779.l" that was treated.

    In Normal mode, I ran BitDefender 8 Free Edition (not online scan; I downloaded program on disk and loaded onto my computer) - See attached log.

    Because I could not load any updates to Windows Defender (and it said 189 days old without updates), I did not run the scan, but let me know if I should. Because no internet access, I could not run Panda ActiveScan either. And, I screwed up while writing down directions and did not see the directions to perform the "Runkeys.txt and Newfiles.txt" actions until after I had run all the other scans. Sorry. Please let me know if I should do so.

    After running scans and cleaning infections, I turned off "System Restore" and then rebooted and turned back on. I also made sure to do "Normal Bootup" before HJT log.

    Attached are the BitDefender and HJT logs. I hope I saved them in the correct format; like I said, I'm a computer novice. Any help would be GREATLY appreciated! Thank you!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Yes please post the runkeys.txt and newfiles.txt logs now.

    You also need to uninstall all but one antivirus program as step 3 of the READ ME specifies.
     
  3. kc17

    kc17 Private E-2

    Chaslang,

    Thanks for reply. Attached are the two logs you requested. Regarding the anti-virus programs, Norton is not listed as a program in the Control Panel (and I used their uninstall program to get rid off), so I'm not sure how to totally delete it from the computer. I use ZoneAlarm for its firewall (I just ran the Anti-Virus program to see if it found anything that others did not). Is this not okay to do? Thanks again.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Who mentioned Norton? You have Avast and Bitdefender AV installed. Uninstall one and then attach a new HJT log. You must NEVER have two antivirus applications installed at the same time. This can really mess up Windows Security Center.
     
    Last edited: Aug 4, 2006
  5. kc17

    kc17 Private E-2

    Okay, I uninstalled BitDefender and I've attached the newest HJT log. Please let me know if you think there's anything else I should uninstall now (like Windows Defender or the like). Thanks again for your help.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You logs do not show any major malware problems that would be causing problems with internet access. Are you still unable to connect to the internet?

    Note: In message number 1 you said you toggled System Restore. You should should only have done this after verifying that all malware was removed. Now you have no restore point to fall back on which is the whole point behind waiting until all malware is removed. It is a safety net to fall backon if something goes wrong.

    You still appear to be using to antivirus application. You have isafe.exe, which is a part of Computer Associates eTrust AntiVirus (this is also where you got ZoneAlarm firewall from). Is this a paid version? If it is, then you need to uninstall Avast.

    Is Ewido a paid version or free trial version?

    You have a few minor things that should be fixed!

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ms101.mysearch.com/sa/srchlft.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ms101.mysearch.com/sa/srchlft.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ms101.mysearch.com/sa/srchlft.html
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
    R3 - Default URLSearchHook is missing
    O20 - Winlogon Notify: AutorunsDisabled - C:\WINDOWS\

    After clicking Fix, exit HJT.:

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now and answer any questions that were asked.
     
  7. kc17

    kc17 Private E-2

    Chaslang,

    First, to answer the questions you had:
    1. No, I do not have eTrust Antivirus installed on my computer (even though I see it listed in HJT log). Should I delete it?
    2. I have the free version of Ewido. I do not run it in the background of my computer; I only use it to scan and then I close the application.

    I reset the web settings like you asked, but quick (and probably dumb) question: I use Firefox most of the time (unless the site only supports IE) - so is there anything I need to do specifically with Mozilla?

    Attached is the latest HJT log. However, a few novice questions:
    1. For "08 - Extra content menu items" I definitely don't recognize the first one (mywebsearch.com) and I don't know about any Excel addons for IE. May I delete these two items?
    2. For "016 - DPF" there are three entries from symantec.com. Because I have tried to delete any sign of Norton from my computer, may I delete these three entries?
    3. For "017 HKLM\System\CCS\Services\Tcpip\...Nameserver = ..." I tried to Google the IP address but didn't find it (and hopefully I googled correctly). Should I delete this entry?

    And, if I can ask one other quick question (though I realize you're extremely busy helping other people so feel free to ignore), do you have any personal recommendations for anti-virus/spyware programs I should use that may reduce likelihood of this happening in the future?

    Thank you so much!!!!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below line is a system service:

    O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe

    It cannot be simply deleted.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to CA ISafe ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    CAISafe

    If you receive any error messages just ignore them and continue.

    Now exit HJT and reboot when it tells you it needs to.

    Not really true as you think! A service for Ewido is always running

    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe

    and it is using system resources and could conflict with Windows Defender.


    You could just clear the cache.


    That is part of what I had you fix in my previous message. I just missed that line. Fix it.

    Yes!

    Isn't it your ISP?
    It's all in the final steps of our cleanup! ;) See below!

    You never said whether you still had problems connecting to the internet!

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  9. kc17

    kc17 Private E-2

    Chaslang,

    Okay, I (hope) I did what you said:
    [1] I disabled CAISafe and then deleted it as "an NT Service" per your instructions.
    [2] I uninstalled Ewido.
    [3] I deleted the first "08 Extra context menu items" but I did not understand from your previous message whether or not you wanted me to delete the second "08 Entry" so I've kept it for now. Please let me know if I should do otherwise, as well is with the 09 Entry - "Extra button: Research..."
    [4] I also deleted the three "016" Symantec entries.
    [5] I disabled/re-enabled System Restore.
    [6] I've run HJT again and attached the newest log.

    My internet connection seems to be working now!

    Although everything seems to be working fine, if the above 08 and 09 HJT entries seem odd, or if you see anything in the attached HJT log that still looks bad, please let me know! And again, I really appreciate you taking the time to go through this and help me out (as well as the patience that you needed to deal with someone who hasn't read the word 'binary' since biology class). Thank you so much!!!!!
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds