Lost internet after running ccleaner

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by webbyte, Dec 20, 2007.

  1. webbyte

    webbyte Private E-2

    Attempting to get rid of BHO.CVX and Packed.Morphine.d
    Working through Read and Run Me First. After running CCleaner as user went to Safe Mode and ran it as Administrator. Now internet connection no longer working. The Local Area Connection is there but no I/P addresses appearing under Status. Tried repair and get message: Windows could not finish repairing the problem because the following action cannot be completed. Failed to query TCP/IP setting of the connection, cannot proceed.

    System Restore was shut off (I didn't shut it off.)

    There was an entry under the system event log re: TCP/IP Protocol Driver Invalid.

    Tried netsh winsock reset catalog - then - netsh int ip reset c:\resetlog.txt but didn't help

    Dell Dimesion E521, Windows XP SP2, Broadcom 440X.

    Other programs and printer seems to be working okay.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    CCleaner only removes temporary non-required and non-useful files and will not impact the ability to connect to the internet. That is unless more than just what was specified in the READ ME was run. What options of CCleaner were run? Did you use the Issues tab an perform registry cleaning?

    You can try giving the below a run and see what happens:

    XP TCP/IP Repair
     
  3. webbyte

    webbyte Private E-2

    I ran ccleaner with default options. Didn't make any changes. Didn't even check to see if anything was selected under Applications tab. If I clicked Run Cleaner with the Windows tab displayed would it have done anything with the items under Applications tab? Used ccsetup203_slim.exe. Didn't even look at Registry, Tools, or Options.

    Also had problems with AVG AntiSpyware (which had been installed and run before running ccleaner). After running ccleaner, AVG Antispyware didn't appear to be starting at Windows startup. Got an error message when trying to run manually, which I wasn't able to write down. Tried uninstalling AVG Antispyware and it hung. Went into Task Manager and avg antispyware was running. Ended the process and then the uninstall completed.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Potentially yes!

    Did you try the link I gave you? If so, did it help?


    Have you been able to run ComboFix and MGtools?
     
  5. webbyte

    webbyte Private E-2

    After the problems with ccleaner, I didn't try any other tools. The computer is at another location so won't be able to get back to it until tomorrow. Thanks for your prompt response. I'll let you know as soon as I try the other things.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Even if you do not get the internet connection working, try to download ComboFix and MGtools.exe onto another PC and transfer to the problems PC somehow (USB drive, CD....etc) then get the logs from the infected PC posted here in the reverse manner if possible.
     
  7. webbyte

    webbyte Private E-2

    Tried running the TCP/IP program and it didn't restore internet connectivity. Didn't try the Winsock portion of the program because wasn't sure what might need to be reinstalled after that was run.

    Attached are the log files from combofix and mgtools
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But this is more than likely the critical one to run since a broken LSP chain is often (but not always) the reason for not internet access.



    You have no protection software installed!!! No wonder you are infected.

    Once you get your internet connection working you need to uninstall J2SE Runtime Environment 5.0 Update 6 and then install the current version of Sun Java from the below link:
    Sun Java Runtime Environment

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [1sr48] C:\WINDOWS\system32\1sr48.exe
    O4 - HKCU\..\Run: [1sr48] C:\WINDOWS\system32\1sr48.exe

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  9. webbyte

    webbyte Private E-2

    Did have AVG AntiVirus and AVG AntiSpyware installed but after running ccleaner the first time was having problems with AVG AntiSpyware not running correctly so uninstalled both AVG products. Since the computer had lost internet connectivity figured it didn't matter until it was back on the internet.

    When running avenger, got Windows - No Disk
    Exception Processing Message
    c0000013 Parameters 75b6bf9c 4 75b6bf9c 76b6bf9c

    Only ran ccleaner under user - should it also be run again under Safe Mode for Administrator?

    When running GetLogs.bat got ProcessDll.exe window
    Application has generated an exception that could not be handled
    Process id=0xfbc (4028), Thread id=0xfe8 (4072)
    Chlick OK to terminate the application
    Click Cancel to debug the application

    New logs attached
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not really a valid assumption! The tools do not just protect you while connected. They are meant to protect you anytime your PC is running. Also note AVG Antispyware only provides protection during a 15 day trial period. After that, it is only a scanner and offers no protection. You need a realtime antispyware blocking tool, an antivirus, and a real bidirectional firewall installed at all times.

    Did you run the Winsock fix part of XP TCP/IP Repair yet? If not, you should run it.
     
  11. webbyte

    webbyte Private E-2

    Ran the winsock portion of TCP/IP repair but still no internet connection. When restarting the computer it appears to stall but think it is trying to connect to the internet as the link light on router blinks about ten times, stops, and then blinks again. Then windows finishes the startup. After that the link light on the router blinks occasionally so believe the hardware and cables are all okay. Under Status it is incrementing the time like it has a connection but there is no activity and no I/P numbers under Support.

    SpyBot is also installed and running Immunize.

    How do the logs look?
     
  12. webbyte

    webbyte Private E-2

    Under Event Log System

    TCP/IP Protocol Driver Service failed to start:
    specified driver is invalid


    Following boot-start or system-start drivers failed to load
    nvatabus
    nvraid
    Tcpip
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean! Your problem appears to be related to other issues that you may wish to work thru in the Software Forum. Your tcpip.sys file could be corrupted and so may other files. You should run sfc /scannow from the Start, Run, box. If could ask for your Windows CD if it finds problems and cannot find appropriate files on your PC to fix the problems. Be prepared to give it your CD if it asks for it.

    Those other files are for your Nvidia graphics controller.
     
  14. webbyte

    webbyte Private E-2

    In checking driver files, found that tcpip.sys file in system32\drivers was dated 12/20/2007, 6:57PM which was when I was running clean-up on the computer but don't know if it was when I was running ccleaner. Renamed tcpip.sys and was going to replace it with tcpip.sys from another XP computer but when I tried to copy it, was told that it already existed. Unhid system files and tcpip.sys was there. Don't know how there could have been 2 versions of the same file in the directory at the same time, one hidden and one not, but that appears to be what happened. Rebooted and was was able to connect to the Internet.

    However, there were still problems. First clue was Google warned that a program was trying to change the search engine in IE and I hadn't even opened IE.

    Ran Spybot and nothing.

    Installed and ran AVG free Antivirus and it found infections:
    wdtzuvc.bak (Packed.morphine.d) in a user directory in Documents&Settings
    dsdmoprpl.dll and audiodevf.dll in C:\qoobox\Quarantine
    dsdmoprpl.dll.bak in windows\system32 identified as Obfustat.ACRR
    AVG indicated found 4 items, moved 2 items to vault and deleted 1.

    So don't know if the machine is re-infected. How can I be sure it is not?

    Do I need to do any clean-up? Where did C:\qoobox\Quarantine come from?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No that is not what you had. As soon as you renamed tcpip.sys, the Windows OS replace it with a backup copy from the dllcache folder. That is why you could not copy another one in.

    This is a quarantine folder created you ran ComboFix. Things in this folder are not issues since they are quarantined. You can delete the whole C:\Qoobox folder though since we do not need it.

    NOTE: Other user accounts on your PC could also be infected which may be why you said AVG found things in a user account.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created.
     
    Last edited: Jan 12, 2008
  16. webbyte

    webbyte Private E-2

    Here is the final scan after all cleanup completed.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have some problems.

    Run this procedure: Trojan.Win32.Agent.akk (aka IEDefender) Removal Procedure
    Attach the requested log later.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: Rates - {04B0AACB-ADE6-45C7-9989-7836E8DC8C3D} - C:\WINDOWS\toprates.dll (file missing)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.

    Now download the current version of MGtools.exe to C:\
    Then double click on C:\MGtools.exe to run the new version and create a new C:\MGlogs.zip file.

    Attach the new MGlogs.zip file and also the FixIEDef.log
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds