malware prevent my internet connection

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by haitech, Jun 27, 2007.

  1. haitech

    haitech Private E-2

    Hello Major Geeks,

    Sorry about the trouble, but I have no idea what i've been infected by.

    All I know is that when I start my PC up I get the following message windows pop-up before my PC has fully completed it's start-up.

    "Web page unavailable while offline" - The Web page you requested is not available offline. To view this page, click Connect. [Connect]/[Stay Offline]

    "Work Offline" - No connection to the Internet is currently available. To view Internet content that has been saved on your computer, click Work Offline. Click Try Again to attempt to connect. [Work Offline]/[Try Again]

    I close these windows using either ALT-F4 or clicking on the close window icon as opposed to responding to the prompts.

    These pop-up window combinations continue about 10 - 15 times usually alternating between the two.

    I have followed the advice in the Prep Guide before posting but I still seem to have the same problem.

    What I've done.

    Updated and run Ad-Aware SE - It picked up one critical thing and removed it, I didn't think to note the name of it and it's not mentioned in any of the A-A SE logs that I can see.

    Updated and run Spybot S&D - It picked up a bunch of little stuff but flagged two things, Smitfraud-C.Toolbar888 and SeachToolbarCorp.ToolbarVision

    I'm running Windows XP Pro, SP2.
    I then went to your website and followed your instruction from step 1 to 7. However, I could not use the online scan on step 6a because the virus prevent me from using the internet. I got the counter spy scanned and runkey.bat file, newfile.txt, and hijack this. Please help. the files are attached.

    The Hijackthis file is attached on next post. thanks
     

    Attached Files:

  2. haitech

    haitech Private E-2

    malware prevent my internet connection (Hi jack this file)

    Here is my hijack file
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Hi...my name is Tim and I will be helping you with this.

    You needed to remove all your browser toolbars!! Look at your counterspy log!!
    Please use add/remove programs to uninstall:
    Enhanced Ads by Think-Adz removal
    J2SE Runtime Environment 5.0 Update 10
    Think-Adz Search Assistant removal

    Re-boot and install:
    Java Runtime 6

    Did you notice this in the HJT log:
    O10 - Broken Internet access because of LSP provider 'c:\windows\system32\rlls.dll' missing ----> restore C:\!KillBox\rlls.dll
    C:\!KillBox\rundll32.exe

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt
    Please attach new logs for:
    ShowNew
    GetRun
    HJT
    Avenger
     
  4. haitech

    haitech Private E-2

    HI Tim, Thanks for your help. I followed all the steps you instructed accepted one step you asked me to restore rlls.dll file. You wrote : restore c:\!KillBox\rlls.dll
    C:\!KillBox\rundll32.exe

    I am not sure where to type those. Could you please help?
    Thanks. Here is the attached files



    Long
     

    Attached Files:

  5. haitech

    haitech Private E-2

    Here is the updated HJT file
    Thanks
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You will find the files in C:\!KillBox\ -->(backup files), you should be able to do a restore of those files.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:
    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt
    Please attach new logs for:
    ShowNew
    GetRun
    HJT
    Avenger
     
  7. haitech

    haitech Private E-2

    HI Tim, thanks for your help.

    I am not sure how to restore rlls.dll and rundll32 file so I just copied them from HJT folder and pasted them to c:\windows\system32.

    I only pasted rlls.dll file because it said rundll32.exe already existed in the folder I tried to pasted into. I still could not access to the internet with the same error message.

    here are the logs

    thanks
    Long
     

    Attached Files:

  8. haitech

    haitech Private E-2

    here is the newfile log
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Forgive me...some days are better than others....

    Please download LSPfix from here:
    http://www.downloads.subratam.org/lspfix.zip
    Unzip it to the desktop and run it. Check "I know what I'm doing", and then select each instance of "rlls.dll" in the left-hand panel and click >> to move it to the right-hand panel. Then click Finish to allow LSPfix to rebuild the LSP chain.

    Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:
    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Download SDFix and save it to your Desktop.
    • Run the SDFix.exe by double clicking on it.
    • Allos it to install into the default location which is c:\SDFix
    • Now please reboot your computer into Safe Mode (see this if you don't know how: Starting your computer in Safe mode )
    • When you have booted into safe mode, open the C:\SDFix folder and double click RunThis.bat to start the script.
    • Type Y to begin the cleanup process.
    • It will remove any Trojan Services or Registry entries found and then prompt you to press any key to Reboot.
    • Press any Key and it will restart the PC.
    • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
    • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
    • Attach the Report.txt file to your next message.
    Please attach new logs for:
    SDFix
    Avenger
    HJT
     
  10. haitech

    haitech Private E-2

    Hi Tim,

    Here are the files you requested. I still could not access to the internet. I checked my network card status in the system devices and it was disabled, I enable it and reboot the computer but I still can't connect to the internet service provider. the labtop I use to write you this reply connected on the same router.

    Thanks for your helps
    Long
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run HJT and have it fix this item:
    02 - BHO: (no name) - {DC192567-65F9-4AB6-ADB7-E13575F81726} - C:\WINDOWS\system32\khfefdc.dll (file missing)
    After clicking fix, exit HJT

    Try these to repair your connection.

    IEFix:
    http://www.majorgeeks.com/download4467.html

    Tell me how things are running.
     
  12. haitech

    haitech Private E-2

    Hi tim, I could not run IEfix because during the setup, it asked for a file from service pack 2 cd with address c:\windows\inf\386. I don't have service pack 2 cd.

    other link you gave me was broken, I could not find the site.

    Thanks
    Long
     
  13. haitech

    haitech Private E-2

    Hi Tim, I was managed to get the IEfix run but I still could not get on to the internet. I used the command prompt and type ipconfig and found out that the media status "Media disconnected" in my connection to the ethernet card. I tried to renew but result is still the same. The ethernet cable is connected properly as the router is functioning ok since it allow my laptop connected.

    any Idea?


    Thanks
    Long
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You get no ipconfig info? This is a desktop? Sounds like the eternet card is dead ....you can purchase a card....or a USB connection ....have you tried powering down and removing and then reinstalling the card?
     
  15. haitech

    haitech Private E-2

    Hi Tim,
    )
    It was a desktop. I tried to uninstalled the ethernet card and let the comp detected it again and reinstall it back but same result: no connection. I also tried other ethernet port (built-in on my motherboard ) but same error appear. Should I get a new Ethernet card? If so what brand would you recommend?

    thanks
    Long
     
  16. haitech

    haitech Private E-2

    Hi Tim, here is my most recent HJT scan. the O:23 said something about symantec file missing. Does this have anything to do with my internet connection?
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No it doesn't ...its a left over from when you uninstall the symatec programs ...I also notice you still have Counterspy installed ...unless you plan on purchasing it, uninstall it also.

    The cheapest thing you can purchase is a USB connector (@$30) ....or a USB Wireless connector (@$50) ....

    Are you saying that you moved the card to a different connection on the motherboard?
    This is a hardware issue at this point and I would suggest you post in Hardware ..you will get far more suggestions and troubleshooting in that forum.

    Good luck.
     
  18. haitech

    haitech Private E-2

    Hi Tim,

    I replaced the ethernet card and same error happened. I can't renew the IP address and my LAN display that I have limmited or no connectivity to the ISP. Could you forward this to your hardware guy?

    Thanks
    Long
     
  19. haitech

    haitech Private E-2

    Hi Tim,

    I downloaded the winsockfix and run it. After the reboot, I got my internet connection back, however, once I open yahoo.com, My computer slowed down and adds pop up. I ran the HJT again and serveral supsicious files appear. Please Help.
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What have you done???

    1. Download this file - Combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    * Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    * On the page that opens, scroll down to Command Service
    * then right click the entry, select Properties and press Stop Service.
    * When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    * noW DO THE SAME FOR Network Monitor
    * Click OK until you get back to Windows.

    Tell me if you have problems with this!!

    * Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    * At the lower right, click on the Config button
    * Then click the Misc tools button
    * Select Delete an NT Service
    * Copy/paste cmdService into the box that opens, and press OK
    * If you receive any error messages just ignore them and continue.
    * Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.


    Now re-Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:
    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Attach new logs for:
    ShowNew
    GetRun
    HJT
    Avenger
    ComboFix
     
  21. haitech

    haitech Private E-2

    HI Tim,

    There were some steps I could not follow through in your instructions.

    - I installed and ran combo fix
    -I could not find comand service and network monitor in the services.msc window.
    - I ran HJT first time and I have error when I type cmdService in the box so this step did not go through.
    - I ran HJT again but could not find and check all the boxes that you said. I only found two on my file that were on your list.

    Here are the files.

    Thanks for the help
     

    Attached Files:

  22. haitech

    haitech Private E-2

    Here are the HJT and runkeys
     

    Attached Files:

  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The problems you had were not a problem....some of the nasties were already removed.

    Please use add/remove to uninstall:
    Outerinfo
    Now re-Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking fix, exit HJT

    Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:
    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Attach new logs for:
    ShowNew
    GetRun
    HJT
    Avenger
     
  24. haitech

    haitech Private E-2

    Hi Tim, Happy July 4th.

    I ran HJT but could not find 2 files that you mentioned.

    Here are the attachments
     

    Attached Files:

  25. haitech

    haitech Private E-2

    here is the runkeys
     

    Attached Files:

  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    OK ...your logs look clean...now keep it that way!!!!!!;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds