network connection still broken after SAS Repair

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by thekops, Nov 13, 2008.

  1. thekops

    thekops Private E-2

    Network connection is still broken after running SAS.

    I'm fixing a computer for a friend and following the READ & RUN ME FIRST step-by-step on a Dell Dimension 4300 , Windows 2000 SP4. His harddrive showed UNKNOWN in the bios setup and would not start. I connected his drive as an external drive to my computer, and was able to see all his files. While clicking into some of his Documents & Settings local folders, MY antivirus warned of a TROJAN found. Moved the drive back to his computer. Removed his RAM battery for several minutes, started it up (let chkdsk run, set time and date in bios, etc) and able to get his computer back to showing the desktop. Decided his problem was not hardware, but a malware problem; so came to your site (it's been a GREAT help in the past).

    Had no trouble with HOUSE CLEANING & SETUP (installed current Sun Java, NAV had no quarantined items, ran and installed CCleaner). ENABLED VIEWING HIDDEN FILES... All tools were downloaded onto my computer and moved to his computer via CD. Installed, updated, changed settings, and ran SUPERAntiSpyware with no problems (it detected a few items). I followed the steps to quarantine and remove, then answered YES to reboot.

    Found network connection was broken and followed those steps, using the REPAIRS tab, and answered YES to reboot again. The connection is still broken.

    NOTE: it took a little while to figure out I had to use the REPAIRS button within SAS, but not too long.

    I restarted once again, watching... during startup, the NIC card light flashes once, very briefly, and that's it.

    Attached is the SASlog.txt from SuperAntiSpyware.

    Jeanne
     

    Attached Files:

  2. thekops

    thekops Private E-2

    I do recall during the SAS scan that NAV (norton antivirus) did popup two warnings about the TROJAN. Usually I turn off NAV when doing such things, and usually in SAFE MODE. But that was not in the cleaning steps.

    Any harm/benefit to run SAS again with NAV turned off? Or in SAFE MODE?

    I didn't want to try other things without hearing from you.

    Thanks for help (looks like lots of people are needing it too).
     
    Last edited: Nov 14, 2008
  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, thekops

    Please refer back to the READ & RUN ME FIRST:Malware Removal Guide

    Run all of the tools and attach the requested logs:
    • SASlog.txt log from SuperAntiSpyware.
    • Malwarebytes Anti-Malware log
    • ComboFix.txt (normally C:\ComboFix.txt)
    • MGlogs.zip - normally it is C:\MGlogs.zip - only attach this log from MGtools.exe DO NOT attach any logs seen in the MGtools folder.
    • You will need to post 2 messages to attach all four logs since only 3 attachments are allowed in any single message. Post all of them in one thread.

    Thanks!
     
  4. thekops

    thekops Private E-2

    Thanks. I didn't do anything with MSCONFIG because it didn't apply to Win2000. I skipped the Spybot install per your list of what to finish installing and running. So, I finished installing and running the remaining tools.

    Malwarebytes found and cleaned three:
    Trojan.Agent
    Rogue.XPertAntivirus
    Hijack.Startmenu

    ComboFix ran and completed.

    MGTools ran giving one error box not listed:
    ProcessDll.exe - unable to locate DLL
    The dynamic link lib mscoree.dll could not be found in the specified path
    C:\MGTool;,;C:\WINNT\System32..... C:\WINACS;.... F:
    (some are a couple other of my network drives and folders)

    Rebooted.

    Still do not have network connection to the internet.

    Previously attached the SASlog; so now attached:

    Malware log
    Combofix log
    MGLogs.zip

    Thanks for looking at this to help me.
    Jeanne
     

    Attached Files:

  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    thekops

    I've found no other signs of malware in your most recent logs. Let's do this:

    *Make sure you have all web browsers closed.
    • Go into Control Panel -->Network Connections.
    • Right click on your connection
    • and click Properties.
    • On the Properties page, highlight Internet Protocol(TCP/IP)
    • Click Properties. This will bring up another page.
    • Select Obtain DNS Server Automatically.
    • Click the ok button. The page will close.
    • Press ok on the page in front of you.
    • Restart the computer.
    • Reconnect to the Internet using Internet Explorer.

    Please let me know if this is successful or not - I might need to send you to the Networking Forum.

    Thanks!
    dr.m
     
  6. thekops

    thekops Private E-2

    The DNS server was already set to automatic. But I did notice my network icon said "network cable unplugged". So just for grins, I tried a different CAT5 and all is now working! Go figure; I KNOW the first cable WAS working (just bad timing).

    Thank you again! Your group has helped me save quite a few of my friends (from themselves).

    Jeanne
     
  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome, Jeanne.

    It is time to do our final steps:
    Safe surfing! :cool
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds