No internet connection and other problems!!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by leebert, Feb 7, 2006.

  1. leebert

    leebert Private E-2

    Hi
    I have a laptop that is runninng slow and now refuses to show any internet pages even though windows says it's connected and the virus scanner appears to update itself (but Ad-aware does not). I have tried all the steps in your 'Read & run me 1st' but can't do the online stuff and I am still having problems. Spybot reports 3 entries of 'Command Service' but can't clear 2 of the entries. Can someone help please???
    Regards
    Leebert
     
  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

  3. leebert

    leebert Private E-2

    Thanks for getting back so quickly.
    A bit more background info...
    Dell Inspiron 1100, Intel Celeron 2.4 GHz, 256 Mb RAM, XP Home 2002 SP2.

    CCleaner - cleaned.
    Microsoft Malicious tool found nothing.
    Ad-aware found 7 issues, all fixed.
    Spy-bot - found 3 entries of Command Service, 1 cleaned and the other two it couldn't.
    AntiSpyWare - all clear, nothing found.

    Attached is the HJT logfile.

    Cheers Leebert
     

    Attached Files:

  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Uninstall WinAntiVirus Pro 2006, I don't know about this version but it's predecessor, WinAntiVirus 2005, is on the list of Rougue Anti-Spyware applications. http://www.spywarewarrior.com/rogue_anti-spyware.htm

    In HJT Choose Open the Misc Tools Section choose Process Manager, Highlight:
    Choose Kill Process

    Now scan and have HJT Fix the following:
    Download
    - Pocket Killbox
    - ExplorerXP

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click the RED X.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open ExplorerXP navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Post a fresh HijackThis log.
     
  5. leebert

    leebert Private E-2

    Hi
    I did all you put in your post. The four Windows AntiVirus 2006 files in the first HJT scan were not there so the uninstall must have been sucessful I guess.
    Some of the other items you asked me to remove weren't there either - is this OK?

    Attached is the latest HJT log as requested.

    Many thanks
    Leebert.
     

    Attached Files:

  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Scan with HijackThis and fix the following:
    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click the RED X.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open ExplorerXP navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Follow the directions for Running WinPfind by OldTimer.

    Post teh WinPFind.txt and a fresh HijackThis log.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    SPD,

    This is a Look 2 Me infection.
     
  8. leebert

    leebert Private E-2

    Hi
    Followed instructions and have attached WinPFind and HJT logs as requested.
    Cheers
    Leebert
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run the steps in the below and attach the two requested logs.

    Look2Me VX2 Removal

    Then also attach a new HJT log and indicate how things are working.
     
  10. leebert

    leebert Private E-2

    Hi
    Went through L2Me fix and then ran HJT. Logs attached
    Regards
    Leebert
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your L2ME_log.txt log is not a complete log. Did you follow the direcions in the link exactly as written? Did you check to make sure the service was running as requested? Are you logged in with Adminstrator priviledges.
     
  12. leebert

    leebert Private E-2

    I think so.
    I am running in normal windows mode (as opposed to Safe mode) - is this correct?
    I am the only user account on the machine. If I go into User Accounts in control Panel it describes me as a Computer Administrator. Am I missing something??
    The only thing that was different was the l2mfix.bat sequence of events. The computer scanned first (after opening a second batch file) and then requested a reboot after it had finished.
    I am a bit, no, a lot of a newbie at this level!!
     
  13. leebert

    leebert Private E-2

    Also, the service was Started and Automatic.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you extract ALL the files from the ZIP file into a folder on your Desktop!

    Which files do you see in the folder on your Desktop?

    It is failing here;
    It is not able to setup the L2MFix account it needs to create. Normally this is due to the Secondady Logon service not running.
     
    Last edited: Feb 10, 2006
  15. leebert

    leebert Private E-2

    I'll Check on the install. Just one thing... Does L2Mefix need an internet connection? I ask as I am posting this on a seperate PC as the laptop IE doesn't work. Sorry if this is a stupid question. I'll post the L2M dir files in a min...
    Leebert
     
  16. leebert

    leebert Private E-2

    In the L2mfix dir there is the following...

    3 dirs:
    backregs (9 reg entries)
    dlls (dir empty)
    regfixes (2 reg entries)

    backup.zip
    cleanup.bat
    direct.txt
    echo.reg
    fixautont.html
    keypress.com
    l2mfix.bat
    locate.com
    log.txt
    ntrights.exe
    process.exe
    readme.txt
    report.txt
    restart.exe
    second.bat
    strings.exe
    zip.exe

    Leebert
     
  17. leebert

    leebert Private E-2

    Just ran L2mfix again and noticed when option 1 is selected that after is reports "scanning" a line comes up very briefly "can't find file.... ....user.???"
    I can't reaad what it says as it is too fast.
    Leebert
     
  18. leebert

    leebert Private E-2

    The file is "user1.txt"
    Leebert
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it does not need a connection as far as I know! Try booting into safe mode and running just the option 2 procedure and let's see the new log it produces.
     
  20. leebert

    leebert Private E-2

    It reports...
    RUNAS ERROR: Unable to run - C:\WINDOWS\System32\second.bat
    1084: This service cannot be started in Safe Mode.


    ...Could not find C:\WINDOWS\System32\log.txt

    ...Please fix missing 020 with HJT after reeboot.

    These are some other 'interesting' lines that the batch file reports

    Leebert
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's what I suspected would happen. Okay boot into normal mode and try option 2 one more time. If this does not work, I will give you a dfifferent procedure to use.
     
  22. leebert

    leebert Private E-2

    Hi chaslang
    I tried option 2 again with no luck. L2mfix still could not generate or use the second account. I haven't bothered posting the log as it was the same as last time.
    Regards
    Leebert
     
  23. leebert

    leebert Private E-2

    Hi
    Have given up on the removal of the malware and re-installed the OS. Added ZoneAlarm et all and it seems OK now.

    Thank you for your help so far.

    Leebert
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds