Godaddy.com is unreachable

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by arco123, Mar 20, 2007.

  1. arco123

    arco123 Private E-2

    Problem: cannot access godaddy.com. All 4 computers on my home network cannot access godaddy.com. I do not get porn I just time out.

    What I've done so far:

    • numerous anti-spyware programs have been run including spybotS&D and HijackThis (both before I found your forums), AdwareSE.
    • called both godaddy.com and verizon.net (my provider) with no luck, both say everything is fine on their end.

    I have followed the FAQ with two problems:

    -I mistakenly exited out of Counterspy without the log.
    -Bitdefender crashed just as it was going to show the "detected problems" Explorer was the named culprit. I do remember mostly trojans found in email (trash box, Eudora Pro) that were deleted.

    I do have the other 4 log files. I hope you can help, I have a website at godaddy.com that needs attending to.
     

    Attached Files:

    Last edited: Mar 20, 2007
  2. arco123

    arco123 Private E-2

    logs continued.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majrogeeks!

    Do you recognize the below as things you downloaded yourself?
    Code:
    Virus:W32/Happy
    C:\Program Files\Gravity\newsdb\at\IQSnewsgroup.txt[~0008269.~][Happy99.exe]
     
    Security Risk:HackTool/Gendel.A          
    C:\GENDEL32.EXE 
     
    Security Risk:HackTool/Gendel.A               
    F:\WINDOWS\SYSTEM32\Setup\GENDEL32.EX_ 
     
    Potentially unwanted tool:Application/NirCmd.A            
    F:\fixwareout\FindT\NIRCMD.EXE 
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I see a load of startup processes and services that are stopped/disabled. It does not appear that you are stopping them with MSConfig. Are you stopping all of these items from running by using Windows Defender or another similar program? If so, why. I even see things from McAfee in there but you don't have McAfee installed anymore. Uninstalling software while process/services are disabled like this often results in incomplete software removal and typically results in problems in some form (this is not a malwar problem however).

    Do you know what the below file is for?
    Code:
    "F:\Documents and Settings\All Users\Application Data\"
    uyaŽ31~1.sys  Jan 27 2007          13  "UYAŽ3113>.sys"
     
  5. arco123

    arco123 Private E-2

    Gravity is a newsreader. It exists only as text not an actual file..a reference to a file that wasn't downloaded.

    There are a handful of messages online about it, indicating that it's a spyware of some kind. The online recommendations are to delete the file, stop the service. I don't see it as a running service on my computer so I'm wondering if it's really a problem.

    Fixwareout is an anti-spyware program. I don't remember where or how I found it...i've attached a report from running the program. But the problem I have was in existence before running this app.


    No idea what this is. Very strange collection of accents there, eh?! nothing online.
     

    Attached Files:

    Last edited: Mar 20, 2007
  6. arco123

    arco123 Private E-2

    In the spirit of figuring this out. Here is the tracert that I recorded the morning i talked to godaddy about the problem. They indicated that it was strange that I was actually reaching their servers but my browser was timing out before the connection was made.

    I'm behind a router so the details of the tracert aren't all that enlightening. When I did this same tracert using WinPoet connecting directly to my modem it was full of stops along the way, ending up at the same place.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since you don't know what they are, you should delete the below files:
    C:\GENDEL32.EXE
    F:\WINDOWS\SYSTEM32\Setup\GENDEL32.EX_
    F:\Documents and Settings\All Users\Application Data\UYAŽ3113>.sys

    You did not answer my question about all those processes and services being stopped!

    You problems do not appear to be malware related at this time. Perhaps you need to flush your DNS cache. Also why are you using IP Routing and why is WINS Proxy enabled too?

    I do however have somethings for you to do besides the above.

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    F:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Now Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 4
    J2SE Runtime Environment 5.0 Update 5
    J2SE Runtime Environment 5.0 Update 6

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Stop using whatever it is that you are using to disable all those startup processes and services. If you don't need startups, delete them permanently or uninstall the softare. Some items listed are not even installed on your PC anymore.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: Google Desktop Search Capture - {7c1ce531-09e9-4fc5-9803-1c2956615786} - blank (file missing)l
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "F:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O16 - DPF: {CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_01) -
    After clicking Fix, exit HJT.

    Now reboot in normal mode
    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  8. arco123

    arco123 Private E-2

    msconfig. I disable unneeded services.

    These questions I can't answer. I don't know what "WINS Proxy" is or exactly what IP Routing is. FWIW, I'm on a home network, behind a Netgear router with 3 other computers.

    Thanks for the suggestions. I'll report back.
     
  9. arco123

    arco123 Private E-2

    I'm still unable to reach GoDaddy.com. Still timing out.

    Any further suggestions would be much appreciated! Thanks.
     

    Attached Files:

  10. arco123

    arco123 Private E-2

    I was able to disable WINS Proxy. Both Verizon and Godaddy continue to view each other as the problem's source. I remain screwed.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I said previously, I don't believe this is a malware issue.

    Did you enable IP Routing while doing debgging with Verizon? You should disable this too unless you need it setup for some reason. Do you use this PC as a router to allow other PCs to connect to the internet?

    Look at an ipconfig /all report from your other PCs on the network and compare. They probably do not have IP Routing enabled (nor the Wins Proxy).

    Do other PCs connect to GoDaddy without a problem?

    Try bypassing your router and directly connect your problem PC to your DSL/Cable modem and see what happens. (Yes this will temporarily disconnect the other PCs while testing this).

    Also if you boot your PC in safe mode can you connect to the net? If so, can you connect to godaddy in safe mode?

    Try another browser too like FireFox. Does it connect?
     
  12. arco123

    arco123 Private E-2

    safe mode doesn't help...
    all the computers on the network cannot connect to godaddy.
    all browsers do not work.
    i tried to bypass the router..no dice.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are all PC's setup with IP Routing and WINS Proxy? I'm not sure if this is the cause of the problem or not but these settings are not normally required on a home network unless something special is being done. The reason I'm not sure is because I don't understand why it would impact only one IP address unless there is something setup in your IP Route to stop it.

    You are going to have to check to make sure you are not blocking godaddy in your firewall or with any other protect software. Make sure you have not some how put it into the Restricted Zone too.

    Have you done an ipconfig /flushdns from the command prompt? If not, run that.
     
  14. arco123

    arco123 Private E-2

    The mystery ended this morning as godaddy.com all of sudden became available to me. Nothing was changed on my system(s). I believe that something on the godaddy side was fixed but I have no way of proving it.

    Anyway thanks for all your help here. If I ever do get spyware I know where to turn.

    best,

    e
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well at least that proves what I had been saying..... that it was not malware! ;) Happy to hear everything is working now.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds