Suspect malware - Acquire ip address

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jeepfanatixs, Sep 24, 2014.

  1. jeepfanatixs

    jeepfanatixs Private E-2

    Hi there experts.
    I cant remember what i was doing on my Dell Lattitude D620 (running windows XP32 bit) laptop at the time, but three days ago I noticed that AVG Free AntiVirus was showing an exclamation mark.
    It related to identity protection.
    When i tried to fix this - I noticed that the laptop was not connected to the internet.
    I found that it was not finding my wireless network.
    I then plugged it in to my modem directly (as I do daily)
    I then found it was trying to acquire network address.
    Also the database for my most important program was suddenly missing!

    Luckily I have my wife's laptop that is still working fine.
    after researching via google - I found your website and followed the instructions under Windows XP Malware Removal/Cleaning Procedure.
    Downloaded to CD:
    RogueKiller, Malwarebytes Anti-Malware, TDSSKiller, HitmanPro, MGtools.

    I have run RogueKiller - (the logfile is on the infected computer:confused {can I copy it onto a memory stick and import onto this computer without infecting this computer?})

    Installed MalwareBytes....

    here is where I am stuck.rolleyes
    I am instructed to update the database (currently v2014.03.04.09)
    but am not able to go online with my laptop at the moment.

    should I just continue running that program with this database?

    Thanking you in anticipation
    Mauritz
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes should be fine. :)


    Yes, just continue on.
     
  3. jeepfanatixs

    jeepfanatixs Private E-2

    update: HISTORY
    I remember now where this all started:
    When trying to run itunes i received an error message about DEP
    I uninstalled itunes and around that time i found that there was a problem with aqcuire ip address.

    Update2: MALWARE BYTES
    I found update malwarebytes manually
    downloaded the file and transferred to infected computer.
    ran the mbam-rules.exe
    but MalwareBytes still says that the database is out of date.
    I ran the program anyway - logfile attached.

    I ran all the rest of the tools and have attached all logs
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode.

    This next bit takes a long time, so go off and do something else whilst it runs...

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    After reboot, run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  5. jeepfanatixs

    jeepfanatixs Private E-2

    `Thank you Kestrel
    MGlogs.zip attached
    i followed the steps to start with a clean system.
    when I tried to do a registry backup - I received a error message saying that it had errors or failed.
    set a system restore point.
    then ran the specific repiar options.
    Thank you soooooooo much for all your help!
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sorry for the late response. I've been ill.

    Please download the following file to your desktop

    Dhcp.reg



    • Now please click Start, and type regedit into the search box.
    • You should see a regedit.exe and icon appear in the Programs area of the Start Menu.
    • Right click on regedit.exe and select Run As Administrator
    • Then in the Registry Editor menu click File and select Import.
    • Navigate to the Dhcp.reg file saved to your Desktop and double click it. Allow it to be added to the registry.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  7. jeepfanatixs

    jeepfanatixs Private E-2

    Hi Kestrel
    Sorry to hear you have been sick!
    hope you feel better soon!

    Thank you for all your help!

    I did as suggested.
    new logs attahced.

    Found the following:
    When running Regedit as administrator - I could not see the DHCP file that I had saved on the desktop.
    So i just imported it directly from memory stick.

    it imported successfully
    ran mgtools\getlogs
    attached logs.zip
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. I'm sorry, but at this point I am going to have to refer you to the software forum. Alot is broken that is none malware. Best of luck :)

    One last thing before you post in software, when you rescan with Malware Bytes does it find anything else?
     
  9. jeepfanatixs

    jeepfanatixs Private E-2

    Good morning Kestrel.
    I hope you are recovering well.

    Actually - on the last reply I started writing about the windows registration issue I have.
    But I decided to not cloud the issue we have been addressing - so deleted it.

    This laptop had an infection about 5 years ago.
    A friend helped me get rid of the virus by reformatting the HD and reloading windows.
    About a year ago I contacted microsoft regarding an issue.
    They checked the windows registration and reported that it was an invalid registration.
    This laptop still has the original sticker with the windows product key pasted to the bottom.

    Is there a way that I can reset this to the original settings etc?
    If this would solve all the problems - then I am prepared to 'write-off' all the data etc on this laptop and start from scratch.

    Is this something software supprt can help me with or do I need to take it in to a store?

    Thank you for your help and advice.
    Sincerely
    Mauritz
     
  10. jeepfanatixs

    jeepfanatixs Private E-2

    I am running anti-malware bytes right now and will let you know the results as soon as it is completed.
     
  11. jeepfanatixs

    jeepfanatixs Private E-2

    Good news?
    Malaware bytes did not find any malicious items!
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Glad MBAM didn't find anything else.

    I am on the mend. Thankyou very much. :)
    By all means yes post about all remaining issues in the software forum. Very best of luck.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  13. jeepfanatixs

    jeepfanatixs Private E-2

    Hi Kestrel.
    Thank you for all your help here.
    I started that new thread and have been getting help and advice from Mdonah
    I am now at the point of wiping the whole computer and will re-install XP.
    Again thank you for all your help.
    Sincerely
    Mauritz
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. :)
     
  15. jeepfanatixs

    jeepfanatixs Private E-2

    Hi Kestrel
    Just a quick note to let you know that I have managed to
    wipe, format and re-install windows XP to that laptop.
    Updated all security fixes - and only have one last issue to sort....


    Hotfix Id: EOL-Adobe End of Life
    Adobe Flash Player 6.0.88.0 ActiveX 32-bit is vulnerable and no security updates are provided by the vendor

    I have posted this in the thread with Mdonah and await some advice.

    I'm not sure of the protocols, but I would suspect that it would be good to close this thread?

    Again - thank you for all your help
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Glad it's all going well for you. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds