![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
Dell Inspiron mini with Window XP, 32 bit, sp3 installed. Google searches were redirecting for a few days in Mozilla Firefox. Found AVG scan components absent. Did some search on google forums and took advise of running ComboFix after removing AVG. Post combofix, unable to connect to internet. Lists wireless networks but no ip is allocated. Task manager shows no active network adapters. Wired ethernet also same status. Re-installed driver of wireless card (Dell Wireless 1397 WLAN Minicard) from Dell cd but no luck.
Also it is now taking too long to start up and show active task bar. Sometimes shutdown is taking much longer than usual and gets stuck with the shutdoen screen. Followed and ran all the processes of READ ME AND RUN ME FIRST. The logs are attached. Any help will be much appreciated. Thanks in advance for your time! |
| Sponsored links |
|
|
|
#2
|
|||
|
|||
|
MGlogs attached now.
|
|
#3
|
||||
|
||||
|
Welcome to Major Geeks!
Please see step 4 of the READ & RUN ME and run MSconfig and put your PC in normal startup mode as requested. Now we need to use ComboFix
Quote:
Do not mouseclick combofix's window while it is running. That may cause it to stall. If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem. Now continue with the below procedure:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| The Following User Says Thank You to chaslang For This Useful Post: | ||
visitavisroy (05-03-12) | ||
|
#4
|
|||
|
|||
|
First I must thank you profusely for your time and attention to my problem.
I followed all your exact instructions. ComboFix actually detected ZeroAccess Rootkit again, so clearly it was not removed initially. After combofox and reboot, the internet connection was actually back!! yet, to follow your full prescription, I went through the rest of the 5 steps to re-intall the TCP/IP stack. The internet connectivity is back now - both wired and wireless. I have made some test searches and no re-directions have been observed. You are GOD. ABSOLUTE RESPECT! The 2 logs are attached. Now that the connectivity is back, should I remove the tools recently installed and re-install AVG? Please advise. Thanks again and again! |
|
#5
|
|||
|
|||
|
Hi chaslang, couple of hours back when I made the last post, everything was fine as I had mentioned. I had kept the machine shutdown because there was no anti-virus running and it was connected to the net.
I started the computer a few minutes back to take a few files and strangely the machine was back to its previous state - no connectivity, no active network adapters detected ![]() I rebooted the machine, but no luck. May be the malware is still there and messing around. |
| Sponsored links |
|
|
|
#6
|
||||
|
||||
|
Quote:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| The Following User Says Thank You to chaslang For This Useful Post: | ||
visitavisroy (05-04-12) | ||
|
#7
|
|||
|
|||
|
I am 100% sure I have not tried to edit anything in the logs. Kept the network cable connected now, No AV, rerun the MGtool. New logs attached.
Thanks for your response. |
|
#8
|
||||
|
||||
|
Okay we need to run a couple other scans and then apply some additional fixes.
Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
See the download links under this icon
Now we need to use ComboFix
Quote:
Do not mouseclick combofix's window while it is running. That may cause it to stall. If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem. Now please download Farbar Service Scanner and run it on the computer with the issue.
Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). Then attach the below logs:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| The Following User Says Thank You to chaslang For This Useful Post: | ||
visitavisroy (05-06-12) | ||
|
#9
|
|||
|
|||
|
Thanks again for your advises. Ran the TDSSKiller, MBRcheck and Combofix as instructed.
This time ZeroAccess Rootkit was not detected while running ComboFix. However, unlike last time, the network connectivity was not back after reboot post-ComboFix. Ran Farbar Service Scanner. Still no connectivity. So re-ran the procedure from the 2nd half of message #3 with nettcpip.inf again. BUT at the last stage (step 4 of the procedure), when I clicked OK after selecting Internet Protocol (TCP/IP), it popped up an error message as "Access is Denied". So, could not complete this procedure. Ran MGtools getlogs. Attached MGlogs and error message snapshot in next message. |
|
#10
|
|||
|
|||
|
MGlogs and error screenshot attached now.
2 observations: - at step 2 of nettcpip.inf procedure, while selecting Internet Protocol (TCP/IP), I observed that it was not digitally signed - At step 4 of the procedure, in the Network Connections window, both the wired and wireless network connection icons had 'connected' written underneath them though there was no connection. |
| Sponsored links |
|
|
|
#11
|
||||
|
||||
|
Okay some additional registry entries for services have now gone missing. When I last had you run the fix with ComboFix, only the IPSec service had entries missing. Now several other services are missing from the registry. And in addition, the fix with ComboFix was only able to partially restore the IPSec service. I'm wondering if there are permissions issue broken in the registry and also whether there is still some active component of the infection that is hiding somewhere. Let's run another tool to check deeper for possible infections and also attempt some fixed to correct permissions.
Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
Please download OTL by OldTimer.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| The Following User Says Thank You to chaslang For This Useful Post: | ||
visitavisroy (05-08-12) | ||
|
#12
|
|||
|
|||
|
Hi! Thanks again for spending so much time on my problem and trying so hard to solve it. Whether or not my machine finally gets fixed, you will always have my best wishes.
I performed your instructions. The logs are attached. While executing the Repair_Windows.exe, an error popped up several times. A screenshot is attached. The program went on everytime I clicked OK. So not sure whether the program could actually do the job it was supposed to do. Just for sake of records, no connectivity yet. Thanks again. |
|
#13
|
||||
|
||||
|
You're welcome.
Quote:
Quote:
Click Start, Run, and enter sfc /scannow and click OK. There is a space after the sfc. This runs System File Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it. WARNING: The below fix is only meant for visitavisroy and no other PCs!!! Download the below file and save it to your Desktop visitavisroy.reg Then double click on it and allow it to be added to your registry. Let me know if you receive a success message. You may receive a message stating something like not all keys were successfully added or merged to the registry. Now reboot your PC. If you do no have a network connection at this point, rerun the procedure from the 2nd half of message #3 with nettcpip.inf again Now please download Farbar Service Scanner and run it on the computer with the issue.
Then attach the below logs:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter Last edited by chaslang; 08-20-12 at 21:32.. Reason: change stored location of reg patch |
| The Following User Says Thank You to chaslang For This Useful Post: | ||
visitavisroy (05-13-12) | ||
|
#14
|
|||
|
|||
|
Hi chaslang, firstly apologies for the late response; was traveling on work a bit.
Ran your instructions today. During the /scannow process, it did access the windows CD several times. The visitavisroy.reg gave a clear success message. No connectivity thereafter, so went through the nettcpip.inf procedure. Bingo! Connectivity was back after the nettcpip.inf process. I even updated the Malwarebytes database and ran a quick scan to see there are no infections. So ran the Faber scan and MGlogs. Logs attached. However, just like last time .... one reboot and strangely the connectivity was again gone ... as if something is getting corrupted during reboot. So, for your analysis, ran FSS and MGlogs again. These logs are named with the postfix '-after' and attached too. |
|
#15
|
||||
|
||||
|
Repeat all the instructions in message #13 again including redownloading visitavisroy.reg
because it has been modified. This time or any time in the future, once your network access is working, DO NOT power down, reboot, reset....etc your PC. Just attach the latest logs and wait for me to get back to you.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter Last edited by chaslang; 08-20-12 at 21:32.. |
| The Following User Says Thank You to chaslang For This Useful Post: | ||
visitavisroy (05-15-12) | ||
| Sponsored links |
|
|
|
#16
|
|||
|
|||
|
Hi chaslang, thanks indeed. I ran the procedure again. This time after the visitavisroy.reg successful execution and reboot, the connectivity was back. So did not have to go through the nettcpip.inf precedure. The 2 logs are attached.
Not shutting down, rebooting, etc. Will await your instructions. Sincere thanks once again! |
|
#17
|
||||
|
||||
|
These logs look fine, but still do not allow a reboot yet.
Did you knowingly install and do you use the below remote access applications? O23 - Service: B-Service - Unknown owner - C:\Documents and Settings\Bubble\Application Data\Mikogo Extra\B-Service.exe O23 - Service: TeamViewer 7 (TeamViewer7) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe Also I don't see where the Mikogo B-Service program is even still installed but the service is there. Did you uninstall it? Now follow the instructions in the below to run an online scan with ESET. Attach the log. Note, it will likely find a few files like process.exe in the MGtools folder. The process.exe file is completely safe. It is just a command line task manager program ( a process manager hence the file name ). Using ESET's Online Scanner
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| The Following User Says Thank You to chaslang For This Useful Post: | ||
visitavisroy (05-16-12) | ||
|
#18
|
|||
|
|||
|
Hi chaslang, yes I had installed both Mikogo and Teamviewer but uninstalled Mikogo long ago. Mikogo is a screen sharing add-on that comes with skype. I use the Teamviewer quite frequently.
Attached is the ESETScan.txt. No reboot yet. Thanks once again. |
|
#19
|
||||
|
||||
|
Okay well since it still is trying to load a service, let's remove it.
Open a command prompt window by clicking Start, Run, and enter cmd and click OK. If the window opens type each of the below commands in. Follow each by the enter key. Note there are spaces after the sc and after the stop and after the delete. sc stop B-Service sc delete B-Service Now see if the below folder exists and delete it if found: C:\Documents and Settings\Bubble\Application Data\Mikogo Extra Now let's power down your PC ( not reboot -- power down ). Leave it powered down for at least a two minutes. Then make sure that any/all removable type devices have been disconnected from any USB ports. Then power your PC back up and see where we stand as far as having network access. Attach the below new log no matter what the status is. Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). Then attach the below log:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| The Following User Says Thank You to chaslang For This Useful Post: | ||
visitavisroy (05-17-12) | ||
|
#20
|
|||
|
|||
|
Hi chaslang, followed all your instructions. This time connectivity was OK after starting up the machine. Finally, it seems like OK now
![]() Attached is the logs. Should I now go ahead and re-install AVG? Many many many thanks once again for all this effort and attention! |
| Sponsored links |
|
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Combifix removed rootkit zeroaccess now no internet | Denver5613 | Malware Removal | 92 | 01-08-12 15:33 |
| Rootkit zeroaccess cleaned by Combofix but still no internet access | thekops | Malware Removal | 13 | 01-06-12 14:46 |
| ZeroAccess Rootkit removed after combofix, internet won't work | typro | Malware Removal | 5 | 01-04-12 15:13 |
| Rootkit Zeroaccess Gone With Combofix, but comes back and have no internet access | Cap116 | Malware Removal | 2 | 12-30-11 21:04 |
| Zeroaccess Rootkit Removed - Still no connection | dmoranda | Malware Removal | 4 | 11-30-11 23:02 |