Browser Connection Problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by And21ob, Feb 18, 2008.

  1. And21ob

    And21ob Private E-2

    Hi

    I've been having a lot of problems with connecting to Google, just Google, and having tried everything I can find am wondering if it may be either a virus, or spyware. The connection always times out after I have moved away from my Google homepage and then try to go back.

    I've run every scan that I can and found nothing, so I've run the read me & run me and attached the logs for the brilliant guys here to have a look at and see if there's anything there to be concerned about that hasn't been picked up by my attempts.

    Thanks
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your problem may not be due to malware but let's take care of a few things and reset some settings and see what happens.
    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

    After clicking Fix, exit HJT.

    Now click Start > Run and type in cmd
    • Click OK.
    • This will open a command prompt.
    • Type or copy and paste the following line in the command window:
      ipconfig /flushdns
    • Hit Enter
    • Exit the command window

    Now we will flush both your FireFox and IE caches.
    FireFox Cache

    To flush your FireFox Cache:
    • click Tools
    • select Options
    • select Privacy
    • in the section labeled Private Data click Clear Now

    Internet Explorer Cache

    To flush your Internet Explorer Cache:
    • click Tools
    • Internet Options
    • Now on the General tab and click Delete Files and select Delete all Offline content too
    • Click OK.
    • When it finishes Click OK.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    File::
    C:\WINDOWS\system32\se731.dat
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "DisableCAD"=-
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe Photo Downloader]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\TEMP
    C:\Documents and Settings\Andy\Local Settings\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. And21ob

    And21ob Private E-2

    Hi Chaslang

    Thanks for your assistance. Followed your instructions, there doesn't seem to be any improvement, but it's always good to know you've had a look.

    Here are the new logs.

    Thanks again
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry but it seems to be some kind of issue on your end that is not related to malware. You could try another browser and things like power cycling your DSL or cable modem and also your router.
     
  5. And21ob

    And21ob Private E-2

    OK, Thanks for your help anyway.

    I assume my logs are clean

    Cheers
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It was brought to my attention by Abri that I had a typo in my registry patch that actually cause it not to work. Also your new MGlogs.zip file is not a new log. I don't believe that either of these are going to change your Google problems but lets correct them and get new logs.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Tell me if you receive a success message about adding this to the registry or not. This is important so that I can be sure it worked.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Make sure that you allow it to run all the way thru until completion. Last time it did not complete and as a result your log was not complete and actually contained only 2 old logs.

    Then attach the below log:
    • C:\MGlogs.zip
     
  7. And21ob

    And21ob Private E-2

    There was a message to say that the command successfully merged and I rebooted straight away, in case it was required to take effect.

    Please find attached the new C:\MGlogs.zip.

    Thanks again
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is still the old MGlogs.zip file. Please delete the current c:\MGlogs.zip file. And then go into the C:\MGtools folder and double click on GetLogs.bat. Watch for error messages like the ones mentioned in this link Using MGtools which was reference while running the READ & RUN ME. Apply the fixes if you get any of those errors and then run GetLogs.bat again. If still getting error messages, tell me what they are. Also notice in the above link the thumbnail snapshot of the command prompt window that opens when GetLogs.bat is running. It shows what it should like like when the program finishes running.

    When finished attach a new MGlogs.zip file.
     
  9. And21ob

    And21ob Private E-2

    I must have made a mistake, but I thought I had deleted the old MGlogs.zip before running the last one. However, I deleted the lot and have downloaded the MGTools again and have attached the log from GetLogs.bat (MGlogs.zip)

    There were no error messages and I didn't have to fix anything.

    Cheers
     

    Attached Files:

    Last edited: Feb 23, 2008
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean but I see you started using MSconfig again which is not recommended. And it appears that you may not have run the below as previously requested:
    It is also possible that you did run this but it did not work properly for the simply reason that you are using MSconfig which you should not be using. See this: Dealing with Startup Processes


    You may want to try using a different browser to see if your problem with Google still happens.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    3. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
     
  11. And21ob

    And21ob Private E-2

    I followed everything as you said Chaslang and am happy that logs are clean, I'll deal with the startup processes properly and do the final steps.

    Thanks for your help.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds