Can't access internet after malware attack

Discussion in 'Malware Help (A Specialist Will Reply)' started by kirk48, Jun 15, 2010.

  1. kirk48

    kirk48 Corporal

    I have a laptop I'm hoping to get back into service without having to format the HD. When I first saw this system it was loaded malware to the point where running anything was a chore. Superantispyware was already in place as is Malware Bytes. Mcafee was installed but it was badly outdated and turned off anyway. I did see a reference to Panda Active Scan as well. I removed Mcafee via the instructions from their website, and also tried to remove Panda, I don't know with what success. I ran SAS and Malware Bytes in safe mode without the updates since I can't get an internet connection. I tried loading Avast via another computer and it seems to install, bu won't run. I tried uninstalling but Combofix say it is still avtive although I can't access it. I put combofix, root repeal and Mgtools on by downloading on another computer and burning them on a cd. I tried running Combofix in safe mode, it found rootkits infections and rebooted back into regular Windows then completed as best it could. I couldn't down and install the Wndows Restore software and couldn't turn off Avast so it may not have gotten all it could have. It did do some good because after it finished I was able to run Rootrepeal and MG tools which seemed to run okay. I've still not been able to establish an internet connection or get the antivirus to run, so I suspect there are still malware concerns. I moved the logs over to a computer with IE connection and I'll attach the logs to this thread.
    Thanks for looking at this mess.
     

    Attached Files:

  2. kirk48

    kirk48 Corporal

    And here is Mgtools.zip
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing much in the way of malware on your system. However, let's do some clean up and see where we stand.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now use windows explorer to find and delete:
    c:\documents and settings\Steve\Local Settings\Application Data\tvyyelf
    c:\documents and settings\Steve\Local Settings\Application Data\qdxscpuol

    Since I don't think you set up the proxy settings, please follow these instructions:
    Change Proxy Settings.

    Now tell if you can connect.
     
  4. kirk48

    kirk48 Corporal

    Okay did the clean up and reset lan settings, still no connection either with a wired or wireless connection. I can get to the network, but not online.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have a home network and can access other computers on that network? This may be an issue that needs pursuing in the networking forum. Are you seeing any ! or ? in device manager?
     
  6. kirk48

    kirk48 Corporal

    Yes this is a home network. I'm on a wireless notebook right now, and I've got a wired computer within eyesight. Both are connected to the internet. No hardware problems are being experienced. The (previously?)infected computer recognizes the wired network and the wireless says I have little or no connectivity. I just tried to install Avast again and it went though. So, it would seem the malware is no longer blocking the internet access and something else is going on. I guess I should mention this is one of my old laptops that I "loaned" to an inlaw and it still has my name and stuff as the user. Perhaps I should ship it back to him and see if it connects on his home network.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What else is going on?
     
  8. kirk48

    kirk48 Corporal

    Sound question to a kind of dumb statement on my part. I meant that the computer seems to be acting normally with the exception of not accessing the internet. I've got Linksys software that shows all of the computer on the network. The software sees all of the computers, with the exception of the one I'm having the concerns, with even thought the computer itself says I have a local area connection. I don't know what to say about that. I suppose however if you find the computer to be clean of malware I should use the proceedure to uninstall combofix et al and move over to another forum. Would this be the correct direction to take?
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go to start / run / type:
    cmd
    In the window that opens, type:
    ipconfig /all

    Post that.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This info is already present in MGlogs.zip in nwktst.txt

    However it shows no physical connection to a network was present.
     
  11. kirk48

    kirk48 Corporal

    Okay the info that show up is:

    Ethernet adapter local area connection 3:

    Connection-specific DNS suffix:
    IP address: 192.168.0.1
    Sbnet mask: 255.255.255.0
    Default gateway:

    the Ethernet adapter wireless network connection shows

    DNs suffix:
    IP Address: 169.254.31.124
    Subnet mask: 255.255.0.0
    Default gateway:
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you saying you can connect wired but not wirelessly?
     
  13. kirk48

    kirk48 Corporal

    No internet connection either way. Didn't mean to confuse the issue.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well, this is not a topic for the malware forum. I suggest you post in the networking forum for further assistance.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     
  15. kirk48

    kirk48 Corporal

    I agree, thanks for the expert assistance anyway.
    I'll be back with another malware screw up if history holds true.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome!! And heaven forebid!! LOL
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds