av security suite removed, but still no internet

Discussion in 'Malware Help (A Specialist Will Reply)' started by hitokiri007, Jul 11, 2010.

  1. hitokiri007

    hitokiri007 Private E-2

    hi, i i got the av security suite malware yesterday and i think i removed it by manually editing the registry and using super antispyware, malwarebytes, and avast antivirus while in safe mode; however, i still don't have internet. i have changed the proxy settings in ie and firefox, but still no go. chrome got corrupted, and aim and msn can't connect either. network settings says i'm connected, but when i check the status, there's no ip address or address type or anything. i tried fixing the winsock, but it didn't work. i also tried repairing, but it gives me the error msg: "failed to query tcp/ip settings of the connection." my computer just can't access the internet.

    i have run the programs again and included the logs with the exception of root repeal. it never goes past the initializing popup. i have already disabled everything, and even tried in safe mode. can someone please help me?
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your problem with no internet is likely due to either your hardware being broken or no drivers for it being installed ( at least not anymore ) since your logs show no evidence of a Network Interface Card being installed. You will have to reinstall them. This is something you can work on in the Networking Forum.

    You skipped two very important instructions in the READ & RUN ME. First you skipped step 6 and did not run defogger to disable disk emulation (Daemon Tools) and you also did not disable Spybot's Teatimer as requested. You need to do both of these now while I work thru your logs.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make that three instructions you skipped. You did not uninstall your very old J2SE Runtime Environment 5.0 Update 22 and install the current verion which is 6.0 update 20.
     
  4. hitokiri007

    hitokiri007 Private E-2

    i def ran defogger and disabled teatimer. i don't know what it shows as it hasnt been. everytime my computer rebooted, daemon tools said something about a missing dll or something. i can't remember the exact message. but i will try enabling and then disabling daemon tools again. same with teatimer

    and i thought the one i installed was the most updated java >_< when i followed the link to the download, that's the file i downloaded. before i installed that one, i had 4 other older versions of java, which i removed before installing the 'newer' one
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You may have previously ran defogger. I just saw Daemon Tools still trying to load in your startups but could not fully tell if it was running. However Teatimer was running. Possibly because you had two versions of Spybot installed.

    The error message you see from Daemon tools is on c:\windows\daemon.dll and you get the error because ComboFix removed the file since it does not belong in this folder at all. DLLs belong in C:\Windows\system32.

    ComboFix also deleted c:\windows\system32\STEC3.sys which may ( or may not be legit and for SVKP driver for NT by AntiCracking ) The problem with it again is that it does not belong in this folder. It should be in the system32\drivers folder if they wish it to be considered a legit driver.

    No you only have this old version of Java installed. You did not install the current version which will be in my fix below.


    I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.
    You need to attach the below log from SUPERAntiSpyware that shows what was found rather than the log you attached finding nothing
    Code:
    "C:\Documents and Settings\Chris\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\"
    2010-07-10 112019 "SUPERAntiSpyware Scan Log - 07-10-2010 - 11-20-10.log"{/code]
     
    [B]Uninstall the below software:[/B]
    Free Window Registry Repair
    J2SE Runtime Environment 5.0 Update 22
    Spybot - Search & Destroy 1.4  [B][COLOR=purple]<-- way out of date[/COLOR][/B]
    Viewpoint Media Player   [B][COLOR=purple]<-- should have been uninstalled in step 5 of the READ ME[/COLOR][/B]
     
    [b]Did you purchase the below? If not then uninstall it and if you did purchase, be very careful with it.[/b]
    RegTweaker version 3.2.1
    
    Run C:\MGtools\analyse.exe by double clicking on it  ([B][COLOR=red]Note:[/COLOR] [/B]if using Vista, don't double click, use right click and select Run As Administrator).  This is really HijackThis (select [b]Do a system scan only[/b]) and select the following lines but [B][COLOR=darkred]DO NOT CLICK FIX[/COLOR] [/B]until you [B]exit all browser sessions[/B] including the one you are reading in right now:
    
    O2 - BHO: (no name) - {348FE907-249E-4C65-A838-F34A193FE1D1} - (no file)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
    O2 - BHO: (no name) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - (no file)
    O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - 
    O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - 
    O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - 
    
    [B]After clicking Fix, exit HJT.[/B]
     
    [B]Now we need to use ComboFix to remove a bunch of malware files.[/B] 
    [LIST]
    [*]Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but [B]Do not run it![/B]
    [LIST]
    [*]If it is not on your Desktop, the below will not work.
    [/LIST]
    [*][B][COLOR=darkred]Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.  [/COLOR][/b]
    [*]If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    [*]Open Notepad and copy/paste the text [B]in[/B] the below quote box into it:
    [/LIST][quote]
    KILLALL::
                                                
    Driver::
    McAfeeFramework                                
    
    File::
    C:\WINDOWS\Temp\GUR2.tmp
    C:\Documents and Settings\Chris\Local Settings\temp\hph2
    C:\Documents and Settings\Chris\Local Settings\temp\hph3
    C:\Documents and Settings\Chris\Local Settings\temp\hph4
     
    Folder::
    C:\Program Files\Network Associates
    C:\Program Files\Free Window Registry Repair
    C:\Documents and Settings\Chris\Local Settings\temp\div1.tmp
    C:\Documents and Settings\Chris\Local Settings\temp\div2.tmp
    C:\Documents and Settings\Chris\Local Settings\temp\div3.tmp
     
    Registry::
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{348FE907-249E-4C65-A838-F34A193FE1D1}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{18EAB056-9057-F224-FD4C-1F6569C4D8D2}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ViewpointMediaPlayer]
    [/quote]
    [LIST]
    [*]Save the above as [B]CFscript.txt [/B]and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    [*]At this point, you [COLOR=darkred][B]MUST EXIT ALL BROWSERS NOW [/B][/COLOR]before continuing!
    [*]You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    [*]Now use your mouse to drag [B]CFscript.txt [/B]on top of ComboFix.exe
    [*]Follow the prompts.
    [*]When it finishes, a log will be produced named c:\combofix.txt
    [*]I will ask for this log below
    [/LIST][U][B][SIZE=3][COLOR=red]Note:[/COLOR][/SIZE][/B][/U] 
     
    [B][COLOR=darkred]Do not mouseclick combofix's window while it is running. That may cause it to stall.[/COLOR][/B]
     
     
    After reboot, now install the current version of Sun Java from: [URL=http://www.majorgeeks.com/Sun_Java_Runtime_Environment_d4648.html][B][COLOR=blue]Sun Java Runtime Environment[/COLOR][/B][/URL] 
    
    [B]Now run Ccleaner.  Only use the Run Cleaner button.  Do not run anything else on any other forms.[/B]
     
    Now run the [COLOR=black][B]C:\MGtools\GetLogs.bat [/B][/COLOR]file by double clicking on it  ([B][COLOR=red]Note:[/COLOR] [/B]if using Vista or Win7, don't double click, use right click and select Run As Administrator). 
     
    [B]Then attach the below logs:[/B]
    [LIST]
    [*][B][COLOR=darkred]C:\ComboFix.txt[/COLOR][/B]
    [*][B][COLOR=darkred]C:\MGlogs.zip[/COLOR][/B]
    [/LIST][B]Make sure you tell me how things are working now![/B]
     
  6. hitokiri007

    hitokiri007 Private E-2

    do you know how to disable avast! free antivirus? i disabled the shields control permanently, and also set it to silent/gaming mode, but combofix said it's still active. did putting it on 'silent/gaming mode' reenable it? i started up combofix, but haven't continued further yet. i want to know how to disable it 100% before continuing.

    in the meantime, i have included the logs from super antispyware. i have two because i stopped the first scan cause it was only quickscan, and i wanted to change it into a fullscan. it found some things during the quickscan, and that's why i included it.
     

    Attached Files:

  7. hitokiri007

    hitokiri007 Private E-2

    i just ended up uninstalling avast free antivirus. i can always install it again later. well, i did all the steps (except uninstall spybot s&d 1.4. i forgot, considering that it's 5:30 am in the morning >_<. i'll uninstall it now though), but still no internet =T

    you said earlier that i was missing drivers. should i put in my drivers/utils cd and reinstall them?
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I doubt it will do any good until the hardware itself is being found by Windows. This is something you will need to work in the Networking Forum. Windows needs to identify the network interface hardware and then you can install the drivers for it. You may need to run a search of new hardware if it is not finding it automatically.

    We still have one bad driver to remove and I want to repair a few things that ComboFix should not have removed. To complete this repair, I will need you to attach a couple files here by first putting them into a ZIP file and then attach it. Put the below into a ZIP to attach:
    C:\Qoobox\Quarantine\Registry_backups\Legacy_STEC3.reg.dat
    C:\Qoobox\Quarantine\Registry_backups\Service_STEC3.reg.dat



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    Now we need to use ComboFix to DeQuarantine some files
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use
    right click and select Run As Administrator).


    Then attach the below logs:
    • C:\avenger.txt
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. hitokiri007

    hitokiri007 Private E-2

    here are the logs from the qoobox

    so after i'm done here, i should head over to the networking forum and post my problem?
     

    Attached Files:

  10. hitokiri007

    hitokiri007 Private E-2

    okay, so i ran avengers, combofix, and mglogs, but after i ran combofix, it dind't create a log. or at least i can't find it. i saw the log pop up, but i closed it because i assumed it was going to save it in the c:. i did a search for it and it only gave me the old log. should i run combofix again? here are the other two logs in the meanwhile.
     

    Attached Files:

  11. hitokiri007

    hitokiri007 Private E-2

    oh, actually, i found it. it was saved as dequarantine.txt instead of combofix.txt
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes!

    Before I add the drivers back to your registry, do you have any idea what the below file is for:

    c:\windows\system32\STEC3.sys

    Info on it states SVKP driver for NT by AntiCracking

    Does any of this look familar?
     
  13. hitokiri007

    hitokiri007 Private E-2

    i really have no idea. never heard of it before.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay than let's avoid adding those keys back for now. Also please put copies of the below two files into a ZIP file and attach it and perhaps we can get some additional info from them.

    C:\WINDOWS\system32\ijl11.dll
    C:\WINDOWS\system32\STEC3.sys
     
  15. hitokiri007

    hitokiri007 Private E-2

    here it is
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The ijl11.dll file is part of an Intel Jpeg Library.

    The svkp.sys file appears to be related to some kind of software copy protection. Posssibly used for games. If removed some games or the software using it may not work. It would be best to add these registry keys back in to avoid problems with some software you may be using.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  17. hitokiri007

    hitokiri007 Private E-2

    It gives me an error message saying it can't access the registry when I double click it.

    Also, Daemontools tells me that it can't find a scsi driver or something upon bootup
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try running it in safe boot mode.

    You will have to worry about Daemon Tools after we finish your cleaning process. You may need to reinstall it which is not something we recommend due to all the problems it cause especially they way it makes your system appear to be infected.
     
  19. hitokiri007

    hitokiri007 Private E-2

    same message from safe mode

    "Cannot import c:\documents and settings\chris\desktop\fixme.reg: error accessing the registry."
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What about the below registry patch?


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  21. hitokiri007

    hitokiri007 Private E-2

    k, that one worked. says it has been successfully entered into the registry.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that's good. How are things working?

    If still having problems using Daemon Tools after reenabling, you may have to reinstall it.

    Also as stated earlier, if still having a problem connecting to the internet, you will need to post in the Networking Forum since from your logs it looked like no network interface hardware was installed. I was seeing the below error when trying to check network information. You can google this to check what people have tried but seems there is a lack of success.

    Unable to contact IP driver, error code 2

    You may want to look at this link: http://www.ehow.com/how_4910210_reinstall-ip-driver-windows-xp.html

    If you run into problems trying to fix this, you may be headed towards a clean reinstall.
     
    Last edited: Jul 14, 2010
  23. hitokiri007

    hitokiri007 Private E-2

    thanks a lot! uninstalling the nic card, and then reinstalling it with updated drivers worked! i have my internet back, but now i got a msg on boot up that say "googleupdate.exe - corrupt file. the file or directory c:\windows\temp\gur2.tmp is corrupt and unreadable. please run the chkdsk utility"

    and also, when i open up the task manager, the 'menu' on top, where the 'file' dropdown menu should be, is missing. is there a way to fix this?

    i seem to be missing internet explorer also, not that i ever really use it. just wondering what happened to it.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not a malware problem. Just reinstall whatever software from Google you are using. Post in the Software Forum for any help you need related to this.

    Also not a malware problem. Just double click anywhere on the border of the Task Manager form.

    It's not missing. It is right where it is supposed to be. The below is right from your logs:
    Code:
    "C:\Program Files\Internet Explorer\"
    iexplore.exe   2004-08-04       93184  "IEXPLORE.EXE"
    Since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds