pc has no network connection after malware removal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by kitkat2003, Aug 26, 2011.

  1. kitkat2003

    kitkat2003 Private E-2

    Can someone help me with this issue? I am currently using another machine to see if I can solve this on the infected machine. I got an infection earlier today. After I ran combofix and MGtools I noticed there was no networking. I do all of my scans in safemode as a precaution. I have been trying everything I can think of and reading a lot of posts on this forum in how to resolve this issue. Nothing has helped. :( I would hate to have to resort to Re-installing the OS. That would be the last resort.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    It would be more helpful if you attached all the logs we asked for.


    It would be after ComboFix. MGtools does not fix anything that would cause this. It is 99.5% just an information collector. The 0.5% of items fixed/changed are just to restore a few registry keys that malware may have changed. Nothing related to networking is changed by MGtools.

    Try shutting off your PC for a few minutes. The turn it back on. If that does not help, attach your logs using your other PC. Also check to make sure your network settings are configured properly.


    Not what we asked you to do. This should only be done when normal boot mode cannot be used.
     
  3. kitkat2003

    kitkat2003 Private E-2

    Thank you for your speedy reply. I ended up just doing a system restore and it solved the problem. However now, I have in the last hour received a few virus alerts from MSE. MSE immediately removed the threats. I just hope that the alerts have been taken care of. Thank you again for your speedy reply.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you find out you still have a problem, attach the logs from the previous cleaning procedure steps you ran. The should all still be there.
     
  5. kitkat2003

    kitkat2003 Private E-2

    Hey Chaslang,

    Attached are the logs that I have done as of yesterday. I have network capabilities but now I feel like the pc is "hanging up" during the shutting down process. I have also been receiving a lot of alerts from MSE since Sunday. I hope I have successfully attached all the logs that you would need. Thank you so much for helping!


    Cathy
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure that you are in Normal Boot Mode now for all steps unless we ask you to boot in safe mode.

    You forgot to attach the requested log from SUPERAntiSpyware. Please attach the below file:
    Code:
    "C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\"
    Aug 30 2011  6554  "SUPERAntiSpyware Scan Log - 08-30-2011 - 20-37-03.log"
    Also you are extremely out of date with your copy of Malwarebytes. You need to keep programs updated and should have updated as requested in the READ & RUN ME FIRST. So just to be safe, let's update and rescan.

    Now run Malwarebytes and click the Update tab. Then click the Check for Updates button so you update to the current version of the program and database. Then run a new scan with it too. Make sure you fix the problems found before saving a log. Attach the new log.

    You also used an out of date copy of ComboFix. You should have updated to use the version given in the procedure. You must not use or even keep old copies of ComboFix. You must delete your old copy now and download and save the below one to your Desktop. Do not run it. We will run it later.

    combofix.exe


    Do you know what the below servce is for?

    O23 - Service: KMService - Unknown owner - C:\WINDOWS\system32\srvany.exe


    Uninstall the below old versions of software:
    Java(TM) 6 Update 22
    Viewpoint Media Player (Remove Only) <-- should have been uninstalled in step 5 of the READ ME

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. kitkat2003

    kitkat2003 Private E-2

    Chaslang,

    Attached are the logs you requested.

    I have no idea what this service is.

    Currently the pc is now giving me issues when shutting down. It HANGS during the logging off process forcing me to power off the machine holding the main power button. Thanks for all the help so far!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    Now please also download MBRCheck to your desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  9. kitkat2003

    kitkat2003 Private E-2

    Attached are the logs that you requested. I have been hearing an "error thump", which I think is from a background program. I never see an error message nor any program that I have open displaying an error box. I also received another alert from MSE. I am starting to get disheartened with this pc. Might have to go ahead and just Reinstall the OS. Thanks for the help!
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This may not be necessary. Both MBRcheck and TDSSkiller show that you most likely have an infected Master Boot Record ( MBR ) which needs to be fixed. First a couple questions.
    1. Do you have all important data backed up? While most of the time, repairing the MBR works without any problems, there is still the risk that there could be a problem due to how malware has hooked into the operating system of your PC. So it is prudent to be backed up first.
    2. Do you have your Windows XP boot CD so that we can use it to boot to the Recovery Console to repair your MBR?
     
  11. kitkat2003

    kitkat2003 Private E-2

    I do have my important data backed up.

    As far as the Windows Boot Cd. The only recovery disks that I have the original 6 cd's that came with XP Home Edition. Would not know what cd to use. :(
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What are the tiles on the disks? Not sure how your PC vendor is labelling them but something like System CD or Operating System CD or similar may be the correct one. As long as it is not a factory recovery CD. You need a the Windows Operating System boot CD which will be a bootable CD that you can bootup your PC from and then get into the Recovery Console as instructed in the below. See the section titled

    Option 2: Starting the Windows Recovery Console from the Windows XP CD-ROM

    I don't want you to install the Recovery Console on your hard disk like requested in the ComboFix instructions nor do we want you to boot from this installed version. You must boot from the CD.
     
  13. kitkat2003

    kitkat2003 Private E-2

    On each of the 6 discs they are all labelled the same. Compaq System Recovery Windows XP Home Edition. Should I just load each cd. I have to get my hands on an XP cd that is a bootable. Sorry this has become such a mess. :(
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! This are likely just factory recovery CDs and you have a factory recovery partition on your hard disk already. Factory Recovery is used to put your PC back to the state it was in when you took it out of the box. Not something most people really want to do since you loose everything you have added/changed since that time.


    See what was posted in message # 12 of the below thread and see if you can get this CD to run.

    whistler/black internet@mbr again!
     
  15. kitkat2003

    kitkat2003 Private E-2

    I managed to get this cd to run. Is there a log that I should have to send to you? Just to make sure I have executed the cd correctly. Thank you again for helping me!

    :)
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes if you ran the fix for the MBR then rerun MBRcheck and attach a new log.

    Also tell me how your PC is working.
     
  17. kitkat2003

    kitkat2003 Private E-2

    Attached is an updated log. Thank you again for all the help!
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is no change in the MBR

    1. Are you sure that you booted from this CD? You have to BOOT from this CD. You cannot allow your PC to boot from the hard disk.
    2. Are you sure that you actually performed the fix of the MBR?
     
  19. kitkat2003

    kitkat2003 Private E-2

    Yes I am sure I booted from the cd. Maybe the cd I burned was missing something? I will try again.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Were you able to follow all the instructions for fixing the MBR? Did it give you any confirmation? If running a repair from the type of boot disk does not work, you may be at a point where you will need an original Windows installation disk to delete partitions, recreate partitions, format and reinstall.

    Are you actually having any remaining malware problems? Are you still having the problem that your network connection does not work?


    There is another possible option that may or may not work. And that is the Factory Recovery partition that appears to be on your hard disk as drive D. You may be able to use this but it will put the PC back to "out of box" condition and you will lose all info you have on the drive which means you must back up everything you need before trying this.
     
  21. kitkat2003

    kitkat2003 Private E-2

    I haven't seen any errors since we did the MBR and Kasperky scans. I think something was missing from the disc that I burned from Hirens zip file was incorrect. I will follow the directions again to make a new cd.

    At this point since I see no errors, is leaving my sick pc this way okay? Or is the pc not sick anymore?
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you making a bootable CD or are you just copying the iso file to a CD which would not be correct? I need to know if you made a bootable CD and that you actually BOOTED your PC up from powerup direct from this CD and not from your hard disk. You cannot boot into Windows and then run the Hiren utilities.

    If it is really an infected MBR, it can be dangerous to your security. It could result in stolen information.
     
  23. kitkat2003

    kitkat2003 Private E-2

    Attached is the updated log. I have attempted to do the fix one more time. This time I made sure it booted from the cd by disabling the hd from the boot process. Is the log still displaying the MBR is still infected?
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does not say you are infected. It says the format of your MBR is unknown ( that is, it is not recognized to be one of the forms that MBRcheck knows ). It may or may not be a problem. I don't like the fact that it is not being rewritten/fixed using the special boot CD from Hiren, but that still does not mean it is bad. We have seen this occur more and more in recent times and do not have an explanation as to why.

    Since you say you are not having any problems, it may be okay, but again we cannot guarantee that.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds