Lost Internet Options

Discussion in 'Malware Help (A Specialist Will Reply)' started by tribalpath55, Jul 1, 2013.

  1. tribalpath55

    tribalpath55 Private E-2

    Thank you in advance for any help.
    Five days, no internet options.
    Windows XP Home Edition with 8 update, (but it never completly updates.)
    Five days, or thereabout,
    I ran a Malwarebytes scan, it found a babylon toolbar, removed that.
    Ran SuperAnti Spyware, it found a few suspicious files, removed them.
    Ran spybot, it also found a few suspicious files, removed them, backed up everything.
    Rebooted and lost Internet Options.
    Could not update, from Microsoft, it would attempt and give a "failed to install" message on updates.
    IE running slow. Then was unable to run internet, click and it did nothing.
    I switched to Firefox, no issues there.
    I finally got system to restore yesterday, it would not restore, I used ERUNT to reboot my registry and then I had IE internet back but no options. I did delete Spybot thinking it disables that option, to no avail.
    Today:
    I did the clean system from Major Geeks and have logs from Malware, Hitman Pro, Tdsskiller, MG tools, Defogger found nothing running.
    I followed the clean to the letter, still no IE options.
    I did manage to get the service Pack 3 manually installed.
    I ran Panda Cleaner tool.
    I have internet, I still have no IE options in either control panel or tools on IE browser. I have attached the reports.
    Suggestions?
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    please rerun Hitman and have it delete Potential Unwanted Programs.


    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Files
    C:\Documents and Settings\Tracy\My Documents\5729
    C:\Documents and Settings\Tracy\Local Settings\Application Data\4662
    C:\Documents and Settings\Tracy\Application Data\3888
    C:\Documents and Settings\Tracy\Application Data\BabSolution
    C:\Documents and Settings\Tracy\Application Data\Babylon
    C:\Documents and Settings\All Users.WINDOWS\Application Data\1374
    C:\Documents and Settings\All Users.WINDOWS\Application Data\4794
    C:\Documents and Settings\All Users.WINDOWS\Application Data\8680
    C:\Documents and Settings\All Users.WINDOWS\Application Data\Babylon
    C:\Program Files\Internet Explorer\SIGNUP\SET2F.tmp
    C:\Program Files\Internet Explorer\SIGNUP\SET381.tmp
    C:\Program Files\Internet Explorer\SIGNUP\SET80.tmp
    C:\Program Files\Internet Explorer\SIGNUP\SET9.tmp
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document into a text file and attach it here in your next post.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now! :)
     
  3. tribalpath55

    tribalpath55 Private E-2

    Hitman won't delete the programs, I attempted to download it again after the one I had would not remove the files, they will not open, get a message it is an invalid program.I have not done anything else in the message you sent.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member


    Code:
    :Files
    C:\Documents and Settings\All Users.WINDOWS\Application Data\Babylon
    C:\Documents and Settings\Tracy\Application Data\BabSolution
    
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document into a text file and attach it here in your next post.


    Now run Hitman again and attach log.
     
  5. tribalpath55

    tribalpath55 Private E-2

    Thanks,
    Here is OTM and Hitman logs...
     

    Attached Files:

  6. tribalpath55

    tribalpath55 Private E-2

    A wee note, really, thanks, am sure you have a ton of things more interesting than dealing with my tech issues, whether it gets resolved or not, am very appreciative of your efforts!
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That is very nice of you to say, and you really are welcome. :) I love killing malware so let's plough onwards to be rid of this rubbish that's left.

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Please save the work in your browsers before proceeding.
    • Double-click JRT.exe to run (Vista/7 right-click and select Run as Administrator)
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Please attach JRT.txt to your next message. (See: HOW TO: Attach Items To Your Post )


    Now rescan with Hitman and atach log.
     
  8. tribalpath55

    tribalpath55 Private E-2

    Danka Shane!
    Here are the two logs...Happy Almost Fourth~
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Is everything running well currently? :)
     
  10. tribalpath55

    tribalpath55 Private E-2

    No, still no internet options and I keep getting an error message saying scripts are running slow and my computer might become unresponsive. Ideas?
    I have a major research job to start in the morning and the sites and info is very sensitive , so am concerned if my network is compromised.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Temporarily disable the Panda Cleaner from running and also MSSE and then let me know whether intenet options are available now or not.
     
  12. tribalpath55

    tribalpath55 Private E-2

    How do I temp disable Panda? I can't find an option to do that. I did disable MMSE that did nada.
     
  13. tribalpath55

    tribalpath55 Private E-2

    Also, I went into Control Panel, Panda Anti Virus is there with Cleaner, it says it cannot be "installed" on the computer , I found that odd.My computer is running so slow snails are gathering snickering at it's speed.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall anything Panda related please. Reboot, and then let me know if the problem persists.
     
  15. tribalpath55

    tribalpath55 Private E-2

    That did not work, I also lost my email access, cookies are now disabled is the message so I downloaded Firefox and got in that way. This is a nightmare but at least i have firefox. I also noticed several instances of Mbam in processes and lots of Panda processes running , cpu is at 100%, is it time to toss it all and buy another computer? If I attempt to stop processes the system stalls and freezes.
     
  16. tribalpath55

    tribalpath55 Private E-2

    Just a footnote: My work as a grant writer for affordable, green initiative housing is very competitive and the security of my searches are extremely sensitive. 50Mil grant in process so if I can't be sure of security while dealing with those numbers, I am dead in the water and many, many people will not get a home. My organization, Collaboration Nation, takes on those noone will help, the lost causes of society, skid row, abuses, runaways, we have a very open ended process and building community and co housing initiatives. A very innovative approach. I am not saying my work is more important than anyone else on this forum, but it is benefiting the people who get left behind, they are depending on me to get my grants researched , written and sent to private philanthropists. The grants are very time sensitive. I can't afford another computer as I don't get paid till the grant gets approved. I am against the wall here with time and number crunching...
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am a volunteer here and will do what I can to remove malware, we are almost finished with that now, so any outstanding issues you will have to work out in the software forum.

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  18. tribalpath55

    tribalpath55 Private E-2

    After I downloaded OT, my compter froze. I rebooted and now it won't take my admin pw, unable to logon to xp. Also, my gmail photo was changed. It seems a hostile takeover of my system is underway.
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I have alerted the head of malware, Chaslang, to your thread, as soon as he gets chance he will take a look. :)
     
  20. tribalpath55

    tribalpath55 Private E-2

    Thanks, it is what it is. At least I have my blackberry to access gmail and internet.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Seem you have other issues going on besides malware. Simply downloading OTL would not cause any of these problems. Nor would anything else the Kestrel13! has done. For that matter, the junkware that you had would not cause these problems either. And there was no real insidious malware. Justy the basic junkware stuff.

    Have you been running anything else on your own? Making any changes at all or running any other scans or tools....etc? Is see from your logs that you had run Combofix on 6/30/2013. Who asked you to run this? Were you working on another forum?

    Per the All Users.WINDOWS user account folder seen in your logs you either had previous and/or current problems with Windows. Had you done an inplace reinstall at anytime? This is not the normal All Users profile name. Same is true for LocalService.NT AUTHORITY.000


    Can you boot your PC up in safe boot mode?

    Note you should never have installed Panda Antivirus and Microsoft Security Essentials at the same time. Not that it has anything to do with not being able to login now but it sure could contribute to the slowness. And so can the lack of adequate memory. Per your logs you have
    Code:
    Total Physical Memory 1,024.00 MB 
    Available Physical Memory 371.39 MB 
    I recommend at least 3 times this especially for older slower processors like you have.


    Additional question: When you say you lost internet options, are you referring to it not showing or not being selectable in Internet Explorer? Or did you mean it does not show in Control Panel. It is possible to block seeing these due to settings in Spybot!
     
    Last edited: Jul 7, 2013
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    One more question: In your first logs attached I noticed the below
    Code:
    "C:\WINDOWS\Tasks\"
    activa~1.job  Jul  1 2013         282  "Activate Windows.job"
    Is a legit copy of Windows? Has it been activated?
     
  23. tribalpath55

    tribalpath55 Private E-2

    I haven't run anything. IE options are not showing in control panel or browser tools. I deleted spybot a few weeks ago, everything appeared fine then. Haven't a clue what is the cause. Kestral did a terrific job, am at a loss as to the why or how of any of the issues.
     
  24. tribalpath55

    tribalpath55 Private E-2

    I haven't a clue. My desktop came with Xp on it, I have, in tHe past, used erunt to back up and reload when things went wrong.
     
  25. tribalpath55

    tribalpath55 Private E-2

    I bought the computer refurbished on Amazon. It came preloaded, I did, as I recall, reinstall this past winter, not sure exactly when, the reinstall was a bit tricky and had driver issues, a friend downloaded driver updates on a usb stick and mailed it to me, I used that to finish the driver install and have issues, intermittently since. I do have the phone number of the company I bought the desktop from on amazon, they were very helpfuand seem to have a good rep with amazon. I could contact them if you think it would be helpful. The first computer they sent me had a virus so they shipped me a new one a no charge. As for panda and mbam, poinT noted.
     
  26. tribalpath55

    tribalpath55 Private E-2

    Oh, I found my pw! I was typing it wrong or in caps, finally today it worked. I think I am all set aside from no internet options in control panel or IE browser, not sure if you would deal with this issue or Kestral? Thanks for the info, am not especially savvy with most tech issues....
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download this registry patch and save to your Desktop: Restore Internet Options

    Double-click it to merge it to the registry.

    Now Reboot your PC.

    Note: if the reg patch opens as a text file when you double click it then right-click it and select Open With > Choose Program... Then, select the Registry Editor.

    If the Registry Editor is not in the list, browse to C:\WINDOWS and select regedit.
     
  28. tribalpath55

    tribalpath55 Private E-2

    I downloaded the restore internet options and opened as instructed, rebooted to no avail. Still no internet options in IE or Control Panel.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Open Windows Explorer by pressing the Windows Logo key + the 'e' key at the same time. Navigate to the C:\windows\system32 folder. Do you see a file named inetcpl.cpl
     
  30. tribalpath55

    tribalpath55 Private E-2

    It is not there.
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay do you see one in this folder C:\windows\ie8

    If yes, copy the one in the above folder to the C:\windows\system32 folder

    Now reboot your PC ( only if you found the file and did the copy successfully ). After reboot see if anything has changed.
     
  32. tribalpath55

    tribalpath55 Private E-2

    I found it in a notepad in Ie8, should I copy it and if so what folder in 32? There are a ton of them, I am very not savvy at this level. Don't want to go into the frying pan.
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what you mean. This makes no sense. notepad is a program in Windows that is a simple text editor. You will not find the files in the C:\Windows\system32 folder in a notepad file so I'm not quite sure what you mean.

    You need to copy ONLY the inetcpl.cpl file!!!!! Notice the file extension ( the .cpl ). If you do not still have viewing of file extensions enable as per the READ & RUN ME then perhaps you are not seeing file extensions and you thus cannot tell on file from another. See the below:

    How to view hidden, system files & folders!

    Also makes no sense. There can only be one file named inetcpl.cpl in any given folder. It is impossible to have the same file name duplicated. Again, perhaps you are not seeing file extensions. Or maybe you are not using Windows Explorer to locate files?
     
  34. tribalpath55

    tribalpath55 Private E-2

    As I said, I am not very literate when it comes to computer language, so treat me as if I were learning a foreign language. Sorry but I honestly am clueless when it comes to finding files in c:windows. Could be why it makes no sense to you as it makes even less sense to me. All I meant is the only area I found a notation of that file was in a notepad text file.
    I have searched the windows files, the inetcpl is not anywhere to be found, I searched windows, policy area, microsoft, IE8 IE, not sure where else. I think this is a lost cause, but then again, I am not versed enough to know how to proceed which is why I came to this website. Bear with me and my ignorance...and thanks for all the help however it ends...
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    :-D

    Let's see if we can locate a copy of the file.

    please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2
    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      inetcpl.*
      
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. You can just close this notepad window since the log is already saved on your Desktop. Be patient! It may look like it is not doing anything, but it takes awhile for this to scan thru your whole system look for matches.
    • Please attach the SystemLook.txt log found on your Desktop to next reply.
     
  36. tribalpath55

    tribalpath55 Private E-2

    It took seconds to finish, you mentioned it might take a while so I thought I would mention that.
     

    Attached Files:

  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay back in message # 30 you said you could not find inetcpl.cpl in c:\windows\system32 and also later you said you could not find it in c:\windows\ie8. The correct file is actually located in both folders. Thus this is not the reason for your problem. This is most likely not a malware problem and I may be sending you to the Software Forum for this. However the first thing you may want to try is a repair or reinstall of Internet Explorer 8. See the below link:

    http://support.microsoft.com/kb/318378
     
  38. tribalpath55

    tribalpath55 Private E-2

    Sorry it took so long for me to respond, storms and wind damage at my house last week. I will attempt to do the reinstall but now I have another issue, my keyboard appears fried, It won't work now. I got another one and for some strange reason my admin password will not work when I sign in to windows, it will work on my guest account...very strange. I am stuck unfortunatly in guest mode. That mode denies me access to download or do anything like a reinstall. Now what?
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You said the same thing previously in message #18 about your password. Then in message # 26 you said you figured it out. I have to assume you are having the same problems again. If not then I suggest that you continue in the Software Forum because you are not having malware problems that we can help you with.

    You may also want to try booting in safe mode and using the Administrator user account ( that is case sensistive ). I don't know whether you ever set a password on it ( like the same one as your account ) or you left it blank which is quite common.
     
  40. tribalpath55

    tribalpath55 Private E-2

    I managed to gain access to my admin using safe mode, I attempted the fix it, it failed. I am unable to remove the old installation of windows 8 as the button to remove it is missing . I am using another keyboard and enabled the onscreen keyboard...should I continue to post here or are we at the end of the road ? Thx.
     
  41. tribalpath55

    tribalpath55 Private E-2

    As I said, I fixed it myself by going into safe mode, I had set passwords for admin and gen acct, they never changed , and they are working now after I went into safe mode. So, still unable to reinstall windows or fix it, fix it tool fails, add remove has no remove button to delete windows 8 to do a fresh reinstall, so should I switch over to another forum as you last suggested? Thanks!
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You mean Internet Explorer 8.

    Yes I would say that you possibly have lots of Windows operating system issues and may need a clean reinstall. A repair install may work, but I would opt for a clean reinstall. These are topics for the Software Forum.
     
  43. tribalpath55

    tribalpath55 Private E-2

    Thanks for your patience. Will fresh reinstall if further issues will talk to software forum.
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Sorry we could not help you further. The only malware forum related issues that we really saw in your logs were some basic adware and the mutliple antivirus programs. All these other issues were not due to malware.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds