Bosses computer won't access Servers

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by f0zzy91, Jun 16, 2011.

  1. f0zzy91

    f0zzy91 Private E-2

    My boss couldn't sign into Skype so he came to me. I tried everything I could think of and everything that any blog out there including the Skype Help sites could offer. Updating, uninstalling, reinstalling, deleting .lock files, changing ports, changing internet configurations, disabling firewalls, uninstalling antivirus software...

    It then became apparent that it wasn't only the Skype server. Dropbox wouldn't connect. AVG couldn't get to its server to update. And now, after running the READ ME, I see Malware bytes can't connect to update as well so I ran the May 28 version that was available for download.

    He runs Windows Vista. I run Windows 7. I downloaded Skype and it worked fine for me. It works fine for the other guy in the office who runs XP.

    We're all connected wirelessly to the same router.

    I posted this in Networking about two weeks ago, but my boss held off from coming back to me about a solution so I never had access to his computer to run the READ ME until now. He instead went to the building's IT guy, but he was also unable to solve the problem.

    Internet works fine, but connecting to servers for updates and uploads aren't working.

    My boss isn't the most careful with his computer so I don't know what he's done since I last looked at it two weeks ago, but since then there are new error messages at start up about his WD Manager not able to run.

    The problem was noticed about two weeks ago after he had been infected with the Windows Recovery Virus. His partner told him to run rkill.exe so he did and that resolved the WRV issue, but then this arose.

    Sorry about the lengthiness.
     

    Attached Files:

  2. f0zzy91

    f0zzy91 Private E-2

    I don't know how relevant this bit of information may be, but my boss just told me that, since he is frequently traveling, he has stayed at many Marriotts and to get on their system he had to install... something. He didn't know what and I haven't had a chance to look. I'm not presently writing this from his computer.
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What is this, and have you tried uninstalling it>
    Kaseya Agent

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\Users\Paul Fenton\AppData\Local\0f2l2e05ro6g3nk5so2v66x11d8eyqgxqcb66v5ntpb6xe
    C:\Users\Paul Fenton\AppData\Roaming\Microsoft\Windows\Templates\0f2l2e05ro6g3nk5so2v66x11d8eyqgxqcb66v5ntpb6xe
    C:\ProgramData\0f2l2e05ro6g3nk5so2v66x11d8eyqgxqcb66v5ntpb6xe
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  4. f0zzy91

    f0zzy91 Private E-2

    Thanks TimW.

    I don't know what that is. I'll try this on Monday.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  6. f0zzy91

    f0zzy91 Private E-2

    I ran your code and uninstalled Kasaya and still no access to servers.

    I tried Skype again. And I tried to do the Java Update from the Task Bar. Neither could connect. Java gave me the message that: "The installer cannot proceed with the current Internet Connection settings. Please visit the following website for more information: [java download help page]"

    I believe there's some setting deep down or right under my nose that I don't know about that isn't connecting or is blocking these programs. Internet works just fine. It's only when a program tries to access it's server that the failure occurs.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. I suggest you pursue this in the software forum. But let me ask this, have you mapped the drives to the server? If you right click start, click explorer, is the server not showing in the tree?
    This isn't a topic for the malware forum, so do create a thread in software for this issue.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  8. f0zzy91

    f0zzy91 Private E-2

    Thanks TimW.

    I don't have access to his computer at the moment, but I'll follow through with your final inquiry when I do.

    I did originally post it in the Networking Forum and they sent me to you and asked that I return to them with a link to your thread. I'll try the Software forum as well.

    I really do appreciate you guys being here and it baffles my boss that you do what you do. He's all "and you trust those guys." I'm like, "hell yeah I do."
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. I hope you are able to get it straightened out in the software forum. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds