Can't access Google, Microsoft, and other - Seriously frustrating malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by nuguy, Apr 14, 2009.

  1. nuguy

    nuguy Private E-2

    I am an idiot.

    First the problem: Wife uses this computer mostly for school, and started about 2 weeks ago not being able to access google, I didn't pay too much attention to her about it assuming something was going on with googles servers from the conficker virus or something. Well I sit down to set up opendns.org as the dns servers on 3-31-09 to prevent any serious bs from conficker and it doesn't really load right, and realise she is right (I know, suprise right) you can't get anything from google to work.

    Now I've been using CCleaner AVG free, spybot, and windows firewall for a great while, keeping them and MSUpdates up to date, I also tend to keep my settings tight, not a lot of extra services running, and IE settings on most things to ask first, so I wasn't too concerned.

    So I start trying to resolve whatever is taking over my host file, or DNS, and I begin what has now been about a week of B.S. with this, I had done each of the steps listed here as well as a bunch of other before coming to MajorGeeks.com except the MGtools, so I have run that now too (logs attached). I have been able to get rid of most crap in the past with little difficulty, But this is drivin' me nuts!

    I am sure I have made things more difficult by doing as much as I did prior to MajorGeeks and hope someone with some mad anti-malware skillz can help get me out of this mess!

    As of right now:
    -still can't access google through either IE or Chrome
    -can ping and tracert to google, resolves correctly
    -sunbelt firewall (installed after infection) seems to be allowing traffic to tons of random ports, especially to 007Guard.com (which I have blocked in Sunbelt as well as in my openDNS settings
    -the computer is not bogging down as much as it was
    -it seems that I have disabled javascript, or something is limiting it
    -most prevalent issues in most of the antivirus scans I ran were about iframe.downloader.**

    -HELP!-
     

    Attached Files:

  2. nuguy

    nuguy Private E-2

    Here are the other logs

    Also using the TCPView tool from sysinternals (now MS) I can see a lot of SYSTEM:4 processes, that don't seem right to me so I attatched a log for you too, (hope that's all right)

    Edit: if I type in www.google.com it times out, if I type in the IP it goes right to google (74.125.67.100), but of course I can't search through the page that way...
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    This may not be a malware issue since your logs appear to be clean. Try the below steps:



    Click Start > Run and type in cmd
    • Click OK.
    • This will open a command prompt.
    • Type or copy and paste the following line in the command window:
      ipconfig /flushdns
    • Hit Enter
    • Exit the command window


    If the above does not help, answer the below questions:
    1. Do you have another PC on your network and is it working OK?
    2. Does the problem PC work OK if you shutdown your firewall?
    3. Does the problem PC work OK if you boot into safe mode?
    4. What happens if you reset your hosts file back to the default of only having 127.0.0.1 localhost
    5. Are you using a router? If yes, follow the instructions for your hardware and reset it to factory default settings. Normally there is a recessed push button type switch that needs to be held down for some number of seconds to do this. After resetting to factory defaults on your router, you will need to reconfigure the router for your network if you have made any changes to the default network setup.
     
  4. nuguy

    nuguy Private E-2

    Thanks Chaslang, I appreciate your help!

    I have flushed the DNS and no change.

    I do have 1 other PC and a PPC on this network, they are both fine.
    I have run naked through the net (no firewall), and run in Safe Mode and as Administrator - same thing...

    While I haven't reset my host file, I have scoured through my host file and do not se anything that is blocking me there.

    I am on Camcast Cable, using a cable modem followed by a wireless gateway (this comp is actually plugged into the gateway), while I don't have full access to either(they're comcasts) and I haven't reset it to factory defaults, I have soft reset it (flipped the power off to let it reset) -no change...

    I definitivly did have some nasty trojan that was tryin' like he11 to take me over, it even changed something enough that I had to reset my bios, and master boot table in order to boot, but that was now weeks ago, and I have been trying to completely clean everything from the ba5tard... I am glad to hear you beleive the logs are clean, that in itself is a breath of fresh air!

    However the lack of Google was one of the first things noticed, and I think it somehow is left over from whatever it was my comp had. As I stated in my op I realise I have made it harder with the ammount of clearing out I have done prior to finding Majorgeeks, and for that, I appologise, and wish I had taken better notes. But I am where I am, I can't go backwards...

    So any other ideas at this point? I will try the hosts file, just to be sure.
    What would the next step be?
     
  5. nuguy

    nuguy Private E-2

    The host file didn't do it, do you have any other suggestions?
     
  6. nuguy

    nuguy Private E-2

    Chaslang,

    Thank you so much for helping me, I know it may not seem like you did much in this case, however, just knowing that you saw the logs as clean, got me to stop looking for another rougue prog on my wifes pc, and ended up indirectly leading me to the sollution.

    Thank You!

    Mike M.

    Everyone else...

    Just wanted to let you know that I resolved my issue!!!

    I didn't even consider opendns as the culprit, but it was!

    While I love OpenDNS and will continue to use it for most things, however it only works if you update everything; ie- if you have a router that has DNS settings locked by your ISP (Comcast in my case) OpenDns will not allow you to use Google.com (making the computer ineffective to my student wife).

    Even though my computers DNS settings were using OpenDNS, the router was using comcasts standard DNS servers.

    That caoused the to to mess with each other - but only for Google.com - - Wha? why only Google???

    Because OpenDNS, actually caches a special page for google (I believe that's the only one) and the two don't jive, -so going to google.com in a browser doesn't work, but tracert to google.com does work....

    I hope my reply helps someone else out there.

    I also hope OpenDNS knocks off the google cache trick...

    - I switched her PC to advantagedns for now, no probs with google.com anymore!!!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome and thanks for letting us know what your real problems was! :)


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds