Can't get on line

Discussion in 'Malware Help (A Specialist Will Reply)' started by kirk48, Mar 17, 2011.

  1. kirk48

    kirk48 Corporal

    I haven't been able to access the internet in real or safe mode. I've downloaded the read me first stuff to another computer and run it the best I can. I'm uploading the logs from another computer for the same reason. I hope this is satisfactory. Four Logs attached, one to follow. Thanks in advance for your time.
     

    Attached Files:

  2. kirk48

    kirk48 Corporal

    Last log attached.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You will need to work in the Networking Forum. You logs do not show any network interface card in your PC. You either have to put one in, or you have to fix the one you have. Perhaps bad, missing, or corrupt drivers. Check in Device Manager to see if there is a problem showing for your Network Adapters.
     
  4. kirk48

    kirk48 Corporal

    Okay, control panel said the built in internet card was working correctly, but obviously that is not the case. I just plugged in a USB ethernet card and loaded the drivers and now I'm connected. I know there was some malware and incorrectly assumed they were blocking the internet connection. What should I do next?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to look at Device Manager as I stated.

    There are a few minor things I see in your logs that we can cleanup, but none of them are going to change anything related to your Network Interface Card that seems to be missing based on the first logs you attached. If you reran MGtools now, it will likely show the USB device you added but would not show any other device. You can see this by executing
    Code:
    [B]ipconfig  /all [/B]
    from a command prompt window.

    This is still something you will have to work out in the Networking Forum.


    But would you like me to work up a miscellaneous fix for other issues I observed on your logs?
     
  6. kirk48

    kirk48 Corporal

    Yes, any assistance would be good. I do appreciate that your time is valuable. There were some Trojan's removed in the scans so I was concerned I hadn't gotten them all. I meant to say device manager when I said the network card was shown working in control panel. I've got a thread started in the network forum as you suggested. No response from anyone there as yet, but I'm confident someone will take a look at the tread soon.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay, I will post something shortly. Most of what I will post is just general cleanup of things you either don't need or that were uninstalled and left stuff behind. I'm assuming that you have not made any changes to your PC ( as we requested in the READ & RUN ME ) since attaching your logs.

    Are the below all things you knowingly installed?
    MapNeto_1
    Conduit Engine
    nbox Toolbar
     
  8. kirk48

    kirk48 Corporal

    I don't recognize the three things you detail, so I'll say they were not deliberately downloaded. And yes, I read the instructions so I've not tried to do anything else, other than try to get online without any real success. I'll keep an eye out for further instructions.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then begin by going to Add/Remove Programs and uninstall the below:
    Inbox Toolbar
    MapNeto 1 Toolbar


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. kirk48

    kirk48 Corporal

    Okay, Just learned my daughter has been trying to help out with this. I've asked her to leave it alone because I need to stay focused on what we're doing.
    I deleted the two tool bars and ran the text on combofix. Logs attached. I had to put them on a flash drive and send them from another computer since I still can't get on line. Zack is looking into that problem.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I thought you had a USB interface installed??? If you removed it, then you have changed your system again.

    Have you checked Device Manager as I first suggested. Not Control Panel.


    Okay we are finished here but I'm not going to have you toggle system restore off and on because it is possible you may need it for your networking problem.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. After doing the above, you should work thru the below link:
     
  12. kirk48

    kirk48 Corporal

    Nope, didn't remove the usb connection, it just stopped working. Both it and the built in card are just fine and dandy according to device manager. But neither will locate an IP address other than 0.0.0.0.

    I'll follow the rest of the instructions as written. Have a good night and thanks for taking the time to help get this box cleaned out.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you look inside the MGlogs.zip file, you will see a file named nwktst.txt which is a collection of info related to the network piece of your PC. You will see a section where the output from ipconfig /all was run ( it says Checking ipconfig in the log ). Notice there is no defined information for any network interface. It should look something like below depending on which type and how many different interfaces you have.

    Code:
    C:\Documents and Settings\owner>ipconfig /all
    Windows IP Configuration
            Host Name . . . . . . . . . . . . : SuperDell
            Primary Dns Suffix  . . . . . . . :
            Node Type . . . . . . . . . . . . : Hybrid
            IP Routing Enabled. . . . . . . . : No
            WINS Proxy Enabled. . . . . . . . : No
    Ethernet adapter Local Area Connection 3:
            Connection-specific DNS Suffix  . :
            Description . . . . . . . . . . . : Intel(R) PRO/1000 MT Network Connection
            Physical Address. . . . . . . . . : xx-xx-xx-xx-xx-xx
            Dhcp Enabled. . . . . . . . . . . : Yes
            Autoconfiguration Enabled . . . . : Yes
            IP Address. . . . . . . . . . . . : 192.168.1.105
            Subnet Mask . . . . . . . . . . . : 255.255.255.0
            Default Gateway . . . . . . . . . : 192.168.1.1
            DHCP Server . . . . . . . . . . . : 192.168.1.1
            DNS Servers . . . . . . . . . . . : 167.206.245.129
                                                167.206.245.130
            Lease Obtained. . . . . . . . . . : Friday, March 18, 2011 1:49:38 PM
            Lease Expires . . . . . . . . . . : Saturday, March 19, 2011 1:49:38 PM
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In fact, try the below.


    Click Start > Run and type in cmd
    • Click OK.
    • This will open a command prompt.
    • Type or copy and paste the following line in the command window:
      netsh interface show interface > C:\iflist.txt
    • Hit Enter
    • Exit the command window
    Now attach the C:\iflist.txt file which should show what network interfaces names are found and their operational states.
     
  15. kirk48

    kirk48 Corporal

    okay here's the iflist.txt
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that shows the internal connections like you were probably seeing from Control Panel/Network Connections. But nothing is still showing in ipconfig, so it would seem you have somekind of driver or hardware issue. You should continue in the Networking Forum as previously suggested but you may wish to pursue deleting the devices and then rebooting and see if the hardware is automatically redetected and if drivers are reinstalled. Possibly even the below program ( which has a video tutorial ) may be of use

    SlimDrivers
     
  17. kirk48

    kirk48 Corporal

    I downloaded the slimdrivers and ran it, it says no updates are found. Of course it couldn't get the the internet so that might be the reason. I uninstalled and reinstalled the built in connection and the usb connection, then tried to get online. No luck. I ran ipconfig /all and it rang up both the built in and usb the way you said it should look. I tried pinging the IP address and it timed out four times.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click Start > Run and type in cmd
    • Click OK.
    • This will open a command prompt.
    • Type or copy and paste the following line in the command window:
      ipconfig /all > C:\ipcfg.txt
    • Hit Enter
    • Exit the command window
    Now attach the C:\ipcfg.txt file.

    What IP address?
     
  19. kirk48

    kirk48 Corporal

    Here ya go. I pinged the ip address that shows up under the USB wired connection.
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes I see the USB interface now. Not sure why it shows up now but not before when you ran MGtools since the commands are the same. However, no builtin network connection show to be in the proper states (possibly because you have no cable connected to them right now). The below devices show as Media Deconneced
    Code:
    Ethernet adapter Local Area Connection 8:
     
            Media State . . . . . . . . . . . : Media disconnected
            Description . . . . . . . . . . . : NVIDIA nForce Networking Controller
     
    Ethernet adapter Local Area Connection 11:
     
            Media State . . . . . . . . . . . : Media disconnected
            Description . . . . . . . . . . . : PANTECH USB Modem WWAN Driver #5

    Your USB connection has an IP address that was assigned from your router's DHCP function and your DNS server addresses (from your ISP) are showing up so that connection should be fine based on just the log. You need to make sure you are plugging your ethernet cable into this USB connection. All of the below addresses should answer a ping:
    Code:
            IP Address. . . . . . . . . . . . : 192.168.1.123
            DHCP Server . . . . . . . . . . . : 192.168.1.1
            DNS Servers . . . . . . . . . . . : 68.87.77.134
                                                68.87.72.134
    I'm going to give you a couple more scans to run just to error on the safe side, but if no problems show up here, you will have finish resolving this in the Networking Forum.





    Download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • If TDSSKiller does not run, try renaming it. To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123tdk.com).
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )

    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )




    Now attach the below log:
    • C:\MGlogs.zip
     
    Last edited: Mar 20, 2011
  21. kirk48

    kirk48 Corporal

    Okay here are the logs. I couldn't get signed in for awhile. I'm working with the guys on the network forum, but so far they've got me doing stuff I've already tried. I may have to give up and format the drive if it takes much longer.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Perhaps that would be best or more expedient. Your logs have not shown any signs of malware. The only issue I saw was that any builtin network interface is not being properly detected. And based on your output from ipconfig, your USB device should work okay.

    Perhaps you could also just try a System Restore to a point in time that is before when your problems began to see if that helps you avoid a reinstall.
     
  23. kirk48

    kirk48 Corporal

    That's what's driving me over the edge. If I have an ip configuration I should be able to go on line. Everything points to go, but both IE8 and Firefox come up with a cannot find server.

    For some reason the owner had system restore turned off so the only recovery I've got is after the problems started. Well I can't beat myself up anymore, I'm going to do a reinstall.

    Thanks for trying so hard to help, I would have given up along time ago if your hadn't been backing me up. I'll bet you think I'm a real dork with all these problems, but actually I'm a disabled Vietnam vet with too much time on my hands so people bring me their sick computers to fool around with.

    I guess that's a warning of sorts. If I live long enough I'll probably be back with another set of problems someday. Hopefully not on this computer though, LOL.
     
  24. kirk48

    kirk48 Corporal

    I gave up and did a reinstall of WIN XP. All is well. I still don't know why I couldn't connect, but maybe someone will come up with a solution. Thanks for all of the hand holding.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    No! Not at all. We see all kinds of troubles here and sometimes things just don't make sense. If we were able to sit hands on in front of the PC, we may be able to figure out what the problem is via trial and error. That is not something we can really do via a message forum like this though.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds