Followed Instructions-but Now I can't get on the internet! Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by Gigig, Jul 16, 2010.

  1. Gigig

    Gigig Private E-2

    Hello-Recently my computer contracted some sort of virus-it kicked me off the internet and a window opened stating that a virus had been detected by my virus software-which I didn't have. A red flag. After that-nothing worked. I couldn't open any window or do anything. I logged on and read your "READ & RUN ME FIRST" Malware removal guide. I have followed the instructions-

    Its a HP Pavilion lap top with Windows XP Service Pack 3 32-bit

    Removed all virus software but-AVG
    Cleaned out the recycle bin & all quarantine files
    Downloaded (to a disk) and installed CCleaner in all profiles (mine, my husbands and administrator)
    Windows would not allow me to remove "ASK Toolbar" it says the Windows installer could not be accessed.
    Disabled the emulation software
    Downloaded (to disk) and installed: Super Anti Spyware, Malwarebytes (renamed MB.exe), Combofix, Root repeal & MG Tools

    Followed directions for installs-with ONE HUGE exception-I couldn't update the software because I can't get online-and I couldn't install the programs from the computer I downloaded them from so, I ran all the scans without being updated.

    Also attempted to download combofix but it said that I didn't have the Microsoft Windows Recovery console installed. I tried but couldn't down load it from the web site? (don't have the disk) It worked without it I think?

    Finally finished-the computer works (no more popups and I can open things)-but I still can't connect to the internet. Have followed the instructions for "if you still can't get on the internet" It tells me there is a strong connection and that it is connected but I can't open any pages? It just says "connecting" then "Internet Explorer cannot display the webpage"

    I also still cannot remove the "ask toolbar"

    Please let me know if I've skipped a step-they are pretty in-depth instructions so I wouldn't be surprised if I missed something. Also, can I download the updates to the software (Malewarebytes, Super Anti Spyware, etc) without installing it on the computer I down load it too to put on the disk to install on the laptop? (I hope that makes sense!)

    My logs are attached.

    Thanks in advance!

    G
     

    Attached Files:

  2. Gigig

    Gigig Private E-2

    One more log-wouldn't let me attach it to the original post.

    Sorry.

    G
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Use windows explorer to find and delete:
    c:\documents and settings\Griff\Local Settings\Application Data\oavisxgvr

    Otherwise your logs are clean. Are you unable to boot to normal mode? Why did you run MGTools in safe mode?

    You are having issues with your internet which could be a problem with your drivers. Have you checked device manager for any X's or ! or ?

    You may need to post in the networking forum for additional assistance.

    Also if a URL ( like www.google.com ) does not work. Do an IP address look up and try using using the IP address ( like 74.125.95.103 ) instead. If the IP works and the URL does not, it is a sure sign of a DNS problem
     
    Last edited: Jul 17, 2010
  4. Gigig

    Gigig Private E-2

    Hello there TimW. Thanks for your reply. I appreciate the help!

    I deleted the c:\documents and settings\Griff\Local Settings\Application Data\oavisxgvr file.

    I ran everything in safe mode, not just MGTools, because it wouldn't let me install anything. The only way I could run anything was in safe mode.

    I can now remove the "ask toolbar" though, Thanks!

    There are ! on two items in my device manager the SM BUs controller and the Video Controller (vga Compatible) But I think they were there before I had the problem? But I don't remember.

    I have also typed in the ip address you gave me and it says that the address is not valid. I still have full signal strength and a good connection-but alas, no internet web page.

    Do I need to post it to the networking forum as well?
    As a side note-when it starts up it tells me that the hardware id is missing?

    Thanks in advance for your help! I really appreciate it.

    Gigi
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I think you should first post in the software forum regarding your inability to run anything in normal mode. You are definitely having an issue with your networking setup. You can approach that in the networking forum after you get your system running properly again.
     
  6. Gigig

    Gigig Private E-2

    I can now, after running all the scans and rebooting, run the programs I downloaded in normal mode, but before the end-I couldn't. However, I will take your advice and post in the software forum anyway!

    Thanks for all your help! It's very much appreciated.

    Gigig:)
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Before you do that, please run the scans in normal mode just so I can check them.
     
  8. Gigig

    Gigig Private E-2

    Ok, but do I update them? and if so, how without logging onto the internet?

    I will re-run them and post the logs. If I have to update the log files-i'll do it a third time, just let me know how-without internet access and being able to download them to the computer i'm e-mailing from?

    Thanks,

    Gigig
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can run the portable edition of SAS> SUPERAntiSpyware_Portable

    And you can update MBAM from here>
    If you have a problem automatically installing the update due to no internet connection or other reason, you can manually download and install the update from here: Malwarebytes' Anti-Malware Database
     
  10. Gigig

    Gigig Private E-2

    Hello there TimW-

    This computer is just screwy. I was able to run all the scans in regular mode-and update them via the internet?

    I was not able to log onto the internet and search anything though until I ran combo fix-which was able to download the missing files it needed-apparently that was the problem i'm guessing. Who knows. Here are my updated logs.

    I will have to post one more time for the additional log-I can only upload 4 at a time. Sorry.

    Thanks for all your help!

    G
     

    Attached Files:

  11. Gigig

    Gigig Private E-2

    Sorry,

    Last log.

    Thanks for all your help!

    G
    :-D

    P.s. It still gives me a warning that says "hardware.ID is missing"

    Thanks,

    Its very much appreciated!

    G
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to post in the software forum for that error message. In the meantime, your logs are clean, but we need to check your proxy settings.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now see these instructions to check your settings:
    Change Proxy Settings.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds