IE7 and Firefox Internet Access

Discussion in 'Malware Help (A Specialist Will Reply)' started by Jonor85, Nov 3, 2008.

  1. Jonor85

    Jonor85 Private E-2

    I have recently had a fairly nasty malware/spyware attack on my PC. I think I have cleared most of it up using methods and programs recommended on this website (superantispyware, spybot, malwarebytes antimalware remover etc). I have also scanned using AVG but it turned up nothing.

    Since doing this at some point Internet Explorer 7 and Firefox have both completely lost internet access. But updates for AVG and the other programs above have still downloaded fine and utorrent is also still functioning.

    THe microsoft diagnostic tool thinks that this is a firewall issue but I only use the firewall on my netgear DG834G router and the other computers connected to it have no problems with internet access.

    Im not really sure what other info you may need but I think I have logs for the aforementioned programs. I am completely at a loss of what to do next and very frustrated.

    Please help!!!

    Jonor85
     
  2. Outrider

    Outrider Private E-2

  3. Jonor85

    Jonor85 Private E-2

    first 3 logs....
     

    Attached Files:

  4. Jonor85

    Jonor85 Private E-2

    Ok thats all the logs I think. Just as an update, now I can't even download updates on it. I have gone through the whole malware clean up process you suggested and it has made not noticeable difference to firefox or IE7.

    I just opened utorrent to check the limits of my connectivity.

    As for the firewall issue, windows firewall is disabled and my computer is self built so no firewall program has even been installed.

    I've just realised you told me to post my logs in the malware forum.... whoops. Will do so now.
     

    Attached Files:

  5. Jonor85

    Jonor85 Private E-2

    Cannot access internet, recent malware attack

    I have recently had a fairly nasty malware/spyware attack on my PC and now I can't access the internet.

    Windows claims to be connected. The connection loss was gradual; first both explorers went and updates for programs such as AVG and superantimalware functioned for a while but have now lost the connection.

    Other computers on the same network can still access the internet and my computer still claims it is connected.

    Completed the malware removal guide. Logs attached on a different thread, apologies I didn't realise I had been asked to post on this forum rather than the other.

    http://forums.majorgeeks.com/showthread.php?t=173490&goto=newpost

    Please help!!!

    Jonor85
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Cannot access internet, recent malware attack

    I will merge your other thread into this one so we can look at your logs in the Malware Forum. ;)
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay there are some problems to remove; however, first we need to get a complete MGlogs.zip file. Yours is inccomplete which may be a sign that you either did not allow it to finish running, or that your protection software got in the way, or that you are getting one of the errors mentioned in the Using MGtools instructions.

    Please try running it again and check for any error messages or other problems. Then attach the new C:\MGlogs.zip file.
     
  8. Jonor85

    Jonor85 Private E-2

    Ok here is a new Mgtools log. I hope it is ok, I am sure it has run to completion and I ensured that none of my protection was blocking it as far as I know. Teatimer disabled, AVG is currently uninstalled. Other programs include malwarebytes antimalware and super antispyware but I don't think they even have protection on the free versions. My firewall is on the router.

    Hope this is better, thanks for your help on this, much appreciated.

    Jonor85
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O23 - Service: AVG8 WatchDog (avg8wd) (avg8 watchdog (avg8wd) ) - Unknown owner - C:\Program Files\tinyproxy\tinyproxy.exe (file missing)
    O23 - Service: Error Reporting Service (ERSvc) (error reporting service (ersvc) ) - Unknown owner - C:\Program Files\tinyproxy\tinyproxy.exe (file missing)
    O23 - Service: Event Log (Eventlog) (event log (eventlog) ) - Unknown owner - C:\Program Files\tinyproxy\tinyproxy.exe (file missing)
    O23 - Service: Network Connections (Netman) (network connections (netman) ) - Unknown owner - C:\Program Files\tinyproxy\tinyproxy.exe (file missing)
    O23 - Service: Network Location Awareness (NLA) (Nla) (network location awareness (nla) (nla) ) - Unknown owner - C:\Program Files\tinyproxy\tinyproxy.exe (file missing)
    O23 - Service: System Restore Service (srservice) (system restore service (srservice) ) - Unknown owner - C:\Program Files\tinyproxy\tinyproxy.exe (file missing)
    O24 - Desktop Component 0: Privacy Protection - (no file)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. Jonor85

    Jonor85 Private E-2

    Here are the logs you requested. I still can't access the internet but my computer still insists I am connected.

    Thanks
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Open notepad and copy and paste the following text in the quote box into the window:
    Save this as fix.bat
    Choose to save as all files.
    Doubleclick fix.bat and let the program run.
    A small black dos window will flash, this is normal.

    Now use windows explorer to find and delete:
    C:\WINDOWS\privacy_danger(2)

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file and tell me what issues you still have.
     
  12. Jonor85

    Jonor85 Private E-2

    The mglog is attached. Nothing has changed; still cannot access internet, computer still claims to be connected to the network.

    Thanks

    Jonor85
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Please download OTMoveIt3 by OldTimer and save to your Desktop.
    • Double-click on OTMoveIt3.exe to launch the program.
    • Copy the file(s)/folder(s) paths listed below - highlight everything in the quote box and press CTRL+C or right-click and choose Copy.


    • Return to OTMoveIt3, right-click in the open text box labeled "Paste Instructions for Items to be Moved" (under the yellow bar) and choose Paste.
    • Click the red MoveIt! button.
    • The list will be processed and the results will be displayed in the right-hand pane.
    • Highlight everything in the Results window (under the green bar), press CTRL+C or right-click, choose Copy, right-click again and Paste it in your next reply.
    • Click Exit when done.
    • A log of the results is automatically created and saved to C:\_OTMoveIt\MovedFiles \mmddyyyy_hhmmss.log <- the date/time the tool was run.
    -- Note: If a file or folder cannot be moved immediately you may be asked to reboot your computer in order to finish the move process. If asked to reboot, choose Yes. If not, reboot anyway.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from OTMoveIt.
     
  14. Jonor85

    Jonor85 Private E-2

    Logs attached. Since the last set of instructions my wireless adapter driver encounters errors on start up. Also the network connections button on the right of the taskbar has disappeared. When getting to network connections via the control panel, neither my wireless or ethernet (usually disabled) connections show

    Thanks for the help.
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Tinyproxy has messed with quite a few items.

    Go to start / run / type "services.msc"....check the following:
    Network Connections
    Network Location Awareness
    System Restore Service
    Tell me if they are disabled.

    Go to start / run / type "sfc /scannow" without qoutes and note the space, Have your xp disc handy.

    Also check device manager for any ! ? or X .....your drivers may well be corrupt.

    Let me know.
     
  16. Jonor85

    Jonor85 Private E-2

    checked the services list.

    Network connections (netman) startup type: automatic status: blank.
    NLA startup type: automatic status: blank.
    System Restore Service Startup: Automatic Status: Started.


    ran the scan and used the CD but it gave me notifications on what it had done, it just closed. I presume it worked ok.

    Checked device manager, all fine except "Nvidia nforce networking controller #2" which I presume is my ethernet connection that I have disabled.

    Regarding my network connections icons, the fact that they have disappeared, is that a result of the problem or should I try to reestablish it?

    Also with my wireless card driver errors, when I look at device manager it says it is working properly and that presumably means the driver is actually ok?

    Thanks for your help on this, much apprieciated.
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    OK....go back to services.msc and for the Network connections and the
    NLA , double click on each ....tell me what you get....general/recovery/ and dependencies.

    Do you have My Network places icon on the desktop?

    Can you establish a new connection?
     
  18. Jonor85

    Jonor85 Private E-2

    Net connections

    General tab: Path to executable : C:\Program Files\tinyproxy\tinyproxy.exe
    Service status: stopped
    Recovery tab: All fails say restart service reset fail count after 0 days and restart service after one minute.

    Dependancies tab: None

    NLA says the same as network connections under each tab

    My network places are not on my desktop or the taskbar do you mean network connections? That is not on the desktop or taskbar either. I can access both via the control panel.

    When I try to connect to the network using the new connections wizard, the wizard simply doesn’t start.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This is what should be in the "path to executable":
    C:\WINDOWS\SYSTEM32\svchost.exe -k netsvcs

    On the general tab for both the netconnections and NLA.

    Can you copy and paste those into the box?
     
  20. Jonor85

    Jonor85 Private E-2

    No I can't, the boxes are grey rather than white. I have no idea how to change it.

    What do you suggest?
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's try this...go to the device manager and uninstall your network adapters...reboot.

    Then see what is reported in the services.msc
     
  22. Jonor85

    Jonor85 Private E-2

    network adapters uninstalled. the tinyproxy path remains.
     
  23. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Before you start the below, physically unplug the cable to your computer and shut down all antispy and antivirus programs.

    Now, download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Once you comlete the above, attach the log from Avenger.
     
  24. Jonor85

    Jonor85 Private E-2

    Avenger log attached
     

    Attached Files:

  25. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, download a fresh copy of ComboFix and run this once more. Attach the new log once completed.

    Second, please download Registry Search (see the link titled RegSearch Download Link )
    • Extract the files from Regsearch.zip into a folder.
    • Doubleclick regsearch.exe to start the program.
    • Enter tinyproxy in the top area of the form and then click "OK".
    • Notepad will be opened with text in it (the file named RegSearch.txt will be saved in the program's folder as well). Attach this file along with the new ComboFix log.
     
    Last edited: Nov 12, 2008
  26. Jonor85

    Jonor85 Private E-2

    attached
     

    Attached Files:

  27. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  28. Jonor85

    Jonor85 Private E-2

    I do have the XP disc and the recovery console is already installed on my computer.

    Here is the GMER log.
     

    Attached Files:

  29. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Let's start by copying the bold text below to notepad. Save it as fixDNSC.reg to your desktop. Be sure the "Save as" type is set to "all files".
    • Please go to this link:http://live.sysinternals.com/
    • find the psexec.exe file listed in the list and click on it and download and save it to your Desktop. Doing this properly is critical for other steps below.
    • Now click Start, Run, and enter cmd and click OK. This will open a command prompt window with a prompt that shows the current folder you are in.
    • For you the prompt should show C:\Documents and Settings\User>
    • Now type cd Desktop and hit the enter key. There is a space after the cd.
    • If you do this properly, your prompt will change to C:\Documents and Settings\User\Desktop>
    • Type the below bold text and hit the enter key. This will open the Window Registry Editor. You will have to agree to the SysInternals License Agreement first that pops up.
      • psexec -s -i regedit
    • In the Registry Editor click File, Import and then navigate to the fixDNSC.reg file on your Desktop from the previous fix and double click on it to import it into your registry. If it works properly you should get a success message.
    • If you get a success message continue on with the below, otherwise stop and explain to me any problems you had.
    Now, download a fresh copy of ComboFix and attach the new log, also run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • ComboFix Log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds