Internet Access blocked

Discussion in 'Malware Help (A Specialist Will Reply)' started by enikolich, Nov 8, 2010.

  1. enikolich

    enikolich Private E-2

    Hi all. I've never posted for help before. I read everything I can and I'm always able to figure it out. Here's what I have - Windows 7 64bit system with IE8. Open Windows Explorer and I get "Internet Explorer cannot display the webpage." I run with no add ons and the same happens. I can reboot in safe mode and Explorer opens to google homepage without issue.

    I have run every virus program I could find and nothing found. I've run malware bytes, hitman, adaware, rkill, spybot, super antispyware, tdsskiller, trojan remover and nothing. So here is my Hijackthis log. I hope someone can help.

    EDITED by dr.moriarty: Posted inline HJT log removed - R & R ME FIRST not followed.
     
    Last edited by a moderator: Nov 8, 2010
  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, enikolich

    Do you have the same problem when using another browser?

    NOTE: Because of your 64bit OS, you can't use ComboFix - Please download and run this in its place in the scanning sequence. OTL by OldTimer, saving it to your desktop:
    • Close all open windows on the Task Bar. Double-click the OTL icon to start the program and let it run uninterrupted.
    • When the windows appears, underneath Output at the top - change it to Minimal Output.
    • Under the Standard Registry box, change it to All.
    • Check the boxes beside LOP Check and Purity Check.
    • Now click the Run Scan button at Top left and let the program run - the scan may take 5-10 minutes.
    • Do not TOUCH your keyboard until the scan completes!
      • It will produce two (2) logs on your desktop, one will pop up called OTL.txt and the other - Extras.txt. These logs are saved normally directly under your C:/ directory.
      • Now exit Notepad.
      • Exit OTL by clicking the [X] at top right.

    Attach both OTListIt.txt and Extras.txt logs to your next reply -- along with the requested logs from this procedure:

    Please read ALL of this message including the notes before doing anything.

    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and then attach the requested logs to your next reply when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.
    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    * Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated - our system works the oldest threads FIRST.
     
  3. enikolich

    enikolich Private E-2

    Hello and thanks for taking time to investigate. The first question "Do you have the same problem when using another browser?" The answer is yes. I downloaded Firefox and had the same result.

    Prior to posting on this site, I attempted a system restore. When I first rebooted, IE worked fine. It was only after Windows downloaded and installed updates that the problem reocurred.

    The instructions said to remove all but one protection application. I attempted removal of Norton and there was no response at all. I attempted removal of Super Anti-Spyware, and I got a message that said "Error reading uninstall information." Norton is also completely unresponsive in safe mode.

    From the Vista Cleaning Procedure, I was unable to install MG tools. I get an error message that says "cannot start of run due to imcompatibility with 64 bit versions of Windows.

    Attached are the logs from Super AntiSpyware, Malwarebytes, and OTL.

    I did run CCleaner and defogger as instructed.

    Thank you all again for the help.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We need to run an OTL Fix

    • Right-click OTL.exe And select " Run as administrator " to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the Image textbox. Do not include the word Code
    Code:
    Code:
    :otl
    @Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:D287FACF  
       
    :commands
    [EMPTYTEMP]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.

    Now run this online scan:

    Running Kaspersky Online Scanner

    Rename C:\MGTools.exe to bullfinch.com > reboot into safe mode and double click C:\bullfinch.com to run it. Attach the C:\MGlogs.zip if successful for Dr M's reviewal as well as the log from OTL and the results from Kaspersky.
     
  5. enikolich

    enikolich Private E-2

    Hello. Attached is the OTL log and the MGtools log. I was unable to run Kaspersky on line scanner. (I can only get on line in safe mode.)

    Two things seemed to be preventing me from running it. I received a message that I was not running Java 1.6 or higher. So I downloaded the latest version of Java, copied it to a flash drive and installed it. Rebooted and made sure Java was actually installed and still got the error message. I also got a message about disabling any virus protection program. Norton is still on my machine and I was unable to uninstall it. I did not want to download and run the Norton removal tool without asking first. Don't want to take any steps without your advice.

    Thanks again. You are all amazing for taking the time to help the rest of us.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What can you tell me about these two files?

    • C:\Windows\$÷Á
    • C:\Windows\,ûÍ
     
  7. enikolich

    enikolich Private E-2

    Sorry for the late reply. I can't tell anything about either of those files. They are both 20 Bytes, the first one created 11-8-2010 at 10:28 a.m. and the other crated 11:19 A.M. Both say "attributes A" under details.

    That's all I know.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you don't know what those files are, then delete them. I am not seeing any malware in your logs. What issues are you still having?
     
  9. enikolich

    enikolich Private E-2

    Hello everyone. The problem is resolved!!! After all the advice and scans and everything else, my problem persisted. I could access the internet in safe mode, but not in normal. No logs showed any malware.

    What I ended up doing was downloading the Norton uninstall tool and completely wiping Norton Antivirus from the computer. I then went through the malware removal process thread at the beginning of this forum. I am now back in business!

    Thank you al so much for your assistance and your time. COmputer is up and running and protected by AVG. I learned tons from the forum and have some great tools now for keeping my computers clean. Thanks again!!
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know!! :)

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds