Internet connection not working after system defender removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by karri0n, Dec 2, 2009.

  1. karri0n

    karri0n Private E-2

    Hello All,

    Thanks for all the great info on this site. I was able to finally get rid of the spyware infection using the tools and tips listed on this forum.

    I'll give a bit of background on the machine in question.

    This machine is used primarily for online gambling. Most of the casinos that are downloaded are legit, but once in a while there is one that causes an issue. I'm fairly well versed in malware removal, as I've worked as an IT professional in desktop support for several years, and done work on home machines with bad malware infections plenty of times. I usually use malwarebytes, spybot, and ad-aware. This combination usually fixes most things for me. As this is not my machine, changing web habits (I.e. STOP DOWNLOADING CASINOS) isn't really a possibility, so my intent is simply to lock the machine down as tight as possible.

    The problem started with google searches redirecting to random ad-search pages that were vaguely related to the keywords used. This was not affecting internet explorer at all.

    I ran malwarebytes and spybot several times, and it did find things, but never seemed to fully fix the problem. Through some manual searching and using the recovery console, I was able to restore my hosts file to a proper state, and I identified some potentially problematic services. I was still receiving the same issues after doing this, and I had heard decent things about AVG. I installed AVG, and it found more things and removed them. after rebooting after the AVG install, my network connection seemed to not be working. I couldn't get a connection in any programs other than Internet Explorer. I was able to reach DNS and ping as well, and DHCP seemed to work fine. I also noticed that the redirection from google started happening in IE. this had never been the case before; it was only happening from firefox.

    I ran the winsock fix from within SUPERAntispyware, and I ran a "netsh winsock reset catalog" and a "netsh int ip reset resetlog.txt", to no avail. I had doubts about it bein a winsock issue to begin with, as I can still access the network through internet explorer.

    I have attempted to simply run system restore, and system restore is unable to restore to any restore points whatsoever.

    The way the computer is acting seems to be as if there is a firewall running blocking my web traffic, with an exception setup only for IE. I saw one thing out of the ordinary in my Windows security center. Security center seems to think system defender is still installed. I have attached a screenshot of this in my log file.

    EDIT: Security center is no longer reporting system defender after running the "read and run" cleaning process. No screenshot is in the log file.

    One final step I tried was checking in my config for my wireless card. I did find, along with tcp/ip, client for microsoft networks, file and print sharing, and qos packet scheduling, a "symantec web filter driver" or something to that effect. Upon seeing this, I thought I might have found the problem. After removing this, there didn't seem to be any change.

    I have run the procedures in the "read and run" process, and attached my logs in an mgtools.zip file. the logs from the other programs are located in a directory within the zip. I have NOT attempted to run a system restore since, as I feel the machine is fully clean now, and do not wish to restore to a point that the infection was present.


    Thank you in advance for your help.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Looks like the PC is used for lots of game playing too!!!!

    No it is not fully clean yet.;)

    Note this PC has no antivirus, no realtime antispyware and no real firewall protection installed. It is basically unprotected.


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O8 - Extra context menu item: &Search - ?p=ZUfox000
    O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe (file missing)
    O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (file missing) (HKCU)
    O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (file missing) (HKCU)
    O15 - Trusted Zone: http://*.trymedia.com (HKLM)

    After clicking Fix, exit HJT.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Also, I noticed you are more than 200 database versions out of date with Malwarebytes. You really need to update to the current version and another scan would be a good idea too just to be safe.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. karri0n

    karri0n Private E-2

    Looks like that fixed everything up. Net connection is working now, and I can reinstall AVG and get the updates for spybot and MWB.

    I followed the rest of the procedures you gave me, and here are the logs. Combofix log is inside the mgtools zip.


    It looks to me like some part of Symantec was sticking around and messing up my network config. Do you think that was the case?



    Thanks a lot for the great help and site.
     
  4. karri0n

    karri0n Private E-2

    added attachment.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    While that could happen with leftovers from programs like Symantec, I think your problems were the below drivers:

    c:\windows\system32\drivers\fajgcozpqfmdi.sys
    c:\windows\system32\drivers\qxnnidn.sys


    Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds