Internet only works in Safe Mode (with networking)

Discussion in 'Malware Help (A Specialist Will Reply)' started by glassdome, Jul 11, 2008.

  1. glassdome

    glassdome Private E-2

    Internet only works in Safe Mode (with networking) – normal mode outlook downloads and some updates work, but, no internet

    Hi there.

    Thanks for your incredibly useful and user friendly instructions to sorting out PC problems. I, like quite a few others it seems, have a problem with internet access. This was posted in another forum and then moved here - before moving here I followed the instructions for Malware removal and gone through the process steps using the tools listed. I still have the problem as detailed below.

    The problem:
    I have 2 PCs – 1 HP media centre desktop and 1 Sony Vaio Laptop. This problem only relates to the Sony Vaio laptop as the PC can still access the internet without any problems at all.

    Sony latptop: running XP SP2; 1.73GHz, 513 RAM, NVDIA GeForce Go 6200.
    When I access the internet through IE or through Firefox I get the same error: Internet Explorer cannot display the webpage. Outlook and Windows updates still seem to be working, and I can see that I am connected by the Windows wireless icon, by ipconfig /all (results below). The internet works in windows safe mode (with networking).

    What I have tried:
    Unistalled all antivirus and firewalls (previously had Lavasoft Adaware and Avira). Have reset the router
    Have removed security from the router
    Have removed all PC checking software
    Run the steps in your help section: i.e. spybot, superantispyware, CCleaner, Combo-fix., MGtools, etc.
    Various pieces of Malware were found and successfully removed and all seems to be clean.
    Reset IP address and flushdns, also reset winsock
    I have disabled services and startup items through msconfig and services.msc and even tried to replicate the services in safe mode in normal mode.
    I have also tried a system restore to various prior dates, but, none of them completed successfully.
    After all of the above, the laptop still will not connect to the internet. I can ping web addresses with no problems and no lost packets.

    ANY HELP ANYONE CAN PROVIDE WILL BE GREATLY APPRECIATED AS I AM AT A LOSS AS TO WHAT TO TRY NEXT. THANKS IN ADVANCE.

    Ipconfig results:
    DHCP enabled: Yes
    Autoconfiguration enabled: Yes
    IP address: 192.168.0.4
    Subnet mask: 255.255.255.0
    Default Gateway: 192.168.0.1
    DHCP server: 192.168.0.1
    DNS servers: 192.168.0.1
    Lease obtained: 2008-07-11 12:21
    Lease expires: 2008-07-12 12:21

    Media state: Media disconnected


    Hijak this log:
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 13:03, on 2008-07-11
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16674)
    Boot mode: Normal

    Edit by chaslang: Inline HJ log removed. MBMA & CF inline logs attached.
     

    Attached Files:

    • mbam.txt
      File size:
      846 bytes
      Views:
      0
    • cf.txt
      File size:
      10.9 KB
      Views:
      0
    Last edited by a moderator: Jul 11, 2008
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please do not post inline logs like you are doing. The READ & RUN ME explains in several places how to attach log files. Halo also gave you a link on how to attach logs in the Software Forum thread you started.

    You need to attach the requested logs from SUPERAntiSpyware and MGTools which did not ask you to post a HijackThis log.
     
  3. glassdome

    glassdome Private E-2

    Thanks and apologies. I am having difficulties in tranfering the log files from my laptop to a machine with internet access and am new to this forum - I will hopefully attach the correct logs as attachments shortly - thanks for your patience and in advance for your help.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I thought you stated that Safe Boot mode worked? You could just transfer them in safe mode.

    Is the connection you are usining a wireless connection?

    What browser are you using?
     
  5. glassdome

    glassdome Private E-2

    Thanks - you are ablsolutely right it is working in Safe Mode - I had not even considered switching between normal and safe to send the messages and attachments and have been trying to transfer the logs between two machines by data key.

    I have run the scanners, downloaded the logs and attached the two requested log files. The problem with safe mode is that the screen is tiny on my widescreen Sony laptop which makes it hard to read so I hope I have completed all of the actions as required.

    I am using a netgear router and the desktop is working via the wireless connection. The laptop appears to be fully connected through the wireless also (and I can ping websites and get a response). I have both IE 7 and the latest Firefox, but neither work outside of SafeMode with networking. Please let me know if there is anything more I can provide in terms of information - I am really impressed with the ultra quick responses to my messages and hope that I can back onto the internet with my laptop soon.

    Thanks again.
     

    Attached Files:

    Last edited: Jul 11, 2008
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your problem may not be due to malware. Please do the below:

    • while in safe boot mode, run the C:\MGtools\GetLogs.bat program by double clicking on it. Wait for it to finish running and then attach the new C:\MGlogs.zip file that will be created. Attach this first before continuing.
    • now boot into normal mode and instead of using URL's in your browser, try IP addresses. Examples:
    • what happens with IP addresses
     
  7. glassdome

    glassdome Private E-2

    I have run the GetLogs.bat in Safe Mode and attached the new MGlogs.zip file. As I have done this in safe mode, I will now go back into normal mode and try using the IP addresses to look up the websites in IE. Thanks
     

    Attached Files:

  8. glassdome

    glassdome Private E-2

    Returning to normal mode I tried both IP addresses and for both received the message that the address is not valid and Internet Explorer cannot display the webpage. I also tried the IP address for the router and this gave the same response.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why is Spybot's Teatimer running? Please disable it now. See the READ ME.

    From normal boot mode, run MSconfig and using the Startups tab and the Services tab locate all the items for Symantec and disable them. The below are the items you will be looking for:
    Then reboot your PC in normal boot mode. You will get a message from MSconfig at startup warning you about being in Selective Startup mode. Just ignore it.

    Can you browse now? Attach a new MGlogs.zip file after running C:\MGtools\GetLogs.bat again right now in this mode.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I just noticed that the log you gave from safe boot mode is for the wrong user account. You need to use the user account you are having a problem with in normal boot mode. You logged into the Administrator account in safe boot mode. You need to use th Owner account which is the account you us in normal mode.

    Does your user account ( the Owner account) allow you to browse in safe boot mode?
     
  11. glassdome

    glassdome Private E-2

    I have checked the instructions for disabling the Teatimer in Spybot and the option is not ticked (i.e. redisent "TeaTime" [Protection of overall system settings] active" and so it should not be running. Is there any other way for me to check?

    I have logged in to Safe Mode as Owner and the internet works fine (Safe Mode with networking).

    I have de-selected the Symantec services and in start up and re-run in selective / diagnostic start up mode and the internet still does not work. I had previously tried to disable the start up and services options to match those in safe mode and this did not seem to work either. I have tried to remove all of the Symantec components a few times - as this is a very old anti-virus software setup (since have run Norton, and then more recently Avira - each on their own removing old versions first) is there a way to remove the Symantec software that remains?

    Thanks for your quick responses and help - hopefully this is narrowing down the potential problems.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It was only setup to run on the Administrator account.

    Yes it would be best to totally remove Symantec. Put your PC into Normal STartup mode with MSconfig first and then please run this Norton Removal Tool (SymNRT) then reboot your PC and then run it one more time and reboot again. Afterwards, run GetLogs.bat again and attach another MGlogs.zip file so we can be sure that all of it was removed. DO NOT install any other protection programs yet.
     
  13. glassdome

    glassdome Private E-2

    You are a genius - I have followed your steps and I am now sending this from my laptop which is connected and working. I am delighted. Prior to coming onto this forum, I spent ages trawling the internet and wasted almost a full day attempting to fix my PC. A few hours on here and it is working. Sincerest thanks.

    I have included the updated log file just in case there is anything else of concern.

    Is there anything else that I should do prior to installing anti-virus and firewall software? If not, I realise that you are probably not able to recommend any public domain anti-virus and firewall software, but, are there any good review sites where I could find info? I want to avoid causing the problems associated with downloading free software that might contain malware.

    Overall, this website has been fanastic help.

    Cheers
     

    Attached Files:

    Last edited: Jul 11, 2008
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. I figured it was Symantec and not malware. ;) Let's finish off some other things now that you can surf.


    Uninstall the below old versions of Sun Java:
    J2SE Runtime Environment 5.0 Update 1

    Now reboot

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!

    And now let's also cleanup from running the READ & RUN ME and the last step will work on getting you properly protected too.

    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  15. glassdome

    glassdome Private E-2

    I removed the old version of Java and replaced it with the new version.
    I merged the Reg file fixme.reg and it worked successfully
    I have run CCleaner and then the Getlogs.bat (attached the log files as requested).
    Removed combo-fix

    I will do the rest of the clean up and flush the restore points shortly.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs look fine! Don't wait to long to get your system protected by completing my final instructions ASAP.
     
  17. glassdome

    glassdome Private E-2

    Chaslang - thanks. I have installed anti-virus and firewall software as per your malware post. I am currently running the updates as I write. I have also gone through the security on my router to ensure that all is up-to-date and secure.

    I am so glad to be back online. You have been fantastic help.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds