Is it Malware?

Discussion in 'Malware Help (A Specialist Will Reply)' started by KevinSL, Jan 16, 2007.

  1. KevinSL

    KevinSL Private E-2

    I have a frustrating problem with my desktop running Win 2K Pro, with Kaspersky 6.0 (virus protection only) and Zone Alarm personal firewall, and I am not sure if it is malware, software or hardware related.

    For the last 6 days, I get a can't find server or DNS error when trying to access the Internet, and " the host could not be found..blah blah.. Protocol POP3, Port 110, Secure SSL; no socket error: 1022, error No 0x800CCC0D" when trying to get email.

    The problem started after trying to download and install a shareware engineering program from www.pwr-tools.com - a member of Association for Shareware Professionals, and OISV. The download took over 10 minutes on a cable modem. After trying to install on my secondary hard drive, I could not get onto the Internet.

    Trying to re-establish a connection, but message was that Ethernet cable was disconnected. Tried new cable - no change. Tried changing the PCI slot of the Ethernet module - no change. Lap top works with wireless so cable modem is ok. Ran Ethernet cable to laptop- that works. Ran Ethernet cable from desktop to cable modem - bypassing router - that did not work. Bought new Ethernet PCI module - did not work.

    I rebooted into bios - and looked at PCI connections in advanced section. I have 5 slots, and 5 PCIs were listed, however, I could only arrow down from 1 to 4. I rebooted in safe mode with networking, and could get on the Internet as well as my email. Went to Microsoft and redownloaded IE6 service pack 1. No change. Downloaded Mozilla Firefox but could not get a web page - only a white screen under the tool bar.

    While fighting through this over the last two days, I did receive an alert from Kaspersky Proactive defense that HKEY_LOCAL_MACHINE\System\control set 004\services\NMSCFG is trying to gain write access to a list of system services - value Imagepath - whatever that means?? I did not allow this as I was not familiar with it and had not done anything to initiate a call for anything.

    Now while I can't access the Internet, Kaspersky has been able to go out and get updated signatures. I used the CMD ping yahoo and got a reply. When I do a CMD ipconfig, I show an IP address, subnet mask, default gateway, but under media state it says cable disconnected. . I downloaded the LSP fix to my laptop and transferred to my desktop. It found no problems. I have tried disabling Zone Alarm, and paused protection with Kaspersky, and still could not get connected.

    About a month ago, I wanted to install Comodo Personal Firewall, but the install wizard never showed up after opening the files. After the download file "box" disappeared, I was prompted to disable any third party firewalls and click ok. Since I had already uninstalled previously used products, Trend PC Cillin, and CA AV, I should not have had any firewalls, yet after clicking OK, all boxes/popups disappeared, and nothing else proceeded. From loading Comodo on my laptop, I know that an install wizard should have started up.

    So then I tried Zone Alarm, but while trying to install it, my computer locked up, and I had to reboot in safe mode to correct issues. I went back to trying to get Comodo.

    Comodo forums recommended that I scan with numerous other free scan services from other AV vendors to insure that I got a good mix of weapons aimed at the problem. However, upon downloading Webroots new AV/FW scan, my computer locked up again, and I had to contact their tech help to reboot in safe mode and download their cleanup utility. Their tech help incidentally was superb.

    Spybot S&D would not download. Anything security oriented would not download, yet other programs would download with no problem. Since Kaspersky had notified me upon loading, that it had found an Invader trojan, and Backdoor trojan, I suspected that I had a security problem, and contacted their tech help. While their product might be highly rated, their approach to tech help is that it detracts from profits, and they make it extremely difficult to contact a person, don't respond to email requests, and offer weak solutions/suggestions when you finally do get in touch. Very unhappy with the product.

    In desperation, I tried Zone Alarm for a 4th time, and low and behold it loaded. Everything worked fine for a month till this problem of not being able to connect to the internet started last week. I have disabled the program and still can't get a connection.

    Meanwhile, Kaspersky periodically notifies me that Microsoft Intellitype Pro is trying to access the internet (I deny), and that Process PID 1048 tried to access Kaspersky Anti-virus 6.0 process PID 680 but has been blocked. Then within a minute of that event, I will get a notice that Running process C:\Program Files\Microsoft Hardware\Keyboard\type 32.exe: detected a new variant of riskware Invader(loader). The fact that Kaspersky shows these malware items present, and that I have had difficulty downloading any security related programs, but not other programs, and that I am naturally paranoid, leads me to believe that I have a malware problem.

    I have downloaded Getrunkeys, and Shownew to my laptop, transferred to my desktop and run them, but can’t get on the internet with my desktop. Any ideas where my problem lies and what to do?
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds