Maleware ?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by theremotedr, Mar 11, 2012.

  1. theremotedr

    theremotedr Master Sergeant

    My sister has given me a laptop of which she was using no problem or so she tells me.
    I have an issue where i cant connect to the internet,either wireless or wired.
    The router is also used for my pc which is working fine.
    Any advice how i can check for maleware etc if i cant connect to the internet on the laptop,i could use the pc with a usb stick but not sure which programme to download etc from the working internet connection on the pc.
    I have also noticed on the laptop that i cant access the firewall,i now and then get a message like windows firewall settings cannot be displayed because the associated service is not running etc etc,clicking yes windows cannot start the windows firewall/internet connection sharing (ics) service.
    Any advice would be great to sort this issue.
    WINDOWS XP HOME 32 BIT
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything. Note if you cannot save things in C:\ then just save them to your Desktop. Make sure that you have disable UAC and rebooted first if you are running Windows Vista or Windows 7.

    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.

    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.



    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!

    Helpful Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:


    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. theremotedr

    theremotedr Master Sergeant

    I should also mention that my network connections folder is empty ?
    Do i still need to follow the advice mentioned or do i need to install windows ?

    Just asking before i start.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run through the procedures so we can get a better idea as to what is happening and decide if it would be better just to reformat and re-install.
     
  5. theremotedr

    theremotedr Master Sergeant

    No Joy.
    I have downloaded and transfered the tools to the laptop but thats as far as it goes.
    I double click on a tool and i see a black dos box pop up then it dissappears.
    Nothing happens as it is the same for each tool i tried to double click on.

    I have noticed that on the pc they were downloaded to is a nice icon etc but when on the laptop they are just a small grey box with a blue header.
    I double clicked a setup file on the pc and it starts to install it but on the laptop as advised above,just a black does box pops up ??
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please do the below so that we can boot to System Recovery Options to run a scan. There will be two options to choose from. One if you do not have your Windows 7 boot DVD and another when you have your DVD.

    For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Option1: Enter System Recovery Options from the Advanced Boot Options:

    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    Option2: Enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  7. theremotedr

    theremotedr Master Sergeant

    Windows 7 ? i am using xp home edition
     
  8. theremotedr

    theremotedr Master Sergeant

    I have restarted the pc and pressed f8
    I now see a blue box with the following and not the standard black screen with white text.

    PLEASE SELECT BOOT DEVICE

    PS-TSSTcorpCD/DVDW TS-L532A
    PM -SAMSUNG MP0603H
    USB2.0
    Intel UNDI,PXE-2.0 (BUILD 082)

    Please confirm
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am assuming that your PM -SAMSUNG MP0603H is the boot drive. Can you boot to it or get into safe mode?
     
  10. theremotedr

    theremotedr Master Sergeant

    The laptop is made by packard bell
    When i start the laptop i see the NEC logo on the screen,just for your information.

    I have selected the item you advised but just started like i had switched it on.
    I do not see the black screen with white text like the normal safe mode screen.
    shall i try another selection ?
    I have no disc for this laptop only the microsoft product key.
    This is driving me nuts
     
  11. theremotedr

    theremotedr Master Sergeant

    I have put the files onto a cd and put them on the laptop.
    This has allowed me to start the first tool,so i will be back with logs i hope.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your only hope may be to remove the disc and put it in an external drive enclosure. Then see if you can run our scans on it.
     
  13. theremotedr

    theremotedr Master Sergeant

    I am running the Superantispyware tool at the moment.
    So far so good.
    I will report back with logs once done.
     
  14. theremotedr

    theremotedr Master Sergeant

    Just an update.
    I have run a few of the tools in order of the list and now nearly at the end of the combo fix tool.
    As its been a long day trying to fix this laptop and combo fix running now for at least 2 hours i have just read RUN FROM DESKTOP & NOT A FOLDER ON THE DESKTOP,i ran the tool from a folder on the desktop !
    It has ran the 50 stages of the scan and deleted files / folders etc.
    It then restarted the laptop.
    I have a blue box which reads REBOOTING WINDOWS...PLEASE WAIT.
    The screen is still showing the same message for some 15 minutes now...SHOULD I BE WORRIED ?
    I see my desktop photo at the moment and this message in a blue box but no folders yet.

    Please advise if this is normal or advise otherwise.
    I have logs for all other scans that have been run.
     
  15. theremotedr

    theremotedr Master Sergeant

    After i posted my last reply combo fix advised me that it needed to shutdown as an error occurred.
    It had scanned for around 2 hours and had deleted files & folders.
    I had no option but to click on ok and the laptop switched itself off.
    After 5 minutes i switched it back on again,no log had been created so i continued to the next tool.
    I have attached the logs of the other tools run as per listings.
    Should i run combo fix again ? i will await instructions as it took around 3 hours only then to hang / crash.
     

    Attached Files:

    Last edited: Mar 12, 2012
  16. theremotedr

    theremotedr Master Sergeant

    This morning when i got up i decided to run combo fix again.
    It completed the scan this time in about 40 minutes as opposed to last nights 3 hours.
    I have attached the log file for combo fix.
    I did notice whilst running the scan the following.
    It asked to update via the internet but it could not do this because one of my reasons for running this is becuase i cant connect to the internet.
    It restarted the laptop fine today whilst last night it hung for say 1 hour then crashed.
    I get a message pop up 2 times like the following,IPCONFIG.EXE APPLICATION ERROR this application failed to initialize properly (0cx0000006) click on ok to termintae the application.
    After i did this twice the log file was produced.
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Use windows explorer to find and delete:
    c:\windows\system32\uha.exe

    Please download MiniToolBox and save it to your desktop and run it by right clicking and selecting Run As Administrator.


    Checkmark following checkboxes:

    • Flush DNS
    • Report IE Proxy Settings
    • Reset IE Proxy Settings
    • Report FF Proxy Settings
    • Reset FF Proxy Settings
    • List IP configuration
    • List Winsock Entries
    • List Devices -> All
    • List last 10 Event Viewer log

    Press Go and attach the result (Result.txt) that pops up. A copy of Result.txt will be saved in the same directory the tool is run from.




    Now download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.

    • Now open Repair_Windows.exe
    • Go to Start Repairs tab.
    • Choose "Custom Mode" and press "Start".
    • Create a System Restore point if prompted.
    • In the Custom Mode window, select the following repair options:
      • Repair Windows Firewall
      • Repair Internet Explorer
      • Repair Hosts File
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Windows Updates

    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • If asked to reboot the computer for the changes to take affect, make sure other tasks in the program are not still running before accepting to restart.

    Reboot after running Windows Repair.
     
  18. theremotedr

    theremotedr Master Sergeant

    There is no option on the MiniToolBox for LIST LAST 10 EVENT VIEWER LOG so i put a tick in the cloest thing which is LIST LAST 10 EVENT VIEWER ERROR.
    Whilst it was doing its scan twice popped up the ipconfig error message as mentioned before.

    With regards to the Windows Repair tool i assume i did the correct thing and UNTICK ALL the items that were ticked and then selected only the ones you mentioned.
    I restarted the laptop as advised,there is no log for this tool correct ?

    I have attached the log Result.txt
     

    Attached Files:

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip
     
  20. theremotedr

    theremotedr Master Sergeant

    Where is this file to ?

    I have downloaded yesterday MGtools.exe ?
     
  21. theremotedr

    theremotedr Master Sergeant

    I have read it again and now running the scan,sorry
     
  22. theremotedr

    theremotedr Master Sergeant

    Here is the logo files attached as requested
     

    Attached Files:

  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    1. Go to Start ==> Run (or Windows key+R)
      • Type the following in the run box and click OK: notepad c:\windows\inf\nettcpip.inf
        (note that there is space after notepad)
      • The above file will open in the notepad.
      • Under TCP/IP Primary Install section find the following: Characteristics = 0xA0
      • Edit 0xA0 and replace it with 0x80 (replace A with 8)
      • Under File menu click Save and close the notepad.

    2. Go to Start ==> Control Panel. Double-click Network Connections. Right-click Local Area Connection, and select Properties.
      • On the General tab, click Install a popup window opens.
      • Select Protocol from the list and then click Add.
      • A new window opens, click Have Disk....
      • In the browse... box type c:\windows\inf
      • Click OK.
      • Select Internet Protocol (TCP/IP), and then click OK.
      • On the Local Area Connection Properties screen select Internet Protocol (TCP/IP) and click Uninstall, and then click Yes.
      • Wait until it asks to restart, and then restart as requested. Continue with the below after restarting.

    3. Go to Start ==> Run (or Windows key+R)
      • Type the following in the run box and click OK: notepad c:\windows\inf\nettcpip.inf
        (note that there is space after notepad)
      • A file opens in the notepad. Under TCP/IP Primary Install section find the following: Characteristics = 0x80
      • Edit 0x80 and replace it with 0xA0 (replace 8 with A)
      • Under File menu click Save and close the notepad.

    4. Go to Start ==> Control Panel. Double-click Network Connections. Right-click Local Area Connection, and select Properties.
      • On the General tab, click Install
      • A popup window opens. Select Protocol.
      • A new popup window opens. Select Internet Protocol (TCP/IP), and then click OK.
      • Wait until it asks to restart, and then restart as requested. Continue with the below after restarting.

    5. Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    6. Then attach the below logs:
      • C:\MGlogs.zip

     
  24. theremotedr

    theremotedr Master Sergeant

    When i get to step 2 there is nothing in the Network connections folder.
    It is empty like original post.
     
  25. theremotedr

    theremotedr Master Sergeant

    Would it be best if we re-wrote Windows ?
    Nothing on the laptop is anygood to me anyhow.
    As i did not get a Windows disc with this laptop i have purchased a Windows Home Edition disc from ebay.
    I hope you use it to re-install Windows on the laptop & use my Product key which is on the bottom of the laptop of which is for the current version currently installed.
    This would also be fresh & free of problems ?
    Once installed i only wish to use this laptop for an email account & access to the internet.

    Please advise.
    Thanks for your help.
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You could try posting in the networking or software forum, but without a disc, I doubt they will be able to help you. If you don't have anything important on the system, then doing a fresh install would probably be best.
     
  27. theremotedr

    theremotedr Master Sergeant

    Ok Fine thanks very much.
    A question for you.

    As i do not have a disc with the laptop but only the product key i assume the following,
    1,I should be able to install Windows ok & enter my producy key ?
    2,The bugs/viruses "if any left" will be erased/overwritten ?
    3,The network connections folder will then have the local area connection icons ?
    4,Would i need to enter the Bios and change the order for the boot so when i switch it on it will load straight from the windows disc in the drive or do i install Windows by just putting in the disc and go from there ?

    Please advise,
    Thanks very much.
     
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're very welcome.
     
  29. theremotedr

    theremotedr Master Sergeant

    Ok perfect thanks for the quick reply.
     
  30. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem. Hope it all works out. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds