Malware removal stopped internet access on 5/25/10

Discussion in 'Malware Help (A Specialist Will Reply)' started by aholley1, Jun 18, 2010.

  1. aholley1

    aholley1 Private E-2

    This all started when I was downloading piano music for my daughter. I thought it was strange that it was an .EXE file. I could not find the music anywhere else. When I clicked on it, it disappeared. I knew I was in deep dodo. I was here on May 25 "doing it myself" removing malware on an xp machine and ran into a problem. I made it to run SAS and I lost my internet connection. I talked to SAS support for a few days but we were unable to connect to the internet. We ran a lot of software but nothing helped. When it finally came down to "You need to reformat C:\ in order to get an internet conncetion," SAS support had helped me all they could. I posted on another site 4 days ago. No bumping allowed so I am now on page 10 with no replys. Not even any replys after I went to the waiting room yesterday!
    I have a dell 5100 desktop connected to a Belkin router with cable (used 2 different cables and 2 different nics ... also tried wireless adapter w/ no luck). Two other desktops and a notebook connect to the internet with wireless adapters. So far I have run
    TFC
    CCleaner
    mgtools
    erdnt
    gmer
    rootrepeal
    combofix
    dds.scr
    erunt_setup
    HijackThis
    MBam
    MGtools
    OTL
    winsockxpfix
    PCTools on line scanner
    SUPERAntiSpyware (lifetime version)
    I have probably run a few more that I don't remember or can't find.
    Oh yea, I ran Microsoft Security Essentials and removed Trojan:Jave/Selace.L, Trojan:Jave/Selace.K, Exploit:Java/CVE-2008-5353.c and 300 plus copies of Trojan:Win32/Alureon.BP MSE removed Alureon on the 25th, 26th, 27th & 28th. I may still have some.

    I would like to find out if my system is clean. If it is, then I can persue my internet access problem. When my wife asks today, "How are the repairs coming?" I don't want to tell her I am still waiting to here back. (from the other place) It's ok if I am still waiting to hear back from here.

    I have a lot of .txt and .log files that are 4 days old but nothing has been done to the machine in 4 days .... except I removed ie8. It reverted to ie6.
    If you can help I would appreciate it. It you can't, thats ok too, I see that you help a lot other people.

    Please feel free to chew me out if I didn't post the right info/order/location ... at least I will get a reply!;)

    Thanks,
    AH
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the following logs>
    SAS
    MBAM
    RootRepeal
    ComboFix
    C:\MGLogs.zip
     
  3. aholley1

    aholley1 Private E-2

    More files coming.
    Some logs are older than others. The pc hasn't been used for anything since the problem but I will be glad to rerun any or all scans/fixes.
     

    Attached Files:

  4. aholley1

    aholley1 Private E-2

    Combofix.txt file is to large!

    Probably 95% of this file is this line with a different number. I can remove all except the 1st and last of these lines to make it smaller or I could split the file.
    c:\windows\system32\explorer32\Recycle\capture98414266109.jpg
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can zip the Combo log. Did MGTools not run? You posted something that was not the C:\MGLogs.zip.
     
  6. aholley1

    aholley1 Private E-2

    I reran MGTools.
    I think I got it right now.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs. I do see however, that you are not connected. This could be a matter of a bad NIC card. You should probably post in the networking forum for additional assistance.

    While you are here, you can use windows explorer to find and delete:
    C:\Documents and Settings\All Users\Application Data\AVG9
    C:\$AVG

    When you open device manager, are there any ! or ? Are you using a router or are you direct connected to the modem?
     
  8. aholley1

    aholley1 Private E-2

    I took care of the AVG stuff.
    I have the network cable disconnected(Belkin wireless router). I have been worried about the malware. I just reconnected and still no internet access (I have been trying from time to time). No problems show up in device manager. I have tried two NICs and different cables. I also tried wireless with no luck. Three other computers connect wirelessly. I have been worried about rootkits and dns changers. You said that no malware shows up in the logs. Are there some types of malware that could still remain? I am going to proceed to the networking forum regardless.

    Thanks again,
    AH
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Since other computers connect, then it wouldnt be an issue with the router. You say you have swapped out NIC cards with out success? Have you tried updating the drivers? The cheapest method I can think of is to purchase a USB wireless adapter to act as a test.

    I didn't see any thing removed that would indicate an issue with your connection ability. And if you have already hard wired and run the SAS network repair utility without success, I would post in networking.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     
  10. aholley1

    aholley1 Private E-2

    USB wirless wouldn't connect.
    I'll review the final steps again after I get the needed internet access for some of the software.
    I'm going to concentrate on the networking issue now.

    Thanks again for all your help
    AH
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. I hope you can get the wireless figured out.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds