Multiple Problems Spyware etc.. & DSL Modem

Discussion in 'Malware Help (A Specialist Will Reply)' started by shewolf, Apr 25, 2005.

  1. shewolf

    shewolf Specialist

    Ok, I am trying to help out a friend who is having computer problems..
    Windows XP Home Edition SP1 SBC Yahoo DSL

    I know about the Read Me First please bear with me while I explain whats happening.

    When I installed AVG on a friends computer it found like 5 spyware, trojans etc.. during the scan well I had to leave (the scan was still going) and she wanted to know if it would automatically take care of them or not once the scan was done. So we stopped the scan to see what would happen. Well at that point we lost the capability of her computer recognizing the modem or the modem recognizing her computer.

    Now at this point I went through things checking internet connection, went through as much of the read me first as I could. Could not complete the Trend Micro or Symantec online scans as we couldn't get a internet connection. I did the Stinger, AdAware, Spybot, Kill2me, & CW Shredder all of those did find things and took care of them. In total I had about 239 infections removed if not more then that.

    Still unable to get online so we called SBC Tech Support and they had her create a new network connection to connect on broadband using a username and password. Ok well she can now have internet access but the internet light on her modem still won't light up and the computer and modem don't recognize eachother. I have tried uninstalling SBC Yahoo and reinstalling it with the disk that came with it but it won't install because the computer and the modem aren't recognizing eachother.

    So is it possible that when one of the viruses, trojans, spyware crap was removed from her computer during the initial AVG scan that was stopped in process that it also deleted a registry key that was needed to "support" the SBC DSL connection so the computer and modem recognize eachother? If this is possible then how do I get that registry key back? If I do a system restore will that bring it back or will I have to completely dump the computer and start out fresh?

    One thing I should also mention that before she set up the new network connection as instructed by SBC we couldn't even type in the 192.168.0.1 in the IE addy bar to bring up the modem details etc.. Even connecting with the new network connection of Broadband with username and password we still can't type 192.168.0.1 in the IE addy bar to bring up modem details. It just say page can not be displayed.

    I would appreciate any help anyone can give me on this.

    Thanks
    SW:)
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is there a router after the DSL modem or is it a direct connect to the PC?

    Are you getting a IP address assign? Are you set for DHCP? Do you see DNS settings?

    Click Start, Run, and enter ipconfig /all and click OK. That should show you what the connections settings are.

    Did you look to see if there are any O10 lines in a HijackThis log?
     
  3. shewolf

    shewolf Specialist

    No router Modem is connected directly to the PC

    Ok per instructions from SBC I did a CMD (Start Run CMD IPCONFIG) and it did not bring up any IP Addys it brought up 0.0.0.0 for the IP and Gateway. Per SBC instructions I was told to reset the modem via the button to push in with pen/pencil and hold in for 2 seconds. I did that and tried the CMD again and it brought up the same thing 0.0.0.0 for the IP and Gateway.

    SBC told me that this was the last resort and to uninstall and reinstall but still the computer and modem would not recognize eachother for me to be able to reinstall it.

    I was going to do a HJT today but she had to leave for work so I will have to do that on Wednesday. If I do find 010 lines what should I do? I do know she is still infected with spyware because some things are still in the add remove programs that I can't get rid of and they are all similiar in name there are about 3 of them and they are blah by Hotbar such as Outlook by Hotbar as one example I can't remember what the other 2 are but they are by Hotbar. When I click to remove them from the add/remove programs the computer sits idle for a long time and then it goes back to the add/remove program but won't allow me to remove those items.

    I think that once I can get this connection issue resolved then I can do scans online in safemode and update AdAware and Spybot and get rid of even more stuff. Also be able to run HJT and remove more things as well via HJT.

    I would like to mention that we have it so she can use the net its just set up the way SBC told us to that its a Broadband connection that you have to enter a username and password instead of an always on connection. So, I am not sure how to run the online scans in safemode with this type of connection as I have always dealt with an always on connection (which is what she used to have before all these problems began). Which is why I would like to if possible get the connection issue resolved the best we can. I am sure that all this spyware and crap is probably a leading factor in the connection issue.

    Sorry if I am rambling on.. just want to make sure that you are informed as best as possible.

    Chas thanks so much for all your time and help you know how I greatly appreciate all that you, PP, and everyone else do for us.

    SW:)
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must set the PC's connection for DHCP to get an IP address assigned. Otherwise you would have to set a bunch of static information which the DSL provider would have to give you and they never want static connections anyway.

    If the PC is setup properly, it is possible that the DSL modem lost its configuation. It may be setup incorrectly for the type of connection they are providing (I doubt it, but it is possible.) Most often the DSL modems are in what they call a bridged mode. This is a non-routed type connection and is normally the default. In this mode your IP address is assign via a higher level piece of network equipment (like a switch) and is just passed thru the DSL modem directly to your PC. The PC still needs to be in DHCP mode.

    If you are getting 0.0.0.0, you are not getting an assignment from the network or you PCs connection is not set for DHCP.

    I would have to see the O10 lines in an HJT log to know good/bad.

    You can run the online scans in normal boot mode on the Broadband connection.
     
  5. shewolf

    shewolf Specialist

    Ok I won't be able to get back to that computer until Wednesday so I will rerun the "ReadMeFirst" in normal bootmode with all the scans and do a HJT and the IPCONFIG/all and report back to you with what I found and attach an HJT log.

    thanks again..
    sw:)
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    OK! We'll be here at one time or another.
     
  7. shewolf

    shewolf Specialist

    Ok how do I get it set up for DHCP??

    This is totally new territory for me..

    Thanks..
    SW:)
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is a Networking Forum topic.... but I will give you some direction here.

    Click Start, My Network Places, and select View network connections.
    Now right click on your LAN connection and select Properties.
    Now on the General tab of the popup window, double click on the Internet Protocol (TCP/IP) selection.
    Make sure the in the next Window that Obtain an IP address automatically and Obtain DNS sever address automatically are selected and then OK your way out of that. With Windows XP it should not even be necessary to reboot but if it does not get you a connection reboot and see what happens.

    Check your ipconfig /all info at this point.
     
  9. shewolf

    shewolf Specialist

    Chas
    Here is the HJT ther is no 010 lines and currently we don't have AV or Firewall due to the fact that when we went to install the AV that is when we lost the connection between the modem and the computer for internet access..

    As for the IPCONFIG/ALL did that and there is no IP Addy or ip subnet mask they are all 0.0.0.0 and the default gateway has nothing just a blank space.

    The DHCP and DNS servers show 192.168.0.1

    the PPP adapter sbc shows that the DHCP Enabled is NO
    then that has IP, subnet mask, Default gateway, DNS servers with numbers .

    NetBIOS over Tcpip is disabled.

    If you want I will post this in the networking forum as well to get more help on the DNS DHCP portion.

    Thanks for all your time and help
    SW:)

    ps. I will be back over there tmrw to get more stuff gone and get the bad things in the HJT log removed..
     

    Attached Files:

  10. shewolf

    shewolf Specialist

    Chas one more thing this computer is like 4 years old never been cleaned up (defrag, spyware scans, etc.. ) if I do a "dump" of this computer would that help to eliminate all these problems so we can start fresh? I dont want these problems multiplied or still there if I go through the "dumping" process.

    Thanks tons..
    sw:)
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's first do this cleanup before we do anything else!

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\PROGRA~1\COMMON~1\ikqm\ikqmm.exe
    C:\Documents and Settings\VICKIE KNOP\Application Data\eetu.exe
    C:\PROGRA~1\COMMON~1\ikqm\ikqma.exe
    C:\WINDOWS\SYSTEM32\w?crtupd.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {CDE151E7-975C-E4F8-7439-BDA93DEE09E5} - C:\WINDOWS\System32\dyxf.dll
    O4 - HKCU\..\Run: [ikqm] C:\PROGRA~1\COMMON~1\ikqm\ikqmm.exe
    O4 - HKCU\..\Run: [Aida] C:\Documents and Settings\VICKIE KNOP\Application Data\eetu.exe
    O16 - DPF: {1954A4B1-9627-4CF2-A041-58AA2045CB35} (Brix6ie Control) - http://a19.g.akamai.net/7/19/7125/1268/ftp.coupons.com/v6/brix6ie.cab
    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebproducts/PopSwatterInitialSetup1.0.0.5.cab
    O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) - https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/111d47f6477d02a0cb23/netzip/RdxIE601.cab
    O16 - DPF: {7DBFDA8E-D33B-11D4-9269-00600868E56E} - http://www.edipole.fr/kits/en/WebInstall.dll

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\dyxf.dll
    C:\Documents and Settings\VICKIE KNOP\Application Data\eetu.exe
    C:\Program Files\Common Files\ikqm <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  12. shewolf

    shewolf Specialist

    Just wanted to let you know that I ended up having to "dump" the computer so it was back to factory installed state. Her son was messing around and did something or the spyware took over so everything was out of whack when she clicked on one icon it brought up another program. Such as she clicked on Yahoo Messenger Icon and it brought up her AdAware she clicked on AdAware and it brought up Internet Explorer.

    Her computer is working just fine now I went over to do the HJT clean up and discovered the messed up state and she just wanted to start fresh so we did.

    Thanks
    SW
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds