No Internet access, probably a root file?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jerkbucket, Dec 19, 2011.

  1. jerkbucket

    jerkbucket Private E-2

    Hi! Your forum self-clean guide has helped me more than once (Thanks for that!), however this time it is not.

    PC is my Cousin's. WinXP 32bit.
    Basically it will not connect to the internet at all. I installed a PCI network card just to make sure it wasn't a bad motherboard chip, and it still will not connect. The green lights are on the network router as they should be.

    His home page is still google.com. He ran malwarebytes and avast, and spybot and they all came up clean. He then uninstalled avast and ran hijackthis. he then brought it over and I went through the clean-thread.

    I didnt save the super-spyware or malwarebytes logs because they both said it was clean and tbh I didn't expect to need to post them based on past experience, but I have the other 3 attached. Also, the versions I used could not be updated because of no internet connection.

    His PC could not run the windows recovery console as it wasn't installed, and I didn't know if I needed to try and download it on another pc and transfer it in the middle of the programs operation, and then rerun it, especially since the guide says not to rerun it.

    Anyway, see if you can help, one program said his calc.exe file is corrupt.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You are WAY out of date with your version of MGtools. You must download it using another PC and then transfer to this PC via USB flashdrive, CD etc. Do the same with ComboFix.exe too since yours is too old to be used properly

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )



    Now attach the below log:
    • C:\MGlogs.zip
    Once you attach this log, we can continue!
     
  3. jerkbucket

    jerkbucket Private E-2

    The Combofix I downloaded a couple times, and it kept saying out of date. It must get stuck in the registry the first time it runs and wont overwrite? I'll have to uninstall it or something I guess.

    So nothing in them is useable right now?

    I'll repost logs after I rerun it all.
    Thanks.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you downloading from the link we gave?


    Correct. For the problems you are mentioning, we need the logs from the current version of MGtools.

    Part of your problem may be a Zero Access infection and the newer version of ComboFix will address most of this.
     
  5. jerkbucket

    jerkbucket Private E-2

    Alright, I redownloaded all the files and reran them.

    I couldn't get the Super anti-spyware program to run, it crashes, so I have no log for it.

    Again, I have no internet connection, and one of the programs (I forget which one) said it's files were 111 days out of date. (this is the version you had me download)

    Thanks for the help.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Program versions and database versions are two different things. As stated in the READ & RUN ME instructions, after installing programs like SUPERAntiSpyware and Malwarebytes, you still have to update the database being used.

    You have many problems due to a new very nasty infection that has just started appearing. You may have lots of registry corruption/modifications.



    Please download aswMBR ( 511KB ) to your desktop.
    • Double click the aswMBR.exe icon to run it
    • Click the Scan button to start the scan
    • On completion of the scan, click the save log button, save it to your desktop and attach this log to your next reply.
     
  7. jerkbucket

    jerkbucket Private E-2

    I couldn't update the programs without access to the internet, so I didn't. :confused

    I ran the program and attached the log.
     

    Attached Files:

  8. thisisu

    thisisu Malware Consultant

    Hello jerkbucket,


    You can download (from a working computer) and run these (on the infected computer) to update the definitions (on the infected computer).
     
  9. jerkbucket

    jerkbucket Private E-2

    I assume you want me to rerun those programs with the new definitions, and post new logs?
     
  10. thisisu

    thisisu Malware Consultant

    Yes, if you can please do while chaslang gets back to you.
     
  11. jerkbucket

    jerkbucket Private E-2

    Unfortunately, the PC in question has become extremely slow after running the aswMBR program. It has been stuck at the windowsXP screen for ten minutes, reboot and it does the same thing.

    Trying to boot into safemode, it gets stuck at MUP.SYS
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not related to the aswMBR scan. That was a scan only function. It did not make any changes to your system. Nor did it find any problems in the MBR anyway.

    Unfortunately, the problem you are having now is likely a compounding affect of the infection you have. Back in message # 6 where I had you run aswMBR, I also said the below
    Do you have your Windows XP boot CD?
     
  13. jerkbucket

    jerkbucket Private E-2

    Yes, I have the XP disk.

    Is it saveable? or should I just wipe it and start over? I think we got all his files, but you know how people can rathole something away in a folder and decide they need it as soon as you format the drive....

    I'm up for the challenge if you are! tell me how to use the XP disk to boot into the system!

    P.S. I wasn't blaming the slow boot on the MBR thing, just that happened to be the last time I touched it, and it was too slow to use afterwards. I know it is jacked up, that's why I'm here :)
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then give the below a try. It can sometimes be quite useful in fixing issues like this.

    http://support.microsoft.com/default.aspx?scid=kb;en-us;307545&sd=tech

    It is a little long and some people get confused by it, but just take your time and follow the steps carefully. There are significantly easier ways to do this but it requires have another special boot disk and a good understanding of what the above steps are actually trying to accomplish as well as a good understanding of Windows and the special boot disk
     
  15. jerkbucket

    jerkbucket Private E-2

    Well, I read the thread and it says it only works for SP3 disks. Mine is not SP3, and I don't get the option of hitting "R" to recover it.
    I guess we are out of luck?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it doesn't. You are reading a message telling you that support for SP2 is ending. What is in the Microsoft link works for all SP levels of Windows XP.
     
  17. jerkbucket

    jerkbucket Private E-2

    Sorry about that, you are correct.

    At step 5, part one, where it says "type the following...."

    md tmp

    I get "access denied"
     
  18. jerkbucket

    jerkbucket Private E-2

    additional info for prior post:

    Oh, btw, I didn't get the option to enter a password for admin (in recovery), but I know there wouldn't have been one on this machine, so I am assuming it either skipped it and didn't ask for it, or the drive is not allowing write access due to the rootkit junk.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is there already a folder with that name? You can type dir tmp to see .
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you never created a password ( which is a very bad idea since hackers immediately get full administrator rights without needing a password ) then there would not be one to enter. There is no rootkit active when you boot to the Recovery Console from the CD. If you booted from an installed copy of the Recovery Console then you could have problems due to an infected MBR ( that is if your MBR is infected or a partition is infected as with new TDL infections ).
     
  21. jerkbucket

    jerkbucket Private E-2

    This is exactly what it says.

    Code:
    C:\>dir tmp
     Directory of C:\tmp
    
    An error occurred during directory enumeration.
    
    C:\>
    
    C:\>dir
     Directory of C:\
    
    An error occurred during directory enumeration.
    
    C:\>
    I booted using the windowsXP CD. I can't boot without it.
     
    Last edited: Dec 29, 2011
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are not supposed to be at the C:\ prompt when in the Recovery Console.
    You should be at the C:\Windows> prompt.

    In addtion the command I gave you was not just dir
    It was dir tmp
    But you are not in the right folder. Thus you are not following the insructions in that Microsoft link properly.
     
  23. jerkbucket

    jerkbucket Private E-2

    Step 5 does not tell me to change to the /windows folder, it just says generically:
    Code:
    At the Recovery Console command prompt, type the following lines, pressing ENTER after you type each line:
    md tmp
    copy c:\windows\system32\config\system c:\windows\tmp\system.bak
    copy c:\windows\system32\config\software c:\windows\tmp\software.bak
    copy c:\windows\system32\config\sam c:\windows\tmp\sam.bak
    copy c:\windows\system32\config\security c:\windows\tmp\security.bak
    copy c:\windows\system32\config\default c:\windows\tmp\default.bak
    
    delete c:\windows\system32\config\system
    delete c:\windows\system32\config\software
    delete c:\windows\system32\config\sam
    delete c:\windows\system32\config\security
    delete c:\windows\system32\config\default
    
    copy c:\windows\repair\system c:\windows\system32\config\system
    copy c:\windows\repair\software c:\windows\system32\config\software
    copy c:\windows\repair\sam c:\windows\system32\config\sam
    copy c:\windows\repair\security c:\windows\system32\config\security
    copy c:\windows\repair\default c:\windows\system32\config\default
    Well, I did exactly what it said, and it doesn't work. I can't even change directory to /windows, it says 'the path or file specified is not valid', which I am guessing it can't get to the windows folder, and that is why it is stuck at the C:\ prompt.
    Now that we have established this fact, what's next to try?
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's correct. Because when you boot up from a CD into the Recovery Console command prompt, you will already be at the C:\Windows> prompt meaning you are already in the Windows folder. If you are not getting this then I have to question what you are doing. Are you sure you are booting a Windows XP boot CD and logging into the Recovery Console?

    What you should be going thru while booting the CD is Windows like shown in the below ( scroll to the section for Windows XP )

    http://www.windowsnetworking.com/articles_tutorials/wxprcons.html

    Note this example shows the default folder to be C:\WinNT but most people now install Windows XP and call use C:\Windows . Either one is okay because it is still the base folder that Windows is installed into
     
  25. jerkbucket

    jerkbucket Private E-2

    Yep, I get the same blue setup screen. But when the next one shows the command prompt, mine does NOT go to C:\windows, it goes to C:\ and none of the standard dos commands except HELP work. You can question my ability all you want, but I am telling you the truth about the C:\ prompt. I've been using PC's since 286's needed a math-coprocesser to run CAD applications, and I made custom bootable floppys to get specific games to run on 486's. I apologize if I sound offended, I just want to know what to do since the recovery doesn't work. If you don't know, then I will format the drive and start over from scratch. If there are other avenues to try, then I let's give them a go.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not that I'm questioning your abilities. It is more that that results are unexpected and confusing. Remember I'm not sitting in front of your PC so I cannot see 100% of everything that is happening.

    Do you get a screen like below asking you to choose your Windows XP installation?
    http://forums.majorgeeks.com/chaslang/images/RC/Rec_Cons2.gif

    Or did it also show

    1: C:\

    instead of

    1: C:\WINDOWS


    So you are saying no DOS commands work?No dir and no cd windows

    If you only have c:\ and no Windows installation had shown and the output from a dir command does not show any folders, then it would seem your file system has been deleted and a format and reinstall is your best option especially since you say you already backed up files.
     
  27. jerkbucket

    jerkbucket Private E-2

    I get no choice what to work on, no password, no anything. Once I hit "R" at the blue welcome screen, it does its thing and lands me at the C:\ prompt with no commands regarding folders or files useable. Reinstall it is.
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it sounds like this would be the fastest/best solution now.
     
  29. jerkbucket

    jerkbucket Private E-2

    I'm somewhat surprised about this, since it started out as a routine virus. Is this becoming more prevalent? Should I warn friends about backing their stuff up more than normal? (dumb question, I know)

    I've never seen spyware so bad that it causes a reformat before. Especially since it was working ok (without internet) for a good week or more before it got unusable.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The exact end result that you ran into is not prevalent. Of late, we have had lots of these infections that windup breaking internet access. We are getting quite a few per day. And other malware removal sites are too. No other users ran into the problems you ran into.

    Malware is getting more in more destructive lately. And simple act of removing the malware is resulting in many features within the Window Operating System getting broken. Many services and registry keys, and also sometimes important files are getting corrupted or deleted.

    There also many new infections impacting Master Boot Records and even adding infected partitions. Both of these will survive formatting.

    So in short, malware is significantly worse than ever and protection software is lagging extremely far behind in trying to protect against or even find or remove these new infections. Simply put, against these new infections protection software is just about useless.
     
  31. jerkbucket

    jerkbucket Private E-2

    I thank you for your efforts, it would have been nice to save it but sh!t happens.
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds