no internet connection after combofix step

Discussion in 'Malware Help (A Specialist Will Reply)' started by karadziedzic, May 22, 2008.

  1. karadziedzic

    karadziedzic Private E-2

    Hello,
    Thanks in advance for your help. My computer was infected with malware and just about everything else. I followed the steps that you provided in the Read & Run Me First Malware Removal Guide. I've attached the log filesfrom the first 3 steps. AFter running ComboFix, I could no longer access the internet. I tried to repair the connection but it did not work. My computer also is not allowing me to open the log files.....please help!!
    Thank you!
     

    Attached Files:

  2. karadziedzic

    karadziedzic Private E-2

    I was able to fix the internet connection problem by deleting cookies and temp internet files and rebooting. I would be grateful if you would still review my logs to see if you think that my malware problem is fixed.
    Thank you!
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to complete the step for running MGtools and attach the requested MGlogs.zip file.
     
  4. karadziedzic

    karadziedzic Private E-2

    Here is the MGlogs file. Thanks!
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    what is the below file on your Desktop?
    Code:
    "C:\Documents and Settings\FrTom\Desktop\"
    mbsexe~1.exe  May 21 2008     1699142  "mbs.exe.exe"
    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    Java(TM) 6 Update 5

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O8 - Extra context menu item: &Search - ?p=ZRxdm429NWUS
    O20 - Winlogon Notify: ddcdbyy - ddcdbyy.dll (file missing)
    O20 - Winlogon Notify: wvUMdCVM - wvUMdCVM.dll (file missing)
    O20 - Winlogon Notify: __c00CA5C2 - C:\WINDOWS\system32\__c00CA5C2.dat (file missing)
    O21 - SSODL: vbksrofa - {0F3541E7-4B50-4613-B0B4-38B2B347D62C} - C:\WINDOWS\vbksrofa.dll (file missing)
    O21 - SSODL: mpfanvqg - {5AA91E55-1945-44FC-85AB-4C37C91E2691} - C:\WINDOWS\mpfanvqg.dll

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. karadziedzic

    karadziedzic Private E-2

    Thanks so much for your help.
    No - mbs~1.exe was not on my desktop..
    I ran the steps that you requested, and have attached the log files. I ended up having to run combofix a second time at the end - I must have done something wrong because the log file was not created. The machine is looking good so far. Thank you again for your help!
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It was probably what you originally named ComboFix which should have been cf.exe

    Also you DO NOT have cf.exe on your Desktop as requested. Where are you running ComboFix from??? And why do you have the below two folders:

    C:\cf.exe
    c:\cf1.exe

    These can cause problems trying to run the ComboFix file that was supposed to be named cf.exe and that was supposed to be on your Desktop. Since you do not have it on your Desktop, you will have problem completing the below final instructions.

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    8. Go to add/remove programs and uninstall HijackThis.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
    At
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds