No sys restore/No connection

Discussion in 'Malware Help (A Specialist Will Reply)' started by misslaura1987, Dec 10, 2008.

  1. misslaura1987

    misslaura1987 Private E-2

    Hey, I was told to post my logs here and I also have an update on my situation. My internet started working on and off after deleting some stray folders in "C:\Program Files." Half the time my internet connection is EXTREMELY slow and half the time it runs at normal speed. My computer was starting up fine after running the Malware Removal steps I had saved on my USB drive on 12/07/08 but that was short-lived and it is starting up super slow again...sometimes it just freezes up before the desktop can even pop up and I have to restart my computer three times before it actually works or just boot up in safe mode. Here is a list of any problems I've run across in the removal processes:

    CCleaner (In safe mode because my computer kept freezing in regular boot mode)
    - Cleaned & scanned for issues already before Step 1 during "basic maintainence" so I did not know to use default settings and whatnot...

    SAS
    - Could not update (assuming it is because of my slow connection), last update was on 11/30/08
    - Last log did not show any threats but log showing threats from 12/07/08 can be provided if it would be of any help

    Spybot S&D
    - Last scan did not show any threats but WinAgent32.dll was detected and removed on 11/07/08

    ComboFix
    - Could not download newest version of ComboFix because connection was down
    - Tried installing Windows Recovery Console with Windows XP CD but it would not allow me because my "version of windows is newer than version on disc." Also tried downloading it from Microsoft but the download would not start and kept taking me to a page that cannot be displayed. Ran the program anyway...
    - Don't know if it because I ran the prog w/out the recovery console or not but I'm having trouble booting up in regular mode...was before though too so...
     

    Attached Files:

  2. misslaura1987

    misslaura1987 Private E-2

    mgtools log

    mgtools log
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The infection you have is known to infect router hardware. If you have a router hooked up then you need to follow the instructions for your hardware and reset it to factory default settings. Normally there is a recessed push button type switch that needs to be held down for some number of seconds to do this. After resetting to factory defaults on your router, you will need to reconfigure the router for your network if you have made any changes to the default network setup.


    You need to uninstall SUPERAntiSpyware. The version you have is way out of date. Then download and install the one from the link in the READ & RUN ME. Run a new scan and attach the new log.

    Once you can connect to the internet, you need to uninstall the below old Sun Java versions and install the current version as requested in step 1 of the READ & RUN ME:
    Java(TM) 6 Update 6
    Java(TM) 6 Update 7

    Some items in the HijackThis fix given below may not longer exist. Just ignore any that you do not find and continue.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
    O2 - BHO: (no name) - {09F7B221-760D-4865-93CF-6C5E771F53F5} - (no file)
    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O2 - BHO: (no name) - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - (no file)
    O17 - HKLM\System\CCS\Services\Tcpip\..\{668E2034-0CE4-4E27-BDC5-F66D93E857EC}: NameServer = 85.255.115.6;85.255.112.20
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.6;85.255.112.20
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.115.6;85.255.112.20
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.6;85.255.112.20
    O23 - Service: PsExec (PSEXESVC) - Unknown owner - C:\WINDOWS\PSEXESVC.EXE (file missing)
    O24 - Desktop Component 0: (no name) - (no file)
    O24 - Desktop Component 1: (no name) - (no file)
    O24 - Desktop Component 2: (no name) - (no file)
    O24 - Desktop Component 3: (no name) - (no file)

    After clicking Fix, exit HJT.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. misslaura1987

    misslaura1987 Private E-2

    Okayy, I guess my cable modem is considered a router? I did not know this, sorry. :) System is still starting up exteremely slow in regular boot mode and I seem to have to reset my modem every time I restart my computer but I DO get a great connection when I reset so yay for that! Also, could this infection have spread to my flash drive too? Well anyway, here we go again...

    - Uninstalled old versions of Java and installed Java 7 Update 11

    - Uninstalled SUPERAntiSpyware and TRIED to install newest version of SUPERAntiSpyware but I get this error message when attempting run the installer, "SUPERAntiSpyware Free Edition Version 4.1.0.1046 is already installed. You must uninstall the existing version before installer SUPERAntiSpyware Free Edition Version 4.23.0.1006. Do you want to uninstall the existing version of SUPERAntiSpyware Free Edition?" I hit yes and I get "The feature you are trying to use is on a network resource that is unavailable. Click OK to try again, or enter an alternate path to a folder containing the installation package 'WISCDDCBBF1270346BC938BBCC81A1EEAAA_4_1 in the box below." So I skipped this step because I cannot complete it.

    - Ran C:\MGtools\analyse.exe and fixed requested lines

    - Ran C:\MGtools\GetLogs.bat and attached log
     

    Attached Files:

  5. misslaura1987

    misslaura1987 Private E-2

    UPDATE! I went to the SUPERAntiSpyware website and downloaded the uninstall helper and it worked! So I installed and ran the new version, finding/removing 3 threats. I also ran C:\MGtools\GetLogs.bat again and attached both logs. By the way, after removing the stuff detected from SUPERAntiSpyware my computer started booting up fast again but I AM still having problems with my internet connection, even after resetting my cable modem numerous times.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you say resetting your cable modem, what exactly do you mean? Our you talking about power cycling it?


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Laura\Start Menu\Programs\>IMVU\Run IMVU.lnk (file missing)
    O17 - HKLM\System\CCS\Services\Tcpip\..\{668E2034-0CE4-4E27-BDC5-F66D93E857EC}: NameServer = 85.255.115.6;85.255.112.20
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.6;85.255.112.20
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.115.6;85.255.112.20
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.6;85.255.112.20
    O24 - Desktop Component 0: (no name) - (no file)
    O24 - Desktop Component 1: (no name) - (no file)
    O24 - Desktop Component 2: (no name) - (no file)
    O24 - Desktop Component 3: (no name) - (no file)

    After clicking Fix, exit HJT.

    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run a full scan with SUPERAntiSpyware
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • new SUPERAntiSpyware log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. misslaura1987

    misslaura1987 Private E-2

    I'm pretty sure that's what I mean...I hold in the recessed button for 15 seconds until all the lights turn off and then they turn back on and do their blinking thing...

    -Double clicked fixme.reg and merged w/the registry and received a success message
    -Ran SAS, CC, MGtools & attached logs

    SAS prompted me to reboot and it started up nice and fast like it used to! I still have a super slow connection though...maybe I should just reformat? :(
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well then it is not working since you are still infected. It looks like your modem firmware has been modified by the infection. This is happening all the time with this infection. If all you have is a cable modem and you do not have a router of your own in between the cable modem and your PC, then you need to get a new cable modem. If you have a real router of your own, you need to reset it to factory settings.


    You are not using the current updates for SAS. You have:

    Core Rules Database Version : 3661
    Trace Rules Database Version: 1641

    And as of the time I'm writing this they are already on:

    Core Rules Database Version : 3679
    Trace Rules Database Version: 1658

    You need to always check for updates before running a scan.

    Formatting your PC will not fix the problem with an infected router and or cable modem. They have to be restored to factory settings because as they are now, they keep reinfecting your PC.

    The below items in your HJT log (which did not get fixed) are signs of this DNS hijacker:
    O17 - HKLM\System\CCS\Services\Tcpip\..\{668E2034-0CE4-4E27-BDC5-F66D93E857EC}: NameServer = 85.255.115.6;85.255.112.20
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.6;85.255.112.20
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.115.6;85.255.112.20
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.6;85.255.112.20
     
  9. misslaura1987

    misslaura1987 Private E-2

    Well it's nice to know that because I have a lot of programs I cannot replace on my computer! Anyway, I do not have a router but I will go to Comcast immediately to get a replacement modem and let you know how things go. Thanks A LOT for your help, I would have reformatted a long time ago if it weren't for you. :)
     
  10. misslaura1987

    misslaura1987 Private E-2

    ok i swapped my modem and have yet to connect it. i followed the instructions you gave me before but i am still being reinfected with the hijacker somehow. i am reluctant to connect my new modem so im using my phone to post again...also i did not update bc my slow connection will not allow me to dl anything.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You really are not going to have to much of a choice since you say your phone line is too slow to download or do any updates on. You have out dated versions of programs and we need them updated. However do the below before hooking up the new modem.

    Did you fix those O18 lines I pointed out using analyse.exe. I will give you a step by step fix below.



    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.e-centives.com/cif/download/bin/actxcab.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{668E2034-0CE4-4E27-BDC5-F66D93E857EC}: NameServer = 85.255.115.6;85.255.112.20
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.6;85.255.112.20
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.115.6;85.255.112.20
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.6;85.255.112.20

    After clicking Fix, exit HJT.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Click Start > Run and type in cmd
    • Click OK.
    • This will open a command prompt.
    • Type or copy and paste the following line in the command window:
      ipconfig /flushdns
    • Hit Enter
    • Exit the command window

    Now make sure you have all web browsers closed to do this next bullet list of steps.
    • Go into Control Panel -->Network Connections.
    • Right click on your connection
    • and click Properties.
    • On the Properties page, highlight Internet Protocol(TCP/IP)
    • Click Properties. This will bring up another page.
    • Select Obtain DNS Server Automatically.
    • Click the ok button. The page will close.
    • Press ok on the page in front of you.
    • Restart the computer.
    • Reconnect to the Internet using Internet Explorer and use you new cable modem.
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  12. misslaura1987

    misslaura1987 Private E-2

    I don't have a phone line...my cable connection was working, it was just working slower than dial-up. My connection is no longer working, even with a new modem. I think my new modem cannot process the registration because of my horrible connection so I am totally beat for a connection. I am currently using a library computer or a cell phone to respond to your posts.

    - Manually updated SUPERAntiSpyware
    - O18 lines no longer exist
    - Registry merge successful
    - Attached MGlogs.zip

    Followed all requested steps to no avail, computer still runs the same :(
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since you updated SUPERAntiSpyware, does the new version find anything. If so, attach the log.

    Then perhaps the problem is with your cable providers connection.

    Sorry I meant to say 017 lines and they are still in your HijackThis log and also your log shows that you are running in safe boot mode. You need run in normal boot mode and you must make sure that you are selecting the below lines and remembering to click the Fix checked button after all browsers are closed.

    If you are physically disconnected from your cable mode there is no reason why these should not be getting fixed other than the below possibilities:
    1. forgetting select them and then to click Fix checked
    2. malware is blocking the fix. But no active malware was being seen.
    3. the protection software you have installed (AVG AntiSpyware and CA ) are getting in the way of malware removal which would mean your next step should be to uninstall these and then reboot and try and fix the 017 lines again and make sure they really get fixed.
     
  14. misslaura1987

    misslaura1987 Private E-2

    - SAS showed the same DNS Hijacker as it did before.
    - Called my provider and tried resolving the problem but we came to the conclusion that it was my computer that had the problem.
    - I do select/check and fix the O17 lines but they reappear with every start-up and I only ran in safe-mode because my computer would not boot up in normal mode. I do also make sure all browsers are closed when fixing.
    - Removed AVG. Did not know what CA was or how to remove it other than deleting the folder, "CA," in program files so I just left it and repeated all steps afterwards to no avail.

    I ended up backing up all my files to my iPod's hard drive and reformating through disk boot anyway so I will stop wasting your time now. Thank you for all your help though, I really appreciate it. It's nice that you guys do this for people. Hope you had a nice holiday!
     
    Last edited: Jan 1, 2009
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not if they keep returning after we clean everything up. This normally means that your router or cable modem is infected. We have seen this many dozens of times. The only other reason would be that protection software that is installed is getting in the way of the fix.

    Resetting the routers back to factory defaults always resolves the problem when the router is infected. As far as a cable companies modem/router goes, I'm not sure, but if it has the ability to set things back to factory defaults, it should also work.

    However none of this matters now if you have reinstalled. However I would suggest that you make sure those O17 lines have not come back again.

    I also suggest that you work thru this: How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds