This morning I could not connect to the internet suddenly

Discussion in 'Malware Help (A Specialist Will Reply)' started by richkard, Jun 19, 2012.

  1. richkard

    richkard Private E-2

    Hello, I really don`t know what the problem is. I woke up this morning to find out that my computer could not connect to the internet. I am writing this on another computer. Additionnaly sometimes when I restart windows it returns to windows 98/2000 style and get the following message: COULD NOT CONNECT TO A WINDOWS SERVICE. I am attaching the log and hope you guys found the problem. I have to add that I ran combofix yesterday because I suspect something was wrong and maybe this is why problems started but afterwards I could connect normally. After runnig combofix restarted my computer. Please help me, thanks in advance.
     

    Attached Files:

    Last edited: Jun 19, 2012
  2. thisisu

    thisisu Malware Consultant

    Hello richkard :)

    http://img205.imageshack.us/img205/4783/regeditb.gif NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    • Attached is tdx.zip
    • Inside is tdx.reg
    • Extract tdx.reg to your desktop and double-click it.
    • Allow tdx.reg to merge into the registry.
    • If the merge was successful, restart your computer and test for internet connectivity.
     
  3. richkard

    richkard Private E-2

    OMG!!! I don't know what you did but you are a genius. I did everything I could but nothing worked. Just like that I have internet back on my laptop. Thank you very much ;). Do I have malware on my computer?? What was causing that??
     
  4. thisisu

    thisisu Malware Consultant

    Thanks for the compliment :)

    The only suspicious items I see are:

    C:\Users\HP\Desktop\fg729p.exe
    C:\Users\HP\Desktop\u1104.exe
    C:\Users\HP\AppData\Local\Temp\cis54E3.exe

    If you do not know what these are, you can upload them to VirusTotal for analysis.

    Other than that, your logs look fine.

    __

    Just for good measure, can you run a scan with HitmanPro using the Default Scan (Recommended) setting? No need to use Early Warning Scoring now.
    Then attach that new HitmanPro log when finished.
     
  5. richkard

    richkard Private E-2

    The 1st two files I do know them. But the 3rd one: "C:\Users\HP\AppData\Local\Temp\cis54E3.exe" I do not. I have another problem: My computer keeps telling me that I do not have an antivirus software but I have Avast installed. What's up with that??? And I have a second problem: A lot of time my screen flashes and for like 2 seconds I am back with windows 98/2000 interface. If you know how to fix them it would be great. Thanks
     
  6. thisisu

    thisisu Malware Consultant

    The first problem is easy to fix and I'll show you but first can you attach the requested HitmanPro log? Thanks
     
  7. thisisu

    thisisu Malware Consultant

    Also can you let me know the results from VirusTotal after uploading this file: C:\Users\HP\AppData\Local\Temp\cis54E3.exe
     
  8. richkard

    richkard Private E-2

    Hello sorry for the late reply. I tried to find the:C:\Users\HP\AppData\Local\Temp\cis54E3.exe but it was no where to be found. I also have some problem with my windows update settings; I can't turn it on. I attached the hitmanpro log. Thanks
     

    Attached Files:

  9. thisisu

    thisisu Malware Consultant

    http://img406.imageshack.us/img406/3189/windowsrepair.gif Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now open Repair_Windows.exe
    • Go to the Start Repairs tab.
    • Press the Start button
    • Create a System Restore point if prompted.
    • In the Repair Options window, choose the following repairs:
      • Repair WMI
      • Repair Hosts File
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Remove Temp Files
      • Repair Windows Updates
    • Place a checkmark in Restart/Shutdown System When Finished
    • Fill in the Restart System bubble
    • Now click the Start button.
    • Be patient while the tool repairs the selected items. Your computer should automatically restart when finished.

    http://img17.imageshack.us/img17/3214/baticonvista7.gif Now run C:\MGtools\GetLogs.bat by right-mouse clicking it and then selecting Run as Administrator
    This updates all of the logs inside MGlogs.zip.
    When it is finished, attach C:\MGlogs.zip to your next message. (How to attach)
     
  10. richkard

    richkard Private E-2

    I did the fix step by step as you explained it. But it's still not working.The Mgtools log is attached.
     

    Attached Files:

  11. thisisu

    thisisu Malware Consultant

    What error are you receiving when you try to turn on Windows Update? Have you tried pressing the "Check for Updates" button?
     
  12. richkard

    richkard Private E-2

    When I check for updates I receive the following error: Code 8024D00E Windows Update encountered an unknown error. Also the Action Center tells me that I do not have an antivirus software.
     
  13. thisisu

    thisisu Malware Consultant

    Go here http://support.microsoft.com/kb/971058 and press the Run now button. It should prompt you to download and run MicrosoftFixit.wu.MATSKB.Run.exe
    Follow the instructions within this program.

    __

    Afterwards, if you still have problems, do this:

    http://img97.imageshack.us/img97/8120/fss.gif Please download Farbar Service Scanner and run it on the computer with the issue.
    • Make sure all the options are checked
    • Press Scan.
    • It will create a log (FSS.txt) in the same directory the tool was run.
    • Please attach FSS.txt to your next message. (How to attach)
     
    Last edited: Jun 22, 2012
  14. richkard

    richkard Private E-2

    Yes it worked!!!!! Windows update is working. Thanks. But the computer still tells me that I do not have an antivirus software so I attached the Farbar Service Scanner log.
     

    Attached Files:

    • FSS.txt
      File size:
      2.1 KB
      Views:
      3
  15. thisisu

    thisisu Malware Consultant

    The FSS.txt looks fine. Can you try this again? Make sure you are restarting in order for the changes to take effect.

    http://img406.imageshack.us/img406/3189/windowsrepair.gif Repair WMI using Windows Repair by Tweaking.com.
    • Now open Repair_Windows.exe
    • Go to the Start Repairs tab.
    • Press the Start button
    • Create a System Restore point if prompted.
    • In the Repair Options window, choose the following repairs:
      • Repair WMI
    • Place a checkmark in Restart/Shutdown System When Finished
    • Fill in the Restart System bubble
    • Now click the Start button.
    • Be patient while the tool repairs the selected items. Your computer should automatically restart when finished.
     
  16. richkard

    richkard Private E-2

    I did the exact same thing. The action center still notifies me that I do not have an antivirus software.
     
  17. thisisu

    thisisu Malware Consultant

    I'm not sure why it's telling you that. Perhaps try uninstalling and reinstalling Avast? Or just tell the Action Center to ignore messages about Antivirus software.

    __

    If you are not having any other malware related problems, it is time to do our final steps:
    • Any programs we had you download and/or install can be removed at this time.
    • If we had you download and run ComboFix, here is how to uninstall it:
      • Press and hold the Windows key http://i1106.photobucket.com/albums/h363/debojyotidas/Windows_Logo_key.gif and then press the letter R on your keyboard.
      • This opens the Run dialog box.
      • Copy and paste the below text inside the text-field:
        • "%userprofile%\desktop\ComboFix" /uninstall
      • Now press ENTER
      • ComboFix will extract its files one last time and you should receive a notification that ComboFix has been uninstalled shortly after.
    • You can re-enable your Disk Emulation software at this time via DeFogger.
    • If we had you create or download a registry patch or "fix" script, these can be deleted at this time.
    • Go into the C:\MGtools folder and run the MGclean.bat file to remove additional traces of our tools.
    • Now we will toggle System Restore to remove any infected system restore points.
    • Lastly, here is a guide to protect you from future infections: How to Protect yourself from malware!
    • Be safe :)
     
  18. richkard

    richkard Private E-2

    Ok thank you for your help. I'll try to uninstall and reinstall Avast and see what happens. Thanks
     
  19. thisisu

    thisisu Malware Consultant

    You're welcome. Be safe :)
     
  20. richkard

    richkard Private E-2

    I have another problem. I really don't know what's going on. Maybe windows is corrupted. I am connected to the wireless network but it shows that I am not connected and shows me the cable icon. I don't know how to explain so I am attaching a screen shot I took.
     

    Attached Files:

  21. thisisu

    thisisu Malware Consultant

    The icon you circled with a red X through it is mostly likely for a wired (not wireless) connection that you aren't using.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds