W2K/IE6 "The page cannot be displayed" error

Discussion in 'Malware Help (A Specialist Will Reply)' started by NightBadger, Feb 9, 2008.

  1. NightBadger

    NightBadger Private E-2

    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    PC: Fujitsu Siemens Scenic

    I can log onto Internet no probs, browse away for approx one minute, then get "The page cannot be displayed" error, all/any webpage. I'm pretty sure malware is involved. No new installs or anything. This post is from a different PC, different location.

    I have tried IE Repair, reinstalling IE, virus scans, "READ & RUN ME FIRST", etc. I could really do with help interpeting my HijackThis log.

    I have had problems of late with Backdoor spyware:
    "Backdoor.Win32.Rbot.gen",
    "Backdoor.Win32.sdbot.ZG", &
    "Backdoor.Win32.sdbot.gen!A".

    I have run HijackThis (v1.99.1), read and followed all precautions. Here is my log. Please help if you can. Thank you...
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This is not a HijackThis log reading forum. It is a malware cleaning forum, and there is much more to cleaning malware than just HijackThis.

    Malware cannot be completely removed just by seeing a HijackThis log. If you need our help to remove malware DO NOT simply post a HijackThis log which will be deleted. You must follow the instructions in the below link.

    READ & RUN ME FIRST Before Asking for Support

    You will notice that no where in this procedure does it ask you to attach a HijackThis log. This is because it is embedded within our procedures. When you follow them properly, a HijackThis log will automatically be obtained from a properly installed HijackThis progam. And the log will be put into a MGlogs.zip file with a few other required logs. This MGlogs.zip will then be attached to a message. This in all explained in the READ ME.

    Please attach the requested logs.
     
  3. NightBadger

    NightBadger Private E-2

    Thanks for replying, apologies for my neebieness...

    OK. A HJT log can indicate the presense of Malware, yes? Just exploring possibilities right now, looking for a direction to follow.

    How can I follow procedures etc to create logs to bundle into MGlogs.zip when the PC cannot use Internet, as I stated?
     
  4. abri

    abri MajorGeek

    Hi NightBadger,

    Are you only having trouble with Internet Explorer? Can you use Firefox or Opera? If you don't have these alternate browsers installed on your computer, you can get download them at http://www.majorgeeks.com/downloads5.html

    Mozilla Firefox is the featured browser at the top of the list.

    If these browsers don't help you, please go to another computer and download Combofix and the MGTools, which are part of the READ & RUN ME and transfer them using a cd or a flash drive. Install them as per the instructions and run them. They don't need a browser as long as you can get them into your computer.

    abri
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Two things to do to start this:

    Use windows explorer and find and delete:
    C:\WINNT\system32\w32mvs.exe

    Now go to start / run / type "services.msc" without quotes and find Microsoft Visual Studio
    then right click the entry, select Properties and press Stop Service.
    * When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    * Click OK until you get back to Windows.

    * Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    * At the lower right, click on the Config button
    * Then click the Misc tools button
    * Select Delete an NT Service
    * Copy/paste W32MVS into the box that opens, and press OK
    * If you receive any error messages just ignore them and continue.
    * Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Now re-Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking fix, exit HJT.

    Now see if you can run the MGTools.exe and get the logs we need.
     
  6. NightBadger

    NightBadger Private E-2

    Hi guys, thank you for your time/input.
    1. Will try running Firefox, don't have on installed yet, but will certainly try it, ta abri for suggestion & link.
    2. Will follow TimW's instructions, thanks for the detailed list.

    Will get cracking, may take few days, thanks again, NB
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let us know how you get on ...:)
     
  8. NightBadger

    NightBadger Private E-2

    OK, update, things are reasonably sorted for now.

    I redone a total PCclean, virus sweep, etc, etc (many from MGs, thank you), only variation to the previous time was using MS Malware Removal 1.38 (used 1.37 last week) and a RAM change.

    Result IE back to normal for one evening only, next evening - problem returned but not as severe, could refresh page after about 10 attempts, obviously highly fustrating.

    Redone another total PCclean, virus sweep, etc, etc. Had trouble removing Backdoor:Win32/Codbot.By, Rbot.gen!A, & Sdbot.gen!A. Uninstalled Symantec Antivirus and tried some free Antivirus software individually, AntiVir PE Classic helped somewhat.

    Now only Sdbot.gen!A remains, instantly returns on removal. Removal ideas?
    Also Antivirus is suspect of C:\WINNT\System32\sfc.dll. What is this file?

    I will search MG for answers, any post/thread come to mind?

    No more probs to date with IE or Firefox. Will update again nxt week. NB
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We need to see the logs from running the Read and Run First procedures to help you remove the leftovers. :)
     
  10. NightBadger

    NightBadger Private E-2

    I switched to McAfee and that got rid of Backdoor.Win32.Sdbot.gen!A.

    I have run several spy detectors and nothing major popping up.
    Consider case closed.

    Thanks so much for taking time/effort to assist/comment.
    V much appreciated. Great site. NB
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're welcome. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds