Web browsers/ internet work intermittently

Discussion in 'Malware Help (A Specialist Will Reply)' started by tman697, Dec 10, 2009.

  1. tman697

    tman697 Private E-2

    Thank you for any help you can provide.

    The problem started (as far as I know) when I clicked on a pop-up (a couple weeks ago) that said I needed to download codecs to watch a video on a site that I was not very familiar with. The next day, I noticed that my internet connection would stop working after a while. Now my internet connection on that machine rarely works.

    I notice that dwwin.exe shows up in task manager whenever I try to run firefox or ie, and if I "end task" dwwin.exe, that is usually the only way the browser window will open. In ie, it usually says I am connected to the internet, but can't display the webpage. Intermittently, programs that have auto-update features will display pop-ups saying a download is ready.

    I ran firefox off of a ubuntu live cd, and it ran perfectly, which makes me think it is not a hardware problem. I have encountered several BSOD's since the problem started, but also ran memtest with no errors.

    I could not run Rootrepeal w/o an immediate BSOD after selecting the drive to scan (so no log is included). I also ran Superantispyware an additional time on quick only because it popped up with an update right after I finished the initial complete scan. I didn't want to be told I didn't use the most recent update. I pasted the quick scan into the original scan that is attached. *Note: the Trojan Guarder that Superantispyware found was downloaded by me from cnet after the problem started and before I found this forum.

    I have windows xp running. There is currently no antivirus software as I uninstalled AVG and have not had a consistent internet connection needed to install Avast. One of the logs says I had AVG running which may interfere, but I can confirm that it was not. I checked task manager and services.msc. I found a fix by deleting system32\wbem\repository after the log was created.

    Thank you in advance for any assistance you can provide.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    This is not something you should have installed. Uninstall it immediately. See the below to understand why!

    http://www.greatis.com/appdata/d/t/trojan%20guarder.exe.htm

    http://www.bleepingcomputer.com/startups/ComStart-15551.html


    You have a Master Boot Record infection. We will need to boot to the Recovery Console ( you installed it while you installed ComboFix) to remove this infection.

    Now boot to the Recovery Console and run the fixmbr to clear a Master Boot Record infection that you have.

    You can read the below to help you do this:

    http://support.microsoft.com/kb/307654


    After running the fixmbr command and boot back to normal mode, continue with the below.


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 2
    J2SE Runtime Environment 5.0
    Java(TM) 6 Update 7

    Now delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Todd\Local Settings\Temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. tman697

    tman697 Private E-2

    Thank you for your reply. I have uninstalled the trojan guarder software.

    I am having trouble accessing the windows recovery console. When the system boots, it flashes on the "select operating system" screen for a split second and then moves to booting xp normally. I managed to use F8 to get to the menu selection for the recovery console, but when I select that option and press enter, I get a black screen with a single blinking cursor in the upper left corner (no C:windows\ or anything like that).

    I can't find the XP install cd. Do you know of another way to get the recovery console (or fix the mbr w/o it). I tried running combofix again with a manually added copy of the windows setup floppy program dragged onto it, but it did not solve the problem. Unless you have another idea, I will try to find a way to get the windows setup floppies onto a bootable cd. Thanks.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You just need to hit the up arrow key on your keyboard as soon as the menu showing the Recovery Console and XP Boot selections appear. As soon as you hit this key, the boot process stops until you choose one of the boot options by selecting it with the up or down arrow key and then hit the Enter Key. You should not be using the F8 key option during bootup since this has nothing to do with running the Recovery Console.
     
  5. tman697

    tman697 Private E-2

    I can't get the recovery console to work. I used the method you suggested, and it hangs on a black screen with a single blinking cursor. I even created floppy discs w/ xp sp2, which got me to the console menu, but when I selected it, it crashed and restarted the system.

    Is there any other way to go about this repair, or is my system toast? I don't get any internet access under windows, but it works like a charm under ubuntu live.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Here a few options to try:
    • Backing up personal data really should be your first step just incase something goes wrong.
    • Borrow a Windows XP Pro SP2 CD from someone and use it to get to the RC
    • Try making and using this CD: Recovery console for those without an XP disk
    • Try running this which sometimes can fix MBR infections: Using Dr.Web CureIt
    • Try a tool like PrevxCSI: http://www.prevx.com/blog/84/MBR-Rootkit-new-tricks-added.html
    • RootRepeal has a feature to try and repair the MBR but you stated you could not run RootRepeal
    • You could test this link which I have not tried to see if it works for you: http://www.sysint.no/nedlasting/mbrfix.htm
    • Make a CD like the below and boot to it and try to repair the MBR
    • Find and purchase a 3rd party disk utility tool capable of repairing the MBR ( Hard Drive Mechanic comes to mind but I have no personal experience with it )
    • Total reinstall after deleting partitions and repartitioning and formatting but this is not an option if you do not have a Windows XP Pro boot cd which is needed to do this too.
     
    Last edited: Dec 18, 2009
  7. tman697

    tman697 Private E-2

    Okay, I have followed your directions and attached the logs. I used MBRfix from the UBCD4Win. I don't know how to tell if it did anything. I also ran a few of the spyware/virus scans included in the UBCD4Win that are also mentioned on this website as additional things to try. Nothing notable turned up.

    Browsers (IE and Firefox) still do not work. They take a couple of minutes before a window opens with an error message. Something is obviously damaged, but I hope the nasties are gone! Thank you for your help.

    Todd
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes your MBR infection was fixed.

    What error message are you getting exactly? Are you getting a BSOD?

    Uninstall FireFox, reboot, then download and install this version: Mozilla FireFox

    Does the new version work?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds