Win XP Cleaning Done - Still Having Problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by naturalagent, Jan 1, 2009.

  1. naturalagent

    naturalagent Private E-2

    :confused Hi! I ran the Windows XP cleaning procedure for Malware. It seems to have worked! YEA! I'm online through wired ethernet highspeed dsl and am not getting any other popups or registry change notifications through Mcafee BUT! Here's the things I am still encountering:

    1. My Windows Update is not working and tells me that my updates are disabled. Even when I force a windows update request, it gives an error?

    2. I also have a wireless adapter in my laptop. It says it is connected, but when I attempt to use it to connect to the internet it tells me I need to clear my DNS cache?

    Thanks for all your work in helping me resolve these nasty malware problems. I look forward to your suggestions on fixing the above continuing issues. I noticed them before I ran the removal proceedures and they have not changed since removal (I noticed the problem starting about a week ago). I do not know where the malware came from, but I have a teenager in the house and I suspect porn. Although all browing histories have been cleared.

    The SuperAntispyware detected and cleaned over 20 malware. The spybot S&D encountered 24 malware and the Malwarebytes detected over 30 malware, all clean. The Combofix ran fine and the mgtools ran fine. I am attempting to attach log files.

    Thanks again for your help, I look forward to your direction - Julie
     

    Attached Files:

  2. naturalagent

    naturalagent Private E-2

    Re: Win XP Cleaning Done - Still Having Problems - Addtl Logs

    Hello again; The attached logs are from Malwarebytes Anti-Malware and Spybot Search and Destroy. Looking forward to your direction. Thank You So MUCH! Your site has been so very helpful!
     

    Attached Files:

  3. naturalagent

    naturalagent Private E-2

    Hi, Just found a fix in the software forum on the windows update problems. I am able to update all security patches and updates are now working! YEA! :-D
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!


    Uninstall the below software:
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner!

    Now goto this link Using MGtools and download the new version of MGtools.exe from the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. naturalagent

    naturalagent Private E-2

    Hi! Thanks for the info! So far there seems to be no more infection. However, my wireless internal atheros 802.11 b/g card will not connect to my router. I am only connecting through wired ethernet, dsl. The other computer on my network will connect, but it has limited connection as well, so I'm not entirely sure there is something wrong with the card. I have downloaded and installed all updates to the toshiba satelite system I am using so I'm not sure what else is going on. I've attached the logs from the scans to this reply. Looking forward to what you think. Thanks for all your help so far. Take care and keep up the great work on the forum! :) Julie
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why did you remove Freeze.com from the ComboFix procedure. Freeze.com is a toolbar that makes unwanted browser changes, such as reconfiguring browser’s search settings. And it tracks browsing and search queries.

    Your logs are clean other than Freeze.com

    Is is still telling you to clear your DNS cache? I would not think this would help if the wired interface workd, but try it anyway.



    Click Start > Run and type in cmd
    • Click OK.
    • This will open a command prompt.
    • Type or copy and paste the following line in the command window:
      ipconfig /flushdns
    • Hit Enter
    • Exit the command window
    If it does not help, try this: Fixing Wireless Zero Config Service


    Unlikely that this is malware although since you had one PC infected, you should clean the other to be sure. The other PC must be posted in a different thread.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds