BleepingComputer.com: infected with XP Total Security 2011

Jump to content

Forum Guidelines

Posted Image Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help


Posted Image Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.


Posted Image DO NOT RUN ComboFix unless requested to.


Posted Image Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


Posted Image When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Posted Image Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • This topic is locked

infected with XP Total Security 2011 Tried and I cant remove!

#16 User is offline   hep181 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 20
  • Joined: 20-February 10
  • Location:ny

Posted 25 April 2011 - 08:10 AM

Blade 81,
I can't say thank you enough for helping me with my laptop issues. I checked device manager and all is well, everything enabled and no errors. I re-ran MBAM after re-boot and found nothing. I ran the bat file and and here is the log.
Thanks again......
AJ




Windows IP Configuration



Host Name . . . . . . . . . . . . : laptop

Primary Dns Suffix . . . . . . . :

Node Type . . . . . . . . . . . . : Unknown

IP Routing Enabled. . . . . . . . : No

WINS Proxy Enabled. . . . . . . . : No



Ethernet adapter Local Area Connection 2:



Media State . . . . . . . . . . . : Media disconnected

Description . . . . . . . . . . . : Broadcom 440x 10/100 Integrated Controller

Physical Address. . . . . . . . . : 00-12-3F-80-E1-72



Ethernet adapter Wireless Network Connection:



Connection-specific DNS Suffix . :

Description . . . . . . . . . . . : Intel® PRO/Wireless 2200BG Network Connection

Physical Address. . . . . . . . . : 00-12-F0-AC-85-84

Dhcp Enabled. . . . . . . . . . . : Yes

Autoconfiguration Enabled . . . . : Yes

Autoconfiguration IP Address. . . : 169.254.97.90

Subnet Mask . . . . . . . . . . . : 255.255.0.0

Default Gateway . . . . . . . . . :

Server: UnKnown
Address: 127.0.0.1

Ping request could not find host google.com. Please check the name and try again.

===========================================================================
Interface List
0x1 ........................... MS TCP Loopback interface
0x2 ...00 12 3f 80 e1 72 ...... Broadcom 440x 10/100 Integrated Controller - Packet Scheduler Miniport
0x3 ...00 12 f0 ac 85 84 ...... Intel® PRO/Wireless 2200BG Network Connection - Packet Scheduler Miniport
===========================================================================
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
169.254.0.0 255.255.0.0 169.254.97.90 169.254.97.90 20
169.254.97.90 255.255.255.255 127.0.0.1 127.0.0.1 25
169.254.255.255 255.255.255.255 169.254.97.90 169.254.97.90 25
224.0.0.0 240.0.0.0 169.254.97.90 169.254.97.90 25
255.255.255.255 255.255.255.255 169.254.97.90 169.254.97.90 1
255.255.255.255 255.255.255.255 169.254.97.90 2 1
===========================================================================
Persistent Routes:
None

#17 User is offline   Blade81 

  • Bleepin' Rocker
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 6,364
  • Joined: 16-October 06
  • Gender:Male
  • Location:Finland

Posted 25 April 2011 - 12:10 PM

Hi,

Could you try to right click wireless network adapter on list of device manager window and select uninstall? Windows should automatically detect the device after a reboot and install drivers for it.
Microsoft MVP Consumer Security 2008 2009 2010 2011
ASAP & UNITE member since 2006
Posted Image Posted Image

Provided malware removal related instructions are meant to be used in the correspondent user's case only. If you have similar symptoms create own topic instead of following instructions given to some other, please.

#18 User is offline   hep181 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 20
  • Joined: 20-February 10
  • Location:ny

Posted 25 April 2011 - 12:30 PM

Blade,
I tried uninstalling and rebooting and still no luck. The PC shows the signal strength as excellent with "limited or no connectivity". I cant figure this one out?? Thanks again.

AJ

#19 User is offline   Blade81 

  • Bleepin' Rocker
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 6,364
  • Joined: 16-October 06
  • Gender:Male
  • Location:Finland

Posted 25 April 2011 - 01:36 PM

Hi,

Was the wireless connection working earlier? Do you recall at which point it stopped working?
Microsoft MVP Consumer Security 2008 2009 2010 2011
ASAP & UNITE member since 2006
Posted Image Posted Image

Provided malware removal related instructions are meant to be used in the correspondent user's case only. If you have similar symptoms create own topic instead of following instructions given to some other, please.

#20 User is offline   hep181 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 20
  • Joined: 20-February 10
  • Location:ny

Posted 25 April 2011 - 01:44 PM

The wireless connection stopped working right after the the malware dug in. During removal the connection did work at one point for a short while. I did some troubleshooting which revealed that the issue may be a general network issue and not a wireless issue, not sure if that helps.

This was received from the "Manual Diagnostic Tool" where all tests ran were passed except the ping test.

Ping Test
The ping test verifies whether the Wi-Fi adapter successfully sent messages to and received replies from the access point IP address, default gateway, DHCP server (if enabled) and DNS servers.

* Passes - if wireless adapter successfully sent messages to and received replies from the access point IP address, default gateway, DHCP server (if enabled) and DNS servers
* Fails - if wireless adapter sent messages to the access point IP address, default gateway, DHCP server (if enabled) and DNS servers but did not receive a reply

Note: If the ping tests to the access point and default gateway are successful but the ping test to the DNS server fails this is not a Wi-Fi network issue but a general network issue.



Thanks again
AJ

This post has been edited by hep181: 25 April 2011 - 02:05 PM


#21 User is offline   Blade81 

  • Bleepin' Rocker
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 6,364
  • Joined: 16-October 06
  • Gender:Male
  • Location:Finland

Posted 25 April 2011 - 02:21 PM

Hi,

Please run the following command from command prompt window (click start->run->type cmd.exe and press enter):
netsh winsock reset

Reboot to see if that helped in any way.
Microsoft MVP Consumer Security 2008 2009 2010 2011
ASAP & UNITE member since 2006
Posted Image Posted Image

Provided malware removal related instructions are meant to be used in the correspondent user's case only. If you have similar symptoms create own topic instead of following instructions given to some other, please.

#22 User is offline   hep181 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 20
  • Joined: 20-February 10
  • Location:ny

Posted 25 April 2011 - 02:26 PM

I think I got it to connect. I disabled wireless security from router, disabled broadcom from running wireless and let windows do it then switched back to braodcom. Not exactly sure how it did it, but it seems to be holding for now. I really can not thank you enough. I am very grateful. Blade81 RULES!

Thanks AJ

#23 User is offline   Blade81 

  • Bleepin' Rocker
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 6,364
  • Joined: 16-October 06
  • Gender:Male
  • Location:Finland

Posted 25 April 2011 - 02:51 PM

Good to hear the problem got resolved. Infection likely caused some conflict with those settings. Let's hope connection will last now :)
Microsoft MVP Consumer Security 2008 2009 2010 2011
ASAP & UNITE member since 2006
Posted Image Posted Image

Provided malware removal related instructions are meant to be used in the correspondent user's case only. If you have similar symptoms create own topic instead of following instructions given to some other, please.

#24 User is offline   hep181 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 20
  • Joined: 20-February 10
  • Location:ny

Posted 25 April 2011 - 05:02 PM

Blade,
So far so good (4 now) w/ the connection. I really can't thank you enough. This forum is he BEST!

AJ

#25 User is offline   Blade81 

  • Bleepin' Rocker
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 6,364
  • Joined: 16-October 06
  • Gender:Male
  • Location:Finland

Posted 26 April 2011 - 12:12 AM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.
Microsoft MVP Consumer Security 2008 2009 2010 2011
ASAP & UNITE member since 2006
Posted Image Posted Image

Provided malware removal related instructions are meant to be used in the correspondent user's case only. If you have similar symptoms create own topic instead of following instructions given to some other, please.

Share this topic:


  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users