BleepingComputer.com: Still Infected, need help!

Jump to content

Forum Guidelines

Posted Image Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help


Posted Image Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.


Posted Image DO NOT RUN ComboFix unless requested to.


Posted Image Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


Posted Image When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Posted Image Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • This topic is locked

Still Infected, need help! Removed Antispyware 2012 but still can't get online

#16 User is offline   CatByte 

  • Bleepin' curls!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 7,857
  • Joined: 09-November 08
  • Gender:Not Telling
  • Location:Canada

Posted 20 January 2012 - 06:35 PM

well everything is running that should be?

what AV and Firewall do you have active at the moment?

Try uninstalling them

are you trying to connect wirelessly or wired


check in Device Manager are there any warning triangles

run the following:

click start > run then type/copy/paste the following command in

netsh int ip reset c:\resetlog.txt

A log will be generated on the root c drive could you attach that
The help you receive here is free. If you wish to show your appreciation, then you may Posted Image
Microsoft MVP - 2010, 2011

#17 User is offline   Frosty1 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 29
  • Joined: 23-December 10
  • Gender:Male
  • Location:Conejo Valley, CA

Posted 20 January 2012 - 06:56 PM

There is no AV running currently, the only firewall running is the Windows Firewall.

I'm using the wireless connection primarily, but have tried the wired connection which yields the same result.

No warning triangles in the Device Manager.

Here is the log...


reset SYSTEM\CurrentControlSet\Services\Dhcp\Parameters\Options\15\RegLocation
old REG_MULTI_SZ =
SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\?\DhcpDomain
SYSTEM\CurrentControlSet\Services\TcpIp\Parameters\DhcpDomain

deleted SYSTEM\CurrentControlSet\Services\Netbt\Parameters\EnableLmhosts
added SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{DAB03F5A-7A63-4417-A5B6-49C395578BCF}\DisableDynamicUpdate
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{DAB03F5A-7A63-4417-A5B6-49C395578BCF}\IpAutoconfigurationAddress
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{DAB03F5A-7A63-4417-A5B6-49C395578BCF}\IpAutoconfigurationMask
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{DAB03F5A-7A63-4417-A5B6-49C395578BCF}\IpAutoconfigurationSeed
reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{DAB03F5A-7A63-4417-A5B6-49C395578BCF}\RawIpAllowedProtocols
old REG_MULTI_SZ =
0

reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{DAB03F5A-7A63-4417-A5B6-49C395578BCF}\TcpAllowedPorts
old REG_MULTI_SZ =
0

reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{DAB03F5A-7A63-4417-A5B6-49C395578BCF}\UdpAllowedPorts
old REG_MULTI_SZ =
0

deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DontAddDefaultGatewayDefault
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\EnableIcmpRedirect
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\EnableSecurityFilters
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\SearchList
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\UseDomainNameDevolution
reset Linkage\UpperBind for PCI\VEN_14E4&DEV_4311&SUBSYS_00071028&REV_01\4&6C79FC5&0&00E0. bad value was:
REG_MULTI_SZ =
PSched

reset Linkage\UpperBind for PCI\VEN_14E4&DEV_170C&SUBSYS_01AF1028&REV_02\4&2FE911E8&0&00F0. bad value was:
REG_MULTI_SZ =
PSched

reset Linkage\UpperBind for ROOT\MS_NDISWANIP\0000. bad value was:
REG_MULTI_SZ =
PSched

<completed>

#18 User is offline   CatByte 

  • Bleepin' curls!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 7,857
  • Joined: 09-November 08
  • Gender:Not Telling
  • Location:Canada

Posted 20 January 2012 - 07:14 PM

Let's try a manual rebuild of tcpip

I'd like you to uninstall and reinstall TCPIP again, but using the directions from this MS KB How to remove and reinstall TCP/IP on a Windows Server 2003 domain controller This set of directions is a bit different procedure from what you followed earlier. Please be sure to carry out the steps below in the order given: (images and instructions to aid what you've read at the MS link, are provided courtesy of one of our Experts. :)
1. Locate the file - C:\Windows\inf\Nettcpip.inf, and then open it in Notepad.


Posted Image


2. Locate the [MS_TCPIP.PrimaryInstall] section.

3. Edit the Characteristics = 0xa0 entry and replace 0xa0 with 0×80.


Posted Image


4. Save the file, and then exit Notepad.


Posted Image


5. In Control Panel, double-click Network Connections, right-click Local Area Connection, and then select Properties.


Posted Image Posted Image


6. On the General tab, click Install, select Protocol, and then click Add.


Posted Image


7. In the Select Network Protocols window, click Have Disk.


Posted Image



8. In the Copy manufacturer’s files from: text box, type c:\windows\inf, and then click OK.


Posted Image



9. Select Internet Protocol (TCP/IP), and then click OK.


Posted Image


Note This step will return you to the Local Area Connection Properties screen, but now the Uninstall button is available.

10. Select Internet Protocol (TCP/IP), click Uninstall, and then click Yes.


11. It is important that you restart the computer to complete the uninstall.



------------


Step #2 - Reinstall of TCP/IP


Posted Image


Edit the file - C:\Windows\inf\Nettcpip.inf. Replace the 0×80 back to 0xA0

Redo sub-steps 4-11 to re-install TCP/IP
The help you receive here is free. If you wish to show your appreciation, then you may Posted Image
Microsoft MVP - 2010, 2011

#19 User is offline   Frosty1 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 29
  • Joined: 23-December 10
  • Gender:Male
  • Location:Conejo Valley, CA

Posted 22 January 2012 - 06:47 PM

Followed the instructions.

Removed both registry entries and reinstalled TCP/IP, didn't seem to make any difference. Still cannot get online. Really not sure what do at this point.

Maybe you have some other ideas?

Thanks

#20 User is offline   CatByte 

  • Bleepin' curls!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 7,857
  • Joined: 09-November 08
  • Gender:Not Telling
  • Location:Canada

Posted 22 January 2012 - 07:54 PM

You might try uninstalling SP3 then re-installing it

you may be missing some integral files that I'm not seeing in the logs:


  • Click Start, click Run, copy/paste the following into the open run box:
    c:\windows\$NtServicePackUninstall$\spuninst\spuninst.exe then click OK.
  • When the Windows XP Service Pack 3 Removal Wizard starts, click Next.
  • Follow the instructions on the screen to remove Windows XP SP3.


Then go to MS to download and reinstall the service pack:

Download the latest Windows XP service pack from the Microsoft Download Center
You can download the stand-alone update package from the Download Center.
This page will say that this installation package is intended for IT professionals and developers. However, you can safely download this file.

http://www.microsoft.com/downloads/details...08-1E1555D4F3D4
The help you receive here is free. If you wish to show your appreciation, then you may Posted Image
Microsoft MVP - 2010, 2011

#21 User is offline   CatByte 

  • Bleepin' curls!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 7,857
  • Joined: 09-November 08
  • Gender:Not Telling
  • Location:Canada

Posted 04 February 2012 - 07:36 PM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days. Please include a link to your topic in the Private Message. Thank you.
The help you receive here is free. If you wish to show your appreciation, then you may Posted Image
Microsoft MVP - 2010, 2011

Share this topic:


  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users