Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Internet No Longer Works After Deleting Infected Files...help!


  • Please log in to reply
1 reply to this topic

#1 Lanimilbus

Lanimilbus

  • Members
  • 59 posts
  • OFFLINE
  •  
  • Local time:11:36 PM

Posted 19 March 2006 - 11:42 PM

As of today my main computer no longer connects to the internet...the DSL cable is plugged into the back, but nothing related to the internet will work...Internet Explorer, Outlook, etc. etc...but the computer downstairs, which is also connected to the same DSL connects fine. Also, if I unplug the cable from the back of the tower and plug it into my laptop, my laptop connects fine, so it's just my main computer that won't connect...now, as to what I've done differently to my main computer today...
I re-installed Norton Anti-Virus 2005 on my main computer (It's a Windows 98) and ran the full system scan. It came up with 40 or so results, 25 or so which it couldn't delete, and two of which it couldn't delete but it quarantined them, saying they were Trojan Horse viruses...the two files it quaratined were: "uni_eh.exe" and "unin101.exe." Then the ones that it said it couldn't delete I searched for and manually deleted on my own, if they were still there. Two of them wouldn't delete because it said Windows was currently using them, so I went into Safe Mode to delete them...those two files were: C:\WINDOWS\webhdll.dll and C:\WINDOWS\SYSTEM\typftp.exe. Then when I restarted regularly, the internet no longer worked. The internet DID work before I manually deleted the threats that Norton found, but hasn't since I restarted in safe mode after deleting the last two.
With that being said, what should/can I do now? All of my files and folders are on there, including the pages for my website and my website editor which I need to have to be able to update my site. So if anyone could help, it would be greatly appreciated. Thanks in advance,

-Alec

Here's the Norton Anti-Virus log from today (I burned it onto a CD from my main computer and put it on the computer I'm currently on). I deleted the files that couldn't be deleted by Norton:

Category: Threat alerts
Date,Feature,Threat Name,Action Taken,Item Type,Target,Suspicious Action,Virus Definition Version,Product Version,User Name,Computer Name,Details
3/19/06 6:39:32 PM,Virus scanner,Adware.ZenoSearch,Manually deleted,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: AdwareSource: C:\ZICORN001.exe,Description: The file C:\ZICORN001.exe is a Adware threat."
3/19/06 6:39:32 PM,Virus scanner,Adware.ZenoSearch,Manually deleted,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: AdwareSource: C:\RECYCLED\DC0.EXE,Description: The file C:\RECYCLED\DC0.EXE is a Adware threat."
3/19/06 6:39:32 PM,Virus scanner,Trackware.Webhancer,No action taken,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: TrackwareSource: C:\Program Files\whInstall\whInstaller.exe,Description: The file C:\Program Files\whInstall\whInstaller.exe is a Trackware threat."
3/19/06 6:39:31 PM,Virus scanner,Spyware.e2give,Delete failed,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: SpywareSource: C:\Program Files\E2G\IeBHOs.dll,Description: The file C:\Program Files\E2G\IeBHOs.dll is a Spyware threat."
3/19/06 6:39:31 PM,Virus scanner,Adware.Medload,Manually deleted,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: AdwareSource: C:\WINDOWS\unstall.exe,Description: The file C:\WINDOWS\unstall.exe is a Adware threat."
3/19/06 6:39:31 PM,Virus scanner,Adware.NetOptimizer,Delete failed,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: AdwareSource: C:\WINDOWS\nem220.dll,Description: The file C:\WINDOWS\nem220.dll is a Adware threat."
3/19/06 6:39:31 PM,Virus scanner,Adware.NetOptimizer,Manually deleted,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: AdwareSource: C:\WINDOWS\optimize.exe,Description: The file C:\WINDOWS\optimize.exe is a Adware threat."
3/19/06 6:39:31 PM,Virus scanner,Adware.Popuppers,Delete failed,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: AdwareSource: eee2.exe,Description: The compressed file eee2.exe within C:\WINDOWS\4575.exe is a Adware threat."
3/19/06 6:39:31 PM,Virus scanner,Adware.Popuppers,Manually deleted,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: AdwareSource: C:\WINDOWS\4575.exe,Description: The file C:\WINDOWS\4575.exe is a Adware threat."
3/19/06 6:39:31 PM,Virus scanner,Trackware.Webhancer,No action taken,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: TrackwareSource: C:\WINDOWS\whInstaller.exe,Description: The file C:\WINDOWS\whInstaller.exe is a Trackware threat."
3/19/06 6:39:31 PM,Virus scanner,Trackware.Webhancer,No action taken,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: TrackwareSource: C:\WINDOWS\webhdll.dll,Description: The file C:\WINDOWS\webhdll.dll is a Trackware threat."
3/19/06 6:39:31 PM,Virus scanner,Trackware.Webhancer,Delete failed,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: TrackwareSource: whiehlpr.dll,Description: The compressed file whiehlpr.dll within C:\WINDOWS\whCC-GIANT.exe is a Trackware threat."
3/19/06 6:39:31 PM,Virus scanner,Trackware.Webhancer,Delete failed,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: TrackwareSource: Webhdll.dll,Description: The compressed file Webhdll.dll within C:\WINDOWS\whCC-GIANT.exe is a Trackware threat."
3/19/06 6:39:31 PM,Virus scanner,Trackware.Webhancer,Delete failed,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: TrackwareSource: WhSurvey.exe,Description: The compressed file WhSurvey.exe within C:\WINDOWS\whCC-GIANT.exe is a Trackware threat."
3/19/06 6:39:31 PM,Virus scanner,Trackware.Webhancer,Delete failed,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: TrackwareSource: whInstaller.exe,Description: The compressed file whInstaller.exe within C:\WINDOWS\whCC-GIANT.exe is a Trackware threat."
3/19/06 6:39:31 PM,Virus scanner,Trackware.Webhancer,Delete failed,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: TrackwareSource: WhAgent.exe,Description: The compressed file WhAgent.exe within C:\WINDOWS\whCC-GIANT.exe is a Trackware threat."
3/19/06 6:39:31 PM,Virus scanner,Trackware.Webhancer,No action taken,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: TrackwareSource: C:\WINDOWS\whCC-GIANT.exe,Description: The file C:\WINDOWS\whCC-GIANT.exe is a Trackware threat."
3/19/06 6:39:31 PM,Virus scanner,Trojan Horse,Quarantined,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: VirusSource: C:\WINDOWS\unin101.exe,Description: The file C:\WINDOWS\unin101.exe is infected with the Trojan Horse virus."
3/19/06 6:39:31 PM,Virus scanner,Trojan Horse,Quarantined,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: VirusSource: C:\WINDOWS\uni_eh.exe,Description: The file C:\WINDOWS\uni_eh.exe is infected with the Trojan Horse virus."
3/19/06 6:39:30 PM,Virus scanner,Spyware.e2give,Manually deleted,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: SpywareSource: C:\WINDOWS\pi1_34.exe,Description: The file C:\WINDOWS\pi1_34.exe is a Spyware threat."
3/19/06 6:39:30 PM,Virus scanner,Adware.Mirar,Delete failed,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: AdwareSource: WinATS.dll,Description: The compressed file WinATS.dll within C:\WINDOWS\Temporary Internet Files\Content.IE5\Q3KZUP0Z\WinATS[1].cab is a Adware threat."
3/19/06 6:39:30 PM,Virus scanner,Adware.Mirar,No action taken,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: AdwareSource: C:\WINDOWS\Temporary Internet Files\Content.IE5\Q3KZUP0Z\WinATS[1].cab,Description: The file C:\WINDOWS\Temporary Internet Files\Content.IE5\Q3KZUP0Z\WinATS[1].cab is a Adware threat."
3/19/06 6:39:30 PM,Virus scanner,Adware.Medload,Manually deleted,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: AdwareSource: C:\WINDOWS\Temporary Internet Files\Content.IE5\P3331P8E\unstall[1].exe,Description: The file C:\WINDOWS\Temporary Internet Files\Content.IE5\P3331P8E\unstall[1].exe is a Adware threat."
3/19/06 6:39:30 PM,Virus scanner,Adware.NetOptimizer,Manually deleted,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: AdwareSource: C:\WINDOWS\Temporary Internet Files\Content.IE5\P3331P8E\nem220[1].dll,Description: The file C:\WINDOWS\Temporary Internet Files\Content.IE5\P3331P8E\nem220[1].dll is a Adware threat."
3/19/06 6:39:30 PM,Virus scanner,Trackware.Webhancer,Delete failed,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: TrackwareSource: whiehlpr.dll,Description: The compressed file whiehlpr.dll within C:\WINDOWS\Temporary Internet Files\Content.IE5\816B4TMR\whCC-GIANT[1].exe is a Trackware threat."
3/19/06 6:39:30 PM,Virus scanner,Trackware.Webhancer,Delete failed,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: TrackwareSource: Webhdll.dll,Description: The compressed file Webhdll.dll within C:\WINDOWS\Temporary Internet Files\Content.IE5\816B4TMR\whCC-GIANT[1].exe is a Trackware threat."
3/19/06 6:39:30 PM,Virus scanner,Trackware.Webhancer,Delete failed,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: TrackwareSource: WhSurvey.exe,Description: The compressed file WhSurvey.exe within C:\WINDOWS\Temporary Internet Files\Content.IE5\816B4TMR\whCC-GIANT[1].exe is a Trackware threat."
3/19/06 6:39:30 PM,Virus scanner,Trackware.Webhancer,Delete failed,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: TrackwareSource: whInstaller.exe,Description: The compressed file whInstaller.exe within C:\WINDOWS\Temporary Internet Files\Content.IE5\816B4TMR\whCC-GIANT[1].exe is a Trackware threat."
3/19/06 6:39:30 PM,Virus scanner,Trackware.Webhancer,Delete failed,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: TrackwareSource: WhAgent.exe,Description: The compressed file WhAgent.exe within C:\WINDOWS\Temporary Internet Files\Content.IE5\816B4TMR\whCC-GIANT[1].exe is a Trackware threat."
3/19/06 6:39:30 PM,Virus scanner,Trackware.Webhancer,No action taken,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: TrackwareSource: C:\WINDOWS\Temporary Internet Files\Content.IE5\816B4TMR\whCC-GIANT[1].exe,Description: The file C:\WINDOWS\Temporary Internet Files\Content.IE5\816B4TMR\whCC-GIANT[1].exe is a Trackware threat."
3/19/06 6:39:30 PM,Virus scanner,Adware.NetOptimizer,Manually deleted,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: AdwareSource: C:\WINDOWS\Temporary Internet Files\Content.IE5\U6ZTLB1V\optimize[1].exe,Description: The file C:\WINDOWS\Temporary Internet Files\Content.IE5\U6ZTLB1V\optimize[1].exe is a Adware threat."
3/19/06 6:39:30 PM,Virus scanner,Adware.Popuppers,Delete failed,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: AdwareSource: eee2.exe,Description: The compressed file eee2.exe within C:\WINDOWS\Temporary Internet Files\Content.IE5\DPOYW7HV\eeedo[1].exe is a Adware threat."
3/19/06 6:39:30 PM,Virus scanner,Adware.Popuppers,Manually deleted,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: AdwareSource: C:\WINDOWS\Temporary Internet Files\Content.IE5\DPOYW7HV\eeedo[1].exe,Description: The file C:\WINDOWS\Temporary Internet Files\Content.IE5\DPOYW7HV\eeedo[1].exe is a Adware threat."
3/19/06 6:39:30 PM,Virus scanner,Adware.Medload,Delete failed,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: AdwareSource: mm83.ocx,Description: The compressed file mm83.ocx within C:\WINDOWS\Temporary Internet Files\Content.IE5\DMZ91IGU\joysaver[1].cab is a Adware threat."
3/19/06 6:39:30 PM,Virus scanner,Adware.Medload,Manually deleted,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: AdwareSource: C:\WINDOWS\Temporary Internet Files\Content.IE5\DMZ91IGU\joysaver[1].cab,Description: The file C:\WINDOWS\Temporary Internet Files\Content.IE5\DMZ91IGU\joysaver[1].cab is a Adware threat."
3/19/06 6:39:29 PM,Virus scanner,Spyware.e2give,Manually deleted,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: SpywareSource: C:\WINDOWS\Temporary Internet Files\Content.IE5\DMZ91IGU\pi1_34[1].exe,Description: The file C:\WINDOWS\Temporary Internet Files\Content.IE5\DMZ91IGU\pi1_34[1].exe is a Spyware threat."
3/19/06 6:39:29 PM,Virus scanner,Spyware.e2give,Manually deleted,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: SpywareSource: C:\WINDOWS\Temporary Internet Files\Content.IE5\1RZFLPWE\nein[1].exe,Description: The file C:\WINDOWS\Temporary Internet Files\Content.IE5\1RZFLPWE\nein[1].exe is a Spyware threat."
3/19/06 6:39:29 PM,Virus scanner,Adware.Medload,Manually deleted,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: AdwareSource: C:\WINDOWS\Downloaded Program Files\mm83.ocx,Description: The file C:\WINDOWS\Downloaded Program Files\mm83.ocx is a Adware threat."
3/19/06 6:39:29 PM,Virus scanner,Adware.Mirar,No action taken,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: AdwareSource: C:\WINDOWS\Desktop\s\backups\backup-20060319-161253-989.dll,Description: The file C:\WINDOWS\Desktop\s\backups\backup-20060319-161253-989.dll is a Adware threat."
3/19/06 6:39:29 PM,Virus scanner,Adware.Mirar,No action taken,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: AdwareSource: C:\WINDOWS\SYSTEM\WinDmy.dll,Description: The file C:\WINDOWS\SYSTEM\WinDmy.dll is a Adware threat."
3/19/06 6:39:29 PM,Virus scanner,Adware.Mirar,No action taken,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: AdwareSource: C:\WINDOWS\SYSTEM\WinNB57.dll,Description: The file C:\WINDOWS\SYSTEM\WinNB57.dll is a Adware threat."
3/19/06 6:39:29 PM,Virus scanner,Adware.WinBo,Manually deleted,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: AdwareSource: C:\WINDOWS\SYSTEM\Tagasuarus5.exe,Description: The file C:\WINDOWS\SYSTEM\Tagasuarus5.exe is a Adware threat."
3/19/06 6:39:29 PM,Virus scanner,Spyware.e2give,Delete failed,File,N/A,N/A,200603150006,11.0.16.2,chartman,OEMCOMPUTER,"Threat category: SpywareSource: C:\WINDOWS\SYSTEM\typftp.exe,Description: The file C:\WINDOWS\SYSTEM\typftp.exe is a Spyware threat."

BC AdBot (Login to Remove)

 


#2 Herk

Herk

  • Members
  • 1,609 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:S.E. Idaho, USA
  • Local time:11:36 PM

Posted 20 March 2006 - 12:02 PM

Sometimes, threats add content to the Layered Service Provider stack in the Winsock, and when the threats are removed, they leave gaps in the list. These gaps can effectively limit or prevent connection to the internet until they are repaired. There is an easy way to repair the Winsock, but it involves downloading a small program and running it. You can copy the program to a floppy or other media and install it on your computer. It should only be about 182 kb.

If you can't see the word "finish" on the bottom corner of the program window, drag the corner to make it visible.

LSP fix




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users