also @ TechSpot: Microsoft wants Xbox to be the entertainment hub for all your devices

TechSpot

[Solved] Fraudpack, antivirussuite, bad.proxy, and normal can't run explorer properly

Discussion in 'Virus and Malware Removal' started by Olikut, Feb 1, 2011.

Thread Status:
Not open for further replies.
  1. Olikut Newcomer, in training

    computer safe mode.
  2. Broni Malware Annihilator

    Can you check, if IE is having same issue?
  3. Olikut Newcomer, in training

    in normal windows mode, IE won't even open. The process starts, but no window ever shows up. For firefox, the window shows up, but it can't connect to anything now.
  4. Broni Malware Annihilator

    Go Start>Run (Start search in Vista), type in:
    cmd
    Click OK (in Vista and Windows 7, while holding CTRL, and SHIFT, press Enter).

    In Command Prompt window, type in following commands, and hit Enter after each one:
    ipconfig /flushdns
    ipconfig /registerdns
    ipconfig /release
    ipconfig /renew
    net stop "dns client"
    net start "dns client"


    Turn the computer off.

    On your router, you'll find a pinhole marked "Reset".
    Keep pushing the hole, using a pencil, or a paperclip until all lights briefly come off and on.
    NOTE. Simple router disconnecting from a power source will NOT do.
    Restart computer and check for redirections.

    NOTE. You may need to re-check your router security settings, as described HERE
  5. Olikut Newcomer, in training

    Ok. I completed that.

    Firefox still can't connect to anything in windows normal.
    IE process still starts, but window wont' open in windows normal.

    Both operate fine in windows safe mode w/ networking.
  6. Olikut Newcomer, in training

    by the way, TDSSkiller in normal windows found nothing.
  7. Broni Malware Annihilator

    1. Go Start>Run ("Start search" in Vista and Win 7), type in:
    cmd
    Click OK (hit Enter in Vista and Win 7).

    2. At Command Prompt type in (or copy and paste):

    cmd /c ping google.com>%temp%\$.$&notepad %temp%\$.$

    and press Enter.

    3. Notepad will open.

    4. Copy all text in Notepad ([Ctrl-A], then [Ctrl-C]), and then post it (paste = [Ctrl-V]) in your next reply.

    =========================================================================

    1. Go Start>Run ("Start search" in Vista and Win 7), type in:
    cmd
    Click OK (hit Enter in Vista and Win 7).

    2. At Command Prompt, paste this:
    ipconfig /all>c:\ipconfig_all.txt&notepad c:\ipconfig_all.txt&exit
    Hit Enter.

    3. Copy and paste what you see in Notepad into a Reply here.
  8. Olikut Newcomer, in training

    here's my first try, in safemode w/networking which may or may not be useful (I'll do it in normal next).

    ping:
    ipconfig:
  9. Olikut Newcomer, in training

    and here you go for normal windows mode:

    ping:
    ipconfig:
  10. Broni Malware Annihilator

    Yeah, it looks like there is no connection in normal mode, because, for some reason, IP configuration gets messed up in normal mode.
    It looks fine in Safe Mode with Networking.

    Please, reinstall network adapter driver.
  11. Olikut Newcomer, in training

    I gave that a try. Didn't seem to do anything. When I boot into normal mode it still takes an inordinate amount of time to get to the point I can interact with things. The taskbar doesn't show, MSconfig can't apply changes, windows installer service doesn't work. windows firewall can't start. avast can't load up. Firefox and IE can't connect to anything. I can't properly shutdown without a hard restart (choosing any shutdown type of option in windows results in a hang at 'saving settngs). This is the same state that the computer was in back before I ran combofix for the first time, after which it was able to load and restart normally a few times.

    I was able to install the network driver in safe mode w/networking, but normal mode wouldn't allow it due to windows installer issues.
  12. Broni Malware Annihilator

    Please download ComboFix from Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
      • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG users: ComboFix will not run until AVG is uninstalled as a protective measure against the anti-virus. This is because AVG "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.



    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try one of the following:

    1. Run Combofix from Safe Mode.

    2. Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
    Do NOT run it yet.

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click Rkill and choose Run as Administrator

    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    Rkill.com
    Rkill.scr
    Rkill.exe

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.

    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    If normal mode still doesn't work, run BOTH tools from safe mode.

    In case #2, please post BOTH logs, rKill and Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
  13. Olikut Newcomer, in training

    Ran it in safe mode w/ networking. Would it be safe to run again in normal if I'm able to now?

  14. Broni Malware Annihilator

    I don't see anything malicious there.
    I don't think, we're dealing with any infection anymore.

    Do you have Windows XP CD?
  15. Olikut Newcomer, in training

    yup. I've got my win XP cd.
  16. Broni Malware Annihilator

  17. Olikut Newcomer, in training

    I'll give it a try.

    Thanks Broni for all your help
  18. Broni Malware Annihilator

    You're very welcome [IMG]

    Let me know....
  19. Olikut Newcomer, in training

    I repaired my windows install, got all the service packs and security updates installed, and everything appears to be working fine.

    MBAM isn't finding anything and neither has avast. Thanks for all your help Broni.
  20. Broni Malware Annihilator

    Excellent!

    Good luck and stay safe :)
Thread Status:
Not open for further replies.