also @ TechSpot: Most Anticipated PC Games of 2012
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.

Go Back   TechSpot OpenBoards > Tech Support > Virus and Malware Removal

Collaborate in the cloud with Office, Exchange, SharePoint, and Lync

Internet Browsers will not open - possible malware

Thread Tools Search this Thread
  #1  
Old 11-21-2009
aegisrose's Avatar
TechSpot Member
 
Member since: Aug 2007, 70 posts
Internet Browsers will not open - possible malware

Greetings TechSpot forums!
always a pleasure coming here to get answers.

After moving recetly, my old XP machine started experiencing problems opening internet browsers (ie 8 and Firefox 3.0.13). They simply crash.

I know it's not my router or ISP because I have 4 other machines connected and running at full blast. And there is some sort of connectivity because windows updates downloaded some updates.

I read somewhere it might be loose memory sticks so I went into the guts and all is secure in there.

I have the latest application versions of Malwarebytes, Superantispyware, and Hijackthis, but whatever is attacking the PC will not let me update the definitions library. I think Malwarebytes did update, but a weird error flashed for a moment while updating, so i'm not confident it's all the latest info.

Is there a way to get those updates and move them via flash drive from my laptop to the sick PC?

In the mean time, I've attached the hijackthis log, and the superantispy log (last update was july 09).

Any insight would be appreciated. THANKS!
Attached Files
File Type: log hijackthis20091120.log (10.2 KB, 4 views)
File Type: log SUPERAntiSpyware Scan Log - 11-21-2009 - 12-13-55.log (465 Bytes, 2 views)
  #2  
Old 11-29-2009
aegisrose's Avatar
TechSpot Member
 
Member since: Aug 2007, 70 posts
hello~ I'm just writing to /bump



Any assistance would be greatly appreciated
  #3  
Old 11-29-2009
Ex-TechSpotter
 
Member since: Dec 2007, 18,355 posts
I think the topic was not replied to because all 3 logs are not attached
Try again to update Malwarebytes and run a quick scan

Also uninstall the old and obsolete AVG8
Then after uninstalling it, then run the AVG Remover tool: http://www.avg.com/filedir/util/supp...remover_en.exe

Restart

Download and install Free Avira Antivirus: http://www.free-av.com/
Update it, and run a full scan

Restart

Reply with 3 new logs:
Malwarebytes
HijackThis
Avira scan log

Oh you can uninstall SUPERAntispyware to begin with too


Edit:

I mentioned to uninstall AVG8 to you in your thread here: http://www.techspot.com/vb/topic138422.html
Since you still have it, maybe someone else wants to support you in removing malware
I think AVG8 went out about 6 months ago now though (could be more)
  #4  
Old 11-30-2009
aegisrose's Avatar
TechSpot Member
 
Member since: Aug 2007, 70 posts
Thanks for the response Kimsland... I'll see what I can do about AVG and Malware Bytes since I can't seem to update any of the programs.

I'll post again tomorrow.

EDIT: this whole ordeal is on my old PC. I'm not particularly attached to AVG so I've uninstalled it and installed Avira on it. I was able to update it too! More to follow...

Last edited by aegisrose; 12-01-2009 at 06:34 PM..
  #5  
Old 11-30-2009
Newcomer, in training
 
Location: Lake Forest, CA
Member since: Nov 2009, 13 posts
System specs
virus infections usually dont prevent internet applications , they want you to go online so they can steal your info or sell u somthing.. right click on my computer, than click on manage than click on event logs and check sytem folder and applications folder for errors..
  #6  
Old 12-01-2009
aegisrose's Avatar
TechSpot Member
 
Member since: Aug 2007, 70 posts
Quote:
Originally Posted by stellarPCserv View Post
virus infections usually dont prevent internet applications , they want you to go online so they can steal your info or sell u somthing.. right click on my computer, than click on manage than click on event logs and check sytem folder and applications folder for errors..
Hey Stellar... you might be onto something.

I see some errors that say "could not join the network because another machine has the same name..." which is accurate because I named my new PC the same as the old one.

I've renamed the old one and started running all the scans as well.

We'll see what turns up.
  #7  
Old 12-01-2009
aegisrose's Avatar
TechSpot Member
 
Member since: Aug 2007, 70 posts
renamed machine and ran scans

I renamed the machine. This helped me connect to the internet.

Eitheway, to be on the safe side, I ran the scans. If someone could take a peek just to confirm that it looks good, I'd sure appreciate it!
Attached Files
File Type: log AVSCAN-20091201-100339-5A05E450.LOG (18.9 KB, 3 views)
File Type: log hijackthis20091201.log (9.8 KB, 3 views)
File Type: txt mbam-log-2009-12-01 (18-38-19).txt (1.1 KB, 2 views)
  #8  
Old 12-01-2009
Newcomer, in training
 
Location: Lake Forest, CA
Member since: Nov 2009, 13 posts
System specs
i cant see the logs at the moment sence im on my phone, go to pandasecurity.com and run the active scan 2.0 takes about a hour.
  #9  
Old 12-01-2009
Ex-TechSpotter
 
Member since: Dec 2007, 18,355 posts
I can see the logs

Please run IE Reset (you have a number of Browser Helper Objects that just slow down your browsing in my view)

Or manually from here http://www.techspot.com/vb/post682762-2.html
Then restart Internet Explorer

Your Malwarebytes scan only needed to be a quick scan
And you have not removed found Malwares at the end of the scan
As it also has an older database, please open Malwarebytes; Update it; then run a quick (~10min maximum) scan
Please provide this new scan log


Combofix:
  • Download Combofix to your desktop.
  • Disable your Antivirus (as Combofix will remove any found malwares)
  • Double click ComboFix & follow the prompts.
  • A window will open with a warning.
  • When the scan completes it will open a text window. Please attach that log back here
Also restart and provide a fresh HJT Scan log

3 logs required again
  #10  
Old 12-02-2009
aegisrose's Avatar
TechSpot Member
 
Member since: Aug 2007, 70 posts
umm~ forgive the n00bishness... but I can't seem to disable avira
  #11  
Old 12-02-2009
Ex-TechSpotter
 
Member since: Dec 2007, 18,355 posts
Right click on Avira shown on your Taskbar
Remove the tick

  #12  
Old 12-02-2009
aegisrose's Avatar
TechSpot Member
 
Member since: Aug 2007, 70 posts
here we go!

3 logs
Attached Files
File Type: txt combofix_log_20091202.txt (13.0 KB, 2 views)
File Type: log hijackthis20091202.log (7.4 KB, 2 views)
File Type: txt mbam-log-2009-12-02 (09-46-56).txt (834 Bytes, 2 views)
  #13  
Old 12-02-2009
Ex-TechSpotter
 
Member since: Dec 2007, 18,355 posts
Hi, I suspect you are still infected. Please follow the following precisely (we don't want to mess up Windows )

Also, allow any Firewall message that may pop up

  1. Download Atapi.zip to your Desktop
    • Extract Atapi.zip file directly to your Desktop, giving Atapi.sys

  2. Start > Run > cmd /c del /a/f/q c:\atapi.sys > ok

  3. Start > Run > cmd /c start /min cmd /c "copy %windir%\system32\drivers\atapi.sys Desktop\*.suspect >log.txt&log.txt"
    • You will get "1 file(s) copied." Please close this Notepad

  4. Start > Run > cmd /c start /min cmd /c "copy Desktop\atapi.sys %windir%\system32\drivers\atapi.sys >log.txt&log.txt"
    • You will get "1 file(s) copied." Please close this Notepad

  5. Start > Run > cmd /c start /min cmd /c "copy Desktop\atapi.sys c:\atapi.sys >log.txt&log.txt"
    • You will get "1 file(s) copied." Please close this Notepad

  6. Start > Run > cmd /c start /min cmd /c "dir /a c:\atapi.sys >log.txt&log.txt"
    • Please save the text file to be attached to a new reply
Restart

Run Combofix again, attach the log


Last edited by kimsland; 12-02-2009 at 09:44 PM..
  #14  
Old 12-02-2009
aegisrose's Avatar
TechSpot Member
 
Member since: Aug 2007, 70 posts
Quote:
Originally Posted by kimsland View Post

Start > Run > cmd dir /a c:\atapi.sys >log.txt&log.txt
Please save the text file to be attached to a new reply
I followed all the steps... should the quoted step above have yielded a notepad also? it didn't....
  #15  
Old 12-02-2009
Ex-TechSpotter
 
Member since: Dec 2007, 18,355 posts
Yes, I forgot the "/c" I have edited it in above

But instead of doing this single command log file, lets check the entire of the system drive (Note this one will take a bit longer as it searches)
Start > Run > cmd /c start /min cmd /c "PEV -l %systemdrive%\atapi.sys >Log.txt&Log.txt&del Log.txt"
Wait about [COLOR="Red"]30 secs[/COLOR] for this log to show. Please save this log file to be attached later on

Please also provide the new Combofix log as an attachment (this must be performed after Restart)
And also attach the file: atapi.suspect (located on your Desktop) You need to Zip this up first

3 Attachments required

Last edited by kimsland; 12-02-2009 at 09:58 PM.. Reason: changed all commands to not show cmd window
  #16  
Old 12-03-2009
aegisrose's Avatar
TechSpot Member
 
Member since: Aug 2007, 70 posts
3 more....
Attached Files
File Type: txt log.txt (1.1 KB, 2 views)
File Type: txt combofix_log_20091203.txt (9.9 KB, 3 views)
File Type: zip atapisuspect.zip (53.3 KB, 2 views)
  #17  
Old 12-03-2009
Ex-TechSpotter
 
Member since: Dec 2007, 18,355 posts
The atapisuspect file, you have renamed It was originally atapi.suspect
I have tested this file and it looks ok, so be it.

The redirection looks as though it may now be resolved


Un-install Combofix
  • Click Start then Run
  • Now type Combofix /uninstall in the runbox and click OK
  • Any popup errors about Antivirus just ok or close
Note: 1 space after ComboFix in that uninstall command


Clear system restore points

Go to Start >> Run - type or copy/paste control sysdm.cpl,,4 and then press Enter
  • Tick on the checkbox - Turn off System Restore on all drives
  • Click Apply
Turn it back 'On' by unticking the same checkbox & click Apply, and then OK


Update Java

Run JavaRa
This will remove all your old Java stuff (that is not required)
It will also help you check for new Java updates

Run TFC Cleaner
Download and Run TFC
(You may need to Restart)


Restart

Report how everything is running well
  #18  
Old 12-03-2009
aegisrose's Avatar
TechSpot Member
 
Member since: Aug 2007, 70 posts
Excellent

Yep~ the machine is running VERY well now!!!

oh.. and I renamed the atapi zip bexause I wasn't sure if it would like having a "." in the middle of the file name when I zipped it. I guess it doesn't really matter.

Thanks so much for your time and efforts. I've addressed a couple of my issues via TechSpot and I learn a lot each time.

Thanks again Kimsland!!! You rock!!!!
  #19  
Old 12-03-2009
Ex-TechSpotter
 
Member since: Dec 2007, 18,355 posts
No problems

Hey Malwarebytes has just updated to a new version 1.42
Please startup Malwarebytes, and do an update to the program and then the database
Then run a quick scan. I don't expect you'll have any issues, but hey a 5 or 10 minute scan can't hurt
  #20  
Old 12-04-2009
Bobbye's Avatar
Helper on the Fringe
 
Location: Florida
Member since: Mar 2007, 14,934 posts
Thank you kimsland. It gets a bit overwhelming in the V&M forum at times. Sorry you got missed. I usually start at the bottom with the oldest posts, but sometimes I miss.

You really need to do the Java update- (jre1.6.0_05) having the older version leaves a vulnerability to the system.

Would also stress cleaning up the system- especially the temp files- more regularly. Heaps of those can really slow you down.

I didn't see any malware in the logs- or anything that hadn't been handled. Can't help wonder if this was the devil in the system:
Quote:
see some errors that say "could not join the network because another machine has the same name..." which is accurate because I named my new PC the same as the old one.
Thanks for atapi info kimsland. Have saved all for next atapi day!
Closed Thread

Similar Topics
Topic Replies Forum
None of my browsers open 0 Software Apps
Malware will not let me open malware programs even in safe mode 6 Virus and Malware Removal
Internet Browsers, all of them not working 2 Storage and Networking
problems connecting to internet via browsers 2 Storage and Networking
Internet Explorer not open function: Open in new window! and Search don't too 0 Windows OS

Thread Tools Search this Thread
Search this Thread:

Advanced Search
All times are GMT -4. The time now is 04:23 AM.