also @ TechSpot: ATI Radeon HD 5570 Review: Low Profile + Gaming
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.

Go Back   TechSpot OpenBoards > Operating Systems and Software > Virus and Malware Removal

Internet Browsers will not open - possible malware

Reply
Bookmark Thread Tools
  #1  
Old 11-21-2009
aegisrose's Avatar
Newcomer, in training
 
Member since: Aug 2007, 44 posts
Internet Browsers will not open - possible malware

Greetings TechSpot forums!
always a pleasure coming here to get answers.

After moving recetly, my old XP machine started experiencing problems opening internet browsers (ie 8 and Firefox 3.0.13). They simply crash.

I know it's not my router or ISP because I have 4 other machines connected and running at full blast. And there is some sort of connectivity because windows updates downloaded some updates.

I read somewhere it might be loose memory sticks so I went into the guts and all is secure in there.

I have the latest application versions of Malwarebytes, Superantispyware, and Hijackthis, but whatever is attacking the PC will not let me update the definitions library. I think Malwarebytes did update, but a weird error flashed for a moment while updating, so i'm not confident it's all the latest info.

Is there a way to get those updates and move them via flash drive from my laptop to the sick PC?

In the mean time, I've attached the hijackthis log, and the superantispy log (last update was july 09).

Any insight would be appreciated. THANKS!
Attached Files
File Type: log hijackthis20091120.log (10.2 KB, 4 views)
File Type: log SUPERAntiSpyware Scan Log - 11-21-2009 - 12-13-55.log (465 Bytes, 2 views)
Reply With Quote
  #2  
Old 11-29-2009
aegisrose's Avatar
Newcomer, in training
 
Member since: Aug 2007, 44 posts
hello~ I'm just writing to /bump



Any assistance would be greatly appreciated
Reply With Quote
To remove this ad, sign in. To register for a new account, click here.
  
  #3  
Old 11-29-2009
Registered User
 
Member since: Dec 2007, 18,314 posts
I think the topic was not replied to because all 3 logs are not attached
Try again to update Malwarebytes and run a quick scan

Also uninstall the old and obsolete AVG8
Then after uninstalling it, then run the AVG Remover tool: http://www.avg.com/filedir/util/supp...remover_en.exe

Restart

Download and install Free Avira Antivirus: http://www.free-av.com/
Update it, and run a full scan

Restart

Reply with 3 new logs:
Malwarebytes
HijackThis
Avira scan log

Oh you can uninstall SUPERAntispyware to begin with too


Edit:

I mentioned to uninstall AVG8 to you in your thread here: http://www.techspot.com/vb/topic138422.html
Since you still have it, maybe someone else wants to support you in removing malware
I think AVG8 went out about 6 months ago now though (could be more)
Reply With Quote
  #4  
Old 11-30-2009
aegisrose's Avatar
Newcomer, in training
 
Member since: Aug 2007, 44 posts
Thanks for the response Kimsland... I'll see what I can do about AVG and Malware Bytes since I can't seem to update any of the programs.

I'll post again tomorrow.

EDIT: this whole ordeal is on my old PC. I'm not particularly attached to AVG so I've uninstalled it and installed Avira on it. I was able to update it too! More to follow...

Last edited by aegisrose; 12-01-2009 at 06:34 PM..
Reply With Quote
  #5  
Old 11-30-2009
Newcomer, in training
 
Location: Lake Forest, CA
Member since: Nov 2009, 13 posts
System specs
virus infections usually dont prevent internet applications , they want you to go online so they can steal your info or sell u somthing.. right click on my computer, than click on manage than click on event logs and check sytem folder and applications folder for errors..
Reply With Quote
  #6  
Old 12-01-2009
aegisrose's Avatar
Newcomer, in training
 
Member since: Aug 2007, 44 posts
Quote:
Originally Posted by stellarPCserv View Post
virus infections usually dont prevent internet applications , they want you to go online so they can steal your info or sell u somthing.. right click on my computer, than click on manage than click on event logs and check sytem folder and applications folder for errors..
Hey Stellar... you might be onto something.

I see some errors that say "could not join the network because another machine has the same name..." which is accurate because I named my new PC the same as the old one.

I've renamed the old one and started running all the scans as well.

We'll see what turns up.
Reply With Quote
  #7  
Old 12-01-2009
aegisrose's Avatar
Newcomer, in training
 
Member since: Aug 2007, 44 posts
renamed machine and ran scans

I renamed the machine. This helped me connect to the internet.

Eitheway, to be on the safe side, I ran the scans. If someone could take a peek just to confirm that it looks good, I'd sure appreciate it!
Attached Files
File Type: log AVSCAN-20091201-100339-5A05E450.LOG (18.9 KB, 3 views)
File Type: log hijackthis20091201.log (9.8 KB, 3 views)
File Type: txt mbam-log-2009-12-01 (18-38-19).txt (1.1 KB, 2 views)
Reply With Quote
  #8  
Old 12-01-2009
Newcomer, in training
 
Location: Lake Forest, CA
Member since: Nov 2009, 13 posts
System specs
i cant see the logs at the moment sence im on my phone, go to pandasecurity.com and run the active scan 2.0 takes about a hour.
Reply With Quote
  #9  
Old 12-01-2009
Registered User
 
Member since: Dec 2007, 18,314 posts
I can see the logs

Please run IE Reset (you have a number of Browser Helper Objects that just slow down your browsing in my view)

Or manually from here http://www.techspot.com/vb/post682762-2.html
Then restart Internet Explorer

Your Malwarebytes scan only needed to be a quick scan
And you have not removed found Malwares at the end of the scan
As it also has an older database, please open Malwarebytes; Update it; then run a quick (~10min maximum) scan
Please provide this new scan log


Combofix:
  • Download Combofix to your desktop.
  • Disable your Antivirus (as Combofix will remove any found malwares)
  • Double click ComboFix & follow the prompts.
  • A window will open with a warning.
  • When the scan completes it will open a text window. Please attach that log back here
Also restart and provide a fresh HJT Scan log

3 logs required again
Reply With Quote
To remove this ad, sign in. To register for a new account, click here.
  
  #10  
Old 12-02-2009
aegisrose's Avatar
Newcomer, in training
 
Member since: Aug 2007, 44 posts
umm~ forgive the n00bishness... but I can't seem to disable avira
Reply With Quote
  #11  
Old 12-02-2009
Registered User
 
Member since: Dec 2007, 18,314 posts
Right click on Avira shown on your Taskbar
Remove the tick

Reply With Quote
  #12  
Old 12-02-2009
aegisrose's Avatar
Newcomer, in training
 
Member since: Aug 2007, 44 posts
here we go!

3 logs
Attached Files
File Type: txt combofix_log_20091202.txt (13.0 KB, 2 views)
File Type: log hijackthis20091202.log (7.4 KB, 2 views)
File Type: txt mbam-log-2009-12-02 (09-46-56).txt (834 Bytes, 2 views)
Reply With Quote
  #13  
Old 12-02-2009
Registered User
 
Member since: Dec 2007, 18,314 posts
Hi, I suspect you are still infected. Please follow the following precisely (we don't want to mess up Windows )

Also, allow any Firewall message that may pop up

  1. Download Atapi.zip to your Desktop
    • Extract Atapi.zip file directly to your Desktop, giving Atapi.sys

  2. Start > Run > cmd /c del /a/f/q c:\atapi.sys > ok

  3. Start > Run > cmd /c start /min cmd /c "copy %windir%\system32\drivers\atapi.sys Desktop\*.suspect >log.txt&log.txt"
    • You will get "1 file(s) copied." Please close this Notepad

  4. Start > Run > cmd /c start /min cmd /c "copy Desktop\atapi.sys %windir%\system32\drivers\atapi.sys >log.txt&log.txt"
    • You will get "1 file(s) copied." Please close this Notepad

  5. Start > Run > cmd /c start /min cmd /c "copy Desktop\atapi.sys c:\atapi.sys >log.txt&log.txt"
    • You will get "1 file(s) copied." Please close this Notepad

  6. Start > Run > cmd /c start /min cmd /c "dir /a c:\atapi.sys >log.txt&log.txt"
    • Please save the text file to be attached to a new reply
Restart

Run Combofix again, attach the log


Last edited by kimsland; 12-02-2009 at 09:44 PM..
Reply With Quote
  #14  
Old 12-02-2009
aegisrose's Avatar
Newcomer, in training
 
Member since: Aug 2007, 44 posts
Quote:
Originally Posted by kimsland View Post

Start > Run > cmd dir /a c:\atapi.sys >log.txt&log.txt
Please save the text file to be attached to a new reply
I followed all the steps... should the quoted step above have yielded a notepad also? it didn't....
Reply With Quote
  #15  
Old 12-02-2009
Registered User
 
Member since: Dec 2007, 18,314 posts
Yes, I forgot the "/c" I have edited it in above

But instead of doing this single command log file, lets check the entire of the system drive (Note this one will take a bit longer as it searches)
Start > Run > cmd /c start /min cmd /c "PEV -l %systemdrive%\atapi.sys >Log.txt&Log.txt&del Log.txt"
Wait about 30 secs for this log to show. Please save this log file to be attached later on

Please also provide the new Combofix log as an attachment (this must be performed after Restart)
And also attach the file: atapi.suspect (located on your Desktop) You need to Zip this up first

3 Attachments required

Last edited by kimsland; 12-02-2009 at 09:58 PM.. Reason: changed all commands to not show cmd window
Reply With Quote
  #16  
Old 12-03-2009
aegisrose's Avatar
Newcomer, in training
 
Member since: Aug 2007, 44 posts
3 more....
Attached Files
File Type: txt log.txt (1.1 KB, 2 views)
File Type: txt combofix_log_20091203.txt (9.9 KB, 3 views)
File Type: zip atapisuspect.zip (53.3 KB, 2 views)
Reply With Quote
  #17  
Old 12-03-2009
Registered User
 
Member since: Dec 2007, 18,314 posts
The atapisuspect file, you have renamed It was originally atapi.suspect
I have tested this file and it looks ok, so be it.

The redirection looks as though it may now be resolved


Un-install Combofix
  • Click Start then Run
  • Now type Combofix /uninstall in the runbox and click OK
  • Any popup errors about Antivirus just ok or close
Note: 1 space after ComboFix in that uninstall command


Clear system restore points

Go to Start >> Run - type or copy/paste control sysdm.cpl,,4 and then press Enter
  • Tick on the checkbox - Turn off System Restore on all drives
  • Click Apply
Turn it back 'On' by unticking the same checkbox & click Apply, and then OK


Update Java

Run JavaRa
This will remove all your old Java stuff (that is not required)
It will also help you check for new Java updates

Run TFC Cleaner
Download and Run TFC
(You may need to Restart)


Restart

Report how everything is running well
Reply With Quote
  #18  
Old 12-03-2009
aegisrose's Avatar
Newcomer, in training
 
Member since: Aug 2007, 44 posts
Excellent

Yep~ the machine is running VERY well now!!!

oh.. and I renamed the atapi zip bexause I wasn't sure if it would like having a "." in the middle of the file name when I zipped it. I guess it doesn't really matter.

Thanks so much for your time and efforts. I've addressed a couple of my issues via TechSpot and I learn a lot each time.

Thanks again Kimsland!!! You rock!!!!
Reply With Quote
  #19  
Old 12-03-2009
Registered User
 
Member since: Dec 2007, 18,314 posts
No problems

Hey Malwarebytes has just updated to a new version 1.42
Please startup Malwarebytes, and do an update to the program and then the database
Then run a quick scan. I don't expect you'll have any issues, but hey a 5 or 10 minute scan can't hurt
Reply With Quote
  #20  
Old 12-04-2009
Bobbye's Avatar
TechSpot Evangelist
 
Location: Clearwater, FL
Member since: Mar 2007, 6,812 posts
Thank you kimsland. It gets a bit overwhelming in the V&M forum at times. Sorry you got missed. I usually start at the bottom with the oldest posts, but sometimes I miss.

You really need to do the Java update- (jre1.6.0_05) having the older version leaves a vulnerability to the system.

Would also stress cleaning up the system- especially the temp files- more regularly. Heaps of those can really slow you down.

I didn't see any malware in the logs- or anything that hadn't been handled. Can't help wonder if this was the devil in the system:
Quote:
see some errors that say "could not join the network because another machine has the same name..." which is accurate because I named my new PC the same as the old one.
Thanks for atapi info kimsland. Have saved all for next atapi day!
Reply With Quote
Reply

Thread Tools


Similar Topics
Topic Category Replies Last Post
None of my browsers open Software and Utilities in General 0 10-21-2009 04:51 PM
Malware will not let me open malware programs even in safe mode Virus and Malware Removal 6 09-09-2009 02:45 PM
Internet Browsers, all of them not working Storage and Networking 2 07-10-2009 09:56 AM
problems connecting to internet via browsers Storage and Networking 2 11-25-2006 07:48 PM
Internet Explorer not open function: Open in new window! and Search don't too Windows OS 0 12-16-2004 01:53 PM


All times are GMT -4. The time now is 11:38 PM.