also @ TechSpot: Mozilla developing Metro-specific Firefox for Windows 8
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.

Go Back   TechSpot OpenBoards > Tech Support > Virus and Malware Removal

Collaborate in the cloud with Office, Exchange, SharePoint, and Lync

Cannot Find Server in Normal Mode, Only Safe Mode -> Possible Spyware

Thread Tools Search this Thread
  #1  
Old 12-03-2007
almcneil's Avatar
TechSpot Guru
 
Location: Ottawa, CANADA
Member since: Jun 2007, 1,547 posts
Cannot Find Server in Normal Mode, Only Safe Mode -> Possible Spyware

Techies,

I have a toughie here!

A customer cannot find web sites in Normal Mode using any web browser (IE, Mozilla or Netscape.) But in Safe Mode, he can using any of them. Checked in NOrmal Mode and can ping any valid address. Obviously something is running in Normal Mode that is preventing access to DNS. Also, when launching new programs, the mouse becomes very slow.

Initially checked for spyware using Ad-Aware 2007, Spybot Search & DEstroy and AVG Anti-Spyware in NOrmal Mode. Then uninstalled ZoneAlarm, Symantec NOrton INternet SEcurity and disabled Windows Firewall. Still have same problems. Tried disabling devices not used in Safe Mode while in NOrmal MOde, still same problem. Ran Spybot in Safe Mode, nothing.

I have run HijackThis and attached a log. Can someone please review it and advise us on it. TIA!
Attached Files
File Type: log hijackthis.log (8.9 KB, 3 views)
  #2  
Old 12-03-2007
TechSpot Booster
 
Location: Vancouver
Member since: Feb 2007, 357 posts
You need to rename Hijack This.exe to "Big-Fat-One.exe"

and put it in it`s own folder,eg C:\\ProgramFiles\Hijack This\Big-Fat-One.exe

Then run it.After that, run Combo fix.All the details HERE
  #3  
Old 12-03-2007
Jase123's Avatar
Banned
 
Location: England
Member since: Sep 2007, 1,126 posts
System specs
You are running hijackthis.exe in a temp folder. You need to put hijackthis.exe into a folder of it's own. This is because HJT makes backups of any changes you make and if it's in a temp folder - the backups will be deleted.

It also comes to my attention that you are running an outdated version of Hijackthis - please follow my instructions below.

Go and read the [URL="http://www.techspot.com/vb/topic58138.html"][B][COLOR="Blue"]Viruses/Spyware/Malware, preliminary removal instructions[/COLOR][/B][/URL]. Follow all the instructions exactly.

Post fresh [B]HJT[/B], [B][COLOR="Red"]AVG Antispyware[/COLOR][/B] and [B]Combofix[/B] logs as [B][COLOR="Blue"]attachments[/COLOR][/B] into this thread, only after doing the above.
[B]
Also, let me know the results of the Panda Antirootkit scan.[/B]

Regards Jason

[B][COLOR="Red"]This thread is for the use of[/COLOR][/B] [B]almcneil[/B] [B][COLOR="Red"]ONLY[/COLOR][/B]. [B][COLOR="Blue"]Please do NOT post your own virus/spyware problems into this thread. Instead, open a new thread in our [URL="http://www.techspot.com/vb/menu28.html"]security and the web forum[/URL][/COLOR][/B].
  #4  
Old 12-05-2007
almcneil's Avatar
TechSpot Guru
 
Location: Ottawa, CANADA
Member since: Jun 2007, 1,547 posts
HijackThis Experts,

As you requested, attached are the HijackThis, AVG Anti-spyware and ComboFix logs using the latest versions of said programs. I really appreciate your help in all of this! This customer is quite knowledgeable and uses an advanced setup so it's got to be a really tricky piece of spyware to cause him problems! Again, TIA!!
Attached Files
File Type: log hijackthis_log.log (8.6 KB, 3 views)
File Type: txt AVG-AS-Scan-20071129-122607.txt (18.0 KB, 3 views)
File Type: txt combofix_log.txt (11.4 KB, 3 views)
  #5  
Old 12-06-2007
Po`Girl's Avatar
TechSpot Addict
 
Location: London,England
Member since: Feb 2007, 668 posts
I`m not an spyware expert,but I can`t see anything obvious in that lot.

There does seem to be a large amount of security software,though.

My only 2 cents,is that you try :

- A completely clean boot.

Go to msconfig,uncheck everything then go to the services tab,

"Hide all Microsoft services" and then uncheck the 10 ? remaining ones.

Then reboot.

- Search the computer for vsmon.exe

It`s part of ZA that sometimes sticks around to cause grief.

- I`d normally say run Winsockfix but if everythings ok in Safe Mode, it won`t help much.

- Oh and,the Norton Removal Tool is something you could recommend to your customer.It`s the only effective way to get rid of it

Last edited by Po`Girl; 12-06-2007 at 01:49 AM..
  #6  
Old 12-06-2007
momok's Avatar
TechSpot Evangelist
 
Location: Singapore
Member since: Mar 2007, 2,272 posts
Hi,

Have HJT fix this entry:
O16 - DPF: {F09BFD07-20B5-46D8-A6D5-BE4EF22F1F4D} (DGTx.uc1) - http://66.98.144.30/DGTx.CAB

Are the problems still occurring? What exactly happens when you try to open a website? Please explain in detail thanks.

Regards,
momok =)

This thread is for the use of almcneil only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our Security and The Web forum.
  #7  
Old 12-06-2007
almcneil's Avatar
TechSpot Guru
 
Location: Ottawa, CANADA
Member since: Jun 2007, 1,547 posts
Eureka!!

Quote:
Originally Posted by Po`Girl
I`m not an spyware expert,but I can`t see anything obvious in that lot.

...

- Oh and,the Norton Removal Tool is something you could recommend to your customer.It`s the only effective way to get rid of it
Eureka!! Your suggestion to use the Norton Removal Tool did the trick!! Thank you very much!! We owe you one! Maybe a beer? We're canadian so be aware, our beer is STRONGER!! ;-)

Thanks again!
Closed Thread

Similar Topics
Topic Replies Forum
OpenGL Programs Load in Safe Mode, but not Normal Mode? 0 Device Drivers
Unable to start windows XP either in safe mode nor in normal mode 7 Windows OS
Reboot in normal mode, fine in safe mode 15 Windows OS
Cannot view webpages online in normal mode, but can in safe mode.. Virus?! 4 Virus and Malware Removal
XP HE wont boot normal mode, safe mode ok 2 Windows OS

Thread Tools Search this Thread
Search this Thread:

Advanced Search
All times are GMT -4. The time now is 07:04 AM.