Computer Hope

Software => Computer viruses and spyware => Topic started by: Randy1887 on February 09, 2010, 10:26:45 PM

Title: Connected to Internet provider but web browser doesn't work
Post by: Randy1887 on February 09, 2010, 10:26:45 PM
here is the logs for Malwarebytes' and Hijack This, SuperAntispyware did not create a log

[Saving space, attachment deleted by admin]
Title: Re: Connected to Internet provider but web browser doesn't work
Post by: Dr Jay on February 10, 2010, 08:41:12 PM
Please visit this webpage for a tutorial on downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

See the area: Using ComboFix, and when done, post the log back here.
Title: Re: Connected to Internet provider but web browser doesn't work
Post by: Randy1887 on February 11, 2010, 04:42:07 PM
I will look into this ComboFix tonight and get back with you
Title: Re: Connected to Internet provider but web browser doesn't work
Post by: Randy1887 on February 11, 2010, 05:15:18 PM
Ok so I ran ComboFix and it created a log which I am now uploading. When it finished I decided to give my web browser another shot and it is working great!  :) I guess combo fix done the trick!  ;D Please look over the log for me though and let me know for sure if ComboFix was what fixed it! Thanks A million!!!! computerhope and you saved me $130.00!!!!!!!!!

[Saving space, attachment deleted by admin]
Title: Re: Connected to Internet provider but web browser doesn't work
Post by: Dr Jay on February 12, 2010, 07:45:02 PM
Please run a free online scan with the ESET Online Scanner (http://www.eset.com/onlinescan/)
Title: Re: Connected to Internet provider but web browser doesn't work
Post by: Randy1887 on February 17, 2010, 01:47:49 AM
ESET Did not create a log  ???  It did however find a worm whick i allowed it to remove
Title: Re: Connected to Internet provider but web browser doesn't work
Post by: Dr Jay on February 17, 2010, 11:13:14 PM
(http://img233.imageshack.us/img233/7729/mbamicontw5.gif) Please download Malwarebytes Anti-Malware from Malwarebytes.org (http://www.malwarebytes.org/mbam/program/mbam-setup.exe).
Alternate link: BleepingComputer.com (http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe).
(Note: if you already have the program installed, just follow the directions. No need to re-download or re-install!)

Double Click mbam-setup.exe to install the application.

(Note: if you already have the program installed, open Malwarebytes from the Start Menu or Desktop shortcut, click the Update tab, and click Check for Updates, before doing the scan as instructed below!)
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
Title: Re: Connected to Internet provider but web browser doesn't work
Post by: Randy1887 on February 21, 2010, 02:05:55 AM
Malwarebytes' Anti-Malware 1.44
Database version: 3769
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18882

2/21/2010 2:58:58 AM
mbam-log-2010-02-21 (02-58-58).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 324648
Time elapsed: 1 hour(s), 5 minute(s), 48 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 7

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\System Volume Information\{36a401cc-1c16-11df-9898-0016ea6bc556}{3808876b-c176-4e48-b7ae-04046e6cc752} (Malware.Packer.Gen) -> Delete on reboot.
C:\Windows\010112010146114101.xxe (KoobFace.Trace) -> Quarantined and deleted successfully.
C:\Windows\01011201014650115.xxe (KoobFace.Trace) -> Quarantined and deleted successfully.
C:\Windows\rdr_1266215756.exe (Worm.Koobface) -> Quarantined and deleted successfully.
C:\Windows\rdr_1266215937.exe (Worm.Koobface) -> Quarantined and deleted successfully.
C:\Windows\rdr_1266216211.exe (Worm.Koobface) -> Quarantined and deleted successfully.
C:\Windows\rdr_1266216232.exe (Worm.Koobface) -> Quarantined and deleted successfully.
Title: Re: Connected to Internet provider but web browser doesn't work
Post by: Dr Jay on February 23, 2010, 10:31:12 PM
Please run a free online scan with the ESET Online Scanner (http://www.eset.com/onlinescan/)
Title: Re: Connected to Internet provider but web browser doesn't work
Post by: Randy1887 on March 01, 2010, 11:43:05 AM
I ran ESET but once again it did not creat a log, however it did say there was no infected files
Title: Re: Connected to Internet provider but web browser doesn't work
Post by: Dr Jay on March 01, 2010, 12:13:26 PM
Does your web browser work yet?
Title: Re: Connected to Internet provider but web browser doesn't work
Post by: Randy1887 on March 01, 2010, 10:15:15 PM
Yes. After I ran Combo-Fix it works fine. I tried to upload a copy of Combo-Fix's report but I don't know if it uploaded or not. If you want me to upload it again I can. Thank You soooooooooooooo much for your help!!!!!!!
Title: Re: Connected to Internet provider but web browser doesn't work
Post by: Dr Jay on March 01, 2010, 10:33:00 PM
No biggie. Let's clean up. :)

To manually create a new Restore PointNow we can purge the infected ones
You are now done

To remove all of the tools we used and the files and folders they created, please do the following:
Please download OTC.exe (http://oldtimer.geekstogo.com/OTC.exe) by OldTimer:
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

==

Please download TFC by OldTimer (http://oldtimer.geekstogo.com/TFC.exe) to your desktop
==

Download Security Check by screen317 from SpywareInfoforum.org (http://screen317.spywareinfoforum.org/SecurityCheck.exe) or Changelog.fr (http://screen317.changelog.fr/SecurityCheck.exe).