Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: No Internet Access after virus removal :(  (Read 36176 times)

0 Members and 1 Guest are viewing this topic.

SuperDave

  • Malware Removal Specialist
  • Moderator


  • Genius
  • Thanked: 1020
  • Certifications: List
  • Experience: Expert
  • OS: Windows 10
Re: No Internet Access after virus removal :(
« Reply #15 on: January 09, 2012, 01:17:56 PM »
Please download Farbar Service Scanner and run it on the computer with the issue.
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.
Windows 8 and Windows 10 dual boot with two SSD's

nasroo7

    Topic Starter


    Intermediate
    • Computer: Specs
    • Experience: Experienced
    • OS: Windows 10
    Re: No Internet Access after virus removal :(
    « Reply #16 on: January 09, 2012, 02:35:00 PM »
    Here is a log, I didn't check or uncheck anything. Scanned only the Internet Services




    Farbar Service Scanner
    Ran by Annette (administrator) on 09-01-2012 at 16:32:52
    Microsoft Windows XP Professional Service Pack 3 (X86)
    Boot Mode: Normal
    ****************************************************************

    Internet Services:
    ============

    Connection Status:
    ==============
    Localhost is blocked.
    LAN connected.
    Attempt to access Google IP returned error: Other errors
    Attempt to access Yahoo IP returend error: Other errors


    File Check:
    ========
    C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit
    C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit
    C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit
    C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit
    C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit
    C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit
    C:\WINDOWS\system32\svchost.exe => MD5 is legit
    C:\WINDOWS\system32\rpcss.dll => MD5 is legit
    C:\WINDOWS\system32\services.exe => MD5 is legit

    Extra List:
    =======
    Gpc(3) IPSec(5) NetBT(6) PSched(7) Tcpip(4)
    0x0700000005000000010000000200000003000 000040000000600000007000000
    IpSec Tag value is correct.

    **** End of log ****

    nasroo7

      Topic Starter


      Intermediate
      • Computer: Specs
      • Experience: Experienced
      • OS: Windows 10
      Re: No Internet Access after virus removal :(
      « Reply #17 on: January 09, 2012, 02:36:07 PM »
      Checked all the others,
      here is the log (I don't know which one you need)




      Farbar Service Scanner
      Ran by Annette (administrator) on 09-01-2012 at 16:33:33
      Microsoft Windows XP Professional Service Pack 3 (X86)
      Boot Mode: Normal
      ****************************************************************

      Internet Services:
      ============

      Connection Status:
      ==============
      Localhost is blocked.
      LAN connected.
      Attempt to access Google IP returned error: Other errors
      Attempt to access Yahoo IP returend error: Other errors


      Windows Firewall:
      =============

      Firewall Disabled Policy:
      ==================
      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
      "EnableFirewall"=DWORD:0


      System Restore:
      ============

      System Restore Disabled Policy:
      ========================


      Security Center:
      ============

      Windows Update:
      ===========

      File Check:
      ========
      C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit
      C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit
      C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit
      C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit
      C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit
      C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit
      C:\WINDOWS\system32\ipnathlp.dll => MD5 is legit
      C:\WINDOWS\system32\netman.dll => MD5 is legit
      C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
      C:\WINDOWS\system32\srsvc.dll => MD5 is legit
      C:\WINDOWS\system32\Drivers\sr.sys => MD5 is legit
      C:\WINDOWS\system32\wscsvc.dll => MD5 is legit
      C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
      C:\WINDOWS\system32\wuauserv.dll => MD5 is legit
      C:\WINDOWS\system32\qmgr.dll => MD5 is legit
      C:\WINDOWS\system32\es.dll => MD5 is legit
      C:\WINDOWS\system32\cryptsvc.dll => MD5 is legit
      C:\WINDOWS\system32\svchost.exe => MD5 is legit
      C:\WINDOWS\system32\rpcss.dll => MD5 is legit
      C:\WINDOWS\system32\services.exe => MD5 is legit

      Extra List:
      =======
      Gpc(3) IPSec(5) NetBT(6) PSched(7) Tcpip(4)
      0x0700000005000000010000000200000003000 000040000000600000007000000
      IpSec Tag value is correct.

      **** End of log ****

      SuperDave

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Thanked: 1020
      • Certifications: List
      • Experience: Expert
      • OS: Windows 10
      Re: No Internet Access after virus removal :(
      « Reply #18 on: January 09, 2012, 04:43:16 PM »
      Quote
      Localhost is blocked.
      Is it possible your Firewall is blocking this?

      1. Go Start>Settings>Control Panel (Vista/7 users: Start>Control Panel)
      2. Double click Network Connections (Vista/7 users: Network and Sharing Center)
      3. Vista/7 users - From the list of tasks on the left, click Manage network connections.
      4. For a wired network connection, right-click Local Area Connection, and then select Properties.
      For a wireless network connection, right-click Wireless Network Connection, and then select Properties.
      5. From the General tab (Vista/7 users: Networking tab), click Internet Protocol (TCP/IP), make sure it is checked, and then click Properties
      6. Click Obtain an IP Address Automatically, and then click OK.
      Windows 8 and Windows 10 dual boot with two SSD's

      nasroo7

        Topic Starter


        Intermediate
        • Computer: Specs
        • Experience: Experienced
        • OS: Windows 10
        Re: No Internet Access after virus removal :(
        « Reply #19 on: January 10, 2012, 07:55:03 AM »
        Quote
        So, I tried to reset all Iexplorer settings in "Reset Defult" it doesn't solve the problem.
        There is no PROXY, and everything is on "Detect Automatically... IP, DNS..."
        I tried to activate the firewall, it tells me that it cannot start "Connection Sharing ICS service"
        I tried to start Automatic Updates service, but it tells me "It had to stop, because it has no action to take.

        It was already on "Automatically..." But I double checked now... it's still the same

        I saw another topic where a guy had kind of the same issue.
        and you suggested him to use WinsockXPFix.
        It didn't solve the problem for him... but maybe for me.
        Because ComboFix detected a rootkit that was in my TCP/IP. So that's why I'm thinking about resetting all settings related to that.

        But you're the boss, I do whatever you suggest me.

        SuperDave

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Thanked: 1020
        • Certifications: List
        • Experience: Expert
        • OS: Windows 10
        Re: No Internet Access after virus removal :(
        « Reply #20 on: January 10, 2012, 12:12:01 PM »
        Quote
        But you're the boss, I do whatever you suggest me.
        I'm working my way down the checklist.

        Go Start>Run (Start search in Vista), type in:
        cmd
        Click OK (in Vista and 7, while holding CTRL, and SHIFT, press Enter).

        In Command Prompt window, type in following commands, and hit Enter after each one:
        ipconfig /flushdns
        ipconfig /registerdns
        ipconfig /release
        ipconfig /renew
        net stop "dns client"
        net start "dns client"


        Restart computer.

        If that doesn't work...
        Go Start>Run (Start search in Vista and 7), type in:
        cmd
        Click OK (in Vista, while holding CTRL, and SHIFT, press Enter).

        At Command Prompt, type in:
        netsh int ip reset reset.log
        Hit Enter.
        Type in:
        netsh winsock reset catalog
        Hit Enter.

        Restart computer.
        Windows 8 and Windows 10 dual boot with two SSD's

        nasroo7

          Topic Starter


          Intermediate
          • Computer: Specs
          • Experience: Experienced
          • OS: Windows 10
          Re: No Internet Access after virus removal :(
          « Reply #21 on: January 10, 2012, 01:04:07 PM »
          everything was successfully done,
          but didn't solve the problem. :(

          nasroo7

            Topic Starter


            Intermediate
            • Computer: Specs
            • Experience: Experienced
            • OS: Windows 10
            Re: No Internet Access after virus removal :(
            « Reply #22 on: January 10, 2012, 01:06:28 PM »
            at the same time, MSEssentials just blocked Win32.Sirefef

            SuperDave

            • Malware Removal Specialist
            • Moderator


            • Genius
            • Thanked: 1020
            • Certifications: List
            • Experience: Expert
            • OS: Windows 10
            Re: No Internet Access after virus removal :(
            « Reply #23 on: January 10, 2012, 04:57:56 PM »
            Let's try to uninstall/reinstall TCP/IP stack.

            1. Download winsock.zip
            Unzip it.
            Right click on Winsock.reg, click "Merge".
            Allow registry merge.

            2. Restart computer.

            3. Go to Start ==> Control Panel.  Double-click Network Connections. Right-click Local Area Connection, and select Properties.
            • On the General tab, click Install a popup window opens.
            • Select Protocol from the list and then click Add.
            • A new window opens, click Have Disk....
            • In the browse... box type c:\windows\inf
            • Click OK.
            • Select Internet Protocol (TCP/IP), and then click OK.
            • Restart and check the connection.
            Windows 8 and Windows 10 dual boot with two SSD's

            nasroo7

              Topic Starter


              Intermediate
              • Computer: Specs
              • Experience: Experienced
              • OS: Windows 10
              Re: No Internet Access after virus removal :(
              « Reply #24 on: January 11, 2012, 08:39:10 AM »
              I did everything, and now Internet works ! :D

              is it done? or need more work on it ? :s

              nasroo7

                Topic Starter


                Intermediate
                • Computer: Specs
                • Experience: Experienced
                • OS: Windows 10
                Re: No Internet Access after virus removal :(
                « Reply #25 on: January 11, 2012, 08:44:10 AM »
                Quote
                at the same time, MSEssentials just blocked Win32.Sirefef

                I have also a question, because it happened that MSEssentials blocked Win32.Sirefef (Before I asked your help) and tried "ESETSirefefRemover" solution by Kaspersky, but after scan, it told me that Sirefef is not on the computer.

                Does it mean that MSEssentials is blocking it from infecting my computer? Or does it mean that it's infecting my computer but hidden somewhere?


                And on this computer, I had MSEssentials blocked Sirefef when scanning with AVP Tool

                SuperDave

                • Malware Removal Specialist
                • Moderator


                • Genius
                • Thanked: 1020
                • Certifications: List
                • Experience: Expert
                • OS: Windows 10
                Re: No Internet Access after virus removal :(
                « Reply #26 on: January 11, 2012, 12:02:13 PM »
                SUPERAntiSpyware

                If you already have SUPERAntiSpyware be sure to check for updates before scanning!


                Download SuperAntispyware Free Edition (SAS)
                * Double-click the icon on your desktop to run the installer.
                * When asked to Update the program definitions, click Yes
                * If you encounter any problems while downloading the updates, manually download and unzip them from here
                * Next click the Preferences button.

                •Under Start-Up Options uncheck Start SUPERAntiSpyware when Windows starts
                * Click the Scanning Control tab.
                * Under Scanner Options make sure only the following are checked:

                •Close browsers before scanning
                •Scan for tracking cookies
                •Terminate memory threats before quarantining
                Please leave the others unchecked

                •Click the Close button to leave the control center screen.

                * On the main screen click Scan your computer
                * On the left check the box for the drive you are scanning.
                * On the right choose Perform Complete Scan
                * Click Next to start the scan. Please be patient while it scans your computer.
                * After the scan is complete a summary box will appear. Click OK
                * Make sure everything in the white box has a check next to it, then click Next
                * It will quarantine what it found and if it asks if you want to reboot, click Yes

                •To retrieve the removal information please do the following:
                •After reboot, double-click the SUPERAntiSpyware icon on your desktop.
                •Click Preferences. Click the Statistics/Logs tab.

                •Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.

                •It will open in your default text editor (preferably Notepad).
                •Save the notepad file to your desktop by clicking (in notepad) File > Save As...

                * Save the log somewhere you can easily find it. (normally the desktop)
                * Click close and close again to exit the program.
                *Copy and Paste the log in your post.
                ***************************************************
                Please download Malwarebytes Anti-Malware from here.
                Double Click mbam-setup.exe to install the application.
                • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
                • If an update is found, it will download and install the latest version.
                • Once the program has loaded, select "Perform Full Scan", then click Scan.
                • The scan may take some time to finish,so please be patient.
                • When the scan is complete, click OK, then Show Results to view the results.
                • Make sure that everything is checked, and click Remove Selected.
                • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
                • Please save the log to a location you will remember.
                • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
                • Copy and paste the entire report in your next reply.
                Extra Note:

                If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
                *************************************************
                Download DDS from HERE or HERE and save it to your desktop.

                Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

                * XP users Double click on dds to run it.
                * If your antivirus or firewall try to block DDS then please allow it to run.
                * When finished DDS will open two (2) logs.
                * Save both reports to your desktop.
                * The instructions here ask you to attach the Attach.txt.



                1) DDS.txt
                2) Attach.txt
                Instead of attaching, please copy/past both logs into your Thread

                Note: DDS will instruct you to post the Attach.txt log as an attachment.
                Please just post it as you would any other log by copying and pasting it into the reply.

                •Close the program window, and delete the program from your desktop.

                Please note: You may have to disable any script protection running if the scan fails to run.
                After downloading the tool, disconnect from the internet and disable all antivirus protection.
                Run the scan, enable your A/V and reconnect to the internet.
                Information on A/V control HERE .Then post your DDS logs. (DDS.txt and Attach.txt )
                Windows 8 and Windows 10 dual boot with two SSD's

                nasroo7

                  Topic Starter


                  Intermediate
                  • Computer: Specs
                  • Experience: Experienced
                  • OS: Windows 10
                  Re: No Internet Access after virus removal :(
                  « Reply #27 on: January 11, 2012, 12:03:52 PM »
                  After Internet was fixed, I opened MSEssentials, and clicked on update, and then went back to my other stuff...
                  Came back few hours later, and found it updated successfully.

                  But just by curiosity I went on the history... and...
                  I found 15 detected items today (I didn't run any scan)
                   Virus:Win32/Sirefef.N  Desinfected (14 times)
                   Exploit:Java/CVE-2011-3544.L  Removed (1 time)



                  nasroo7

                    Topic Starter


                    Intermediate
                    • Computer: Specs
                    • Experience: Experienced
                    • OS: Windows 10
                    Re: No Internet Access after virus removal :(
                    « Reply #28 on: January 11, 2012, 12:06:03 PM »
                    ok, I do all of that

                    nasroo7

                      Topic Starter


                      Intermediate
                      • Computer: Specs
                      • Experience: Experienced
                      • OS: Windows 10
                      Re: No Internet Access after virus removal :(
                      « Reply #29 on: January 11, 2012, 03:03:31 PM »
                      After I finished with SuperAntiSPyware, MSEssentials blocked Sirefef again, and clicked on Desinfect, but had the error code: 0x800704ec