This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Cannot access IE

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I started describing my problem on a different thread (email, internet problems?) but appleoddity suggested I start a new thread after I mentioned I had ran Malwarebytes' Anti-Malware and it found six registry items infected with a Trojan.DNSChanger. He gave me some things to try, as did struker, but I cannot do anything as I am unable to access the internet. I can sign on through my ISP, but when I click on the IE icon on my desktop, nothing happens. Eventually, I will get the pop-up that says IE explorer ran into a problem and had to shut down and then it asks if I want to send a report. If I click on the Yahoomail, or Google icon, nothing happens for approximately 45 seconds and then a pop-up says "windows cannot locate www.google (or yahoomail).com", or something close to that. Struker suggested I try resetting IE, which I thought was IE7, but when I bring up Internet options, I only have the "Restore Defaults" button, not "Reset Internet Explorer Settings". Struker and appleoddity advise I must not have IE7 loaded, or it is not completely loaded. I went to start - programs - internet explorer - properties and it just says Internet Explorer under the general tab or anyother tab there was. Not IE7. So, I guess I am at a stand-still unless someone on this site can help me out. Oh, early on I tried System Restore but nothing happened after clicking to restore my pc to a date a week ago. I waited over five minutes and it didn't even appear my pc was active in anyway. I have gone back to system restore since then and now it says there are no restore points available, even though there are several days highlighted, or in bold print. Nothing happens when I click on them. The only thing i know for sure is my internet connection (broadband) is good. That was confirmed through my ISP. Also, I ran a "Network Diagnostics for Windows XP" and under HTTP, HTTPS, FTP Diagnostics it showed six warnings. They looked something like this….HTTP: Error 12007 connecting to www.microsoft.com. The server name or address could not be resolved. Also, FTP (Passive): Error 12007 connecting to ftp.microsoft.com: The server name or address could not be resolved. Under the six warnings, two each for HTTP, HTTPS and FTP, there were three errors. #1: Could not make an HTTP connection, #2: Could not make an HTTPS connection, #3: Could not make an FTP connection. Any help/suggestions would be appreciated. FYI - I am using my daughters laptop to access this website. Regards, Bill :pullhair:
Hello and welcome to Posted Image

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

I am checking over your information now, I will post back shortly with instructions.
Hi bwest,

Please try the following:

ONLY if you connect to the internet via a router do this:

Let’s try to reset the router to its default configuration.
  • This can be done by inserting something tiny like a paper clip end or pencil tip into a small hole labeled "reset" located on the back of the router.
  • Press and hold down the small button inside until the lights on the front of the router blink off and then on again (usually about 10 seconds).
  • If you don’t know the router's default password, you can look it up. HERE
  • You also need to reconfigure any security settings you had in place prior to the reset.
  • You may also need to consult with your Internet service provider to find out which DNS servers your network should be using.

NEXT

The infection has attacked your DNS, so we need to reset your DNS server and flush your DNS cache.
I suggest you print out these instructions for easy reference:
  • Go to Start > Control Panel, and choose Network Connections.
  • Right click on your default connection, usually Local Area Connection for cable and DSL or Dial-up Connection if you are using Dial-up, and choose Properties.
  • Click the Networking tab
  • Double-click on the Internet Protocol (TCP/IP) item.
  • Write down the settings in case you should need to change them back.
  • Select the radio button that says "Obtain DNS servers automatically".
  • Click OK twice to get out of the properties screen and restart your computer.
  • If not prompted to reboot go ahead and reboot manually.
CAUTION: It's possible that your ISP (Internet Service Provider) requires specific DNS settings here. Make sure you know if you need these settings or not BEFORE you make any changes or you may lose your Internet connection. If you're sure you do not need a specific DNS address, then you may proceed.
  • Now go to Start > Run > type: cmd
  • Press OK or Hit Enter.
  • At the command prompt, type or copy/paste: ipconfig /flushdns (note the space between “..g /f…” it needs to be there)
  • Hit Enter.
  • You will get a confirmation that the flush was successful.
  • Close the command box.


NEXT

If you are still unable to connect with IE try downloading an alternate browser on your good computer and transferring it to the infected PC via thumb drive or other media (I highly recommend using Firefox)
Firefox may be downloaded from Here

NEXT

(if you are unable to directly access the internet still - download and transfer this program to the infected PC)


Download OTScanIt2.exe to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt2 on your desktop.
  • Open the OTScanIt2 folder and double-click on OTScanIt.exe to start the program. Make sure you close all other programs and don't use the PC while the scan runs.
  • Under File Age at the top, change it from 30 days to 90 days
  • Under Additional Scans check the boxes beside Reg - ActiveX StubPath, Reg - App Paths, Reg - ColumnHandlers, Reg - Desktop Components, Reg - Disabled MS Config Items, Reg - File Associations, Reg - ICQ Agent, Reg - NetSvcs, Reg - Print Monitors, Reg - Protocol Filters, Reg - Protocol Handlers, Reg - SafeBoot Minimal, Reg - SafeBoot Network, Reg - Session Manager Settings, Reg - Winsock2 Catalogs, File - Lop Check, File - Purity Scan, Files - Signature Check, and Evnt - EventViewer Logs ( Last 10 Errors).
  • Under Rootkit Search change it to Yes
  • Under the Custom Scans box at the bottom left paste the following in

    %systemroot%\Prefetch\*.* /s
    %systemroot%\system32\drivers\*.dat
    %systemroot%\system32\*aef
    %systemroot%\system32\drivers\*aef
    %systemroot%\Temp\bca4e2da.$$$
    %systemroot%\Temp\ed47fa.$
    %systemroot%\Temp\fa56d7ec.$$$
    %systemroot%\Temp\*.$$$
    %systemroot%\System32\antiwpa.dll
    %systemroot%\SYSTEM32\wpa.dll
    %systemroot%\setup\scripts\biestart.exe
    %System%\AcroIeHelpe.dll
    %SYSTEMDRIVE%\*.epk
    %systemroot%\*.epk
    %systemroot%\system32\*.epk
    %systemroot%\system32\bb*.dat
    %systemroot%\system32\cookie*.dat
    %systemroot%\system32\kaxs.dat
    %systemroot%\system32\ps*.dat
    %systemroot%\system32\*32.sys
    %systemroot%\*.dr
    %SYSTEMDRIVE%\*.dr
    %systemroot%\system32\*.dr
    %systemroot%\system32\nods32.dll
    %systemroot%\*.res
    %SYSTEMDRIVE%\*.res
    %systemroot%\system32\*.res
    %systemroot%\system32\sockins32.dll
    %systemroot%\system32\Spool\*.*
    %systemroot%\system32\Spool\*.exe
    %systemroot%\system32\Spool\*.rar /s
    %systemroot%\system32\Spool\*.zip /s
    %systemroot%\system32\Spool\*.dat /s
    %ProgramFiles%\MSN Messenger\*.zip
    %ProgramFiles%\MSN Messenger\*.exe
    %ProgramFiles%\MSN Messenger\*.rar.
    %SYSTEMDRIVE%\*.zip
    %SYSTEMDRIVE%\*.rar
    %SYSTEMDRIVE%\*.exe
    %SYSTEMDRIVE%\*.dll
    %systemroot%\*.zip
    %systemroot%\*.rar
    %systemroot%\system32\*.zip
    %systemroot%\system32\*.rar
    %PROGRAMFILES%\*.*
    %DESKTOP%\*.zip
    %DESKTOP%\*.rar
    %DESKTOP%\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %PROGRAMFILES%\Common Files\*bak*.
    %systemroot%\SYSTEM32\*bak*.
    %PROGRAMFILES%\*bak*.
    %systemroot%\ime\imjp8_1\*bak*.
    %PROGRAMFILES%\QuickTime\*bak*.
    %PROGRAMFILES%\Viewpoint\Viewpoint Manager\*bak*.
    %PROGRAMFILES%\Analog Devices\Core\*bak*.
    %SYSTEMDRIVE%\hp\KBD\*bak*.
    %PROGRAMFILES%\Adobe\Photoshop Album Starter Edition\3.2\Apps\*bak*.
    %PROGRAMFILES%\BillP Studios\WinPatrol\*bak*.
    %PROGRAMFILES%\BroadJump\Client Foundation\*bak*.
    %PROGRAMFILES%\Common Files\Real\Update_OB\*bak*.
    %PROGRAMFILES%\Common Files\Sonic\Update Manager\*bak*.
    %PROGRAMFILES%\\Google\GoogleToolbarNotifier\*bak*.
    %PROGRAMFILES%\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\*bak*.
    %PROGRAMFILES%\Yahoo!\Messenger\*bak*.
    %USERNAME%\*.zip
    %USERNAME%\*.rar
    %USERNAME%\*.exe
    %USERPROFILE%\*.zip
    %USERPROFILE%\*.rar
    %USERPROFILE%\*.exe
    %ALLUSERSPROFILE%\*.zip
    %ALLUSERSPROFILE%\*.rar
    %ALLUSERSPROFILE%\*.exe
    %APPDATA%\*.zip
    %APPDATA%\*.rar
    %APPDATA%\*.exe
    %ALLUSERSSTARTMENU%\*.zip
    %ALLUSERSSTARTMENU%\*.rar
    %ALLUSERSSTARTMENU%\*.exe
    %ALLUSERSSTARTUP%\*.zip
    %ALLUSERSSTARTUP%\*.rar
    %ALLUSERSSTARTUP%\*.exe
    %ALLUSERSPROGRAMS%\*.zip
    %ALLUSERSPROGRAMS%\*.rar
    %ALLUSERSPROGRAMS%\*.exe
    %ALLUSERSAPPDATA%\*.zip
    %ALLUSERSAPPDATA%\*.rar
    %ALLUSERSAPPDATA%\*.exe
    %APPDATA%\*.zip
    %APPDATA%\*.rar
    %APPDATA%\*.exe
    %APPDATA%\*.dat
    %APPDATA%\*.dll
    %QUICKLAUNCH%\*.zip
    %QUICKLAUNCH%\*.rar
    %QUICKLAUNCH%\*.exe
    %STARTUP%\*.zip
    %STARTUP%\*.rar
    %STARTUP%\*.exe
    %STARTMENU%\*.zip
    %STARTMENU%\*.rar
    %STARTMENU%\*.exe
    %MYDOCUMENTS%\*.zip
    %MYDOCUMENTS%\*.rar
    %MYDOCUMENTS%\*.exe
    %PROGRAMFILES%\Mozilla Firefox\plugins\*.*
    %PROGRAMFILES%\Internet Explorer\*.*
    %PROGRAMFILES%\Internet Explorer\PLUGINS\*.*
    %PROGRAMFILES%\Mozilla Firefox\*.zip /s
    %PROGRAMFILES%\Mozilla Firefox\*.rar /s
    %PROGRAMFILES%\Mozilla Firefox\*.exe /s
    %PROGRAMFILES%\Internet Explorer\*.zip /s
    %PROGRAMFILES%\Internet Explorer\*.rar /s
    %PROGRAMFILES%\Internet Explorer\*.exe /s
    %SYSTEMDRIVE%\*.dat
    %SYSTEMDRIVE%\*.sys
    %SYSTEMROOT%\*.dat
    %SYSTEMROOT%\*.sys
    %systemroot%\system32\drivers\*.exe /s
    %systemroot%\system32\drivers\*.zip /s
    %systemroot%\system32\drivers\*.rar /s
    %systemroot%\system\*.exe /s
    %systemroot%\system\*.zip /s
    %systemroot%\system\*.rar /s
    %systemroot%\AppPatch\*.exe /s
    %systemroot%\AppPatch\*.zip /s
    %systemroot%\AppPatch\*.rar /s
    %systemroot%\Cache\*.*
    %systemroot%\Downloaded Program Files\*.*
    %systemroot%\Fonts\*.exe /s
    %systemroot%\Fonts\*.zip /s
    %systemroot%\Fonts\*.rar /s
    %systemroot%\Fonts\*.dll /s
    %systemroot%\Help\*.exe /s
    %systemroot%\Help\*.zip /s
    %systemroot%\Help\*.rar /s
    %systemroot%\Tasks\*.*
    %APPDATA%\*.sys
    %APPDATA%\Google\*.*
    %systemroot%\system32\serauth1.dll
    %systemroot%\system32\serauth2.dll
    %systemroot%\system32\sysaudio.sys
    %systemroot%\system32\wdmaud.sys
    %systemroot%\system32\aeaudio.sys
    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32|system32\serauth1.dll /rs
    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32|system32\serauth2.dll /rs
    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32|system32\sysaudio.sys /rs
    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32|system32\aeaudio.sys /rs
    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32|system32\wdmaud.sys /rs
    %PROGRAMFILES%\*TinyProxy*.
    HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla|extensions /rs
    %systemroot%\system32\inf\*.exe /s
    %systemroot%\system32\inf\*.zip /s
    %systemroot%\system32\inf\*.rar /s
    %systemroot%\system32\inf\*.dll /s
    %APPDATA%\Opera\Opera\profile\widgets\*.*
    %PROGRAMFILES%\Opera\program\plugins\*.* /s
    %APPDATA%\Opera\Opera\profile\toolbar\*.* /s
    %systemroot%\Web\*.exe /s
    %systemroot%\Web\*.dat /s
    %systemroot%\Web\*.dll /s
    %systemroot%\Web\*.sys /s
    %systemroot%\Web\*.zip /s
    %systemroot%\Web\*.rar /s
    %systemroot%\Wbem\*.exe /s
    %systemroot%\Wbem\*.rar /s
    %systemroot%\Wbem\*.zip /s
    %systemroot%\Wbem\*.dll /s
    %systemroot%\Wbem\*.sys /s
    %systemroot%\Wbem\*.dat /s
    %systemroot%\twain_32\*.exe
    %systemroot%\twain_32\*.dat
    %systemroot%\twain_32\*.dll
    %systemroot%\twain_32\*.sys /s
    %systemroot%\twain_32\*.zip /s
    %systemroot%\twain_32\*.rar /s
    %systemroot%\system\*.sys /s
    %systemroot%\system\*.dat /s
    %systemroot%\WinSxS\*.exe /s
    %systemroot%\WinSxS\*.dat /s
    %systemroot%\WinSxS\*.sys /s
    %systemroot%\WinSxS\*.zip /s
    %systemroot%\WinSxS\*.rar /s
    %systemroot%\Sun\*.dll /s
    %systemroot%\Sun\*.rar /s
    %systemroot%\Sun\*.zip /s
    %systemroot%\Sun\*.exe /s
    %systemroot%\Sun\*.sys /s
    %systemroot%\Sun\*.dat /s
    %systemroot%\srchasst\*.rar /s
    %systemroot%\srchasst\*.zip /s
    %systemroot%\srchasst\*.exe /s
    %systemroot%\srchasst\*.dat /s
    %systemroot%\srchasst\*.sys /s
    %systemroot%\Shellnew\*.rar /s
    %systemroot%\Shellnew\*.zip /s
    %systemroot%\Shellnew\*.dat /s
    %systemroot%\Shellnew\*.exe /s
    %systemroot%\Shellnew\*.sys /s
    %systemroot%\Shellnew\*.dll /s
    %systemroot%\Security\*.rar /s
    %systemroot%\Security\*.zip /s
    %systemroot%\Security\*.dat /s
    %systemroot%\Security\*.exe /s
    %systemroot%\Security\*.sys /s
    %systemroot%\Security\*.dll /s
    %systemroot%\Resources\*.rar /s
    %systemroot%\Resources\*.zip /s
    %systemroot%\Resources\*.dat /s
    %systemroot%\Resources\*.exe /s
    %systemroot%\Resources\*.sys /s
    %systemroot%\Repair\*.sys /s
    %systemroot%\Repair\*.exe /s
    %systemroot%\Repair\*.dll /s
    %systemroot%\Repair\*.zip /s
    %systemroot%\Repair\*.rar /s
    %systemroot%\Registration\*.exe /s
    %systemroot%\Registration\*.dat /s
    %systemroot%\Registration\*.zip /s
    %systemroot%\Registration\*.rar /s
    %systemroot%\Registration\*.dll /s
    %systemroot%\Registration\*.sys /s
    %systemroot%\RegisteredPackages\*.rar /s
    %systemroot%\RegisteredPackages\*.zip /s
    %systemroot%\pss\*.rar /s
    %systemroot%\pss\*.zip /s
    %systemroot%\pss\*.exe /s
    %systemroot%\pss\*.dll /s
    %systemroot%\pss\*.dat /s
    %systemroot%\pss\*.sys /s
    %systemroot%\Provisioning\*.rar /s
    %systemroot%\Provisioning\*.zip /s
    %systemroot%\Provisioning\*.exe /s
    %systemroot%\Provisioning\*.sys /s
    %systemroot%\Provisioning\*.dat /s
    %systemroot%\Provisioning\*.dll /s
    %systemroot%\PIF\*.*
    %systemroot%\PeerNet\*.rar /s
    %systemroot%\PeerNet\*.zip /s
    %systemroot%\PeerNet\*.dat /s
    %systemroot%\PeerNet\*.sys /s
    %systemroot%\PeerNet\*.exe /s
    %systemroot%\PcTel\*.rar /s
    %systemroot%\PcTel\*.zip /s
    %systemroot%\Offline Web Pages\*.exe /s
    %systemroot%\Offline Web Pages\*.zip /s
    %systemroot%\Offline Web Pages\*.rar /s
    %systemroot%\Offline Web Pages\*.sys /s
    %systemroot%\Offline Web Pages\*.dat /s
    %systemroot%\network diagnostic\*.sys /s
    %systemroot%\network diagnostic\*.rar /s
    %systemroot%\network diagnostic\*.zip /s
    %systemroot%\network diagnostic\*.dat /s
    %systemroot%\mui\*.*
    %systemroot%\msapps\*.*
    %systemroot%\msagent\*.zip /s
    %systemroot%\msagent\*.rar /s
    %systemroot%\msagent\*.sys /s
    %systemroot%\msagent\*.dat /s
    %systemroot%\minidump\*.*
    %systemroot%\media\*.sys /s
    %systemroot%\media\*.dat /s
    %systemroot%\media\*.rar /s
    %systemroot%\media\*.zip /s
    %systemroot%\media\*.exe /s
    %systemroot%\media\*.dll /s
    %systemroot%\Help\*.sys /s
    %systemroot%\Help\*.dat /s
    %systemroot%\ie7\*.sys /s
    %systemroot%\ie7\*.zip /s
    %systemroot%\ie7\*.rar /s
    %systemroot%\ie7\*.dat /s
    %systemroot%\ie7updates\*.sys /s
    %systemroot%\ie7updates\*.zip /s
    %systemroot%\ie7updates\*.rar /s
    %systemroot%\ime\*.sys /s
    %systemroot%\ime\*.zip /s
    %systemroot%\ime\*.rar /s
    %systemroot%\inf\*.sys /s
    %systemroot%\inf\*.dat /s
    %systemroot%\installer\*.sys /s
    %systemroot%\installer\*.zip /s
    %systemroot%\installer\*.rar /s
    %systemroot%\installer\*.dat /s
    %systemroot%\internet logs\*.sys /s
    %systemroot%\Cursors\*.rar /s
    %systemroot%\Cursors\*.sys /s
    %systemroot%\Cursors\*.exe /s
    %systemroot%\Cursors\*.dat /s
    %systemroot%\Cursors\*.zip /s
    %systemroot%\Cursors\*.vbs /s
    %systemroot%\Cursors\*.dll /s
    %systemroot%\Config\*.*
    %systemroot%\Config\*.rar /s
    %systemroot%\Config\*.sys /s
    %systemroot%\Config\*.exe /s
    %systemroot%\Config\*.dat /s
    %systemroot%\internet logs\*.dat /s
    %systemroot%\Assembly\*sys /s
    %systemroot%\Assembly\*.rar /s
    %systemroot%\internet logs\*.rar /s
    %systemroot%\AppPatch\*.sys
    %systemroot%\AppPatch\*.dat
    %systemroot%\internet logs\*.zip /s
    %systemroot%\internet logs\*.exe /s
    %systemroot%\internet logs\*.dll /s
    %systemroot%\l2schemas\*.sys /s
    %systemroot%\l2schemas\*.dat /s
    %systemroot%\l2schemas\*.rar /s
    %systemroot%\l2schemas\*.zip /s
    %systemroot%\l2schemas\*.exe /s
    %systemroot%\l2schemas\*.dll /s
    %systemroot%\Fonts\*.dat /s
    %systemroot%\Fonts\*.sys /s
    %systemroot%\Debug\*.rar /s
    %systemroot%\Debug\*.sys /s
    %systemroot%\Debug\*.exe /s
    %systemroot%\Debug\*.dat /s
    %systemroot%\Debug\*.zip /s
    %systemroot%\Debug\*.dll /s
    %systemroot%\ehome\*.dll /s
    %systemroot%\ehome\*.sys /s
    %systemroot%\ehome\*.rar /s
    %systemroot%\ehome\*.dat /s
    %systemroot%\ehome\*.zip /s
    %systemroot%\Connection Wizard\*.dat /s
    %systemroot%\Connection Wizard\*.exe /s
    %systemroot%\Connection Wizard\*.sys /s
    %systemroot%\Connection Wizard\*.rar /s
    %systemroot%\Connection Wizard\*.zip /s
    %systemroot%\Connection Wizard\*.*
    %systemroot%\system32\1025\*.*
    %systemroot%\system32\1028\*.*
    %systemroot%\system32\1031\*.*
    %systemroot%\system32\1033\*.exe
    %systemroot%\system32\1033\*.sys
    %systemroot%\system32\1033\*.zip
    %systemroot%\system32\1033\*.rar
    %systemroot%\system32\1033\*.dat
    %systemroot%\system32\1037\*.*
    %systemroot%\system32\1041\*.*
    %systemroot%\system32\1042\*.*
    %systemroot%\system32\1054\*.*
    %systemroot%\system32\2052\*.*
    %systemroot%\system32\3076\*.*
    %systemroot%\system32\appmgmt\*.exe /s
    %systemroot%\system32\appmgmt\*.sys /s
    %systemroot%\system32\appmgmt\*.dll /s
    %systemroot%\system32\appmgmt\*.dat /s
    %systemroot%\system32\appmgmt\*.zip /s
    %systemroot%\system32\appmgmt\*.rar /s
    %systemroot%\system32\bits\*.rar /s
    %systemroot%\system32\bits\*.zip /s
    %systemroot%\system32\bits\*.exe /s
    %systemroot%\system32\bits\*.dat /s
    %systemroot%\system32\bits\*.sys /s
    %systemroot%\system32\catroot\*.rar /s
    %systemroot%\system32\catroot\*.zip /s
    %systemroot%\system32\catroot\*.dll /s
    %systemroot%\system32\catroot\*.sys /s
    %systemroot%\system32\catroot\*.exe /s
    %systemroot%\system32\catroot\*.dat /s
    %systemroot%\system32\catroot2\*.rar /s
    %systemroot%\system32\catroot2\*.zip /s
    %systemroot%\system32\catroot2\*.exe /s
    %systemroot%\system32\catroot2\*.dat /s
    %systemroot%\system32\catroot2\*.dll /s
    %systemroot%\system32\catroot2\*.sys /s
    %systemroot%\system32\com\*.sys /s
    %systemroot%\system32\com\*.zip /s
    %systemroot%\system32\com\*.rar /s
    %systemroot%\system32\config\*.rar /s
    %systemroot%\system32\config\*.zip /s
    %systemroot%\system32\config\*.sys /s
    %systemroot%\system32\config\*.dll /s
    %systemroot%\system32\config\*.exe /s
    %systemroot%\system32\dhcp\*.*
    %systemroot%\system32\DirectX\*.rar /s
    %systemroot%\system32\DirectX\*.zip /s
    %systemroot%\system32\DirectX\*.sys /s
    %systemroot%\system32\DirectX\*.dll /s
    %systemroot%\system32\DirectX\*.exe /s
    %systemroot%\system32\DirectX\*.dat /s
    %systemroot%\system32\Dllcache\*.zip /s
    %systemroot%\system32\Dllcache\*.rar /s
    %systemroot%\system32\drivers\*.dat
    %systemroot%\system32\drivers\*.exe /s
    %systemroot%\system32\drivers\*.zip /s
    %systemroot%\system32\drivers\*.rar /s
    %systemroot%\system32\drvstore\*.dat
    %systemroot%\system32\drvstore\*.exe /s
    %systemroot%\system32\drvstore\*.zip /s
    %systemroot%\system32\drvstore\*.rar /s
    %systemroot%\system32\en\*.dat /s
    %systemroot%\system32\en\*.exe /s
    %systemroot%\system32\en\*.zip /s
    %systemroot%\system32\en\*.rar /s
    %systemroot%\system32\en\*.sys /s
    %systemroot%\system32\en\*.sys /s
    %systemroot%\system32\en\*.dat /s
    %systemroot%\system32\en-us\*.exe /s
    %systemroot%\system32\en-us\*.zip /s
    %systemroot%\system32\en-us\*.rar /s
    %systemroot%\system32\en-us\*.dll /s
    %systemroot%\system32\export\*.*
    %systemroot%\system32\GroupPolicy\*.sys /s
    %systemroot%\system32\GroupPolicy\*.dat /s
    %systemroot%\system32\GroupPolicy\*.exe /s
    %systemroot%\system32\GroupPolicy\*.zip /s
    %systemroot%\system32\GroupPolicy\*.rar /s
    %systemroot%\system32\GroupPolicy\*.dll /s
    %systemroot%\system32\ias\*.sys /s
    %systemroot%\system32\ias\*.dat /s
    %systemroot%\system32\ias\*.exe /s
    %systemroot%\system32\ias\*.zip /s
    %systemroot%\system32\ias\*.rar /s
    %systemroot%\system32\ias\*.dll /s
    %systemroot%\system32\icsxml\*.sys /s
    %systemroot%\system32\icsxml\*.dat /s
    %systemroot%\system32\icsxml\*.exe /s
    %systemroot%\system32\icsxml\*.zip /s
    %systemroot%\system32\icsxml\*.rar /s
    %systemroot%\system32\icsxml\*.dll /s
    %systemroot%\system32\ime\*.sys /s
    %systemroot%\system32\ime\*.dat /s
    %systemroot%\system32\ime\*.zip /s
    %systemroot%\system32\ime\*.rar /s
    %systemroot%\system32\inetsrv\*.sys /s
    %systemroot%\system32\inetsrv\*.dat /s
    %systemroot%\system32\inetsrv\*.exe /s
    %systemroot%\system32\inetsrv\*.zip /s
    %systemroot%\system32\inetsrv\*.rar /s
    %systemroot%\system32\LogFiles\*.sys /s
    %systemroot%\system32\LogFiles\*.dat /s
    %systemroot%\system32\LogFiles\*.exe /s
    %systemroot%\system32\LogFiles\*.zip /s
    %systemroot%\system32\LogFiles\*.rar /s
    %systemroot%\system32\LogFiles\*.dll /s
    %systemroot%\system32\Macromed\*.sys /s
    %systemroot%\system32\Macromed\*.dat /s
    %systemroot%\system32\Macromed\*.zip /s
    %systemroot%\system32\Macromed\*.rar /s
    %systemroot%\system32\Microsoft\*.sys /s
    %systemroot%\system32\Microsoft\*.dat /s
    %systemroot%\system32\Microsoft\*.exe /s
    %systemroot%\system32\Microsoft\*.zip /s
    %systemroot%\system32\Microsoft\*.rar /s
    %systemroot%\system32\Microsoft\*.dll /s
    %systemroot%\system32\Msdtc\*.sys /s
    %systemroot%\system32\Msdtc\*.dat /s
    %systemroot%\system32\Msdtc\*.exe /s
    %systemroot%\system32\Msdtc\*.zip /s
    %systemroot%\system32\Msdtc\*.rar /s
    %systemroot%\system32\Msdtc\*.dll /s
    %systemroot%\system32\Mui\*.sys /s
    %systemroot%\system32\Mui\*.dat /s
    %systemroot%\system32\Mui\*.exe /s
    %systemroot%\system32\Mui\*.zip /s
    %systemroot%\system32\Mui\*.rar /s
    %systemroot%\system32\npp\*.sys /s
    %systemroot%\system32\npp\*.dat /s
    %systemroot%\system32\npp\*.zip /s
    %systemroot%\system32\npp\*.rar /s
    %systemroot%\system32\NtMsData\*.sys /s
    %systemroot%\system32\NtMsData\*.dat /s
    %systemroot%\system32\NtMsData\*.exe /s
    %systemroot%\system32\NtMsData\*.zip /s
    %systemroot%\system32\NtMsData\*.rar /s
    %systemroot%\system32\NtMsData\*.dll /s
    %systemroot%\system32\oobe\*.sys /s
    %systemroot%\system32\oobe\*.dat /s
    %systemroot%\system32\oobe\*.zip /s
    %systemroot%\system32\oobe\*.rar /s
    %systemroot%\system32\PreInstall\*.sys /s
    %systemroot%\system32\PreInstall\*.dat /s
    %systemroot%\system32\PreInstall\*.exe /s
    %systemroot%\system32\PreInstall\*.zip /s
    %systemroot%\system32\PreInstall\*.rar /s
    %systemroot%\system32\PreInstall\*.dll /s
    %systemroot%\system32\ras\*.sys /s
    %systemroot%\system32\ras\*.dat /s
    %systemroot%\system32\ras\*.exe /s
    %systemroot%\system32\ras\*.zip /s
    %systemroot%\system32\ras\*.rar /s
    %systemroot%\system32\ras\*.dll /s
    %systemroot%\system32\ReInstallBackups\*.dat /s
    %systemroot%\system32\ReInstallBackups\*.zip /s
    %systemroot%\system32\ReInstallBackups\*.rar /s
    %systemroot%\system32\Restore\*.sys /s
    %systemroot%\system32\Restore\*.zip /s
    %systemroot%\system32\Restore\*.rar /s
    %systemroot%\system32\Restore\*.dll /s
    %systemroot%\system32\Scripting\*.sys /s
    %systemroot%\system32\Scripting\*.dat /s
    %systemroot%\system32\Scripting\*.exe /s
    %systemroot%\system32\Scripting\*.zip /s
    %systemroot%\system32\Scripting\*.rar /s
    %systemroot%\system32\Scripting\*.dll /s
    %systemroot%\system32\Setup\*.sys /s
    %systemroot%\system32\Setup\*.dat /s
    %systemroot%\system32\Setup\*.exe /s
    %systemroot%\system32\Setup\*.zip /s
    %systemroot%\system32\Setup\*.rar /s
    %systemroot%\system32\ShellExt\*.*
    %systemroot%\system32\SoftwareDistribution\*.sys /s
    %systemroot%\system32\SoftwareDistribution\*.dat /s
    %systemroot%\system32\SoftwareDistribution\*.exe /s
    %systemroot%\system32\SoftwareDistribution\*.zip /s
    %systemroot%\system32\SoftwareDistribution\*.rar /s
    %systemroot%\system32\URTTEmp\*.sys /s
    %systemroot%\system32\URTTEmp\*.dat /s
    %systemroot%\system32\URTTEmp\*.zip /s
    %systemroot%\system32\URTTEmp\*.rar /s
    %systemroot%\system32\USMT\*.sys /s
    %systemroot%\system32\USMT\*.dat /s
    %systemroot%\system32\USMT\*.zip /s
    %systemroot%\system32\USMT\*.rar /s
    %systemroot%\system32\Wbem\*.sys /s
    %systemroot%\system32\Wbem\*.zip /s
    %systemroot%\system32\Wbem\*.rar /s
    %systemroot%\system32\Wins\*.*
    %systemroot%\system32\Xircom\*.*
    %systemroot%\system32\XPSViewer\*.sys /s
    %systemroot%\system32\XPSViewer\*.dat /s
    %systemroot%\system32\XPSViewer\*.zip /s
    %systemroot%\system32\XPSViewer\*.rar /s
    %systemroot%\system32\XPSViewer\*.dll /s
    %COMMONPROGRAMFILES%\*.sys /s
    %COMMONPROGRAMFILES%\*.zip /s
    %COMMONPROGRAMFILES%\*.rar /s
    %COMMONPROGRAMFILES%\*.*
    %ProgramFiles%\Movie Maker\*.dll
    %DriveLetter%\RECYCLER\*S-%d-%d-%d-%d%d%d-%d%d%d-%d%d%d-%d*.
    %systemroot%\java\apps\*.*
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\explorer\Shell Folders
    HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
    %systemroot%\winstart.bat
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Runonce
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\RunonceEx
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\VxD
    HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\System\Scripts|Startup /rs
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MPRServices
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Accessibility\Utility Manager
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Option
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Monitors
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AeDebug
    %systemroot%\system32\basequu32.dll
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\BootVerificationProgram
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\BackupPath
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\ChkDskPath
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\cleanuppath
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\DefragPath


  • Now click the Run Scan button on the toolbar. Make sure not to use the PC while the program is running or it will freeze.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Use the Add Reply button and post the information back here in an attachment. I will review it when it comes in.
The last line is < End of Report >, so make sure that is the last line in the attached report.

If the report is too big to upload, then zip the text file and upload it that way

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post


In your next reply I need

  • Update re Internet Access
  • OTSCANIT log
Catbyte, Did I mention I am not good with computers? I must have done so on the other thread. I appreciate your help a lot. However, this is going to take some serious time, so I will have to wait until Fri, Sa, or Sunday, which are my days off. I may even try and get a friend, who knows a lot more about computers than I do, to come over and help me out with your suggestions. Also, I have broadband through Verizon Wireless. I use a little card that plugs into my laptop, or desktop. It is a Pantech UM175. No router. Thanks again and I will get back with you as soon as I can.
Ok, Thanks for letting me know. It might be beneficial to print out the instructions and follow them step by step, take your time. Read them over thoroughly first - if something isn't clear, then ask for me to explain it further. Skip the very first instruction as you don't use a router - start with the DNS flush instructions. If you have any trouble following the instructions at all - STOP - and ask any questions you may have here. I will try and walk you through the steps - the only stupid question is the one that isn't asked - we are here to help. regards CB
It has been an all day event, but I have got to the finish line all by myself. I have managed to install FIREFOX onto the infected desktop and now am able to view the internet and this site. However, I am unable to cross the finish line. I have printed and followed your instructions and have hit a dead end at the final step. I am at the attachment panel and clicked BROWSE to find the file I need to upload. What is the file name I should be looking for?? I tried clicking on one called "ntuser.dat.LOG", but after clicking on UPLOAD I get a message that says "You did not select a file to upload". What am I doing wrong??? Oh, so close. :wacko: Oh, wait a second. I think I just found it. Hope this works! 📎OTScanIt.Txt Bill
CB, I thought I should let you know I am now unable to access the internet using Firefox. I tried going to yahoo to check my mail this morning and could not get on Firefox. It could not locate the server. Same thing happens when i try going to yahoo or google. My internet connection is good, just like before. Is this because the trojan is still on my computer? I uninstalled and reinstalled my McAfee Total Protection yesterday and did a full scan. It found four trojans and quarantined them. There were three DNSChanger.r trojans and one Generic FakeAlert.a trojan. :pullhair: Bill
Hi bwest,

Make sure, it is not your firewall, that is preventing you from accessing the internet. If you are still having trouble connecting, you will need to download the ComboFix program from another computer onto a USB stick or other media and transfer it over to your infected PC.

Hopefully running the first part of the fix will resolve those issues.

Please do the following



Start OTScanIt2.
Copy/Paste the information inside of the codebox below into the panel where it says "Paste fix here" and then click the Run Fix button.

[Kill Explorer]
[Unregister Dlls]
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> 
YN -> HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" -> Reg Error: Invalid data type.
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> 
YN -> HKEY_CURRENT_USER\: Main\\"Page_Transitions" -> Reg Error: Invalid data type.
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\
YN -> {8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://sdlc-esd.sun.com/ESD5/JSCDL/jdk/6u10/jinstall-6u10-windows-i586-jc.cab?AuthParam=1225050062_662221f25c0cb917f68e512d504ac4ec&GroupName=JSC&BHost=javadl.sun.com&FilePath=/ESD5/JSCDL/jdk/6u10/jinstall-6u10-windows-i586-jc.cab&File=jinstall-6u10-windows-i586-jc.cab [Java Plug-in 1.6.0_10]
YN -> {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab [Java Plug-in 1.6.0_10]
YN -> {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab [Java Plug-in 1.6.0_10]
[Files/Folders - Created Within 90 Days]
NY -> 12 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
[Files/Folders - Modified Within 90 Days]
NY -> 1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp
NY -> 12 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
NY -> 33 C:\Documents and Settings\Bill\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Bill\Local Settings\Temp\*.tmp
NY -> 33 C:\Documents and Settings\Bill\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Bill\Local Settings\Temp\*.tmp
[File - Lop Check]
NY -> LimeWire -> C:\Documents and Settings\Bill\Application Data\LimeWire
[Custom Scans]
NY -> 1 C:\WINDOWS\SYSTEM32\*.tmp files -> C:\WINDOWS\SYSTEM32\*.tmp
NY -> 12 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
[Empty Temp Folders]
[Start Explorer]
[Reboot]

The fix should only take a very short time.
When the fix is completed a message box will popup either telling you that it is finished, or that a reboot is needed to complete the fix.
If the fix is complete, click the Ok button and Notepad will open with a log of actions taken during the fix.
Post that log back here in your next reply.

If a reboot is required, click the "Yes" button to reboot the machine.
After the reboot, OTScanIt2 will finish moving any files that could not be moved during the fix and NotePad will open with the final results at that time.
Post that log back here in your next reply.

NEXT

Download ComboFix from one of these locations:
Link 1
Link 2
Link 3

VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


Please make sure you include the combo fix log along with the OTScan it log in your next reply, as well as describe how your computer is running now

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI