This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Partial internet access

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This is continued from this WTT thread

I do not have an anti-virus installed on this PC, but putting the affected drive in my XP machine, AVG 8.0 did not find anything. I am behind a hardware router, and the XP firewall is on. AFAIK, the Norton Removal Tool removed Norton Internet Security 2007 properly. XP believes the ethernet connection is working properly, and indeed most of the Net is fine. Results from typing 'winipcfg' seem normal.

A few sites do not come up (in either IE or Firefox), including avg.com and microsoft.com. Malware did not alter the hosts file to do this. When I ping microsoft.com or avg.com, I get "ping request could not find host www.microsoft.com. Please check the name and try again." Right now, this machine uses OpenDNS.org's octets for DNS service.

Here is the HijackThis log file (hand typed in Linux, forgive spelling problems):

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:10:26 PM, on 4/18/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\ssystem32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Analog Devices\DrvLsnr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_0B\realsched.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.slashdot.org/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =.
02 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
04 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
04 - HKLM\..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
04 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
04 - HKLM\..\Run: {TkBellExe] "C:\Program Files\Common Files\Real\Update_0B\realsched.exe" -osboot
04 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\System32\hkcmd.exe
04 - HKLM\..\Run: [igfxpers] C:\WINDOWS\System32\igfxpers.exe
04 - HKLM\..\Run: [igfxtray] C:\WINDOWS\System32\igfxtray.exe
04 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
04 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
04 - Global StartupL Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
08 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
09 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
09 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-3C9C571A8263} - C:\Program
09 - Extra 'Tools' menuitem: Windows Messenger - {Fb5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmgs.exe
016: - DPFL {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdcommon/download/tgctlcm.cab
016: - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1143168165357
016: - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControlClass) - http://update.microsoft.com/microsoftupdat…b?1143237567484
017: - HKLM\System\CCS\Services\Tcpip\..\{D01B88D3-2A16-48BA-BE84-C0A523E5B086}:NameServer - 208.67.222.222,208.67.220.220
023 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
023 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
023 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\supportsoft\bin\ssrc.exe
024 - Desktop component 0: (no name) - http://profile.ak.facebook.com/profile5/77…718161_8272.jpg

–
End of file - 3764 bytes

If a site can't be reached, it can't be reached in either IE or Firefox. Also it cannot be pinged. If a site can be reached, everything is fine.

I do not have the Admin password to this box (yet), so I cannot install the MS Malicious Software Removal Tool (or various other tools). Also worth noting is that Safe Mode does not work. If you choose Safe Mode, the machine will reboot.

Sysinternals "Process Monitor" will immediately be shut down if started. This may or might not be related to failing to run in Safe Mode.

I could try going to one of those "test my connection" or "what is my IP" sites, but if something was wrong inside my box, I don't know how or even if it would be reflected in the results they show me.

EDIT: I can go to Microsoft.com, avg.com, etc. through an HTTP proxy. If I set up the proxy correctly, I can even submit samples to virusscan.jotti.org (probably another site I can't access the regular way, I'm starting to forget). But because of WGA or ActiveX or whatever, I suspect a proxy wouldn't work to obtain MS Updates, so I really need to find this machine's problem and fix it.

Something's definitely wrong here. Any help is greatly appreciated.
Thank you everyone, you can close this as resolved. I removed the empty R0 line with HijackThis. Then I ran ComboFix, it found some remnants of some "weather" garbage (I prefer to just look out a window, thank you). One or more processes in memory were running under svchost.exe, but not enough to arouse my suspicion. This evil process *_probably_* prevented safe mode from running and *_probably_* prevented Process Monitor from running, and it didn't show up in Mike Lin's control Panel, all so that I wouldn't detect it. Did I mention there is still a phantom item on the desktop? Look at Mark Russinovich's blog (systenternals.microsoft.com, Feb. 9, 2009). The icon is still there (something like "secure erase" that was bundled with the malware), but I don't think it's going to be a problem. Double click and nothing happens – Windows doesn't know what program to open it with. And it's far beyond my skill to remove. Overall, computer is running fine now. Thank you everyone.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.
Thanks! It's still infected. The computer randomly asks for username and password to connect to the internet (NEVER a good sign). When I type them in, it usually asks a second time right away. The WRT-54GL (DD-WRT firmware) has a throughput graph, it is already sending and receiving about 15K/second. Typing the username and password doesn't affect that figure. I can start Outlook and send e-mail from the ISP's mail address to my Yahoo! account, but it cannot receive messages from Yahoo! or any other sender. (Can I remove Outlook Express? I'd prefer to use Office Outlook 2003.) The Computer Associates software that RoadRunner hands out (CA Anti-Spam, firewall, etc.) is not helping. Turning on logging in the router won't tell me which thread or process on the compromised machine is requesting Net access (likely an instance of svchost.exe). Any ideas? What tools would be good for this? Rootkit Revealer? Something from Sysinternals? The DD-WRT firmware has great capabilities, but I don't have much knowledge of networking and how to use the available tools on it. I cleared out the blank R0 line again, not sure which registry location it was in. That would have been a good clue if I hadn't deleted it. I'll run HijackThis again, don't know if I'll see anything. Any help greatly appreciated.
Okay, I got the PC fixed now. We can re-close. When I used the webmail interface (hxxps://webmail.cinci.rr.com) it was clear that I had mail. A quick call to tech support showed me how to make an exception in CA-Personal Firewall to let Office Outlook 2003 collect it off of RoadRunner's server (RR gives out free CA security suite to its customers). I used Outlook Express sporadically in the last 3 years. The last message in OE was spam (herbal v!4gra or some nonsense). Tech support said there might have been a conflict between OE and Office Outlook 03, causing the last message she got in OE to repeatedly arrive (dozens of copies!) in Office Outlook 03. EDIT: And that 15K/second upload and download going through the router? That was coming from a different (read: unaffected) PC. Not caused by spyware. (END of edit) Now I cannot send e-mail from this box. Probably a simple settings problem or something (changed the password used to connect to RR's mail server). I'll look at it shortly. Thanks again.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI