This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] can not get on internet

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

When I go on the internet on our laptop it starts to connect then it comes up with this http://www.fes.sk/sup/test_.php and it starts flashing and will not let us on the computer. Can anyone help me get rid of this?
This is on Windows XP :pullhair:
Hi battle maiden, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Let's see if this will get you online.

If you use Internet Explorer
  • Click your start button, highlight All Programs
  • Highlight Accessories
  • Highlight System Tools
  • Click Internet Explorer (No Add-ons)

If you use FireFox
  • Click your start button, highlight All Programs
  • Highlight Mozilla FireFox
  • Click Mozilla FireFox (Safe Mode)

This will start which ever browser you are using without any add ons. If you can now browse please return to this thread and we will look for the cause.

If you still can not browse we will transfer some tools to the infected computer and go from there. Do you have a CD or flash drive we can use?

Thanks
Hi battle maiden,

On the clean computer

note: insert the flashdrive before running the program. Hold the shift key down while inserting it. Windows will recognise the drive but will not allow it to autorun.

Download Flash_Disinfector.exe by sUBs and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder…it will help protect your drives from future infection.

Download OTL to your flashdrive.

On the infected computer

Transfer OTL directly to the infected computer's desktop
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Save both of these logs to the flashdrive and post them in your next reply.

Thanks
Hi battle maiden,

I can see some of the problem, but before we go after it we need to make sure there aren't any hidden surprises.

On the clean computer

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the bold text listed below into the Notepad.

netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
nvrd32.sys
symmpi.sys
adp3132.sys
mv61xx.sys
/md5stop
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav



Save it to your flash drive.



Next

Go HERE to get a random named copy of GMER. Scroll down to the Download section and click Download EXE. Save it to your flashdrive.

Before scanning with GMER, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

On the infected machine
  • Transfer the copy of GMER to the desktop.
  • Double click on the file. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries




Next,
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Uncheck the boxes beside LOP Check and Purity Check.
  • Open the notepad that you saved to your flashdrive.
  • Copy and paste the text in the notepad into the window under Custon Scans/Fixes
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
There will only be an OTL.txt this time.



Please transfer the Gmer log and the OTL log to your flashdrive and post them in your next reply.

Thanks
Hi battle maiden,

You have a newer infection. We will need access to the Recovery Console to clean this.

Do you have an XP disk? Or do you know if you have the Recovery Console installed?

You will be able to tell if the Recovery Console is installed as when you first start your computer you will be presented with a screen that gives you the option to either boot to windows or the Windows Recovery Console. The screen would look like this.

[external image: Posted Image]

Let me know if you either have the XP disk or the Recovery Console installed.

Thanks
We have the operating system cd for Windows XP and my husband also installed Office XP for Students and Teachers. Let me know what next thanks.
Hi battle maiden,

We have the operating system cd for Windows XP

If it's a retail version of XP it should work.

Before we can go after the infection we need to confirm that you can boot to the Recovery Console.

You computer must be able to boot from the CD. You may need o change the settings in bios in order to do this. When you first start your computer you will be told which key to use to enter the bios or setup. Once in the bios look for an entry called boot order or similar. Follow the instruction there to change the boot ordr to CD first. Save the setting then exit.

Insert the Windows XP CD-ROM into the CD-ROM drive, and then restart the computer.

1. Click to select any options that are required to start the computer from the CD-ROM drive if you are prompted.
2. When the "Welcome to Setup" screen appears, press R to start the Recovery Console.
3. You should now see a list of installations and the prompt "Which Windows Installation would you like to log on to?"
Select the appropriate number for the Windows installation that you want to repair. If you only have one, press 1.
4. When you are prompted, type the Administrator password. If the administrator password is blank, just press ENTER.

You should now have a C:\windows> prompt


If you get that far type exit and hit enter.



Please let me know how you made out.

Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI