1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive Programs' Internet Connection

Discussion in 'Malware and Virus Removal Archive' started by TEMPTii, 2010/07/05.

Thread Status:
Not open for further replies.
  1. 2010/07/05
    TEMPTii

    TEMPTii Inactive Thread Starter

    Joined:
    2010/07/05
    Messages:
    1
    Likes Received:
    0
    [Inactive] Programs' Internet Connection

    Hi, I'm new here and I've been searching everywhere for anyone who has had the same problem as me.

    I have what I suspect to be some kind of malware infecting one of my system services. I recently purchased a new Windows 7 Home Premium, 64-bit computer. When I started using my computer I installed all of my favorite software such as Yahoo Messenger, Halo Custom Edition, MSN, Operation 7, Firefox, etc. However the problem is that none of these programs could connect to the internet. Internet Explorer can connect and browse just fine as well as Xfire, Operation 7, and Halo PC, but the majority of my programs including installers for programs that require internet access are denied access.

    When I ran my computer in safemodeand all the programs I had could connect to the internet. I tried disabling all the unnecessary processes and services in normal mode to mimic safemode, but that didn't work.

    I've tried the following things:
    • Adding exceptions to Windows Firewall
    • Completely disabling Windows Firewall
    • Removing all Antiviral software
    • Changing UAC settings
    • Disabling services
    • DNS flushing
    • Disabling Router's Firewall
    • Used Malwarebytes to remove all harmful material

    I may have left out a few things. Any help at all would be great. thanks in advance!

    Here is a link to the topic I posted on sevenforums regarding my issues. Also, here are my logs from malwarebytes when I cleaned my computer:
    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Database version: 4052

    Windows 6.1.7600
    Internet Explorer 8.0.7600.16385

    6/29/2010 8:17:09 PM
    mbam-log-2010-06-29 (20-17-09).txt

    Scan type: Full scan (C:\|)
    Objects scanned: 244967
    Time elapsed: 24 minute(s), 19 second(s)

    Memory Processes Infected: 2
    Memory Modules Infected: 2
    Registry Keys Infected: 4
    Registry Values Infected: 2
    Registry Data Items Infected: 0
    Folders Infected: 1
    Files Infected: 9

    Memory Processes Infected:
    C:\Program Files (x86)\Gamevance\gamevance32.exe (Adware.Gamevance) -> Unloaded process successfully.
    C:\Users\John\AppData\Roaming\Microsoft\svchost.exe (Backdoor.Bot) -> Unloaded process successfully.

    Memory Modules Infected:
    C:\Program Files (x86)\Gamevance\gamevancelib32.dll (Adware.Gamevance) -> Delete on reboot.
    C:\Program Files (x86)\Gamevance\gvtl.dll (Adware.Gamevance) -> Delete on reboot.

    Registry Keys Infected:
    HKEY_CLASSES_ROOT\CLSID\{beac7dc8-e106-4c6a-931e-5a42e7362883} (Adware.Gamevance) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{beac7dc8-e106-4c6a-931e-5a42e7362883} (Adware.Gamevance) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{beac7dc8-e106-4c6a-931e-5a42e7362883} (Adware.Gamevance) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\gamevance (Adware.Gamevance) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\startup (Backdoor.Bot) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\gamevance (Adware.Gamevance) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    C:\Program Files (x86)\Gamevance (Adware.Gamevance) -> Delete on reboot.

    Files Infected:
    C:\Users\John\Programs\Halo Programs\Standard Malicious Packets.exe (HackTool.Flooder) -> Not selected for removal.
    C:\Windows\x32dott.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Program Files (x86)\Gamevance\ars.cfg (Adware.Gamevance) -> Quarantined and deleted successfully.
    C:\Program Files (x86)\Gamevance\gamevance32.exe (Adware.Gamevance) -> Quarantined and deleted successfully.
    C:\Program Files (x86)\Gamevance\gamevancelib32.dll (Adware.Gamevance) -> Delete on reboot.
    C:\Program Files (x86)\Gamevance\gvtl.dll (Adware.Gamevance) -> Delete on reboot.
    C:\Program Files (x86)\Gamevance\gvun.exe (Adware.Gamevance) -> Quarantined and deleted successfully.
    C:\Program Files (x86)\Gamevance\icon.ico (Adware.Gamevance) -> Quarantined and deleted successfully.
    C:\Users\John\AppData\Roaming\Microsoft\svchost.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
     
    Last edited: 2010/07/05
  2. 2010/07/05
    Admin.

    Admin. Administrator Administrator Staff

    Joined:
    2001/12/30
    Messages:
    6,680
    Likes Received:
    104
    Hi,

    Read this post as indicated at the top of this forum & follow the instructions.
     

  3. to hide this advert.

  4. 2010/07/05
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    ...and please, don't wrap logs in code...
     
  5. 2010/07/05
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,890
    Likes Received:
    387
    Fixed :)
     
  6. 2010/07/05
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Thank you Pete :)
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.