1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive internet access disabled by virus (i think)

Discussion in 'Malware and Virus Removal Archive' started by deangmoxon, 2011/05/06.

  1. 2011/05/12
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Please, always read my instructions very carefully.
    I asked to checkmark only 4 boxes in MiniTool. You checkmarked more.

    Is this laptop, or desktop?
    Are you using wireless connection?
    If so, did you try wired connection?

    Now....

    Download and save HelpAsst_mebroot_fix.exe to your desktop.
    • Close all open programs.
    • Double click HelpAsst_mebroot_fix.exe to run it.
    • Pay attention to the running tool.
    • If the tool detects mbr infection, please allow it to run mbr -f and shutdown your computer. To do so, type Y and press Enter.
    • After restart, wait 5 minutes, then go Start>Run, copy and paste the following command in the run box then hit Enter:

      • helpasst -mbrt
    • When it completes, a log will open.
    • Please post the contents of that log.

    IMPORTANT!
    If the tool does NOT detect any mbr infection and completes, proceed with the following...

    • Click Start>Run and copy and paste the following command, then hit Enter:

      • mbr -f
    • Repeat the above step one more time
    • Now shut down the computer (do not restart, but shut it down), wait 5 minutes then start it back up.
    • Wait another 5 minutes, then click Start>Run and copy and paste the following command, then hit Enter.

      • helpasst -mbrt
    • When it completes, a log will open.
    • Please post the contents of that log.

    **Important note to Dell users - fixing the mbr may prevent access the the Dell Restore Utility, which allows you to press a key on startup and revert your computer to a factory delivered state. There are a couple of known fixes for said condition, though the methods are somewhat advanced. If you are unwilling to take such a risk, you should not allow the tool to execute mbr -f nor execute the command manually, and you will either need to restore your computer to a factory state or allow your computer to remain having an infected mbr (the latter not recommended).
     
  2. 2011/05/12
    deangmoxon

    deangmoxon Inactive Thread Starter

    Joined:
    2010/11/13
    Messages:
    88
    Likes Received:
    0
    oh sorry to have checked of more boxes
    it is a lap top
    with wireless
    no i have not tried a wired connection
    i will get back with the helpasst mebroot info soon
     

  3. to hide this advert.

  4. 2011/05/12
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Ok :)..
     
  5. 2011/05/12
    deangmoxon

    deangmoxon Inactive Thread Starter

    Joined:
    2010/11/13
    Messages:
    88
    Likes Received:
    0
    oC:\Documents and Settings\Administrator\Desktop\HelpAsst_mebroot_fix(2).exe
    Thu 05/12/2011 at 10:06:03.55

    HelpAssistant account Inactive

    ~~ Checking for termsrv32.dll ~~

    termsrv32.dll not found

    ~~ Checking firewall ports ~~


    HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\globallyopenports\list

    ~~ Checking profile list ~~

    No HelpAssistant profile in registry

    ~~ Checking mbr ~~

    user & kernel MBR OK

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    Status check on Thu 05/12/2011 at 10:25:05.36

    Account active No
    Local Group Memberships

    ~~ Checking mbr ~~

    Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

    device: opened successfully
    user: MBR read successfully
    called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys intelide.sys
    kernel: MBR read successfully
    user & kernel MBR OK

    ~~ Checking for termsrv32.dll ~~

    termsrv32.dll not found


    HKEY_LOCAL_MACHINE\system\currentcontrolset\services\termservice\parameters
    ServiceDll REG_EXPAND_SZ %SystemRoot%\System32\termsrv.dll

    ~~ Checking profile list ~~

    No HelpAssistant profile in registry

    ~~ Checking for HelpAssistant directories ~~

    none found

    ~~ Checking firewall ports ~~

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\domainprofile\GloballyOpenPorts\List]

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]


    ~~ EOF ~~
     
  6. 2011/05/12
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    That looks good.

    Do you have any errors in Device Manager, especially regarding network adapters?

    Now, I want you to shut down your computer, find ethernet cable and hardwire your computer to the router.
    Do you have any other computers on the same router?
    If so, do they connect fine?
     
  7. 2011/05/12
    deangmoxon

    deangmoxon Inactive Thread Starter

    Joined:
    2010/11/13
    Messages:
    88
    Likes Received:
    0
    i connected to an ethernet cable at a friends place to no avail
    at home i am wireless on an unlocked signal in my neighborhood
    i am pretty sure it's a virus that came thru facebook which u can google
    a ''wlanccgg.exe has encountered a problem" window keeps popping up too
    i don't think its the wireless or the net connection
    but YOUR the professional
    what next ?
     
  8. 2011/05/12
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Are you saying, that you can connect wirelessly now?
    Why are you using your neighbor connection?

    I also don't understand:
    Why not at your place?
    You didn't say:
    I need you to answer ALL of my questions.
     
  9. 2011/05/13
    deangmoxon

    deangmoxon Inactive Thread Starter

    Joined:
    2010/11/13
    Messages:
    88
    Likes Received:
    0
    i can not connect wireless now
    i do not have internet at my home
    i found a open signal from some where near by which i picked up with the wireless card
    i took my comp to a friends place because she had one and i do not
    i have no router either
     
  10. 2011/05/13
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    OK, we ran several scans and I don't see anything malicious on your computer.

    As for your internet issue...

    In this forum, we make sure, your computer is free of malware and your computer is clean :)
    Because the access to malware forum is very limited, your best option is to create new topic about your current issue, at Windows section.
    You'll get more attention.
     
  11. 2011/05/13
    deangmoxon

    deangmoxon Inactive Thread Starter

    Joined:
    2010/11/13
    Messages:
    88
    Likes Received:
    0
    thanx broni and good luck in the playoffs so to speak
    nucks vs ducks...
    oh yeah and wadda you think of reinstalling windows software to help my problem ?
     
  12. 2011/05/13
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Thanks :)
    I can't comment on reinstalling Windows, since we didn't really established, if the issue is software, or hardware related.
     
  13. 2011/05/13
    deangmoxon

    deangmoxon Inactive Thread Starter

    Joined:
    2010/11/13
    Messages:
    88
    Likes Received:
    0
    i still believe its a virus if you don't mind me saying so
     
  14. 2011/05/13
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    We checked and I don't see any sign of any infection.
    I can't find something, I don't see.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.