Solved

Vista browsers fail to open after malware clean

Posted on 2012-04-07
18
658 Views
Last Modified: 2012-04-13
Emachine with Vista sp2
Removed malware with Malewarebytes, Log attached

After removal, all browsers, IE, FF, Chrome, no internet, page can't be displayed. etc.
Network icon next to time,  "Access Local and Internet"
Ping "127.0.0.1" OK 4 sent and received
Ping www.yahoo.com "Could not find host...."

Uninstalled and rebooted Network Adapter from Device Manager
Installed new PCI Network Adapter

Ran ipconfig /release and renew:
copy attached

I then went to the delete registry procedure from an MSMVP site. Deleted the "winsock" and the "winsock2"
keys.

Reinstalling TCP/IP from cmd:
netsh int ip reset log.txt
Reseting echo request: failed
access is denied
Reseting interface OK!

netsh winsock reset
The system cannot find the file ..

After this procedure, the Network Connect icon shows "Local only"

I can restore the "local and Internet" in the Network icon by restoring the saved Registry but still does nothing to solve the problem. Only confuse me more.
Attached ipconfig /all after TCP/IP reinstall attempt.

Pete
Malwarebytes-Anti-Malware-log.txt
ipconfig-all.txt
ipconfig-all-After-reg-changes.jpg
0
Comment
Question by:cfourkays
  • 9
  • 4
  • 4
  • +1
18 Comments
 
LVL 8

Expert Comment

by:Tymetwister
ID: 37820094
Can you check (let's start with IE) if proxy settings are enabled under the connection/LAN tab? Check your network settings and make sure some different IP has not been set statically due to the malware.
0
 
LVL 2

Author Comment

by:cfourkays
ID: 37820158
Thanks for the quick reply.
No proxies.
I've had that pronlem before. Checked but forgot to post.
0
 
LVL 2

Author Comment

by:cfourkays
ID: 37820286
Unchecked the ip6 to see if anything happened.

ipconfig /all now has the dreaded, (to me), 169.254.xx.xx ip4 autoconfiguration.
The Subnet is 255.255.0.0

No  ip6
0
 
LVL 91

Expert Comment

by:nobus
ID: 37820709
maybe a startup repair can help  :   http://www.bleepingcomputer.com/tutorials/tutorial148.html
0
 
LVL 10

Expert Comment

by:Jim-R
ID: 37821227
Restore the Local and Internet icon and try the following.

173.194.79.94 is one of the IP address' for Google dot CA.  Try entering Google dot CA's IP directly into the address bar of a browser instead of the URL or ping the IP number directly.  If this gets you Google's page or an appropriate response to the ping, you have a DNS problem.  

If not, I would suggest doing a "repair install".  A repair install does NOT change personal data files or installed programs, it only repairs the operating system.  You will need a VISTA SP2 install disc and any updates to SP2 will have to be re-done.  A repair install is done from within Windows, not from booting the install disc.  

I recommend using MSCONFIG to implement a clean boot during the repair install and then re enabling normal start up after the repair is finished, but that is getting ahead of things a little.  See what happens when using an IP address first and we can go from there.
0
 
LVL 2

Author Comment

by:cfourkays
ID: 37821305
Hi Jim
Entering the ip address in browser does nothing. Trying to ping 173.194.79.94 goes to 4 packets of  "Transmit failed error code 1231.
Entering in in a browser fails.

Couple things I should mention; I have multiple ways to connect and they all fail:
Comcast broadband direct or through a Netgear router
ATT DSL through a Netgear combo router/modem
Florida High Speed Internet off the tower to a Routerboard 750 router

However, when I connect thru a booted UBCD4WIN  I can connect running off the CD. Same with the CD runs of Ubuntu and Knoppix which tells me my physical components are OK.
0
 
LVL 10

Expert Comment

by:Jim-R
ID: 37821806
Now that you know that your physical components are OK, the most expedient way to fix this would be a repair install.

Before performing the repair install, you should set your machine up for a clean boot.

Running your machine from a "clean boot".

Step 1

Click Start, type MSCONFIG in the Start Search box, and then press ENTER.

User Account Control permission

If you are prompted for an administrator password or for a confirmation, type the password, or provide confirmation.

Step 2: Configure Selective Startup options

   1. In the System Configuration Utility dialog box, click Selective Startup on the General tab.
   2. Click to clear the Load Startup Items check box.
      Note The Use Original Boot.ini check box is unavailable.
   3. Click the Services tab.
   4. Click to select the Hide All Microsoft Services check box.
   5. Click Disable All, and then click OK. (Disables all NON Microsoft Services)
   6. When you are prompted, click Restart.

When Windows is up and running again, the clean boot should have kept anything from running that would interfere with the Windows Setup process.  Note that the Setup must be performed from within the Windows OS environment.  Booting from a VISTA Setup disc will not have the desired result.

Insert the VISTA SP2 disc and run the install using the "upgrade" option.  Note that you must use a service pack 2 disc.  SP1 will not do as you will need the same SP as is presently installed since there are differences between VISTA, VISTA SP1 and VISTA SP2 system files.  This process will leave all data files, installed programs and their settings untouched while repairing any operating system issues.  Any updates that have been installed since SP2 will require re-installation via Windows Update.

I have done this with VISTA Ultimate SP2 and even the positioning of all the desktop icons was not changed in spite of the in place upgrade process.
0
 
LVL 2

Author Comment

by:cfourkays
ID: 37821888
Thanks, Jim
Great set of instructions.
I've done a few of these myself, even on my own Windows 7 Pro.
Don't have an upgrade Vista, or any for that matter.
I'll find one from one of my customers and get back.
0
 
LVL 91

Expert Comment

by:nobus
ID: 37822534
here they are  9.75$  http://neosmart.net/blog/2008/windows-vista-recovery-disc-download/
disclaimer : i never tried them myself
0
Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

 
LVL 2

Author Comment

by:cfourkays
ID: 37823749
Thanks nobus,
Checked before I bought.
They are basic recovery discs for System Restore, Repair Boot Menu, etc., not an actual Vista DVD.
Pretty good mix of options, same as my Paragon Rescue and a couple of others.
Won't repair or replace what looks like a corrupt "winsock2" "catalog entries".
They don't look anything like my W-7 entries.
Here's what the Reg entry looks like:
Winsock2.JPG
0
 
LVL 91

Expert Comment

by:nobus
ID: 37824094
sinc e you posted :
Ping "127.0.0.1" OK 4 sent and received
Ping www.yahoo.com "Could not find host
it looks like the name resolver is not working
did you try ipconfig /flushdns  cmd yet?
more tips : http://www.ehow.com/how_6640077_fix-internet-explorer-disk.html
0
 
LVL 2

Author Comment

by:cfourkays
ID: 37824115
Did the flush, already. trying to remember all what I did.
Also have FF and Chrome, same problem.
Pete
0
 
LVL 91

Assisted Solution

by:nobus
nobus earned 250 total points
ID: 37824162
yep - i noticed that
seems a reinstall/update case
0
 
LVL 2

Author Comment

by:cfourkays
ID: 37825454
Thanks, guys.
You see any problem with using the system recovery?

The owner never made recovery DVD's but it's a eMachine with a recovery partition.
I have everything backed up.

Pete
0
 
LVL 10

Expert Comment

by:Jim-R
ID: 37825998
This, perhaps, is the second best option to the one I earlier suggested.

With everything backed up (user data c/w email etc.), the recovery partition will reinstate to an "as purchased" condition.  Any apps installed after purchase will have to be re-installed as well as any updates along with the user's data.

The re-install with a VISTA SP2 disc I suggested previously would save all the apps including ones installed after purchase as well as making the replacement of the user data unnecessary.  You should NOT input in the "Vista license key" or leave "activate online" checked off when doing the "repair install".  Doing so would result in activation issues since the key on the COA sticker is not the same as the embedded license key on the computer.  One OEM will have a singe key that activates the license on thousands of computers.  The stickers may all be different, but not the actual embedded key.
0
 
LVL 2

Author Comment

by:cfourkays
ID: 37827539
Hi Jim,
I have no problem doing an "Install/Repair", I've done a few of them. XP, Vista, and my own W-7 Pro.
My problem is finding a Vista DVD. Even if I had an orginal, I could slipsytream it with SP2.
My customers and friends still using Vista have the Mfg disk.
0
 
LVL 10

Accepted Solution

by:
Jim-R earned 250 total points
ID: 37828723
Microsoft MSDN/Technet has the ISO for download and publishes the SHA1 code to confirm unaltered authenticity.

For example

Windows Vista with Service Pack 2 (x86) - DVD (English)
Includes: Home Basic; Home Premium; Business-Retail; Ultimate;
3,093.16 (MB)
File Name: en_windows_vista_with_sp2_x86_dvd_342266.iso
Date Posted (UTC): 5/11/2009 8:49:19 AM ISO/CRC: E2AD10F9
SHA1: 25AD9A776503E6A583BEC07879DBCC5DFD20CD6E

Normally to get this download, you must be an active MSDN member.  However, since you have a legitimate license for VISTA, using such an ISO should not be a problem.  Try the following link for some alternate suggested sources of this ISO.

Possible sources for VISTA MSDN / Technet ISO
0
 
LVL 2

Author Comment

by:cfourkays
ID: 37844980
Got the download and it worked. Had to slipstream SP2.

Interesting there are still links to "megaupload".

All OK. This customer's my car AC guy so I have to take care of him.
Pete
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

The main issue when installing Vista and XP in dual boot is when you have to reinstall any of the two when something fails, let's say a hard disk failure, a lost partition, virus, etc. What commonly happens is that you lose all your hard work config…
So who is this article for? If you are like most of the computer users out there, you probably only realize the meaning of 'System maintenance' after something goes wrong. This article is for you if you care about keeping your system working opti…
The Task Scheduler is a powerful tool that is built into Windows. It allows you to schedule tasks (actions) on a recurring basis, such as hourly, daily, weekly, monthly, at log on, at startup, on idle, etc. This video Micro Tutorial is a brief intro…
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now