Connected but can't browse

Xizzaar

New Member
The system still could be infected. There are some infections out there that can cause this sort of issue. Zero access comes to mind. What virus/malware programs have you used to scan your system?

He's used whatever program comes with windows as well as ADwcleaner and he's going to try Malwarebytes in a few minutes but so far nothing bad has popped up.
 

Xizzaar

New Member
windows-7-network-connection-properties.jpg


Click on details when on this screen

I would tell him to print screen it for you but only problem is, his computer is in portuguese and he doesn't have the english language pack installed.
 

Geoff

VIP Member
I would tell him to print screen it for you but only problem is, his computer is in portuguese and he doesn't have the english language pack installed.
That's fine, the information would be an IP address so language doesn't matter.
 

johnb35

Administrator
Staff member
I would suggest he create an account here so I can help him run some specific programs and he can post the logs. If Zero Access is involved then he would have to run TDSSkiller and Combofix and other programs. Sometimes the only way to really get rid of Zero Access is to format and reinstall windows. There is about a 50/50 chance to actually get it removed totally.
 

Xizzaar

New Member
Just humor us, have him go to Network Connections > Right click on his network card > Properties, and tell us what it says for DNS.

I'm assuming this is the info you wanted:

DNS IPv4-address: 192.168.1.254
DNS IPv6-address: blank
(roughly translated)Connection Specific DNS Suffix: LAN

I would suggest he create an account here so I can help him run some specific programs and he can post the logs. If Zero Access is involved then he would have to run TDSSkiller and Combofix and other programs. Sometimes the only way to really get rid of Zero Access is to format and reinstall windows. There is about a 50/50 chance to actually get it removed totally.

I told him to make an account and he said he'll try tomorrow(he can only do it from his phone).
 

Geoff

VIP Member
I'm assuming this is the info you wanted:

DNS IPv4-address: 192.168.1.254
DNS IPv6-address: blank
(roughly translated)Connection Specific DNS Suffix: LAN



I told him to make an account and he said he'll try tomorrow(he can only do it from his phone).
Earlier you told us he set the DNS to 8.8.8.8, clearly he didn't. Have him try that and let us know. Is 192.168.1.254 his router? If not, what device is that?

As i mentioned, he's already tried this.
 

Xizzaar

New Member
Earlier you told us he set the DNS to 8.8.8.8, clearly he didn't. Have him try that and let us know. Is 192.168.1.254 his router? If not, what device is that?

I'm pretty sure that's his router's IP but after he changed it to 8.8.8.8 like i mentioned earlier and it didn't work he changed back to the default setting.
 

johnb35

Administrator
Staff member
Have him download and run these 2 programs and get me the logs somehow.

1.

Please download and run TDSSkiller

When the program opens, Click on change parameters. Put a check next to detect tdlfs file system, click ok.


click on the start scan button.

tdssstartscan_zps32a151cd.jpg


TDSSKiller will now scan your computer for the TDSS infection. When the scan has finished it will display a result screen stating whether or not the infection was found on your computer. If it was found it will display a screen similar to the one below.

2663-2-eng.png


To remove the infections simply click on the Continue button and TDSSKiller will attempt to clean them or remove them.

After trying to clean them it will pop up with the results of the scan and its actions.

2663_3_en.png


Please reboot the system if asked to do so.

After running there will be a log that will be located at the root of your c:\ drive labeled tdsskiller with a series of numbers after it example, C:\TDSSKiller.2.4.7_23.07.2010_15.31.43_log.txt

Please open the log and copy and paste it back here.

2.

Download and Run ComboFix
If you already have Combofix, please delete this copy and download it again as it's being updated regularly.
  • Download this file here :

    Combofix

  • When the page loads click on the blue combofix download link next to the BleepingComputer Mirror.
  • Save the file to your windows desktop. The combofix icon will look like this when it has downloaded to your desktop.

    cf-icon.jpg
  • We are almost ready to start ComboFix, but before we do so, we need to take some preventative measures so that there are no conflicts with other programs when running ComboFix. At this point you should do the following:

  • Close all open Windows including this one.
  • Close or disable all running Antivirus, Antispyware, and Firewall programs as they may interfere with the proper running of ComboFix. Instructions on disabling these type of programs can be found here.
    Once these two steps have been completed, double-click on the ComboFix icon found on your desktop. Please note, that once you start ComboFix you should not click anywhere on the ComboFix window as it can cause the program to stall. In fact, when ComboFix is running, do not touch your computer at all. The scan could take a while, so please be patient.
  • Please click on I agree on the disclaimer window.
  • ComboFix will now install itself on to your computer. When it is done, a blue screen will appear as shown below.

    cf-preparing.jpg

  • ComboFix is now preparing to run. When it has finished ComboFix will automatically attempt to create a System Restore point so that if any problems occur while using the program you can restore back to your previous configuration. When ComboFix has finished creating the restore point, it will then backup your Windows Registry as shown in the image below.

    erunt.jpg

  • Once the Windows Registry has finished being backed up, ComboFix will attempt to detect if you have the Windows Recovery Console installed. If you already have it installed, you can skip to this section and continue reading. Otherwise you will see the following message as shown below:

    recovery-console-prompt.jpg

  • At the above message box, please click on the Yes button in order for ComboFix to continue. Please follow the steps and instructions given by ComboFix in order to finish the installation of the Recovery Console.
  • Please click on yes in the next window to continue scanning for malware.
  • ComboFix will now disconnect your computer from the Internet, so do not be surprised or concerned if you receive any warnings stating that you are no longer on the Internet. When ComboFix has finished it will automatically restore your Internet connection.
  • ComboFix will now start scanning your computer for known infections. This procedure can take some time, so please be patient.
  • While the program is scanning your computer, it will change your clock format, so do not be concerned when you see this happen. When ComboFix is finished it will restore your clock settings to their previous settings. You will also see the text in the ComboFix window being updated as it goes through the various stages of its scan. An example of this can be seen below.

    still-scanning-clockchanges.jpg

  • When ComboFix has finished running, you will see a screen stating that it is preparing the log report.
  • This can take a while, so please be patient. If you see your Windows desktop disappear, do not worry. This is normal and ComboFix will restore your desktop before it is finished. Eventually you will see a new screen that states the program is almost finished and telling you the programs log file, or report, will be located at C:\ComboFix.txt.
  • When ComboFix has finished, it will automatically close the program and change your clock back to its original format. It will then display the log file automatically for you.
  • Now you just click on the edit menu and click on select all, then click on the edit menu again and click on copy. Then come to the forum in your reply and right click on your mouse and click on paste.

If for some reason, if you try to run a program or open a file and you get an error message saying "illegal operation attempted on a registry key that has been marked for deletion", please just reboot your pc and you'll be fine.


In your next reply please post:

The TDSSkiller log
The ComboFix log
 

Xizzaar

New Member
I actually sent those programs to him earlier today, along with some other programs and a step-by-step tutorial on how to work them all so he'll probably do all that tomorrow.

I'll tell you what happens.
 

johnb35

Administrator
Staff member
There is a bad driver running. Please do the following.

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box

Code:
Driver::

X6va012


3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!


CFScript-1.gif


ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Also run an OTL scan and post the log.

Download OTL to your Desktop


•Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
•Click on Minimal Output at the top
•Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
◦When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL. Just post the OTL.txt file in your reply.
 

johnb35

Administrator
Staff member
Try using Internet Explorer and see if it works. If it does then its a chrome issue. Uninstall chrome and reinstall it should fix it.
 

Xizzaar

New Member
Try using Internet Explorer and see if it works. If it does then its a chrome issue. Uninstall chrome and reinstall it should fix it.

Well, he's already tried starting IE, but again, it affects things like steam or even minecraft as well.
Basically he can't connect to any server what so ever, it's a miracle he can even connect to skype.
 

johnb35

Administrator
Staff member
Looks like a reinstall of windows is in order. You could do a test install on a blank hard drive if there is one laying around just to test. It's either a pc issue or a router issue. I've seen issues like this but it was a router issue with that particular pc. Ended up replacing the router to fix.
 

C4C

Well-Known Member
It could be your modem. I know that's my issue right now and I have to reset it weekly..
 

Agent Smith

Well-Known Member
Before you do the complete nuke option I would use that Tweak program I mentioned and rebuild the TCP/IP stack. If that still doesn't work and I would then try a Windows repair install. What OS is he using?
 
Top