CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

URGENT ATTENTION NEEDED
Goto page Previous  1, 2
 
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
AbuIbrahim

Security Expert
Special Response Team

Joined: Jan 18, 2006
Posts: 1924

1st Responder Mentors 1st Responders MVP Rootkit Experts Rootkit Responders Security Experts SRT

PostPosted: Fri Aug 25, 2006 10:25 am    Post subject:
Reply with quote

Daemon tools is a safe program. You can keep it if you wish. I was suggesting to uninstall the program since you asked about deleteing it from the desktop.

The reason you could not access the link I posted becuase it was a secure web page.
Please follow these steps carefully in order to resolve this problem:
1. Follow the instructions in the microsoft kb articles here:
http://support.microsoft.com/kb/303807/
http://support.microsoft.com/?scid=kb;EN-US;Q246725
http://support.microsoft.com/kb/870700

2. If you still cannot access secure web pages, then download and unzip the attached file into your desktop. Run securefix.bat.

Let us know if both methods do not work.




securefix.zip
 Description:

Download
 Filename:  securefix.zip
 Filesize:  531 Bytes
 Downloaded:  54 Time(s)

Back to top
View users profile Send private message Visit posters website
revolver88

Trooper
Trooper


Joined: Aug 23, 2006
Posts: 15
Location: USA

PostPosted: Fri Aug 25, 2006 6:17 pm    Post subject:
Reply with quote

neither worked.

the securefix said file couldnt be deleted because it was being used, the other things just didnt work. For the first microsoft one changing the HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders said to change the appdata entry point to %userprofile%\Application Data but thats what it was already at so i didnt change it. Should i?

Back to top
View users profile Send private message
AbuIbrahim

Security Expert
Special Response Team

Joined: Jan 18, 2006
Posts: 1924

1st Responder Mentors 1st Responders MVP Rootkit Experts Rootkit Responders Security Experts SRT

PostPosted: Fri Aug 25, 2006 8:09 pm    Post subject:
Reply with quote

No better leave it as it is.

There could be something blocking access to the secure websites.
click start -> run -> type: msconfig and press enter
go to the services tab -> check Hide all microsoft services -> click disable all
go to startup tab -> click disable all -> ok
restart the computer

After the computer restarts, check and see if you can access secure websites such as yahoo login page. Try to not to browse anywhere else.

To undo changes in the system configuration utility, open msconfig as shown earlier -> under general tab, select normal startup -> ok -> restart

Altenatively, you can download and install IE7 from microsoft or firefox browser from mozilla.

Back to top
View users profile Send private message Visit posters website
swatkat

Security Expert


Joined: Mar 04, 2005
Posts: 2039

MVP RootKit Detection Hosts Rootkit Experts Security Experts

PostPosted: Sat Aug 26, 2006 4:44 am    Post subject:
Reply with quote

Hi revolver88,
Download WinPFind.ZIP and completely extract it to a folder.

Reboot in Safe Mode:-
Restart (or switch ON) the PC. Then, keep tapping the F8 Key. From the menu that will be displayed, out of which choose Safe Mode and press Enter.

Then run WinPFind.exe and click "Start Scan". When the scan completes, click "Copy to Clipboard" button to copy the log it gives, and please post it here.


_________________
Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.
- Albert Einstein
Back to top
View users profile Send private message Visit posters website
revolver88

Trooper
Trooper


Joined: Aug 23, 2006
Posts: 15
Location: USA

PostPosted: Thu Sep 07, 2006 3:16 am    Post subject:
Reply with quote

the winpffind would get stuck while scanning the memory (unless the test is supposed to take over 24 hours). Doing what abuibrahim said, i could still not reach secure pages. I downloaded firefox and i have the same problem with that as i do with internet explorer.

Back to top
View users profile Send private message
AbuIbrahim

Security Expert
Special Response Team

Joined: Jan 18, 2006
Posts: 1924

1st Responder Mentors 1st Responders MVP Rootkit Experts Rootkit Responders Security Experts SRT

PostPosted: Thu Sep 07, 2006 9:31 am    Post subject:
Reply with quote

Have you tried using msconfig to disable the startups and services? This will let us know whether something is interfering with the internet.

If you use wireless, dial-up or authneticated DSL connections, you may need to run thier associated programs to re-establish the connection.


_________________
Microsoft MVP - Consumer Security 2008
An Invitation to Think - York University
Back to top
View users profile Send private message Visit posters website
revolver88

Trooper
Trooper


Joined: Aug 23, 2006
Posts: 15
Location: USA

PostPosted: Sun Sep 10, 2006 7:59 pm    Post subject:
Reply with quote

My Norton Antivirus had pretty much crashed so i just deleted it and now everything is working.

Thanks for the help, we can call this problem closed now.

P.s. What are some good free antivirus programs

Back to top
View users profile Send private message
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17542

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Sun Sep 10, 2006 9:48 pm    Post subject:
Reply with quote

AVG free by Grisoft: http://free.grisoft.com/doc/2/lng/us/tpl/v5
It's stable, fast and uses little resources.

AntiVir Personal Edition Classic: http://www.free-av.com/antivirus/allinonen.html


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17542

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Mon Sep 11, 2006 2:20 pm    Post subject:
Reply with quote

Another thing you can do is run a Norton Removal Tool to get rid of the Norton remnants. Norton is notorious for leaving stuff behind that could cause problems later: http://www.mrtech.com/news/messages/4767.html


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Rootkit Revelations All times are GMT
Goto page Previous  1, 2
Page 2 of 2

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer