Removed a virus and now now internet

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by anon1m0us, Dec 11, 2011.

  1. anon1m0us

    anon1m0us Private E-2

    I removed a virus, or attempted too, but I can not longer access the internet using Firefox or IE.

    Using IP Config, nothing appears, not even an ipaddress saying 0.0.0.0

    I ran netsh winsocket reset, and nothing.

    I uninstalled my network drivers and reinstalled, and nothing.

    I ran the logs and attached is the results. However, I cannot run Combofix since it hangs. I also cannot logoff my PC. It hangs and i need to manually shutdown.

    Help?!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    The reason you have no ability to connect is that your registry keys related to the NetBt service have been deleted. And with out this service, your DHCP service cannot start.


    Please download and save the below registry patch to your Desktop.

    fixXPnetbt.reg


    Then double click on the fixXPnetbt.reg patch you just saved to your Desktop and allow it to be added to your registry. Then reboot your PC.

    After reboot, download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )



    Now attach the below log:
    • C:\MGlogs.zip
    We have more work to do but let's get the above done first.
     
  3. anon1m0us

    anon1m0us Private E-2

    Here's my new logs. I ran the reg key and rebooted. Still no ip address.
     

    Attached Files:

  4. thisisu

    thisisu Malware Consultant

    Hi anon1m0us,

    I will help you with your remaining malware problems as chaslang has been very busy.

    [​IMG] Fixing items using ComboFix
    Make sure that ComboFix.exe that you downloaded while doing the READ & RUN ME is on your desktop -- but do not run it.
    If it is not on your desktop, the below will not work.
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Open Notepad and copy/paste the text in the below code box into Notepad:
    Code:
    [COLOR=darkred]KillAll::[/COLOR]
    [COLOR=darkred]FCopy::[/COLOR]
    C:\WINDOWS\system32\dllcache\netbt.sys | C:\WINDOWS\system32\drivers\netbt.sys
    
    Save this file as CFScript.txt to your desktop. So now you should have both CFScript.txt and ComboFix.txt on your desktop.
    Now use your mouse to drag CFScript.txt on top of ComboFix.exe and then release.
    [​IMG]
    This will launch ComboFix.
    Note: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
    Allow ComboFix to update itself if prompted.
    When ComboFix finishes, a log will be produced at C:\ComboFix.txt
    Attach this log to your next message. (How to attach)

    [​IMG] Now download another new version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )



    Now attach the below log:
    • C:\MGlogs.zip
     
    Last edited by a moderator: Dec 15, 2011
  5. anon1m0us

    anon1m0us Private E-2

    My computer keeps crashing when running Combofix with a no_pages_available.

    However, when running Combofix it tells me I am infected with Rootkit.ZeroAccess
     
  6. thisisu

    thisisu Malware Consultant

    Hi,

    Copy: C:\WINDOWS\system32\dllcache\netbt.sys
    and paste it in this folder: C:\WINDOWS\system32\drivers

    Reboot and test your internet.

    Then do the following scan:

    [​IMG] Please download OTL by OldTimer.

    • Save it to your desktop.
    • Double click on the OTL icon on your desktop. (Vista/7 right-click and select Run as Administrator)
    • Check the "Scan All Users" checkbox.
    • Check the "Standard Output".
    • Change the setting of "Drivers" and "Services" to "All"
    • Copy the text in the code box below and paste it into the [​IMG] text-field.
      Code:
      netsvcs
      /md5start
      afd.sys
      atapi.sys
      csrss.exe
      dhcpcsvc.dll
      explorer.exe
      ipsec.sys
      lsass.exe
      netbt.sys
      regedit.exe
      services.exe
      svchost.exe
      tcpip.sys
      userinit.exe
      winlogon.exe
      /md5stop
      %systemdrive%\*.*
      %systemdrive%\MGtools\*.*
      %systemroot%\*. /mp /s
      %systemroot%\system32\*.sys /90
      %systemroot%\system32\*.exe /lockedfiles
      %systemroot%\system32\drivers\*.sys /lockedfiles
      %windir%\assembly\GAC\*.ini
      %windir%\assembly\GAC_MSIL\*.ini
      %windir%\assembly\gac_32\*.ini
      %windir%\assembly\gac_64\*.ini
      %windir%\assembly\temp\*.ini
      %windir%\assembly\tmp\u /s
      %allusersprofile%\application data\*.exe
      hklm\system\currentcontrolset\services\dhcp
      hklm\system\currentcontrolset\services\afd
      hklm\system\currentcontrolset\services\netbt
      hklm\system\currentcontrolset\services\tcpip
      hklm\system\currentcontrolset\services\ipsec
      hklm\software\microsoft\windows\currentversion\run
      hklm\software\microsoft\windows\currentversion\runonce
      
    • Now click the [​IMG] button.
    • Two reports will be created:
      • OTL.txt <-- Will be opened
      • Extra.txt <-- Will be minimized
    • Attach both OTL.txt and Extras.txt to your next message. (How to attach)
     
  7. anon1m0us

    anon1m0us Private E-2

    I added the netbt.sys but with no luck.

    Here are the two files that were outputted.
     

    Attached Files:

    Last edited by a moderator: Dec 29, 2011
  8. thisisu

    thisisu Malware Consultant

    [​IMG] Please download Farbar Service Scanner and run it on the computer with the issue.
    • Make sure the following options are checked:
      • Internet Services
      • Windows Firewall
      • System Restore
    • Press "Scan".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please attach FSS.txt to your next message. (How to attach)
     
  9. anon1m0us

    anon1m0us Private E-2

    here's the log
     

    Attached Files:

    • FSS.txt
      File size:
      2.2 KB
      Views:
      9
  10. thisisu

    thisisu Malware Consultant

    ========WARNING========
    The below is specifically for anon1m0us's computer
    Do NOT run the below if you are not anon1m0us
    Doing so may damage your PC!
    ========WARNING========

    Attached is netbt.zip

    Inside is:
    • netbt.reg
    • fixme+restart.bat

    Extract both files to the infected computer's desktop.

    First double-click netbt.reg and allow it to merge into the registry. You should receive a successful message.

    Now reboot your PC.

    Once you have rebooted...

    Test your internet, If it still is not working, run the fixme+restart.bat file by double-clicking it.
    Your PC will reboot again. Once you are back in Windows, test your internet again.

    If it still does not work, attach the fixme_results.txt file the .bat file created.
     

    Attached Files:

  11. anon1m0us

    anon1m0us Private E-2

    Still no luck. There was an improvement though My wireless connection now says connected versus the disconnected, but I still can not access internet via wired or wireless.

    Also, it still hangs when logging off.
     

    Attached Files:

  12. thisisu

    thisisu Malware Consultant

    First, uninstall Avast antivirus. You can reinstall it when we are finished if you'd like.

    Then download and run Avast! Uninstall Utility for good measure.

    Reboot your PC...

    [​IMG] Please download MiniToolBox and save it to your desktop and run it.

    Checkmark following checkboxes:

    • Flush DNS
    • Report IE Proxy Settings
    • Reset IE Proxy Settings
    • Report FF Proxy Settings
    • Reset FF Proxy Settings
    • List IP configuration
    • List Winsock Entries
    • List Devices -> All
    • List last 10 Event Viewer log
    Press Go and attach the result (Result.txt) that pops up. A copy of Result.txt will be saved in the same directory the tool is run.

    [​IMG] Now download the latest MGtools.exe to the root of your c: drive.
    • Replace your existing MGtools.exe with this one.
    • Now run this new MGtools.exe by double-clicking it. (Vista/7 right-click and select Run as Administrator)
    • When it is finished, attach c:\MGlogs.zip to your next message. (How to attach)
     
    Last edited: Dec 28, 2011
  13. anon1m0us

    anon1m0us Private E-2

    Here ya go.
     
  14. anon1m0us

    anon1m0us Private E-2

    oops, forgot the attachment
     

    Attached Files:

  15. thisisu

    thisisu Malware Consultant

    [​IMG] Fix items using OTL by OldTimer

    Double-click OTL.exe to run. (Vista/7 right-click and select Run as Administrator)
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Copy the text in the code box below and paste it into the [​IMG] text-field.
    Code:
    [COLOR="DarkRed"]:otl[/COLOR]
    O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O3 - HKU\S-1-5-21-73586283-1645522239-1417001333-500\..\Toolbar\WebBrowser: (no name) - {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No CLSID value found.
    O15 - HKLM\..Trusted Domains: microsoft.com ([]* in Trusted sites)
    O15 - HKLM\..Trusted Domains: microsoft.com ([sftus.one] https in Trusted sites)
    O15 - HKLM\..Trusted Domains: remote ([]http in Trusted sites)
    O15 - HKLM\..Trusted Ranges: Range1 ([http] in Trusted sites)
    O15 - HKU\.DEFAULT\..Trusted Domains: microsoft.com ([]* in Trusted sites)
    O15 - HKU\.DEFAULT\..Trusted Domains: microsoft.com ([sftus.one] https in Trusted sites)
    O15 - HKU\.DEFAULT\..Trusted Domains: remote ([]http in Trusted sites)
    O15 - HKU\.DEFAULT\..Trusted Ranges: Range1 ([http] in Trusted sites)
    O15 - HKU\S-1-5-18\..Trusted Domains: microsoft.com ([]* in Trusted sites)
    O15 - HKU\S-1-5-18\..Trusted Domains: microsoft.com ([sftus.one] https in Trusted sites)
    O15 - HKU\S-1-5-18\..Trusted Domains: remote ([]http in Trusted sites)
    O15 - HKU\S-1-5-18\..Trusted Ranges: Range1 ([http] in Trusted sites)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://javadl-esd.sun.com/update/1.6.0/jinstall-6u20-windows-i586.cab (Java Plug-in 1.6.0_20)
    O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
    [5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [COLOR="DarkRed"]:services [/COLOR]
    aswTdi
    aswMon2
    aswFsBlk
    aswSnx
    aswSP
    aswRdr
    [COLOR="DarkRed"]:files[/COLOR]
    C:\WINDOWS\System32\drivers\aswTdi.sys
    xcopy %temp%\smtmp\1 "%allusersprofile%\start menu" /s /i /h /y /c
    xcopy %temp%\smtmp\2 "%userprofile%\application data\microsoft\internet explorer\quick launch" /s /i /h /y /c
    xcopy %temp%\smtmp\3 "%appdata%\roaming\microsoft\internet explorer\quick launch\user pinned\taskbar" /s /i /h /y /c
    xcopy %temp%\smtmp\4 "%allusersprofile%\desktop" /s /i /h /y /c
    ipconfig /all /c
    ipconfig /release /c
    ipconfig /flushdns /c
    ipconfig /renew /c
    netsh int ip reset resetlog.txt /c
    netsh winsock reset /c
    ipconfig /all /c
    sc config netbt start= auto /c
    sc config dhcp start= auto /c
    sc queryex netbt /c
    sc queryex ipsec /c
    sc queryex afd /c
    sc queryex tcpip /c
    sc queryex dhcp /c
    [COLOR="DarkRed"]:commands[/COLOR]
    [emptytemp]
    [resethosts]
    
    Now click the [​IMG] button.
    If the fix needed a reboot please do it.
    Click the OK button (upon reboot).
    When OTL is finished, Notepad will open. Close Notepad.
    A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
    Attach this log to your next message. (How to attach)

    Please go to Control Panel -> open Administrative Tools and see if you have Local Security Policy.
     
  16. anon1m0us

    anon1m0us Private E-2

    In Control Panel\Administrative Tools I have Local Security Policy.
     

    Attached Files:

  17. thisisu

    thisisu Malware Consultant

    Open Local Security Policy.
    First select IP Security Policies on Local Computer.
    Then right click the selected IP Security Policies on Local Computer and select "Export list...". Give it a name and save it.
    Please post the content of it or attach it to your reply.
     
  18. thisisu

    thisisu Malware Consultant

    Also I want you to try running ComboFix the way I describe below:

    First delete ComboFix.exe and empty it from the Recycle Bin too.

    [​IMG] Now download a new ComboFix.exe to your desktop.
    Click the [​IMG] button. > Run - copy and paste this command in the box ComboFix /nombr then click OK.
    Let it unpack and attempt to run.
    Attach c:\ComboFix.txt if it was successful.
     
  19. anon1m0us

    anon1m0us Private E-2

    here are the logs

    There are no policies enabled.

    After running the combofix, i ran it again, and it still picked up Rookit.ZeroAccess.
     

    Attached Files:

    • log.txt
      File size:
      20.5 KB
      Views:
      3
  20. thisisu

    thisisu Malware Consultant

    That's OK. We got a ComboFix log which revealed some more malware. Let's remove what was found and then we can continue on the internet issue.

    [​IMG] Fix items using OTL by OldTimer

    Double-click OTL.exe to run. (Vista/7 right-click and select Run as Administrator)
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Copy the text in the code box below and paste it into the [​IMG] text-field.
    Code:
    [COLOR="DarkRed"]:processes[/COLOR]
    killallprocesses
    [COLOR="DarkRed"]:services [/COLOR]
    tnlvhi
    [COLOR="DarkRed"]:files[/COLOR]
    c:\windows\system32\drivers\vuodkxi.sys
    sc config tnlvhi start= disabled /c
    
    Now click the [​IMG] button.
    If the fix needed a reboot please do it.
    Click the OK button (upon reboot).
    When OTL is finished, Notepad will open. Close Notepad.
    A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
    Attach this log to your next message. (How to attach)

    [​IMG] Now download the latest MGtools.exe to the root of your c: drive.
    • Replace your existing MGtools.exe with this one.
    • Now run this new MGtools.exe by double-clicking it. (Vista/7 right-click and select Run as Administrator)
    • When it is finished, attach c:\MGlogs.zip to your next message. (How to attach)

    [​IMG] Please download the latest Farbar Service Scanner and run it on the computer with the issue.
    • Make sure the following options are checked:
      • Internet Services
      • Windows Firewall
      • System Restore
    • Press "Scan".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please attach FSS.txt to your next message. (How to attach)
     
  21. anon1m0us

    anon1m0us Private E-2

    Still no luck:(
     

    Attached Files:

  22. thisisu

    thisisu Malware Consultant

    Making some progress at least. ;)
    Code:
    =====================================================================================  
    Checking DHCP, AFD, NetBT, TCP/IP, IPsec Service States 
    
       Dynamic Host Control Protocol -DHCP-     is running  
       AFD Networking Support Environment -AFD- is running  
       NetBios over Tcpip -NetBT-               is running  
       TCP/IP Protocol Driver -TCP/IP-          is running  
       IPSEC driver  -Ipsec-                    is running  
    
    ===================================================================================== 
    I am attaching another .bat file (fixme+restart2.bat) for you to run and then attach resulting log (fixme_results2.txt) for review.
    This one will reboot your PC too. Test your internet after the reboot.
     

    Attached Files:

  23. anon1m0us

    anon1m0us Private E-2

    It ran and the log file only says "Completed".

    Internet still not working.
     
  24. thisisu

    thisisu Malware Consultant

    That's it? Should say more than that. Can you attach it anyways.

    [​IMG] Please download MiniToolBox and save it to your desktop and run it.

    Checkmark following checkboxes:

    • Flush DNS
    • Report IE Proxy Settings
    • Reset IE Proxy Settings
    • Report FF Proxy Settings
    • Reset FF Proxy Settings
    • List IP configuration
    • List Winsock Entries
    • List Devices -> All
    • List last 10 Event Viewer log
    Press Go and attach the result (Result.txt) that pops up. A copy of Result.txt will be saved in the same directory the tool is run.
     
  25. anon1m0us

    anon1m0us Private E-2

    I ran the fixme twice, with nothing in the logs.
     

    Attached Files:

  26. thisisu

    thisisu Malware Consultant

    Is this a business computer? Are you able to log into Windows without using the domain: MKLLP

    [​IMG]
     
  27. thisisu

    thisisu Malware Consultant

    Code:
    Error: (12/29/2011 08:24:04 PM) (Source: NETLOGON) (User: )
    Description: No Domain Controller is available for [B]domain MKLLP[/B] due to the following: 
    %%[B][COLOR="Red"]1311[/COLOR][/B].
    Source: http://www.chicagotech.net/wineventid.htm

    The rest of your logs look OK. I think it may be something domain related due to some of the system errors you are receiving. You should review the quoted text and that link I posted.
     
  28. anon1m0us

    anon1m0us Private E-2

    I have been running all the scans on the local account, not domain.
     
  29. anon1m0us

    anon1m0us Private E-2

    Also, I do not have access to the company network, since this is my home computer and always connects via my home network.
     
  30. thisisu

    thisisu Malware Consultant

    Ok good to know.

    [​IMG] Please download Microsoft Fix it 50203 to your desktop.
    • Double-click it to run.
    • Reboot when asked to.
     
  31. thisisu

    thisisu Malware Consultant

    But when log into Windows, is the domain (MKLLP) listed as an option in the "Log on to" field?

    So you would not mind if I wanted to delete the traces of the MKLLP domain from your logs for troubleshooting purposes?
     
  32. anon1m0us

    anon1m0us Private E-2

    ran the fix. Nothing.

    Yes, you can delete whatever needs to be deleted.
     
  33. thisisu

    thisisu Malware Consultant

    [​IMG] I want you to read and follow these instructions: TDSSKiller - How to run

    [​IMG] Run C:\MGtools\analyse.exe by double-clicking it (Vista/7 right-click and select Run as Administrator)
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Choose "Do a system scan only" and select the following lines but do not click fix until you exit all explorer windows and all browser sessions including the one you are reading in right now:

    O16 - DPF: {D3AB4ED4-EFAB-48D2-840D-714CBF76B801} (EPOActiveXEntryPoint.ManagementConsoleEntryPoint) - https://globalsafeboot.mkllp.com:8443/DATALOSS2000/DLP.CAB
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = mkllp.com
    O17 - HKLM\Software\..\Telephony: DomainName = mkllp.com
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = mkllp.com
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = mkllp.com


    After clicking Fix, exit out of Trend Micro HiJackThis - v2.0.4

    [​IMG] Fixing items using ComboFix
    Make sure that ComboFix.exe that you downloaded while doing the READ & RUN ME is on your desktop -- but do not run it.
    If it is not on your desktop, the below will not work.
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Open Notepad and copy/paste the text in the below code box into Notepad:
    Code:
    [COLOR="DarkRed"]KillAll::[/COLOR]
    [COLOR="DarkRed"]ClearJavaCache::[/COLOR]
    [COLOR="DarkRed"]File::[/COLOR]
    C:\Documents and Settings\All Users\Application Data\f7n6beithc3553o8ae7ie4l1neo
    [COLOR="DarkRed"]FileLook::[/COLOR]
    c:\windows\system32\sfcfiles.dll
    c:\windows\dwrcs\DWRCWXL.dll
    C:\WINDOWS\system32\dllcache\mshtml.dll
    C:\WINDOWS\system32\mshtml.dll
    C:\WINDOWS\system32\DRIVERS\netbt.sys
    [COLOR="DarkRed"]Folder::[/COLOR]
    C:\WINDOWS\$NtUninstallKB16441$
    
    Save this file as CFScript.txt to your desktop. So now you should have both CFScript.txt and ComboFix.txt on your desktop.
    Now use your mouse to drag CFScript.txt on top of ComboFix.exe and then release.
    [​IMG]
    This will launch ComboFix.
    Note: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
    Allow ComboFix to update itself if prompted.
    When ComboFix finishes, a log will be produced at C:\ComboFix.txt
    Attach this log to your next message. (How to attach)

    [​IMG] Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now open Repair_Windows.exe
    • Go to Start Repairs tab.
    • Choose "Custom Mode" and press "Start".
    • Create a System Restore point if prompted.
    • In the Custom Mode window, select the following repair options:
      • Register System Files
      • Repair Windows Firewall
      • Repair Internet Explorer
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • If asked to reboot the computer for the changes to take affect, make sure other tasks in the program are not still running before accepting to restart.

    [​IMG] Now run C:\MGtools\GetLogs.bat by double-clicking it.
    This updates all of the logs inside MGlogs.zip.
    When it is finished, attach C:\MGlogs.zip to your next message. (How to attach)
     
  34. thisisu

    thisisu Malware Consultant

  35. anon1m0us

    anon1m0us Private E-2

    Attached Files:

  36. thisisu

    thisisu Malware Consultant

  37. anon1m0us

    anon1m0us Private E-2

  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  39. thisisu

    thisisu Malware Consultant

    Can you attach the TDSSKiller log, they didn't get included.
    And the domain entries were not removed.

    [​IMG] Now download the latest MGtools.exe to the root of your c: drive.
    • Replace your existing MGtools.exe with this one.
    • Now run this new MGtools.exe by double-clicking it. (Vista/7 right-click and select Run as Administrator)
    • When it is finished, attach c:\MGlogs.zip to your next message. (How to attach)

    What exactly happened with ComboFix?
     
  40. anon1m0us

    anon1m0us Private E-2

    Combofix hangs. I ran it twice in 48 hours, and left it running for over 12 hours. Nothing happens
     
  41. anon1m0us

    anon1m0us Private E-2

    I deleted the entries as specified.

    Here are the logs.

    I also ran rkill and it keeps on finding things.
     

    Attached Files:

  42. anon1m0us

    anon1m0us Private E-2

    You are correct, it seems the domain was there still. I deleted it again.
     

    Attached Files:

  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Open up Device Manager and navigate to Network Adapters.
    • Find your Broadcom 440x 10/100 Integrated Controller device and right click on it and select Uninstall BUT DO NOT delete the drivers/software if asked.
    • Then reboot your PC.
    • Upon reboot, it should automatically detect the Broadcom hardware like new hardware and reinstall the drivers.
    • After this reboot, run C:\MGtools\GetLogs.bat by double-clicking it.
    • When it is finished, attach C:\MGlogs.zip to your next message
    Also test if this made any change to your networking issue.
     
  44. anon1m0us

    anon1m0us Private E-2

    Internet now works!!!

    THanks sooo much!
     

    Attached Files:

  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Looks good now.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds