![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
Hi, Have a problem on WinXP machine after malware removal. Cannot obtain IP address from the wi-fi router. AFD.sys file is missing and DHCP client service cannot be started. I have copied afd.sys from i386 folder but still no luck. Attached is FSS scan from Farbar scanner. Please help. Thanks.
|
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
Welcome to Major Geeks!
Please follow the instructions in the below link: READ & RUN ME FIRST. Malware Removal Guide and attach the requested logs when you finish these instructions.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#3
|
|||
|
|||
|
Hi, Here are logs attached. In the meantime I have recovered afd.sys and can connect to the wi-fi router and and can obtain IP address but DNS is still not working. Thanks a lot!
|
|
#4
|
||||
|
||||
|
Several reboots will be necessary during the below procedure!!
Rescan with HitmanPro
Quote:
After reboot, run a new scan with RogueKiller and save a log as in original instructions and attach the new log. Then uninstall the below old versions of software: J2SE Runtime Environment 5.0 Update 10 J2SE Runtime Environment 5.0 Update 6 Java(TM) 6 Update 16 Now run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now: R3 - URLSearchHook: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file) O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) O4 - HKLM\..\RunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninst..."ver=10.0.1424 After clicking Fix, exit HJT. Please download OTM by Old Timer and save it to your Desktop.
Code:
:Processes explorer.exe :Files C:\Dokumente und Einstellungen\muminovic\Lokale Einstellungen\Anwendungsdaten\fc7762e3\X C:\Dokumente und Einstellungen\muminovic\Lokale Einstellungen\Anwendungsdaten\fc7762e3 :Reg [HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\winlogon] "Shell"="explorer.exe" [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MSMSGS] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\QuickTime Task] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ROC_roc_dec12] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\updateMgr] :Commands [purity] [EmptyTemp] [start explorer] [Reboot]
saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message. After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment Be patient while doing the below. The fixes can take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on. Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). Then attach the below logs:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#5
|
|||
|
|||
|
Hi,
Cannot download OTM as it is reported as a virus on my machine. I am downloading on another machine, not the damaged one as DNS is not working on it. Will it work without TM? Any alternative or clean version of OTM? Also didn't find services.exe in the first step. Thanks. |
| Sponsored links |
|
|
|
#6
|
||||
|
||||
|
OTM is not a virus. You need to shutdown your protection software since it appears to be getting in your way and it is incorrect.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#7
|
|||
|
|||
|
Hi, cannot download OTM as my other machine is a business one and cannot shut down anti virus.. Here are two other logs. DNS still does not work. thanks for the advice.
|
|
#8
|
||||
|
||||
|
Your Windows Firewall has now been fixed. It was not running previously.
Quote:
Also please do the below. Now please download Farbar Service Scanner and run it on the computer with the issue.
See the download links under this icon
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Missing Cdfs.sys - CD/DVD Rom drive missing | grammashousecc | Software | 6 | 12-14-10 22:18 |
| Shareware For Missing \system32\ Missing File ??? | gregory447 | Software | 19 | 07-27-07 12:47 |
| Missing Posts, Missing Messages, Missing Accounts | chaslang | Malware Removal | 1 | 10-16-06 15:48 |
| Missing Outlook .DLL & Word Clipart Missing | babynyc | Software | 3 | 03-20-05 12:43 |
| Sound Control Problem/Missing sys32file/missing DLL | CommanderRandom | Software | 1 | 10-19-04 20:46 |