Re: afd.sys lost after "virus repair"

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by elTigrre, Aug 30, 2014.

  1. elTigrre

    elTigrre Private E-2

    By any chance, are you available for another computer that has contracted what appears to be the same problem? Seems that other members of my family thought it was a good idea to use this "coupon" web site. I am attaching the scanned info after running through the cleaning tools.

    Thanks
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, no problem. :)

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode.


    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [RUN][SUSP PATH] HKCU\[...]\Run : SearchProtect (C:\Users\Dad\AppData\Roaming\SearchProtect\bin\cltmng.exe [x]) -> FOUND
    • [RUN][SUSP PATH] HKUS\S-1-5-21-181626487-3978172728-3161019568-1004\[...]\Run : SearchProtect (C:\Users\Dad\AppData\Roaming\SearchProtect\bin\cltmng.exe [x]) -> FOUND
    • [RUN][SUSP PATH] HKUS\.DEFAULT\[...]\RunOnce : SpUninstallDeleteDir (rmdir /s /q "C:\Windows\system32\config\systemprofile\AppData\Roaming\SearchProtect" [x]) -> FOUND
    • [RUN][SUSP PATH] HKUS\S-1-5-18\[...]\RunOnce : SpUninstallDeleteDir (rmdir /s /q "C:\Windows\system32\config\systemprofile\AppData\Roaming\SearchProtect" [x]) -> FOUND

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • R3 - URLSearchHook: (no name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
    • R3 - URLSearchHook: (no name) - {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - (no file)
    • R3 - URLSearchHook: (no name) - {f78bf7a8-cf12-4de7-a6da-c463d1b539a7} - (no file)
    • R3 - URLSearchHook: (no name) - - (no file)
    • R3 - URLSearchHook: (no name) - {1c583e40-0629-4bb9-ab68-1cf539f2f782} - (no file)
    • R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
    • O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    • O16 - DPF: {4F29DE54-5EB7-4D76-B610-A86B5CD2A234} (GameTap Player) -

    After clicking Fix exit HJT.



    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  3. elTigrre

    elTigrre Private E-2

    First, the registry add was successful..
    The computer is still not allowing network connections. I have attached the three files that were requested. But, I have to assume were getting closer with some of the obvious stuff getting pulled off.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    SystemLook

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      afd.sys
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
     
  5. elTigrre

    elTigrre Private E-2

    Attached are the results.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    afd.sys is NOT lost.....

    Check the last log for yourself.

    What do you mean by "not allowing network connections" ?
     
  7. elTigrre

    elTigrre Private E-2

    The computer cannot see or create any network connections. This is the same type of problem I had with the other computer, and appeared to find the same type of "coupon" hijacking. The computer was working on a wireless conenction but was not under control and kept getting redirected to websites. Rather than first hitting it with cleaning tools, I rolled back Windows to a previously know working version of several months ago, the wireless connectivity no longer worked.
    When this happened on the other computer, I used simple cleaning tools and removed add-ons. I also attempted to fix the afd.sys. That's when I gave up at that time and contacted Major Geeks to try to go at it the right way. Obviously a lot of junk has been cleaned up. What I am wondering is if the afd.sys file has been trashed/replaed with something that is not what it shold be. Not sure, not an expert.:)
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What makes you think/believe in the first place that afd.sys has been corrupted or replaced? (Don't get me wrong, not saying I don't believe you) Would rather hear what else you have to say about it before I make any attempts to replace it. :)
     
  9. elTigrre

    elTigrre Private E-2

    Its just a guess at this point, only because the computer acted pretty much the same way the other one did. But, I am wide open for suggestions on what to look at or try next.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I do not believe afd.sys is affected. I think i's just fine. :)

    I think you ought to post in the software forum about the nework connections.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds