![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#21
|
|||
|
|||
|
Here you go
|
| Sponsored links |
|
|
|
#22
|
|||
|
|||
|
OK, ran the analysis.exe from MGtools, fixed the ones you pointed out. But I have to wait until tomorrow to run combofix, because after combofix reboots my PC it doesn't allow my voice recognition software to automatically load, so I'll have to get somebody to reboot it since I'm paralyzed. And they just went to bed.
|
|
#23
|
||||
|
||||
|
Quote:
We will continue tomorrow. I have something new that I want to try in an attempt to get the BFE service running again. This is a new type of infection that just started appearing a couple days ago. And now it is spreading throught the internet like wild fire. There is no known easy fix yet. In fact, there is no know fix short of a total reinstall yet. But we are working on it. ![]()
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#24
|
|||
|
|||
|
There is already a MGtools.zip folder on my hard drive from the last scan we did, should I leave it there?
|
|
#25
|
|||
|
|||
|
Thanks. We were trained to adapt and overcome. A hell of a thing to overcome though. But a lot of my fellow brothers in arms were not quite as lucky. It's weird though kinda like being imprisoned in your own body.
|
| Sponsored links |
|
|
|
#26
|
||||
|
||||
|
Quote:
Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one. Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator ) Now attach the below log:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#27
|
||||
|
||||
|
I cannot even image what it is like.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#28
|
|||
|
|||
|
No change. BFE still won't start
|
|
#29
|
||||
|
||||
|
Now run the C:\MGtools\FixWFW.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). This will run very fast. Let me know if you see any error messages though.
I found a bug in one of the MGtools programs. Please download and save the below new version file to your C:\MGtools folder overwriting the older file. You must save them to the C:\MGtools folder. NwkTst.bat Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). Then attach the below logs:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#30
|
|||
|
|||
|
You ain't kiddin that runs fast. Couldn't tell if there was a error message or not, ran too fast.
|
| Sponsored links |
|
|
|
#31
|
||||
|
||||
|
Download SubInACL.msi from Microsoft.
Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). Then attach the below logs:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#32
|
|||
|
|||
|
Quote:
|
|
#33
|
||||
|
||||
|
Hmmmm! We still have not been able to get the BFE service started. It still looks like there are some items missing/incorrect in the registry. Let's see if we can get the below fix with ComboFix to address this.
Now we need to use ComboFix
Quote:
Do not mouseclick combofix's window while it is running. That may cause it to stall. If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem. Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). Then attach the below logs:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#34
|
|||
|
|||
|
I already have one combofix.txt file on my C drive, should I delete it, move it, or leave it there?
|
|
#35
|
||||
|
||||
|
Quote:
![]()
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| Sponsored links |
|
|
|
#36
|
|||
|
|||
|
For the BFE Instead of Error 5 access denied I now get Error 1073, the dependency service does not exist or has been marked for deletion.
And the path to executable is blank |
|
#37
|
||||
|
||||
|
Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
Quote:
to the registry. If you do not get a success message, it definitely did not work. If the above worked without any errors, run the C:\MGtools\GetNetInf.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). Then attach the below log which should get updated:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#38
|
|||
|
|||
|
The merge was successful. No change in status though.
|
|
#39
|
||||
|
||||
|
In preparation for next steps, I want you to download and save the below to your DesktopThen double click on it to install the RegistrarLite program.
Now run the RegistrarLite Program and copy and paste the below into the address bar line and hit enter: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root It will look like the below RL_CCS_EnumRoot.jpg
Now repeat the same to Take Ownership and Edit Permissions after pasting the below into the address bar and hit enter HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE RL_CCS_Serv_BFE.jpg Let me know if you are able to get the above completed.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter Last edited by chaslang; 12-12-11 at 17:08.. Reason: Add snapshots for clarity |
|
#40
|
||||
|
||||
|
That's my fault. I forgot to change the REGEDIT4 to Windows Registry Editor Version 5.00
We will address this after you get Registrar Lite installed and complete the instructions I just gave.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| Sponsored links |
|
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Virus prevents starting windows firewall and internet connectivity | anton48 | Malware Removal | 11 | 11-28-11 19:57 |
| Windows XP Not Starting Up | Doom | Software | 2 | 04-28-09 08:20 |
| Windows not starting | tej46 | Software | 2 | 07-12-08 15:00 |
| Starting up windows... | birdwig | Software | 6 | 06-12-06 23:28 |
| Windows not starting up | dmaestro | Hardware | 20 | 11-21-04 11:56 |