Can't connect to internet, registry files missing

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by cpk, Dec 30, 2011.

  1. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In fact, you really needed to run a full scan with GetLogs.bat after that fix to properly see what changes if any were made.

    Now run C:\MGtools\GetLogs.bat by double-clicking it.
    This updates all of the logs inside MGlogs.zip.
    When it is finished, attach C:\MGlogs.zip to your next message
     
  2. cpk

    cpk Private E-2

    Hi chaslang,

    Attached is the latest MG log after running the GetLogs batch. Many thanks to you and thisisu for the continued help!
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The permissions changes did not work as I expected since it is not being changed properly. As I stated earlier, first ownership needs to be taken and then Full Permissions of Everyone can be made. Then and ONLY then can you import into the LEGACY keys. I'm not sure this is the whole reason for you inability to connect, but the registry entries need to be fixed inorder to know for sure.
     
    Last edited: Jan 2, 2012
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay first we need to save a new registry patch to your Desktop.

    Copy the bold text below to notepad. Save it as fixserv.reg to your desktop. Be sure the "Save as" type is set to "all files". Once you have saved it don't do anything else with it right now. Just move on to the next instructions.
    Now please click Start, and type regedit into the Run box and click OK. This should open the Windows Registry Editor should open up.


    Now follow the below instructions for changing permissions for registry keys using Regedit.
    • First navigate to the below registry key and have it selected
      • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETBT\0000\Control
    • Then right click on this key and select Permissions
    • Then on the Permissions for Control for click the Add button
    • In the Enter the object names to select box type Everyone and click the Check Names button which should cause the Everyone text to be approved and underlined
    • Then click the OK button which returns you to the Permissions for Control form
    • Make sure you select Everyone from the upper list, and then in the Permissions form Everyone box, select Full Control and see if it allows you to click the Apply button.
    • Then click OK to control this Permissions for Control form
    • Now repeat the above for the below key
      • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_DHCP\0000
    • Now on the Registry Editor menu, click File and select Import.
    • Navigate to the fixserv.reg file we saved to your Desktop and select it and click OK ( double clicking on the file should also auto select it to import )
    • Did it import without an error message?
      • If not, then stop and tell me
      • If yes, then continue.
    Reboot your PC and after reboot continue.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
     
    Last edited: Jan 2, 2012
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I had to edit my last message to add a couple items so please re-create the registry patch if you already started and see the instructions again because I added another key to the permissions fix.
     
  6. cpk

    cpk Private E-2

    The LEGACY_NETBT "full control" and "read" permissions were "grayed out" with the "allow" boxes already checked. The LEGACY_DHCP "full control" allow box was not checked and did let me check "allow". Clicked apply. No error importing fixserv.reg file. MGlogs attached.
     

    Attached Files:

  7. thisisu

    thisisu Malware Consultant

    Don't do anything with the below, this is just for our reference.

    Code:
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_DHCP\0000]
    "ConfigFlags"=dword:00000020 [B][COLOR="DarkGreen"]<--- OK[/COLOR][/B]
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETBT\0000\Control]
    "ActiveService"="NetBT" [COLOR="DarkGreen"][B]<--- OK[/B][/COLOR]
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT]
    "Tag"=dword:00000005 [B][COLOR="DarkGreen"]<--- OK[/COLOR][/B]
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters]
    "EnableLMHOSTS"=dword:00000001 [COLOR="DarkGreen"][B]<--- OK[/B][/COLOR]
     
  8. thisisu

    thisisu Malware Consultant

  9. thisisu

    thisisu Malware Consultant

    More code for reference. Do not do anything with these.

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETBT\0000
    • Cleanxp: "Driver"="{8ECC055D-047F-11D1-A537-0000F8753ED1}\\0017"
    • netinflong.txt: "Driver"="{8ECC055D-047F-11D1-A537-0000F8753ED1}\\0001"

    Edit: Do not think it matters much, just looked at another clean XP machine with value 0021

    0001 is from first clean xp machine.
     
    Last edited: Jan 2, 2012
  10. cpk

    cpk Private E-2

  11. thisisu

    thisisu Malware Consultant

    Go Start>Run, type in:
    services.msc
    Click OK.

    In services window, locate:
    Remote Procedure Call (RPC) - make sure, it's running, and it's set to automatic start
    DCOM Server Process Launcher - RPC service depends on it, so, make sure it's running, and it's set to automatic start
     
  12. cpk

    cpk Private E-2

    RPC and DCOM SPL are both started, both set to automatic.

    Of interest, DHCP Client status does not show as started and is set to automatic.
     
  13. thisisu

    thisisu Malware Consultant

  14. cpk

    cpk Private E-2

    Same result...unable to obtain IP address.

    Can you break it down for me in easy-speak what the issues are? I'm not still infected, am I? We're trying to repair the damage from rkza?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    1. Go to Start ==> Run (or Windows key+R)
      • Type the following in the run box and click OK: notepad c:\windows\inf\nettcpip.inf
        (note that there is space after notepad)
      • The above file will open in the notepad.
      • Under TCP/IP Primary Install section find the following: Characteristics = 0xA0
      • Edit 0xA0 and replace it with 0x80 (replace A with 8)
      • Under File menu click Save and close the notepad.
    2. Go to Start ==> Control Panel. Double-click Network Connections. Right-click Local Area Connection, and select Properties.
      • On the General tab, click Install a popup window opens.
      • Select Protocol from the list and then click Add.
      • A new window opens, click Have Disk....
      • In the browse... box type c:\windows\inf
      • Click OK.
      • Select Internet Protocol (TCP/IP), and then click OK.
      • On the Local Area Connection Properties screen select Internet Protocol (TCP/IP) and click Uninstall, and then click Yes.
      • Wait until it asks to restart, and then restart as requested. Continue with the below after restarting.
    3. Go to Start ==> Run (or Windows key+R)
      • Type the following in the run box and click OK: notepad c:\windows\inf\nettcpip.inf
        (note that there is space after notepad)
      • A file opens in the notepad. Under TCP/IP Primary Install section find the following: Characteristics = 0x80
      • Edit 0x80 and replace it with 0xA0 (replace 8 with A)
      • Under File menu click Save and close the notepad.
    4. Go to Start ==> Control Panel. Double-click Network Connections. Right-click Local Area Connection, and select Properties.
      • On the General tab, click Install
      • A popup window opens. Select Protocol.
      • A new popup window opens. Select Internet Protocol (TCP/IP), and then click OK.
      • Wait until it asks to restart, and then restart as requested. Continue with the below after restarting.
    5. After restart please run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).
    6. Then attach the below logs:
      • C:\MGlogs.zip
     
  16. cpk

    cpk Private E-2

    After the restart following step 2, this popped up:

    MotoHelperService.exe - Application error

    The instruction "0x004053dd" referenced memory at "0x00000014". The memory could not be "written".

    Click on OK to terminate the program
    Click on CANCEL to debug the program

    How should we proceed from here?
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just continue. Many services/startups could have problems during this procedure.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also if you see this before finishing, I just updated MGtools and instead of running the GetLogs program to get a new log, I would like you to do the below

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:

    • C:\MGlogs.zip
     
  19. cpk

    cpk Private E-2

    Downloaded current version of MGtools...logs attached.
     

    Attached Files:

  20. thisisu

    thisisu Malware Consultant

    Looks like you have an IP address now :)

    And DHCP and NetBt are both started and running now.

    Are you able to connect?
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes and nwktst.txt already shows that ping by IP and by URL are working so there is full network connectivity.
     
  22. cpk

    cpk Private E-2

    Unbelievable. You guys are INCREDIBLE! LAN and wireless both work! I can't thank you enough! Add me as a fan of the Geek Army! THANK YOU!
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. thisisu will give you final instructions now.
     
  24. thisisu

    thisisu Malware Consultant

    You're welcome :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis if it present
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work through the below link:

    Take care and be safe! :)
     
  25. cpk

    cpk Private E-2

    Computer is running better than ever, boots up and runs much faster than before and I've had no problems since these fixes. You guys are PHENOMENAL! I can't even explain how much I appreciate all you did! Thank you again!
     
  26. thisisu

    thisisu Malware Consultant

    :cool:cool
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds