DHCP won't start after malware removal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by bamitts, May 29, 2013.

  1. bamitts

    bamitts Private E-2

    Helping a friend with her laptop. She removed some malware and now cannot access any network.

    Neither her wired nor wireless nics can get an ip address. The DHCP client will not start with an error 1068: The dependency service or group failed to start. Also the Function discovery resource publication, Lanman server, TCP/IP netbios helper and lanman workstation.

    This is a Dell Latitude D630, 64bit, Windows 7 home premium. Intel core 2 duo T7250 with 2 GB memory.

    I have read the read and run first and have logs for the programs listed.

    Any help would be immensely appreciated.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall the below:

    • Ask Toolbar
      [*]Inbox Toolbar
      [*]Strongvault Online Backup

    Delete these files:

    • C:\Windows\tasks\PC Optimizer Pro Updates.job
    • C:\Windows\tasks\PC Optimizer Pro64 Scan.job
    • C:\Windows\tasks\PC Optimizer Pro64 startups.job


    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    Download Dhcp.reg to your desktop.


    • Now please click Start, and type regedit into the search box.
    • You should see a regedit.exe and icon appear in the Programs area of the Start Menu.
    • Right click on regedit.exe and select Run As Administrator
    • Then in the Registry Editor menu click File and select Import.
    • Navigate to the Dhcp.reg file saved to your Desktop and double click it. Allow it to be added to the registry.

    Reboot.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  3. bamitts

    bamitts Private E-2

    Thank you so much for your help!

    I was unable to figure out how to uninstall the Strongvault online backup...it wasn't in add/remove programs...but followed your directions and am attaching the MGTools report.

    Thanks again!!
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can use Revo uninstaller to get rid of strongvault.


    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  5. bamitts

    bamitts Private E-2

    Thank you once again for your help!! Here is the log you requested
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download BITS.reg to your desktop.

    Now please click Start, and type regedit into the search box.
    You should see a regedit.exe and icon appear in the Programs area of the Start Menu.
    Right click on regedit.exe and select Run As Administrator
    Then in the Registry Editor menu click File and select Import.
    Navigate to the BITS.reg file saved to your Desktop and double click it. Allow it to be added to the registry.


    Reboot.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  7. bamitts

    bamitts Private E-2

    Sure appreciate all of your help...I would not have known how to start with this!
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Click on start > type in services.msc which will bring up a list of services. Does Background Intelligent Transfer Service show? Please let me know its status and start up type. :)
     
  9. bamitts

    bamitts Private E-2

    The BITS service is set to automatic (delayed start), but when I attempted to start it, I got an error message:

    Windows could not start the BITS on local computer. For more information, review the system event log. If this is a non-microsoft service, contact the service vendor, and refer to service specific error code -2147014846.

    Heading out for a couple of hours, but really appreciate your help!
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem. :)


    Please download Combofix to your desktop. Please refer to these instructions prior to running.


    Now we need to use ComboFix by sUBs

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Fcopy::
    C:\Windows\winsxs\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.1.7601.21887_none_364f3a028e605345\afd.sys | C:\Windows\System32\drivers\afd.sys
    C:\Windows\winsxs\x86_microsoft-windows-dhcp-client-dll_31bf3856ad364e35_6.1.7601.22130_none_d9d16f10a60382b3\dhcpcsvc.dll | C:\Windows\System32\dhcpcsvc.dll
    
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  11. bamitts

    bamitts Private E-2

    Thank you again for your help. I've attached the logs you requested.

    In addition, I received the following error message 4 times after the PC reboot, but before combofix finished it's log.

    ipconfig.exe error
    application was unable to start correctly 0xc00007b
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Does the ipconfig.exe file exist in C:\windows\system32?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The answer is yes. See winfiles.txt in MGlogs.zip ;)
     
  14. bamitts

    bamitts Private E-2

    Yes it does, but if I try to open it, I get the error message that it was unable to start (0x000007b)
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please run the Windows Repair in safe mode and then do the following: (in normal mode)

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  16. bamitts

    bamitts Private E-2

    I'm afraid this may not have the results we want...There were error messages through out, stating that it couldn't start Ipconfig. (0xc000007b)
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run the below scans.



    Now please download Farbar Service Scanner and run it on the computer with the issue.
    • Put a check mark in each option box on the left side.
    • Click "Scan".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please attach this log to your next reply.

    Now please do the below so that we can boot to System Recovery Options to run a scan.

    For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.


    Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  18. bamitts

    bamitts Private E-2

    Thank you so much for your response...Here is the log you requested.
     

    Attached Files:

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do you also have the FSS.txt? :)
     
  20. bamitts

    bamitts Private E-2

    OOPs!! sorry! Here it is
     

    Attached Files:

    • FSS.txt
      File size:
      3.3 KB
      Views:
      5
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now we need to use ComboFix by sUBs

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Fcopy::
    C:\Windows\winsxs\amd64_microsoft-windows-dhcp-client-dll_31bf3856ad364e35_6.1.7601.17514_none_35802f0f452f59bb\dhcpcsvc.dll | C:\Windows\System32\dhcpcsvc.dll
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  22. bamitts

    bamitts Private E-2

    Here are the files requested. Hoping we are getting very close!
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not quite. There are still things to remove and you have a lot of damage to Windows. There are quite a few services that are not running and a found at least one more missing file that is the cause a possible 2 or 3 services not running. We will need to find a replacement file, but first we will fix a few things and also scan for the file.

    We need to make sure that AVG is not getting in our way. Many times it does even though we disable it. So our best course of action right now is to uninstall AVG until we are finished.

    Also uninstall the below programs. Just continue on if the either do not uninstall or you do not see them ( I know you commented on some earlier ).
    DefaultTab
    PC Optimizer Pro
    Strongvault Online Backup


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Download this >> View attachment fixlist.txt



    Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.
    Now reboot back into the System Recovery Options as you did previously.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now boot into normal Windows and continue with the below.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • Fixlog.txt
    • C:\MGlogs.zip
     
    Last edited: Jun 5, 2013
  24. bamitts

    bamitts Private E-2

    Here are the logs you requested...thanks again!
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Hmmm! The file search in FRST did not work or did not find a replacement. Let try the below to search for a replacement file.

    Please download SystemLook_x64 from one of the links below and save it to your Desktop.

    Download Mirror #1

    Download Mirror #2
    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      wuauserv.dll
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. You can just close this notepad window since the log is already saved on your Desktop. Be patient! It may look like it is not doing anything, but it takes awhile for this to scan thru your whole system look for matches.
    • Please attach the SystemLook.txt log found on your Desktop to next reply.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Almost forgot. Now that AVG is uninstalled, I want to rerun the below just to make sure it was not being impacted by AVG.​



    Be patient while doing the below. The fixes can sometimes take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.​

    • Rerun Repair_Windows.exe by using right click and select Run As Administrator
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.
    Now click Start, Run, and enter sfc /scannow and click OK. There is a space after the sfc. This runs System File Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it.​

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). ​


    Then attach the below logs:
    • C:\MGlogs.zip
     
  27. bamitts

    bamitts Private E-2

    Not good news!!
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually this is okay and it helped to uncover a bug in MGtools. For Windows 7, the file name is different than it was for Win XP. The file name is C:\Windows\system32\wuaueng.dll and your is there. So all is good in that area.​

    Just finish the SFC scan and the new run of Windows Repair and we will see if we can get any changes to occur in service status.​
     
  29. bamitts

    bamitts Private E-2

    Thank you so much for your help!
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Did the SFC scan find any problems? Did it ask for the Windows 7 DVD?

    Disable Advance System Care before doing the below.

    Please download each of the below registry patches by whatever method you are currently downloading files:

    Win7AFD

    Win7LegAFD

    Win7BITS

    Win7BROWSER

    Win7LegBowser

    Win7HTTP

    Win7LegHTTP


    After downloading file, copy each one to the DESKTOP folder on the problem PC.
    Then one at a time right click on each file and select Merge. Say yes to any prompts about allowing these to be added to your registry. Tell me if you have any problems and for which ones. Also be sure to tell me which say that they were successful.

    Then reboot your PC.

    Now please run the below anti-rootkit tool from Malwarebytes.


    Attach logs from Malwarebytes Anti-Rootkit


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). ​



    Then attach the below logs:
    • C:\MGlogs.zip
     
    Last edited: Jun 7, 2013
  31. bamitts

    bamitts Private E-2

    We have made major progress!! My wireless nic is working!! YeeeHawww!!

    All of the registry entries finished correctly.

    Thank you!
     

    Attached Files:

  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Excellent!

    There may still be some services that are not running properly.

    Please try going to Windows Update and see if it works.

    Also please rerun Farbar's Service Scanner that I had you run earlier and attach a new log from it.
     
  33. bamitts

    bamitts Private E-2

    Windows update completed updates with no problem. Here is the log
     

    Attached Files:

  34. bamitts

    bamitts Private E-2

    ****got it...I should have searched Google first!! ****

    New issue: When starting the PC after reboot, I get an error message:

    An updated version of Origin has been found on this computer...Do you want to install this previous version.

    I've been pressing no, but it keeps coming up every time I reboot...do you have experience with this...don't want to reinstall a problem!
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not a malware issue. You need to keep track of things you installed. You installed this game.
    Code:
    "DisplayName"="Origin"
    "Publisher"="Electronic Arts, Inc."
    "DisplayVersion"="8.6.0.357"
    "UninstallString"="C:\\Program Files (x86)\\Origin\\OriginUninstall.exe"
    "InstallLocation"="C:\\Program Files (x86)\\Origin"
    "DisplayIcon"="C:\\Program Files (x86)\\Origin\\OriginUninstall.exe"
    "URLInfoAbout"="[URL]http://www.ea.com[/URL]"
    
    Your logs look good.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove, you can delete these files now.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  36. bamitts

    bamitts Private E-2

    Thank you so much for all your help. My friend is over the moon that her laptop is working so well. Thanks again!
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds