virus removed, internet broken

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by kthrone, Apr 6, 2012.

  1. kthrone

    kthrone Private E-2

    Hi, first of all thank you for taking the time to read this, 2 days of banging my head against my laptop and I've decided I need some help.

    About 3 days ago, I was just going about my business, playing some everquest, when all of a sudden an "internet security" virus popped up and began scanning my computer. About 5 seconds into the scan, and before i could even think of what to do about it, my computer blue screened. Upon power up, the virus seemed to be gone, or atleast not popping up. But my internet was completely out and only on this laptop. Everytime I tried to fix it, my IP would set itself to the 169.254.x.x

    Well after days of searching and multiple programs run trying to figure it out I have decided I have a rootkit. I didn't find this site till awhile into my search, and so i did combofix and such out of order. Combofix found a zeroaccess rootkit, but in the middle of fixing it, my computer blue screened again. I had to run tdsskiller to stop the blue screens, which worked, but now combofix doesnt seem to be finding the zeroaccess again.

    After all that I found this site, and followed the guide in order. It all seemed to work fine but RootRepeal, which gives me an "attempt to write to address" error. I followed everything but internet is still down, hoping anyone is able to help. Thanks again!
     

    Attached Files:

  2. kthrone

    kthrone Private E-2

    rootrepeal crash log
     

    Attached Files:

  3. kthrone

    kthrone Private E-2

    sorry about bump forgot TDSS log
     

    Attached Files:

  4. thisisu

    thisisu Malware Consultant

    Hi and welcome to Major Geeks, kthrone!

    http://img850.imageshack.us/img850/4746/programsandfeatureswin7.gif From Programs and Features (via Control Panel), please uninstall the below (you can reinstall it once we are finished with malware removal):
    • CA Pest Patrol Realtime Protection

    /!\ Uninstall SUPERAntiSpyware which is on your DATA partition ( D:\ )

    http://img825.imageshack.us/img825/2648/hjt.gif Run C:\MGtools\analyse.exe by double-clicking it (Vista/7 right-click and select Run as Administrator)
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Choose "Do a system scan only" and select the following lines but do not click fix until you exit all explorer windows and all browser sessions including the one you are reading in right now:

    1. R3 - URLSearchHook: AOL Messaging Toolbar Search Class - {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (file missing)
    2. O2 - BHO: XFINITY Toolbar - {4b9bcce8-a70b-402a-a7e1-db96831ee26f} - C:\Program Files\xfin_portal\comcastdx.dll (file missing)
    3. O2 - BHO: AOL Messaging Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll (file missing)
    4. O2 - BHO: Updater For XFIN_PORTAL - {bb46be07-13eb-4c49-b0f0-fc78b9ea4983} - C:\Program Files\xfin_portal\auxi\comcastAu.dll (file missing)
    5. O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (file missing)
    6. O3 - Toolbar: XFINITY Toolbar - {4b9bcce8-a70b-402a-a7e1-db96831ee26f} - C:\Program Files\xfin_portal\comcastdx.dll (file missing)
    7. O3 - Toolbar: AOL Messaging Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll (file missing)
    8. O4 - HKCU\..\Run: [ComcastAntispyClient] "C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntispy.exe" /hide

    After clicking Fix, exit out of Trend Micro HiJackThis - v2.0.4

    http://img194.imageshack.us/img194/4930/combofix.gif Fixing items using ComboFix
    Make sure that ComboFix.exe that you downloaded while doing the READ & RUN ME is on your desktop -- but do not run it.
    If it is not on your desktop, the below will not work.
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Open Notepad and copy/paste the text in the below code box into Notepad:
    Code:
    [COLOR="DarkRed"]KillAll::[/COLOR]
    [COLOR="DarkRed"]ClearJavaCache::[/COLOR]
    [COLOR="DarkRed"]DirLook::[/COLOR]
    C:\test.{ED7BA470-8E54-465E-825C-99712043E01C}
    [COLOR="DarkRed"]Domains::[/COLOR]
    [COLOR="DarkRed"]Driver::[/COLOR]
    kaxuir
    [COLOR="DarkRed"]File::[/COLOR]
    c:\windows\System32\drivers\wvnxsctt.sys
    C:\Users\Marc\AppData\Roaming\Microsoft\Windows\Templates\0y88jo6s25h487
    C:\Users\Marc\AppData\Roaming\Microsoft\Windows\Templates\73u2m1735ev02k2eow5munt0b3v00j85y263ka
    C:\Users\Marc\AppData\Roaming\Microsoft\Windows\Templates\hdibvf1g3hle3pfs8whq0r460k5q
    C:\Users\Marc\AppData\Roaming\Microsoft\Windows\Templates\y7580ev24u07r5132jo87udiynd5f2pevn20px53np0jf
    [COLOR="DarkRed"]Folder::[/COLOR]
    C:\Windows\$NtUninstallKB7556$
    C:\ProgramData\McAfee
    C:\found.000
    [COLOR="DarkRed"]Registry::[/COLOR]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4b9bcce8-a70b-402a-a7e1-db96831ee26f}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b0cda128-b425-4eef-a174-61a11ac5dbf8}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bb46be07-13eb-4c49-b0f0-fc78b9ea4983}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0B4A10D1-FBD6-451d-BFDA-F03252B05984}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0B4A10D1-FBD6-451d-BFDA-F03252B05984}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ComcastAntispyClient"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "iTunesHelper"=-
    "Adobe ARM"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "QuickTime Task"=-
    "iTunesHelper"=-
    "Windows Defender"=-
    
    Save this file as CFScript.txt to your desktop. So now you should have both CFScript.txt and ComboFix.exe on your desktop.
    Now use your mouse to drag CFScript.txt on top of ComboFix.exe and then release.
    http://softvisia.com/users/Night_Raven/Security/cfsdnd2.gif
    This will launch ComboFix.
    Note: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
    Allow ComboFix to update itself if prompted.
    When ComboFix finishes, a log will be produced at C:\ComboFix.txt
    Attach this log to your next message. (How to attach)

    http://img17.imageshack.us/img17/3214/baticonvista7.gif Now run c:\MGtools\FixNet.bat by right-mouse clicking it and selecting "Run as Administrator".
    It will reboot your computer automatically (don't panic)

    __

    http://img17.imageshack.us/img17/3214/baticonvista7.gif Now run C:\MGtools\GetLogs.bat by right-mouse clicking it and then selecting Run as Administrator
    This updates all of the logs inside MGlogs.zip.
    When it is finished, attach C:\MGlogs.zip to your next message. (How to attach)

    __

    If the internet issue is not resolved by this point, I will need you to follow these set of instructions too:

    http://img205.imageshack.us/img205/1894/otl.gif Please download OTL by OldTimer.

    • Save it to your desktop.
    • Right mouse click on the OTL icon on your desktop and select Run as Administrator
    • Check the "Scan All Users" checkbox.
    • Check the "Standard Output".
    • Change the setting of "Drivers" and "Services" to "All"
    • Copy the text in the code box below and paste it into the http://img14.imageshack.us/img14/66/otlcustomfix.png text-field.
      Code:
      activex
      netsvcs
      /md5start
      afd.sys
      i8042prt.sys
      netbt.sys
      nsiproxy.sys
      svchost.exe
      tcpip.sys
      tdx.sys
      /md5stop
      %windir%\$ntuninstallkb*. /120
      %windir%\system32\drivers\*.sys /lockedfiles
      %windir%\*.* /mp
      %windir%\*.* /rp
      %windir%\*.* /sl
      %systemdrive%\mgtools\*.*
      
    • Now click the http://img171.imageshack.us/img171/2405/runscanotl.png button.
    • One report will be created:
      • OTL.txt <-- Will be opened
    • Attach OTL.txt to your next message. (How to attach)
     
  5. thisisu

    thisisu Malware Consultant

    If the internet is still not working, I want you to follow these instructions too after all of the above has been completed:

    http://img97.imageshack.us/img97/8120/fss.gif Please download Farbar Service Scanner and run it on the computer with the issue.
    • Make sure all the options are checked
    • Press "Scan".
    • It will create a log (FSS.txt) in the same directory the tool was run.
    • Please attach FSS.txt to your next message. (How to attach)
     
  6. kthrone

    kthrone Private E-2

    Thank you for the quick response! I followed all your steps, and all seem to work well. Unfortunately, no internet still. All logs are attached!
     

    Attached Files:

  7. thisisu

    thisisu Malware Consultant

    I would prefer if you ran this fix while in Safe Mode for the highest chance of success.
    See: How to start your computer in Safe mode

    Attached is OTLfix.txt
    Download and save this to your desktop.


    http://img205.imageshack.us/img205/1894/otl.gif Now reopen OTL
    Then drag OTLfix.txt into the http://img14.imageshack.us/img14/66/otlcustomfix.png text-field.
    You should see a bunch of text transferred over into the text-field.
    Now click the http://img3.imageshack.us/img3/407/otlrunfix.png button.
    If the fix needed a reboot please do it. - BUT LET THE FIX RETURN YOU TO NORMAL MODE!
    Click the OK button (upon reboot).
    When OTL is finished, Notepad will open. Close Notepad.
    A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
    Attach this log to your next message. (How to attach)

    http://img17.imageshack.us/img17/3214/baticonvista7.gif Now run C:\MGtools\GetLogs.bat by right-mouse clicking it and then selecting Run as Administrator
    This updates all of the logs inside MGlogs.zip.
    When it is finished, attach C:\MGlogs.zip to your next message. (How to attach)
     

    Attached Files:

    Last edited: Apr 6, 2012
  8. kthrone

    kthrone Private E-2

    Ok, followed your steps and everything went smooth. Here are the logs.

    still no internet :(
     

    Attached Files:

  9. thisisu

    thisisu Malware Consultant

    Reinstall your network adapters. - See below
    Open the Device Manager - Below are instructions on how to do this

    Now press and hold the Windows key http://i1106.photobucket.com/albums/h363/debojyotidas/Windows_Logo_key.gif and then press the letter "R" on your keyboard.
    This opens the Run dialog box
    In this text-field, enter this command and press ENTER: devmgmt.msc
    This opens the Device Manager.

    Collapse the Network Adapters list.
    Right mouse click: 11a/b/g/n Wireless LAN Mini-PCI Express Adapter
    Choose "Uninstall".
    You be asked to confirm your actions, choose OK and let it uninstall.
    If it asks you if you want to delete the driver software / files too, say No.
    When you have done this and 11a/b/g/n Wireless LAN Mini-PCI Express Adapter is no longer in the Device Manager list -- Press the Scan for hardware changes button (http://img803.imageshack.us/img803/2868/scanhardware.png) or Action -> Scan for hardware changes
    Allow it to reinstall your network adapter.

    Do this same process for : Intel(R) PRO/1000 PL Network Connection
    Reboot for changes to occur.
    Test internet once you have rebooted.
     
  10. kthrone

    kthrone Private E-2

    Reinstalled both adapters and everything went smoothly, found them and reinstalled them right away. Still having some problem on reboot, I had to re-enter the password and all for the wireless, but I am still getting the limited connectivity to unidentified network problem. Thanks again for all your time so far, it is greatly appreciated.
     
  11. thisisu

    thisisu Malware Consultant

    Do you have a Ethernet cable to test the wired connection?
    Please run getlogs.bat and attach the updated mglogs.zip for review.
     
  12. kthrone

    kthrone Private E-2

    Sadly I do not have an ethernet handy atm (I know who doesn't). I have been trying to avoid getting one, but if I need it I'll get one ASAP. All of the other devices in the network (hp mini & iphone) are connected fine, are you thinking maybe my wireless adapter is not working, or maybe the drivers are old?
     
  13. kthrone

    kthrone Private E-2

    Sorry I forgot to include the Mglog in the last post.

    Also to note, after running Getlogs.bat the yellow triangle on my wifi symbol dissappeared. When I went and looked at the icon, it showed me as connected to my network totally fine and looked as if everything should work. But when I opened IE I got the same no connection error. Rebooted, and yellow triangle is back again.
     

    Attached Files:

  14. thisisu

    thisisu Malware Consultant

    We're getting close. You are now able to ping google which is good.

    If you open a browser and type the following into the address bar you should be able to view the webpage: 74.125.113.106

    __

    Follow these steps: here
    When you get to step #4, you should be looking for: Wireless LAN adapter Wireless Network Connection 2

    Let me know how it goes.
     
  15. kthrone

    kthrone Private E-2

    Glad we are getting closer! I typed 74.125.113.106 into my internet explorer and got the "Internet Explorer cannot display the webpage" error. After running the diagnose, it told me ""Wireless Network Connection 2" doesn't have a valid IP configuration."

    I decided to try and change the IP to static, once I did it displayed my network name rather than "unidentified network", but still has the yellow triangle. I tried diagnose in static and the diagnose tool cant find any error. Also 74.125.113.106 doesn't connect in static nor DHCP.
     
  16. thisisu

    thisisu Malware Consultant

    Did you have trouble uninstalling SUPERAntiSpyware? I still see it in your logs.

    __

    http://img706.imageshack.us/img706/3941/minitoolbox.gif Please download MiniToolBox and save it to your desktop and run it.

    Checkmark following checkboxes:

    • Flush DNS
    • Report IE Proxy Settings
    • Reset IE Proxy Settings
    • Report FF Proxy Settings
    • Reset FF Proxy Settings
    • List IP configuration
    • List Winsock Entries
    • List Devices -> All
    • List last 10 Event Viewer log
    Press Go and attach the result (Result.txt) that pops up. A copy of Result.txt will be saved in the same directory the tool is run.
     
  17. kthrone

    kthrone Private E-2

    Sorry about the Superantispyware miss, it wasn't in my uninstall programs tool, so I manually deleted it from D:, I geuss it was in C: as well.

    Minitool ran without a problem, here is the log!
     

    Attached Files:

  18. thisisu

    thisisu Malware Consultant

    Are you willing to uninstall Comcast Desktop Software (v1.2.0.9) to see if that helps?

    It seems like a software related problem now.
     
  19. thisisu

    thisisu Malware Consultant

    placeholder
     
    Last edited: Apr 7, 2012
  20. kthrone

    kthrone Private E-2

    Of course, anything that could help! Comcast Desktop Software uninstalled, computer rebooted, same yellow triangle. I'm up to delete anything else you may see that could pose a problem, and thanks again for all of your time.
     
  21. thisisu

    thisisu Malware Consultant

    Try downloading and installing this wireless driver: atheros-wlan-win7-9204190.zip

    Afterwards, attach a new MGlogs.zip so I can make sure all traces of ComcastAntiSpy are gone.
     
  22. thisisu

    thisisu Malware Consultant

    No I just wanted to see if it was a problem with the wireless driver or not. If the wired connection worked fine, but wireless wasn't working, then we'd know it was it was an issue with wireless driver.

    We're reinstalling the wireless driver now. It should be compatible, but let me know if it is not.
     
  23. kthrone

    kthrone Private E-2

    Ok downloaded the driver, extracted it to my desktop and the TC00384500B.exe opened up. It stated that the program would start up after extraction. The blue bar was complete, and program closed, but the installation never started up. The mouse had the loading symbol displayed, as if something was trying to load, but it never happened. Tried in safe mode as well, with the same results. I went into my temp folder, where it had extracted the tinstall.exe, and again I just get a blue loading circle on my mouse, but nothing opens.
     
  24. thisisu

    thisisu Malware Consultant

    Yeah the installer doesn't work as it claims. :\

    You said you found tinstall.exe, right?
    Go back to the folder with tinstall.exe in it, then look for a folder called: Win7Drv
    Open that folder, and then look for setup.exe
    Run setup.exe
     
  25. kthrone

    kthrone Private E-2

    New MGlog attached
     

    Attached Files:

  26. thisisu

    thisisu Malware Consultant

    Is this after you successfully installed the new wireless driver?
     
  27. kthrone

    kthrone Private E-2

    Just finished installing, got it to work, thank you for pointing out the setup.exe. Rebooted and reset the router, but still having the same problems with the limited access to unidentified network.
     
  28. kthrone

    kthrone Private E-2

    Here are the good MGLogs, that were done after the drivers successfully installed.
     

    Attached Files:

  29. thisisu

    thisisu Malware Consultant

    http://img850.imageshack.us/img850/4746/programsandfeatureswin7.gif From Programs and Features (via Control Panel), please uninstall the below:
    • Thinkpad Wireless LAN Adapters Software (11a/b/g/n)
    • WinPcap 3.0

    http://img196.imageshack.us/img196/3557/tdsskiller.gif I want you to read and follow these instructions: TDSSKiller - How to run
    TDSSKiller is run differently than how you ran it previously.

    http://img805.imageshack.us/img805/9659/rktigzy.gif Please download RogueKiller to your desktop.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    When it is finished, there will be a log on your desktop called: RKreport[1].txt
    Attach RKreport[1].txt to your next message. (How to attach)

    http://img194.imageshack.us/img194/4930/combofix.gif Fixing items using ComboFix
    Make sure that ComboFix.exe that you downloaded while doing the READ & RUN ME is on your desktop -- but do not run it.
    If it is not on your desktop, the below will not work.
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Open Notepad and copy/paste the text in the below code box into Notepad:
    Code:
    [COLOR="DarkRed"]KillAll::[/COLOR]
    [COLOR="DarkRed"]ClearJavaCache::[/COLOR]
    [COLOR="DarkRed"]Domains::[/COLOR]
    [COLOR="DarkRed"]Driver::[/COLOR]
    !SASCORE
    AntiSpywareService
    [COLOR="DarkRed"]File::[/COLOR]
    D:\SASWINLO.DLL
    D:\SASCORE.EXE
    [COLOR="DarkRed"]FileLook::[/COLOR]
    C:\Windows\System32\drivers\afd.sys
    C:\Windows\System32\drivers\tdx.sys
    C:\Windows\System32\drivers\netbt.sys
    C:\Windows\System32\drivers\nsiproxy.sys
    C:\Windows\System32\drivers\tcpip.sys
    [COLOR="DarkRed"]Folder::[/COLOR]
    C:\Program Files\comcasttb
    C:\Program Files\Net Tools
    c:\program files\CA
    [COLOR="DarkRed"]RegLock::[/COLOR]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    
    Save this file as CFScript.txt to your desktop. So now you should have both CFScript.txt and ComboFix.exe on your desktop.
    Now use your mouse to drag CFScript.txt on top of ComboFix.exe and then release.
    http://softvisia.com/users/Night_Raven/Security/cfsdnd2.gif
    This will launch ComboFix.
    Note: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
    Allow ComboFix to update itself if prompted.
    When ComboFix finishes, a log will be produced at C:\ComboFix.txt
    Attach this log to your next message. (How to attach)

    http://img834.imageshack.us/img834/2930/fixiticon.gif Download and run: MicrosoftFixit50195.msi
    Follow the instructions provided within the tool.

    http://img17.imageshack.us/img17/3214/baticonvista7.gif Now run C:\MGtools\GetLogs.bat by right-mouse clicking it and then selecting Run as Administrator
    This updates all of the logs inside MGlogs.zip.
    When it is finished, attach C:\MGlogs.zip to your next message. (How to attach)
     
    Last edited: Apr 7, 2012
  30. kthrone

    kthrone Private E-2

    Ok, deleted both programs and restarted. Once the computer loaded I got an "driver did not successfully install" error and my internet icon now has a big red X.

    Finished all the steps and I am attaching all the logs, also am adding the TDSSKiller log incase.
     

    Attached Files:

  31. kthrone

    kthrone Private E-2

    When I ran microsoft fixit, it seemed to freeze up after I hit "reset internet settings". I had to close the little window that had popped up, and then rest of microsoft fixit finished up in seconds. So I'm not sure if that worked correctly. Here is the new MGlog after it attempted to run.

    Also, in this program it looked like it was trying to make a system restore point but failed, I have noticed this in some of the other programs we have been using, they don't say failed, just seem to skip without finishing. I'm not sure if that matters or not.
     

    Attached Files:

    Last edited: Apr 7, 2012
  32. thisisu

    thisisu Malware Consultant

    http://img196.imageshack.us/img196/3557/tdsskiller.gif Re-scan with TDSSKiller with the parameters you used before.
    This time if TDSS File System appears, delete it!
    Then attach the latest TDSSKiller log. (How to attach)

    __

    Can you rerun the setup.exe you downloaded earlier for the wireless driver?

    Let me know if the installation of the wireless driver was successful or not.

    Double-check that the Atheros wireless network adapter is installed in the Device Manager under Network Adapters.
     
    Last edited: Apr 7, 2012
  33. kthrone

    kthrone Private E-2

    TDSS system was found again, and removed. I have attached that log. Re installed the driver through setup.exe, and got connected to the wifi again with limited connectivity :cry.

    EDIT - If I right click my main network adapter ( 11a/b/g/n Wireless LAN mini-PC Express Adapter ) then the manufacturer is Atheros Communications and the driver provider as well. But there isn't its own Atheros adapter.
     

    Attached Files:

    Last edited: Apr 7, 2012
  34. thisisu

    thisisu Malware Consultant

    Just so we're on the same page, you're trying to connect to your own wireless network right? :-D

    Please attach an updated MGlogs.zip and FSS.txt
    Yes this is fine.
     
  35. kthrone

    kthrone Private E-2

    Yes, it is mine I promise you haha, it shows it as connected to mine when i pull up the list of nearby wifi's. It just says unidentified in the Network and Sharing center. I attached both logs.
     

    Attached Files:

  36. thisisu

    thisisu Malware Consultant

    I believe you :)

    It seems like the only problem now is that you can't get an IP address.

    This may seem drastic but we are running short on options now. You may want to try uninstalling Service Pack 1 (at least temporarily).

    Visit this page for instructions on how to do this: http://windows.microsoft.com/uninstallwindows7sp1
     
  37. kthrone

    kthrone Private E-2

    Found Service Pack for Microsoft Windows (KB976943) and clicked uninstall. Took a few minutes then pop up said "An error has occurred. Not all of the updates were successfully uninstalled." And it is also still listed in the "Uninstall an update".
     
  38. thisisu

    thisisu Malware Consultant

    Hmmm, have you tried again?
     
  39. kthrone

    kthrone Private E-2

    I tried twice in normal mode with no luck. I restarted and gave it a shot in safe mode and same error. Sorry about this, it's really beginning to seem hopeless.
     
  40. thisisu

    thisisu Malware Consultant

    Double-check something for me in Device Manager
    When you're in Device Manager, at the top, press View -> Show Hidden Devices
    Are there any items here that have a red X or a yellow exclamation mark?

    ___

    Follow these steps: here
    When you get to step #4, instead of pressing Diagnose, select Properties
    List everything that appears under: The connection uses the following items:
    Verify that Internet Protocol Version 4 (TCP/IPv4) is in this list.
    Then double-click Internet Protocol Version 4 (TCP/IPv4) to view these properties.
    Let me know which bullets are selected in the Networking and Sharing tabs.
    Hint: There should be 3 total.
     
    Last edited: Apr 7, 2012
  41. kthrone

    kthrone Private E-2

    Also tried the service pack uninstall with the command prompt method. Recieved a WUSA installer error "installer encountered an error: 0x80073701
    The reference assembly could not be found."

    In device manager 3 items have a yellow exclamation. -

    TouchChip Fingerprint Coprocessor (WBF advanced mode)
    Bluetooth AV source
    Bluetooth Peripheral Device

    none of which I really use/know what they are.
     
  42. kthrone

    kthrone Private E-2

    Under "connection uses the following terms" there all these 6 items, all of which are checked. -

    QoS Packet Scheduler
    File and Printer Sharing for Microsoft Networks
    Internet Protocol Version 6 (TCP/IPv6)
    Internet Protocol Version 4 (TCP/IPv4)
    Link-Layer Topology Discovery Mapper I/O Driver
    Link-Layer Topology Discovery Responder

    Nothing is checked in the Sharing tab.

    In IPv4 Obtain IP address and also Obtain DNS server automatically is checked. (DHCP) In alternate config. Automatic Private IP address is checked.
     
  43. thisisu

    thisisu Malware Consultant

    Client for Microsoft Networks is not in the list? - Please doublecheck
    If it's not, we'll need to reinstall that.
     
  44. kthrone

    kthrone Private E-2

    Client for Microsoft Networks is nowhere to be found.
     
  45. thisisu

    thisisu Malware Consultant

    Hmm.. by default it should be listed. It's worth a try...

    • When you are viewing that list, there should be 3 buttons:
      • Install...
      • Uninstall
      • Properties
    • Click the Install... button
    • Now select Client
    • If "Client for Microsoft Networks" appears, choose to install it.
    • Press OK
    • Press OK again to exit the network properties.
    • Reboot.

    --

    Once you have rebooted, if internet is still not working:

    Let me know what output you receive from typing in the two commands below from a DOS Command Prompt window with Administrative privileges:
    • ipconfig /release
    • ipconfig /renew
     
  46. kthrone

    kthrone Private E-2

    Installed the Client for Microsoft Networks and rebooted, same issue still.

    ipconfig /release -
    An error occurred while releasing interface Wireless Network Connection 2 : An address has net yet been associated with the network endpoint

    Local Area Connection, Bluetooth Network Connection, and Wireless Network Connection 4 all have their media disconnected.

    ip config /renew -
    An error has occurred while renewing interface Wireless Network Connection 2 : An address incompatible with the requested protocol was used.

    Local Area Connection, Bluetooth Network Connection, and Wireless Network Connection 4 all have their media disconnected.
     
  47. thisisu

    thisisu Malware Consultant

  48. kthrone

    kthrone Private E-2

    Ok, tried all of those suggestions. The SFC scan said it found a few errors and removed them, I attached the logs incase. Still no internet for some reason, I am completely stumped. I can't thank you enough for all of your help today!
     
  49. thisisu

    thisisu Malware Consultant

    http://img825.imageshack.us/img825/2648/hjt.gif Run C:\MGtools\analyse.exe by double-clicking it (Vista/7 right-click and select Run as Administrator)
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Choose "Do a system scan only" and select the following lines but do not click fix until you exit all explorer windows and all browser sessions including the one you are reading in right now:

    O18 - Protocol: qcom - {B8DBD265-42C3-43E6-B439-E968C71984C6} - (no file)

    After clicking Fix, exit out of Trend Micro HiJackThis - v2.0.4 and reboot your computer.

    __

    http://img17.imageshack.us/img17/3214/baticonvista7.gif Now run C:\MGtools\GetLogs.bat by right-mouse clicking it and then selecting Run as Administrator
    This updates all of the logs inside MGlogs.zip.
    When it is finished, attach C:\MGlogs.zip to your next message. (How to attach)
     
  50. kthrone

    kthrone Private E-2

    Analyse.exe ran and protocol: qcom fixed. New MGLogs attached.
     

    Attached Files:


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds