Vista Security 2012

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by masannes, Dec 29, 2011.

  1. masannes

    masannes Private E-2

    big troubles i can not get online with computer with problem have tried to install melwarebytes but can not update the newer files. any suggestions on this problem
     
  2. thisisu

    thisisu Malware Consultant

  3. masannes

    masannes Private E-2

    here is the file you requested
    hope this will help
     

    Attached Files:

    • FSS.txt
      File size:
      4.7 KB
      Views:
      14
  4. thisisu

    thisisu Malware Consultant

    http://img805.imageshack.us/img805/9659/rktigzy.gif Please download RogueKiller by Tigzy to your desktop.

    Rename RogueKiller.exe to winlogon.exe
    Double-click winlogon.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the number "2" and press ENTER.
    When it is finished -- Notepad will open with the report and the log is saved to your desktop.
    Attach RKreport[1].txt to your next message. (How to attach)
    You can now type the number "0" and press ENTER to exit RogueKiller.

    http://img843.imageshack.us/img843/5891/erunt.gif Backup Your Registry with ERUNT

    • Please download Erunt
    • Run the setup program to install ERUNT on your computer
    Click Erunt.exe to backup your registry to the folder of your choice.
    This is to be used only in emergency scenarios.

    There may be too much malware that will prevent this fix but try the below in an attempt to get your internet up and running.

    http://img406.imageshack.us/img406/3189/windowsrepair.gif Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now open Repair_Windows.exe
    • Go to Start Repairs tab.
    • Choose "Custom Mode" and press "Start".
    • Create a System Restore point if prompted.
    • In the Custom Mode window, select the following repair options:
      • Reset Registry Permissions
      • Register System Files
      • Repair WMI
      • Repair Internet Explorer
      • Repair Hosts File
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Unhide Non System Files
      • Set Windows Services To Default Startup
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • If asked to reboot the computer for the changes to take affect, make sure other tasks in the program are not still running before accepting to restart.

    ========WARNING========
    The below is specifically for masannes's computer
    Do NOT run the below if you are not masannes
    Doing so may damage your PC!
    ========WARNING========

    Attached is nsi+nsiproxy.zip

    Inside is:
    • nsiproxy.reg
    • nsi.reg
    • fixme+restart.bat

    Extract all 3 files to the infected computer's desktop.

    The sequence of events below is important. Do them in the order as they are typed here. Stop if you run into a problem or if you have any questions

    First double-click nsiproxy.reg and allow it to merge into the registry. Let me know if it merged successfully or not.

    If it did not, STOP here and let me know.
    ____________________________________________

    If it did merge successfully, continue on...

    Now double-click nsi.reg and allow it to merge into the registry. Let me know if it merged successfully or not.

    If it did not, STOP here and let me know.
    ____________________________________________

    If it did merge successfully, continue on...

    Now reboot your PC.

    Once you have rebooted...

    Test your internet, If it still is not working, run the fixme+restart.bat file by double-clicking it.
    Your PC will reboot again. Once you are back in Windows, test your internet again.

    If the internet is still not working, attach the fixme_results.txt file on your desktop.
     

    Attached Files:

    Last edited: Dec 29, 2011
  5. masannes

    masannes Private E-2

    looking better but still no internet
     

    Attached Files:

  6. thisisu

    thisisu Malware Consultant

    Sorry I gave you some incorrect instructions on how to run the fixme+restart.bat file.

    I want you to run it by right-mouse clicking it once and then selecting "Run as Administrator" from additional menu that appears.

    Do this now and then attach:
    • RKreport[1].txt <--- From RogueKiller
    • fixme_results.txt

    I take it you did not have any issues merging those registry (.reg) files into the Windows registry?
     
  7. masannes

    masannes Private E-2

    found the final problem was in the network protocol Version 4 (TCP/IPv4) had to change to obtain an IP address automatically

    thanks for all your help
     
  8. thisisu

    thisisu Malware Consultant

    Good job :)

    If you need further assistance follow this guide: READ & RUN ME FIRST Malware Removal Guide
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds