Author Topic: New Virus?  (Read 25051 times)

0 Members and 1 Guest are viewing this topic.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: New Virus?
« Reply #75 on: September 27, 2011, 05:09:30 PM »
OK this does not appear to make any sense so I will do some deeper research

RoughDobermann

  • Guest
Re: New Virus?
« Reply #76 on: September 27, 2011, 05:12:05 PM »
Under the Dependencies tab in DHCP Client Properties,  I now have:

AFD
TCP/IP Protocol Driver

But no NetBT

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: New Virus?
« Reply #77 on: September 27, 2011, 05:18:00 PM »

Could you type the following in the run box pleae and let me know what the output is

CMD /K SC QC DHCP

It should be this

Quote
[SC] GetServiceConfig SUCCESS

SERVICE_NAME: dhcp
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\WINDOWS\system32\svchost.exe -k netsvcs
LOAD_ORDER_GROUP : TDI
TAG : 0
DISPLAY_NAME : DHCP Client
DEPENDENCIES : Tcpip
: Afd
: NetBT
SERVICE_START_NAME : LocalSystem

RoughDobermann

  • Guest
Re: New Virus?
« Reply #78 on: September 27, 2011, 05:18:50 PM »
There is no data listed under DependOnGroup.  No idea if that is helpful!

RoughDobermann

  • Guest
Re: New Virus?
« Reply #79 on: September 27, 2011, 05:21:46 PM »
Yes mine is the same

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: New Virus?
« Reply #80 on: September 27, 2011, 05:38:38 PM »
Darn this is where I could do with an XP machine so that I could export that set of registry entries for you

Now  do the following

Click Start, Run and type DEVMGMT.MSC
In the View menu, click Show hidden devices
Double-click Non-Plug and Play drivers section
Double-click the entry AFD, and click the Driver tab
Set the Startup type to System.
Start the service. Note down the error message if any.
Similarly start the two other drivers namely:
TCP/IP Protocol Driver
NetBios over Tcpip

Close Device Manager and restart Windows.

Then run Regedit via the run key

Navigate to HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ Dhcp
Right click the DependOnService select modify (shot 1)
Ensure that in the box that shows that you have the following entries (or add them) (shot 2 )

RoughDobermann

  • Guest
Re: New Virus?
« Reply #81 on: September 27, 2011, 05:46:39 PM »
Afd and tcip both started.  There is no entry for netbios under dm, nonplugandplay!  It's not there!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: New Virus?
« Reply #82 on: September 27, 2011, 05:53:20 PM »
Is the registry entry the one in your post if so I will export mine (XP Pro SP3) ?

See image extract of the key on my system.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

RoughDobermann

  • Guest
Re: New Virus?
« Reply #83 on: September 27, 2011, 05:54:28 PM »
I looked for netbt.sys under windows/system32/drivers and it IS there.  Shod I go to another xp machine copy it's netbt file and put it on mine?  There's a win 7 mChine downstairs

RoughDobermann

  • Guest
Re: New Virus?
« Reply #84 on: September 27, 2011, 05:57:31 PM »
Yes mine looks identical

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: New Virus?
« Reply #85 on: September 27, 2011, 05:59:23 PM »
Aye the file is there and it is a good copy, that was the one I replaced earlier

Go to control panel
Open the Network Connections folder.
Right click the local area network connection and click Properties.
Double click Internet Protocol (TCP/IP).
Click Advanced.
Click WINS.
Click the Enable NetBIOS Over TCP/IP button.

RoughDobermann

  • Guest
Re: New Virus?
« Reply #86 on: September 27, 2011, 06:09:59 PM »
Ok enabled netbios on both LAN and wireless connections.  Rebooted and no Internet.  Netbt not shown under dependencies

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: New Virus?
« Reply #87 on: September 27, 2011, 06:11:26 PM »
@ essexboy
I have that enabled, part of the default setting, see image and works fine on my system.
« Last Edit: September 27, 2011, 06:13:09 PM by DavidR »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: New Virus?
« Reply #88 on: September 27, 2011, 07:33:33 PM »
OK back into the registry to ensure that the path is set correctly

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBT
check that the image path is set at system32\drivers\netbt.sys

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBIOS]
check that the image path is set at system32\drivers\netbios.sys

RoughDobermann

  • Guest
Re: New Virus?
« Reply #89 on: September 27, 2011, 08:53:08 PM »
That worked, mostly!   Netbios still seems funny.  Dns works but not for wins resolution?