Author Topic: Win32.DNSChanger VJ.Trj VIRUS INFECTION: IMMEDIATE HELP REQUIRED  (Read 23478 times)

0 Members and 1 Guest are viewing this topic.

MikeMello

  • Guest
Re: Win32.DNSChanger VJ.Trj VIRUS INFECTION: IMMEDIATE HELP REQUIRED
« Reply #60 on: December 27, 2011, 05:55:39 PM »
The FixIt applied fixed but was not able to start the Windows Firewall.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32.DNSChanger VJ.Trj VIRUS INFECTION: IMMEDIATE HELP REQUIRED
« Reply #61 on: December 27, 2011, 07:29:50 PM »
OK further investigation for this error by some of my malware collegues has found a possible cause and solution (courtesy RKinner)

This will mean going into the registry manually as we have not yet developed an autofix

Go into regedit, (Start, Search, regedit, doubleclick on the regedit that it finds, Continue)
Navigate to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services (Find HKEY_LOCAL_MACHINE\SYSTEM and click on the + in front of it.
Find CurrentControlSet and click on its plus.
Click on Services
Then right click on Services and select Permissions then click Add.
Type in:

NT Service\bfe and click on Check Name. (It will change your typing to BFE )

OK. You should be back on the first Permissions page.
Now select BFE on the permission page and click on the first box to the right of Full Control (Allow column).
Then Apply.
Reboot and go back into Services and see if BFE is running.

MikeMello

  • Guest
Re: Win32.DNSChanger VJ.Trj VIRUS INFECTION: IMMEDIATE HELP REQUIRED
« Reply #62 on: December 27, 2011, 08:44:06 PM »
after reboot, i had to manually start BFE. Once it started, i checked to see if i can turn on the windows firewall and i still can not turn on firewall

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32.DNSChanger VJ.Trj VIRUS INFECTION: IMMEDIATE HELP REQUIRED
« Reply #63 on: December 27, 2011, 08:48:09 PM »
Darn - ok back to the drawing board on this one