http://support.gatew...=1&modelId=3250
TrojanDownloader:win32/Unruy.H
Started by
Steven Gottlieb
, Mar 02 2012 01:13 PM
#61
Posted 09 March 2012 - 08:01 PM
#62
Posted 09 March 2012 - 09:52 PM
Ok, I found two additions under network adapters (RAS Async Adapter and microsoft tv/video connection) and neither one could be uninstalled--needed for boot.
I downloaded the chipset but do not know which files to install. I also think the chipset is for windows 7 and I have xp.
Thank you.
I downloaded the chipset but do not know which files to install. I also think the chipset is for windows 7 and I have xp.
Thank you.
Edited by Steven Gottlieb, 09 March 2012 - 10:03 PM.
#63
Posted 10 March 2012 - 12:14 AM
It say it is for all OS so go ahead and install the chipset driver. It should contain your network driver.
#64
Posted 10 March 2012 - 09:28 AM
There were many installation software. I tried them all. Some installed some said wrong OS. I still have the same problem.
I appreciate your support.
Thank you,
S
I appreciate your support.
Thank you,
S
#65
Posted 10 March 2012 - 12:51 PM
Pick one of the drivers and do solution 1 on this page
http://thetechcorner...p-the-computer/
BUT instead of deleting the driver, right click on it and Export it to your desktop. Call it "baddriver" then close regedit, right click on baddriver.reg and EDIT. Copy and paste to a reply.
Ron
http://thetechcorner...p-the-computer/
BUT instead of deleting the driver, right click on it and Export it to your desktop. Call it "baddriver" then close regedit, right click on baddriver.reg and EDIT. Copy and paste to a reply.
Ron
#66
Posted 10 March 2012 - 08:14 PM
Ron,
Here is the file you requested (WAN Miniport (PPTP)
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_PPTPMINIPORT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_PPTPMINIPORT\0000]
"ClassGUID"="{4D36E972-E325-11CE-BFC1-08002BE10318}"
"Class"="Net"
"HardwareID"=hex(7):6d,00,73,00,5f,00,70,00,70,00,74,00,70,00,6d,00,69,00,6e,\
00,69,00,70,00,6f,00,72,00,74,00,00,00,00,00
"Driver"="{4D36E972-E325-11CE-BFC1-08002BE10318}\\0003"
"LowerFilters"=hex(7):4e,00,64,00,69,00,73,00,54,00,61,00,70,00,69,00,00,00,00,\
00
"Mfg"="Microsoft"
"Service"="PptpMiniport"
"DeviceDesc"="WAN Miniport (PPTP)"
"ConfigFlags"=dword:00000000
"Capabilities"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_PPTPMINIPORT\0000\Device Parameters]
"InstanceIndex"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_PPTPMINIPORT\0000\LogConf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_PPTPMINIPORT\0000\Control]
"ActiveService"="PptpMiniport"
Here is the file you requested (WAN Miniport (PPTP)
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_PPTPMINIPORT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_PPTPMINIPORT\0000]
"ClassGUID"="{4D36E972-E325-11CE-BFC1-08002BE10318}"
"Class"="Net"
"HardwareID"=hex(7):6d,00,73,00,5f,00,70,00,70,00,74,00,70,00,6d,00,69,00,6e,\
00,69,00,70,00,6f,00,72,00,74,00,00,00,00,00
"Driver"="{4D36E972-E325-11CE-BFC1-08002BE10318}\\0003"
"LowerFilters"=hex(7):4e,00,64,00,69,00,73,00,54,00,61,00,70,00,69,00,00,00,00,\
00
"Mfg"="Microsoft"
"Service"="PptpMiniport"
"DeviceDesc"="WAN Miniport (PPTP)"
"ConfigFlags"=dword:00000000
"Capabilities"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_PPTPMINIPORT\0000\Device Parameters]
"InstanceIndex"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_PPTPMINIPORT\0000\LogConf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\MS_PPTPMINIPORT\0000\Control]
"ActiveService"="PptpMiniport"
#67
Posted 13 March 2012 - 09:41 PM
Ron,
Sorry to say but it did not work. The log is below. I did restore the registry. I bet you already know this but here is something I observed-In services, although DHCP client is set to automatic it does not start automatically. If I wait until the computers icon appear in the lower right hand side and click on to start the dhcp client in service then I get internet service. I never get internet service until the computers icon appear in the lower right hand side even using command prompt--command prompt freezes until the computers appears.
Thank you,
Steven
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_11162277\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_14860170\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_24658365\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_28328266\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_29571358\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_LMIGUARDIANSVC\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_LMIMAINT\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_LMIRFSCLIENTNP\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_LMIRFSDRIVER\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_LOGMEIN\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles\Current\System\CurrentControlSet\SERVICES\LMImirr\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_38070743\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_38089730\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_38556024\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_48342036\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_58470934\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_60212291\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_64561889\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_66290607\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_67228322\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_75444467\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_86485895\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_89825617\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_91523719\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_97059967\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ASP.NET_2.0.50727\Names\\qKhFyCkVTDLbPRulszVXxE6E8W6FilmiFk32PzURqTlKotqWpjBmax0aGWSyeoR8GE2aD5SI0eDnPAmwD4p9wu7mBAv6qV9dGA9syfYxp9nEWG3xdIMFGL deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\LogMeIn\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\LogMeIn Guardian\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lmimirr\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LMIRfsClientNP\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LMIRfsDriver\ deleted successfully.
========== COMMANDS ==========
[EMPTYJAVA]
User: Administrator
User: All Users
User: Default User
User: LocalService
User: LogMeInRemoteUser
User: Math On DVDs
->Java cache emptied: 0 bytes
User: NetworkService
User: UpdatusUser
Total Java Files Cleaned = 0.00 mb
[EMPTYFLASH]
User: Administrator
User: All Users
User: Default User
User: LocalService
User: LogMeInRemoteUser
User: Math On DVDs
->Flash cache emptied: 662 bytes
User: NetworkService
->Flash cache emptied: 0 bytes
User: UpdatusUser
Total Flash Files Cleaned = 0.00 mb
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
OTL by OldTimer - Version 3.2.34.0 log created on 03132012_231521
Sorry to say but it did not work. The log is below. I did restore the registry. I bet you already know this but here is something I observed-In services, although DHCP client is set to automatic it does not start automatically. If I wait until the computers icon appear in the lower right hand side and click on to start the dhcp client in service then I get internet service. I never get internet service until the computers icon appear in the lower right hand side even using command prompt--command prompt freezes until the computers appears.
Thank you,
Steven
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_11162277\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_14860170\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_24658365\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_28328266\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_29571358\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_LMIGUARDIANSVC\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_LMIMAINT\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_LMIRFSCLIENTNP\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_LMIRFSDRIVER\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_LOGMEIN\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles\Current\System\CurrentControlSet\SERVICES\LMImirr\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_38070743\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_38089730\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_38556024\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_48342036\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_58470934\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_60212291\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_64561889\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_66290607\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_67228322\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_75444467\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_86485895\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_89825617\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_91523719\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_97059967\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ASP.NET_2.0.50727\Names\\qKhFyCkVTDLbPRulszVXxE6E8W6FilmiFk32PzURqTlKotqWpjBmax0aGWSyeoR8GE2aD5SI0eDnPAmwD4p9wu7mBAv6qV9dGA9syfYxp9nEWG3xdIMFGL deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\LogMeIn\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\LogMeIn Guardian\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lmimirr\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LMIRfsClientNP\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LMIRfsDriver\ deleted successfully.
========== COMMANDS ==========
[EMPTYJAVA]
User: Administrator
User: All Users
User: Default User
User: LocalService
User: LogMeInRemoteUser
User: Math On DVDs
->Java cache emptied: 0 bytes
User: NetworkService
User: UpdatusUser
Total Java Files Cleaned = 0.00 mb
[EMPTYFLASH]
User: Administrator
User: All Users
User: Default User
User: LocalService
User: LogMeInRemoteUser
User: Math On DVDs
->Flash cache emptied: 662 bytes
User: NetworkService
->Flash cache emptied: 0 bytes
User: UpdatusUser
Total Flash Files Cleaned = 0.00 mb
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
OTL by OldTimer - Version 3.2.34.0 log created on 03132012_231521
#68
Posted 14 March 2012 - 01:02 AM
See if you can turn off netbios. That might speed things up a bit:
http://www.petri.co....w2k_xp_2003.htm
I have an idea for a work-around. Start, Run, services.msc, OK. Find DHCP client and right click and select Properties. Click on the Recovery Tab. Next to First Failure, change it from Take No Action to Restart the Service. Restart Service after should say: 1
Apply and restart. It should restart the DHCP client if it fails because AFD is not ready so hopefully we will get an IP address assigned without having to use the cmd.
http://www.petri.co....w2k_xp_2003.htm
I have an idea for a work-around. Start, Run, services.msc, OK. Find DHCP client and right click and select Properties. Click on the Recovery Tab. Next to First Failure, change it from Take No Action to Restart the Service. Restart Service after should say: 1
Apply and restart. It should restart the DHCP client if it fails because AFD is not ready so hopefully we will get an IP address assigned without having to use the cmd.
#69
Posted 14 March 2012 - 10:10 AM
Ron,
I found DHCP client stopped after doing what you requested.
Steven
I found DHCP client stopped after doing what you requested.
Steven
#70
Posted 14 March 2012 - 05:08 PM
Go back into Services and try setting the 2nd and 3rd time boxes to restart too.
Also we can try a bat file:
Copy the next line:
net start dhcp
Then open notepad (Start, Run, notepad, OK) and paste in the text (Edit, Paste) then File, Save as, to your desktop
"dhcp.bat" (Make sure you include the quotation marks)
Close notpad. Find dhcp.bat and copy it then right click on Start and select Explore All Users.
It should open in Start Menu. Under Start Menu should be Programs. Click on the + in front of Programs and then click on Startup. In the right pane, right click and Paste.
Close Explorer and restart.
Also we can try a bat file:
Copy the next line:
net start dhcp
Then open notepad (Start, Run, notepad, OK) and paste in the text (Edit, Paste) then File, Save as, to your desktop
"dhcp.bat" (Make sure you include the quotation marks)
Close notpad. Find dhcp.bat and copy it then right click on Start and select Explore All Users.
It should open in Start Menu. Under Start Menu should be Programs. Click on the + in front of Programs and then click on Startup. In the right pane, right click and Paste.
Close Explorer and restart.
#71
Posted 14 March 2012 - 06:14 PM
Ron,
Very interesting trick. Does it work-well yes and no. Before this last request of yours I could start up my computer and open up the command prompt and type net start dhcp and nothing would happen for about two minutes. As soon as the computers appear on the lower hand hand corner then the command prompt starts the dhcp client. Now after doing what you last asked me to do, it is basically the same except that the command prompt opens automatically and already has 'net start dhcp' typed in. After 2 minutes the internet works.
Can I remove the dhcp.bat file from my desktop?
Thanks,
Steven
Very interesting trick. Does it work-well yes and no. Before this last request of yours I could start up my computer and open up the command prompt and type net start dhcp and nothing would happen for about two minutes. As soon as the computers appear on the lower hand hand corner then the command prompt starts the dhcp client. Now after doing what you last asked me to do, it is basically the same except that the command prompt opens automatically and already has 'net start dhcp' typed in. After 2 minutes the internet works.
Can I remove the dhcp.bat file from my desktop?
Thanks,
Steven
#72
Posted 14 March 2012 - 07:21 PM
Yes. IF you go back into the dhcp.bat with notepad and put an Enter after the net start dhcp and save it then it should work on its own.
#73
Posted 14 March 2012 - 08:42 PM
Ron,
I tried what you suggested because you asked me to but I did not think it would work and it didn't. Here is what happens regardless of whether I go to the command prompt and type in net start dhcp enter or if the computer does it automatically--computer is started and command prompt opens (by me or automaticaly)and net start dhcp along with enter is there (if manually, then of course I typed it in), now the cursor is blinking (so it is not frozen??) but nothing happens with the cp until two to three minutes later when the computer tries to acquire an ip address (when the little computers appears in the corner)and within seconds the dhcp according to the cp is now running and the internet is running.
I'm sorry that you are having a hard time with this.
Thank you,
Steven
I tried what you suggested because you asked me to but I did not think it would work and it didn't. Here is what happens regardless of whether I go to the command prompt and type in net start dhcp enter or if the computer does it automatically--computer is started and command prompt opens (by me or automaticaly)and net start dhcp along with enter is there (if manually, then of course I typed it in), now the cursor is blinking (so it is not frozen??) but nothing happens with the cp until two to three minutes later when the computer tries to acquire an ip address (when the little computers appears in the corner)and within seconds the dhcp according to the cp is now running and the internet is running.
I'm sorry that you are having a hard time with this.
Thank you,
Steven
#74
Posted 14 March 2012 - 09:26 PM
It sounds terribly slow starting up.
Start Run, msconfig, OK
Go to Services tab and click on the box to hide Microsoft Services then uncheck
everything that remains. Go to Startup tab and uncheck everything. OK and
reboot. If it doesn't run faster then go back into msconfig and recheck the
things you turned off. If it helps then go back and turn on a few items each
time until you find the culprit.
Start Run, msconfig, OK
Go to Services tab and click on the box to hide Microsoft Services then uncheck
everything that remains. Go to Startup tab and uncheck everything. OK and
reboot. If it doesn't run faster then go back into msconfig and recheck the
things you turned off. If it helps then go back and turn on a few items each
time until you find the culprit.
#75
Posted 14 March 2012 - 09:35 PM
Ron,
Same two plus minute delay.
Thank you,
Steven
Same two plus minute delay.
Thank you,
Steven
Similar Topics
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users